EXPERTISE

Compliance Audits and Assessments

Systematic compliance audits, security assessments, and maturity evaluations across GDPR, ISO 27001, NIS 2, SOC 2, and AI Act frameworks for organizations in regulated industries.

Section 01 · Assessment expertise

What separates an IT security audit from an opinion

A finding only means something relative to stated criteria. Before evidence is collected, an audit has to fix what it is measuring against — a regulation, a standard, a contract, or a documented internal requirement — and what falls inside the boundary. Assessments that skip that step produce observations that cannot be disputed or acted on, because nobody agreed in advance what "good" looked like.

ISO 19011:2018 sets seven principles for auditing management systems, and two of them do most of the work. The evidence-based approach means a conclusion must trace back to something verifiable — a record, a configuration, an observation, a test result — rather than to an assurance given in a meeting. Fair presentation means the report states what was found including obstacles, disagreements, and anything the audit could not reach.

The standard also distinguishes three audit types, and the distinction is commercial as much as technical. First-party audits are internal, run by or for the organisation itself. Second-party audits are conducted on suppliers or by customers. Third-party audits are performed by an independent body for certification. Up Secure works in the first two categories: internal audit on your behalf, and audits of your suppliers. Certification remains with an accredited body.

That separation is not a preference. Under clause 5.2.7 of ISO/IEC 17021-1, a certification body may not certify a management system it has provided consultancy on for at least two years after that consultancy ends. Choosing who prepares you and who certifies you is therefore a sequencing decision worth making early, because getting it wrong can delay a certificate by two years.

7
Auditing principles in ISO 19011:2018
3
Audit types: first, second and third party
2 years
Consultancy-to-certification separation
6
Framework criteria sets audited against
Criteria-led
Basis for every finding
What the auditing standard enumerates

Method and independence follow published auditing guidance rather than a private house style. Each cell represents one entry; point at a group to see its contents. Counts are the complete published sets.

ISO 19011:2018, clause 4

7 of 22
  • Integrity
  • Fair presentation
  • Due professional care
  • Confidentiality
  • Independence
  • Evidence-based approach
  • Risk-based approach
Section 02 · Assessment drivers

Why an independent assessment gets commissioned

An audit is usually bought because someone external will not take the organisation's word for it. A customer sends a security questionnaire that cannot be answered from memory, a certification body has scheduled a Stage 2, a supervisory authority has opened correspondence, or a board has asked whether the controls it approved two years ago still exist. In each case the value lies in the evidence trail rather than the conclusion, because the conclusion is what somebody else will re-test.

  1. 01 External assurance demand A customer, auditor, or regulator requires evidence that internal assertions alone will not satisfy. Strength 5 of 5
  2. 02 Certification readiness A gap analysis before Stage 1 costs less than a nonconformity raised during Stage 2. Strength 4 of 5
  3. 03 Documentation drift Policies describe a system that has been replaced, and only sampling against records will show where. Strength 4 of 5
  4. 04 Remediation prioritisation Structured findings separate foundational gaps from improvements that can wait a cycle. Strength 3 of 5
  5. 05 Supplier verification A second-party audit tests a vendor's claims where a completed questionnaire is not sufficient. Strength 2 of 5
Indicative strength on a 1–5 scale, based on Up Secure engagement patterns.
Organisations preparing for certification

A readiness audit surfaces nonconformities while they are still cheap to fix, and keeps the preparing party separate from the accredited body that will certify.

Buyers auditing their suppliers

Second-party audits give substance to the supply-chain obligations in NIS 2 Article 21(2)(d) and GDPR Article 28, where a returned questionnaire proves little.

Teams without an internal audit function

ISO 27001 clause 9.2 and ISO 42001 both require internal audit before certification, and it cannot be performed by the people who built the controls.

Section 03 · How Up Secure helps

Where you will get supported

The areas we work in, and where each one falls across the audit process. Remediation stays management's decision and is supported separately, so that the party assessing a control is not also the party that designed it. The services that deliver each area are listed further down.

Areas of support across the audit process
Audit support by process stage
Area of support ScopeEvidenceValidateReportFollow up
Planning
Criteria, boundary and sampling plan Covered during Scope Not covered during Evidence Not covered during Validate Not covered during Report Not covered during Follow up
Stakeholder and evidence request Covered during Scope Covered during Evidence Not covered during Validate Not covered during Report Not covered during Follow up
Compliance audit
GDPR compliance audit Covered during Scope Covered during Evidence Covered during Validate Covered during Report Not covered during Follow up
ISO 27001 and NIS 2 gap analysis Covered during Scope Covered during Evidence Covered during Validate Covered during Report Not covered during Follow up
AI governance and ISO 42001 review Covered during Scope Covered during Evidence Covered during Validate Covered during Report Not covered during Follow up
Technical validation
Penetration testing Not covered during Scope Covered during Evidence Covered during Validate Covered during Report Not covered during Follow up
Secure source code review Not covered during Scope Covered during Evidence Covered during Validate Covered during Report Not covered during Follow up
Secure SDLC and architecture audit Not covered during Scope Covered during Evidence Covered during Validate Covered during Report Not covered during Follow up
Maturity
Privacy and security maturity audit Covered during Scope Covered during Evidence Covered during Validate Covered during Report Not covered during Follow up
Reporting & follow-up
Findings, prioritisation and evidence re-check Not covered during Scope Not covered during Evidence Not covered during Validate Covered during Report Covered during Follow up
Section 04 · Related services

Audit and assessment services by subject area

The catalogue below groups the available audit and assessment services by subject, keeping regulatory, technical, and maturity work distinct. The distinction matters when scoping, because a compliance audit and a penetration test answer different questions and a scope that merges them usually answers neither well.

