Agree
Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.
Internal audit / New Zealand
Aegentra conducts scoped ISO 27001 internal audits for New Zealand organisations. We evaluate the agreed management-system criteria and evidence, including scope, risk treatment and operating controls, and report findings and follow-up needs.
Start with the boundary
For organisations preparing or maintaining a ISMS, fulfilling an internal-audit programme or needing an objective review of information security evidence.
An internal audit is not a certification audit or a guarantee of certification. Auditor assignments require impartiality checks; we do not present review of our own implementation work as independent assurance.
What the engagement can produce
Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.
How we work
Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.
Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.
Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.
Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.
We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.
An illustrative starting point
Fictional example to explain the service, not a New Zealand client case study or a promised outcome.
An ISMS risk treatment is marked complete, but the selected records do not show that the control operated. The audit distinguishes documented intent from evidence and reports the resulting gap.
Before you begin
Auditor objectivity and impartiality must be protected. Before accepting an internal-audit scope, we check responsibilities and potential conflicts. Implementation and audit assignments cannot simply be treated as interchangeable; another suitably competent and impartial resource may be needed.
The agreed scope can include audit objectives, ISMS boundary and the applicable standard edition; auditor competence, conflicts and impartiality checks; risk-based sampling of scope, risk treatment and operating controls; findings, conclusions and agreed corrective-action follow-up. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.
Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.
We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.
Bring answers to these starting questions: Which ISMS activities, sites and period should the audit cover? What implementation work has already been performed, and by whom? Which prior findings or changes should inform the audit plan? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.
Reference points
Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.
Discuss your requirement
Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.