Independent external auditing · ISO/IEC 27001 · ISO/IEC 42001 · ISO 22301

Independent audit services for ISO 27001, ISO 42001 and ISO 22301.

Attestware Systems provides internal audits, certification readiness audits, supplier audits and outsourced internal audit across information security, Artificial Intelligence (AI) governance and business continuity. Whether you need to meet the internal audit requirement of your standard, walk into your certification audit with no surprises, or give your board evidence it can rely on, you get a qualified independent auditor, a fixed price for an agreed scope, and a plain-English report that certification bodies, boards and customers accept.

What we audit

The standards we audit

We audit management systems: the policies, risk assessments, controls and records that a standard requires an organisation to run. Our focus is the three standards where demand for qualified, independent auditors is sharpest.

ISO/IEC 27001:2022

Information security

The international standard for an Information Security Management System (ISMS). We audit whether your ISMS actually operates as documented: risk treatment, control effectiveness, records and management commitment.

Clauses 4 to 10 · Annex A: 93 controls
ISO/IEC 42001:2023

AI governance

The first certifiable standard for an Artificial Intelligence Management System (AIMS). We audit how you govern the AI you build, buy and use: inventory, risk and impact assessments, lifecycle controls and human oversight.

Clauses 4 to 10 · Annex A: 38 controls
ISO 22301:2019

Business continuity

The international standard for a Business Continuity Management System (BCMS). We audit whether your continuity arrangements would actually hold in a disruption: business impact analysis, plans, exercising and recovery evidence.

Clauses 4 to 10 · Impact analysis · Exercising

Services

The audit services we offer

Plain-English findings, prioritised by risk, each with a practical corrective action. No jargon walls, no thirty-page preamble.

For certified & certifying organisations

Internal audits

Every certified organisation must audit its own management system under Clause 9.2, and the auditor must be impartial. We run your internal audit programme so you get a qualified, independent auditor without hiring one.

About internal audits →
Before certification

Readiness audits

A full dress rehearsal before your Stage 1 or Stage 2 certification audit, run with the same rigour the certification body will apply, so nothing they find is a surprise.

About readiness audits →
For your supply chain

Supplier and vendor audits

Independent evidence about the third parties who hold your data or embed AI in your products, in place of taking a questionnaire answer on faith.

About supplier audits →
For certification bodies

Contracted lead auditing

Lead Auditor capacity for accredited certification bodies running ISO/IEC 27001 and ISO/IEC 42001 programmes, including Stage 1 and Stage 2 assessments and surveillance visits.

For certification bodies →
For boards

AI governance health checks

A structured, evidence-based answer to the question boards are starting to ask: where does AI live in this organisation, and who is in control of it?

About AI health checks →
For EU obligations

EU AI Act alignment reviews

A mapping of your current practices against the European Union's AI Act obligations that apply to you, with the gaps stated plainly and ranked.

About AI Act reviews →

Beyond management systems

Outsourced internal audit

Internal audit is bigger than ISO. It is the independent, objective assurance function that tells a board whether risk is managed, controls work and governance holds. Most small and mid-sized organisations cannot justify an in-house internal audit team; we provide the function as a service, led by practitioners with a financial statement audit background, so the discipline of financial auditing carries into everything we examine. Explore outsourced internal audit →

  • I1 Risk-based audit plans An annual internal audit plan built from your actual risk register, agreed with the board or audit committee, not a template calendar.
  • I2 Internal control testing Design and operating effectiveness testing of the controls that matter: finance processes, access management, change management, vendor management.
  • I3 Governance and compliance reviews Independent review of how decisions are made, recorded and followed, and whether the organisation actually complies with the policies it has signed.
  • I4 Reporting people act on Findings ranked by risk, root causes named, corrective actions agreed with owners and dates, and follow-up until they close. Reported to the board, not buried in middle management.

Independence

Structural, not just promised

We only audit. No consultancy, no implementation, no selling you the fix. A firm that builds management systems cannot impartially judge them, so we chose one side of the table and we stay there.

We check for conflicts before every engagement. If any relationship or prior work could compromise impartiality on your audit, we tell you and step aside. One exception is all it takes to turn independence into a slogan, so there are no exceptions.

We never certify. Accredited certificates are issued only by accredited certification bodies. When we audit, you get findings and a recommendation; when we audit under contract to a certification body, their independent decision-maker makes the certification decision, as ISO/IEC 17021-1 requires.

Platform

Audits run on software we build ourselves

Compliance platforms have automated the auditee's side of the table. Almost nothing has been built for the auditor's side. We are building it: the Attestware platform is the tooling our own auditors work in. The principle behind it is simple. AI does not make audit judgements, the auditor does. What AI is genuinely good at is noticing, and an auditor who misses less builds a stronger, fairer case for the organisation being audited.