Data Protection (GDPR) for Business

If your organization processes personal data, GDPR obligations extend across every department. We help you close compliance gaps through audits, DPO outsourcing, privacy engineering, and targeted regulatory training for staff and management.

GDPR Compliance Audit

GDPR compliance audit covering Art.5–35 with gap matrix, RoPA assessment, DPA chain analysis, and remediation roadmap.

GDPR
Read more

AI System Privacy & Ethical Risk Audit

AI system audit covering data protection, ethical risks, bias assessment, and GDPR/AI Act compliance gaps.

AI ActISO 42001
Read more

Cybersecurity for Business

Your applications and infrastructure face threats that evolve faster than most teams can respond. We strengthen your posture through penetration testing, code reviews, SDLC audits, and cybersecurity training for engineering teams under NIS 2, ISO 27001, and SOC 2.

Secure Source Code Review

SAST and manual code review for Python/Django apps. Findings mapped to OWASP Top 10 and CWE with fix guidance.

NIS 2 DirectiveISO 27001
Read more

Web Application Penetration Testing

Web app penetration testing with OWASP methodology. Severity-scored findings and remediation guidance for Python/Django.

NIS 2 DirectiveISO 27001SOC 2
Read more

SOC 2 Compliance Services

SOC 2 compliance services — readiness assessment, controls design, evidence collection, and Type I/II audit support.

SOC 2
Read more

Software Engineering

AI-powered development accelerates delivery but introduces new attack vectors across the SDLC. We help teams secure AI-assisted workflows with architecture reviews, threat modeling, secure coding practices, SDLC security audits, and hands-on training.

Secure Source Code Review

SAST and manual code review for Python/Django apps. Findings mapped to OWASP Top 10 and CWE with fix guidance.

NIS 2 DirectiveISO 27001
Read more

GDPR Compliance Audit

GDPR compliance audit covering Art.5–35 with gap matrix, RoPA assessment, DPA chain analysis, and remediation roadmap.

GDPR
Read more

Web Application Penetration Testing

Web app penetration testing with OWASP methodology. Severity-scored findings and remediation guidance for Python/Django.

NIS 2 DirectiveISO 27001SOC 2
Read more

AI Governance and Compliance

Organizations adopting AI to boost productivity must ensure safe, fair, and compliant use. We provide EU AI Act and ISO 42001 advisory, risk classification, conformity assessments, governance implementation, and AI compliance training.

AI System Privacy & Ethical Risk Audit

AI system audit covering data protection, ethical risks, bias assessment, and GDPR/AI Act compliance gaps.

AI ActISO 42001
Read more

AI Act Compliance Audit

EU AI Act compliance audit — risk classification, gap analysis, and conformity assessment for AI systems.

AI ActISO 42001
Read more
Start the conversation

Scope an audit against criteria agreed before any evidence is collected.

The first conversation fixes what the audit measures against and what falls inside the boundary. That is what makes a finding disputable, actionable, and useful to the certification body or customer who reads it next — and it is the step that separates an audit from an opinion.

Why Up Secure
Independent by design We run first- and second-party audits. Certification stays with an accredited body, as clause 5.2.7 of ISO/IEC 17021-1 requires.
Evidence-based, per ISO 19011 Every conclusion traces back to a record, a configuration, an observation, or a test result rather than to an assurance given in a meeting.
Limits stated plainly The report says what was not examined and why, because the untested boundary is the first thing an experienced auditor looks for.
Section 05 · Frequently asked

Questions asked before an audit is scoped

No, and no consultancy can. ISO certification is issued only by a certification body accredited for the relevant standard, and SOC 2 reports only by a licensed CPA firm. Clause 5.2.7 of ISO/IEC 17021-1 goes further: a certification body may not certify a management system it has consulted on for at least two years afterwards. What we provide is readiness work, internal audit, and supplier audits — deliberately on the other side of that line.

A compliance audit measures evidence against fixed external criteria and concludes whether requirements are met. A maturity assessment examines how consistently and repeatably a capability operates across people, process, technology, and governance, and concludes where it sits on a scale. A scope can include both, but the conclusions must stay separate: an organisation can be fully compliant and operationally immature, or the reverse.

It follows the criteria. Typically policies and procedures, records showing that they were followed, system configuration, tickets and change records, logs, contracts, risk decisions and their approvals, plus interviews and demonstrations. Technical scopes add test results. The request is issued before collection begins so that gaps in availability are known rather than discovered mid-audit and mistaken for control failures.

Yes, and for many organisations that is the practical route. ISO 27001 clause 9.2 and the equivalent requirement in ISO 42001 both require internal audits at planned intervals, conducted by auditors who are objective and impartial about the area they examine. In a small team nobody meets that test internally, because the people who could audit the controls are the people who built them.

The scope and criteria, the evidence approach and sampling, findings separated from conclusions, the limitations of the work, and a link from each material finding to its risk and a practical recommendation. It should also record what could not be examined and why. A report that omits its own limits is less useful to a certification body, because the first thing an experienced auditor looks for is the boundary of what was actually tested.

Yes. Follow-up is the sixth stage of the ISO 19011 audit process and can range from clarifying a finding, through advising on remediation design, to re-testing agreed evidence. The follow-up scope should state which of those it is — advisory, limited verification, or a fresh audit — because they carry different weight with a customer or certification body.