ISO 27001 Audit 2026 — Zero Nonconformities, Without Consultancy

Second consecutive year passing the ISO 27001 audit with zero nonconformities — and the first cycle entirely without external consultancy.

A few days ago we received the final report from DNV for our 2026 ISO 27001 external audit. The result: zero nonconformities. It is the second consecutive year we keep that figure, but this cycle has a detail that makes it especially relevant: it was the first time the company faced the process without external consultancy, and the first time I personally executed the prior internal audit.

I am writing this post because I think the case illustrates well a strategic decision many ISMS leaders are weighing right now: when does it stop making sense to outsource, and when does it make sense to internalize the audit function? I am not selling a universal recipe. I will share what we did, why we did it, and what I read into it.

Why zero nonconformities in ISO 27001 is not a formality

ISO/IEC 27001 is the international reference standard for Information Security Management Systems (ISMS). It does not certify a company as 'secure' in absolute terms — that does not exist — but it certifies that there is a documented, living, auditable system to identify information risks, treat them, and continuously improve.

An external certification or surveillance audit reviews, among other things, the system's scope, risk analysis, statement of applicability, effective implementation of Annex A controls, the continuous improvement cycle, and management's traceability over the system. Any of those blocks can generate major or minor nonconformities, and it is common — even in mature organizations — to close the cycle with at least a minor NC or some observations.

That is why a clean report is not a given. And keeping it clean two years in a row, less so.

The decision: internalizing the cycle when you have a Lead Auditor on staff

For years, the reasonable approach for us was to lean on external consultancy to prepare audits. That decision changed when I obtained the ISO 27001 Lead Auditor credential from AENOR in 2025. From that point, the question stopped being 'who helps us prepare?' and became 'does it still make sense to pay for a layer we already cover internally?'

My answer — after discussing it with management — was no. Three reasons:

  • Context knowledge. Nobody understands the processes, critical assets, and culture of the company better than the internal team. A consultancy always needs warm-up time; we do not.
  • System ownership and traceability. When the internal audit is run by a third party, there is a silent risk: the ISMS gets lived as 'what the consultancy asks for' instead of 'what we need'. Internalizing reinforces real ownership of the system.
  • Economic efficiency. I will not put concrete figures here because the saving depends on each contract, but eliminating a recurring consultancy line frees budget that can be reinvested in controls, training, or tooling.

Adding to this, this year I obtained the ISO 42001 Lead Auditor credential (AI Management System, April 2026), which prepares us to integrate AI governance into the same management framework when the time comes. But that is another conversation.