  • A1 Standardised planning, opening and closing Audit plans, opening and closing meetings and recurring interview questions run from refined templates, so every engagement starts from the discipline of all the ones before it.
  • A2 Interview intelligence Auditors walk into interviews with prepared questions, then deviate to pull on threads. That is exactly when things get missed, because human attention goes to one thread at a time. With consent, interviews are recorded and reviewed by AI against the standard and the evidence file: threads left hanging, answers that contradict a document, follow-up questions worth asking. The auditor decides what matters; the platform makes sure nothing goes unnoticed.
  • A3 Evidence by upload, not by questionnaire You upload the documents you already have: policies, logs, registers, reports. We extract what we need. We do not ask you to retype what a document already shows.
  • A4 Clause-by-clause working papers Every requirement of the standard is tracked from evidence request to conclusion, so nothing is skipped and every finding traces back to a clause, to evidence, and to what was said.
  • A5 Reports generated from the record Findings are logged with severity, owner and due date the moment they are raised, and the audit report is produced from the working papers themselves, so what you read is exactly what was tested.
  • A6 Strict client isolation Every organisation lives in its own secured partition. Your recordings, evidence and findings are never reviewed against, compared with or visible to any other client, and every access is logged.

Process

How an engagement runs

  1. Scoping call

    We establish which standard, which parts of your organisation, and what the audit is for: an internal audit obligation, certification readiness, or assurance for a customer or board. You get a fixed scope and a fixed price. If fieldwork later uncovers more than we scoped, we pause and agree the extension with you before any extra day is worked or billed; the price never changes without your sign-off.

  2. Audit plan and evidence requests

    You receive a plan naming what will be examined and who we need to speak to, plus a single evidence request list. Everything is uploaded once to the platform; nobody chases attachments over email.

  3. Fieldwork

    Interviews, evidence sampling and control testing, on site or remote. We test what actually happens, not what the policy says should happen.

  4. Report and closing meeting

    Findings are prioritised by risk, each with a plain-English explanation and a practical corrective action. We walk your team through every finding so nothing in the report is a surprise.

  5. Follow-up verification

    When corrective actions are done, we verify them and close the findings formally, so your next audit, or your certification body, starts from a clean, evidenced position.

Credentials

Qualified to the standard certification bodies apply

  • ISO/IEC 27001 Lead Auditor Certified Lead Auditor training completed with SEQM: audit planning, execution and reporting under ISO/IEC 17021-1, the standard that governs certification body audits.
  • ISO/IEC 42001 Lead Auditor Certified Lead Auditor training in the AI management system standard, at a time when qualified ISO/IEC 42001 auditors remain genuinely scarce.
  • Financial statement audit background Our practice is led by experience auditing financial statements, where materiality, evidence and professional scepticism are drilled in daily. That discipline carries into every management system audit we perform.
  • Practitioner background Our auditors come from building and operating production systems, including AI systems. We know where evidence lives and where problems hide, because we have owned both.

FAQ

Fair questions, straight answers

Can you certify us?

No. Only an accredited certification body can issue an accredited ISO certificate. What we do is everything around that moment: the internal audits the standard requires, the readiness audit before the certification body arrives, and, under contract to certification bodies, the lead auditing behind their certification decisions.

Will you help us fix what you find?

We explain every finding, agree practical corrective actions and verify them once done. What we will not do is design or implement the fix ourselves, because then we would be auditing our own work. For implementation help, you engage a consultancy of your choice; whoever implements, your auditor must have had no hand in it, and we hold ourselves to that rule without exception.

What makes you independent?

We take no implementation or consultancy work, we run a conflict check before every engagement, and we decline any audit where impartiality could reasonably be questioned. Independence is the product we sell, so we protect it more carefully than anything else.

Do you only audit ISO management systems?

No. We also provide outsourced internal audit as a function: risk-based audit plans, internal control testing, and governance and compliance reviews, reported to the board or audit committee. Our practice is led by financial statement audit experience, so finance processes and controls are home ground. We do not perform statutory financial statement audits, which are a separately regulated activity.

How long does an audit take?

A typical internal or readiness audit for a small or medium organisation runs two to five auditor days depending on scope, spread over two to three weeks including planning and reporting. You get the exact duration and price at scoping, before you commit.

Do you audit organisations outside Ireland?

Yes. Fieldwork can run remotely through the platform, with on-site days where the scope needs them. Management system audits translate well across borders because the standards are international by design.

Request an audit

Ready when you need an opinion that holds up.

Tell us which standard and what the audit is for. We will come back with a fixed scope, a fixed price and a start date.

Contact Attestware