Madrid · Domestic and International Service info@imts.es
ES / EN / PT
Independent Internal Audit

Independent internal audit
for your ICT systems
and physical security.

An internal audit of ICT systems and physical security is the mechanism that allows your organization to determine, with certainty and objective evidence, whether its management system actually works or exists only on paper. It is a specialized service performed by independent professionals, with a level of impartiality that no internal team can guarantee for itself.

GUIDE
ISO 19011
SCAMS
27001 · ENS · TISAX · 22301 · 20000
FREQUENCY
Annual minimum
Scope
ICT + Physical Security
Much more than just a requirement

Reducing it to a mere formality is one of the most costly mistakes.

All relevant ICT standards—ISO 27001, ENS, TISAX, ISO 22301, ISO 20000—require periodic internal audits as part of the continuous improvement cycle. It is a formal requirement. But reducing the internal audit to a mere compliance formality is one of the most common and costly mistakes organizations make.

A well-executed internal audit allows you to: detect actual gaps between documented procedures and actual practice; identify unanticipated risks that have emerged over time; verify the actual effectiveness of controls, not just their formal existence; anticipate findings that the external auditor will uncover, allowing time to correct them; demonstrate the actual status to management with objective evidence; and fuel the cycle of continuous improvement required by all standards.

An organization that does not conduct rigorous internal audits does not improve. It keeps its shortcomings hidden until they are uncovered by an external auditor, a client, or an incident.
Why the auditor must be independent

A structural condition, not a preference.

This is the fundamental principle—and, at the same time, the one most frequently ignored—when organizations attempt to address compliance using their own resources.

An auditor cannot audit their own work. Not because of a lack of technical knowledge, but because the absence of independence inevitably skews the process: what is reviewed, how findings are interpreted, what is documented as a finding, and what is overlooked. This is not necessarily intentional. It is an inherent limitation that standards recognize and require to be mitigated.

ISO 19011 clearly states that auditors must be objective and independent of the activity they are auditing. ISO/IEC 27001, ENS, TISAX, ISO 22301, and ISO 20000 explicitly state this.

Situations in which independence is compromised: the system manager audits controls that he or she has designed; the IT department audits its own processes; the security manager reviews his or her own plan; a consultant who participated in the implementation later conducts the internal audit.

Why Impartial

Formal independence isn't enough. We need to go one step further.

An ICT systems auditor may be formally independent—having not participated in the audited activity—and yet still lack impartiality if they have a stake in the outcome.

An impartial auditor: has no interest in the outcome being favorable or unfavorable; does not tailor their conclusions to what management wants to hear; does not formulate findings based on personal relationships with those being audited; documents what they find, not what is convenient to document; applies the same criteria regardless of department, position, or seniority.

Impartiality is especially critical in small and medium-sized organizations, where personal relationships between the internal auditor and those being audited are inevitably closer. In that context, an independent external auditor is not a luxury option: it is the only way to ensure reliable results.

An audit that doesn't cause any discomfort, doesn't yield any significant findings, and is met with calm acceptance by everyone is probably not a good audit.
Services

Six specialized audit lines.

01

ISO 27001 Internal Audit

Review of the ISMS in accordance with ISO/IEC 27001 and its Annex A. Verification of the effectiveness of controls, compliance with policies, risk management, incident handling, and management review.

02

ENS Internal Audit

Review of compliance with the ENS in accordance with Royal Decree 311/2022 and CCN-STIC guidelines. Verification based on system category (basic, medium, high), gap analysis, and report in the required format.

03

TISAX Internal Audit

Review in accordance with the VDA ISA questionnaire and TISAX assessment criteria. Preparation for the official assessment by an ENX-accredited provider.

04

ISO 22301 Internal Audit

Review of the SGCN. Verification of continuity plans, BIAs, drills and tests, and actual response capability in the event of an outage.

05

ISO 20000 Internal Audit

Review of the SMS in accordance with ISO/IEC 20000-1. Verification of delivery and support processes, incident management, change management, service levels, and continuous improvement.

06

Physical Security Audit

Independent review of physical access control, CCTV, intrusion detection, environmental protection, and procedures. Physical and logical security are inseparable.

How We Conduct the Audit

Seven phases. Complete traceability, objective evidence.

01

Planning

Scope, criteria, timeline, and areas to be reviewed.

02

Literature Review

Analysis of policies, procedures, records, and risks.

03

Field Audit

Interviews, direct observation, verification of evidence.

04

Analysis and Classification

Major nonconformities, minor nonconformities, observations.

05

Audit Report

Reference document for management.

01

Presentation of Results

Closing meeting with management and team leaders.

02

Follow-up (optional)

Verification of the resolution of nonconformities and the effectiveness of corrective actions.

Who is this service for?

Organizations that need real independence, not just nominal independence.

Certified through a mandatory audit In the process of certification SMEs with limited IT resources Where the system and IT are the same people Automotive Suppliers (TISAX) ENS Administration and Suppliers Following significant external findings Physical Security Validation
An inalienable principle

We audit what we implement.

This is one of the structural decisions that defines how IMTS operates and that it applies without exception, regardless of the project, the client, or the urgency.

What this means for you:

  • If IMTS has implemented a system in your organization, another independent provider must audit it.
  • If you want IMTS to conduct the audit, hire a different provider to handle the implementation.
  • We do not combine consulting and implementation services with an audit of the same system within the same organization.
  • The reason: that combination is incompatible with the independence required by the standard and that we guarantee to our clients.
  • A report with no relevant findings raises suspicions contrary to what is intended. A good auditor finds things. A bad auditor does not.
True independence

We don't audit what we implement. That distinction defines the quality of every report we deliver.

IMTS is not committed to selling a one-time service. It is committed to being a reliable and specialized partner in security, compliance, and intelligence. Fifteen years of supporting companies and public agencies back this up.

Do you need an independent internal audit?

Tell us about your situation. We'll get back to you within 48 hours.

To schedule an initial meeting at no cost and with no obligation. Complete discretion from the very first contact.

EMAIL info@imts.es
WEB www.imts.es/en
Seats Madrid · Domestic and International Service
Request a meeting →
IMTS's internal audits are conducted in accordance with the principles of ISO 19011—Guidelines for Auditing Management Systems—and the specific requirements of each standard being audited.