> First internal audit of EthicsPortal against ISO/IEC 27001:2022 found no control failures. Six documentation defects were raised and all six were corrected before the audit closed. Programme, findings, and the limits of a self-performed audit.

Source: https://ethicsportal.eu/policies/internal-audit/
Updated: 2026-09-30

---

# Internal audit record

**Effective date:** 2026-09-23
**Last reviewed:** 2026-09-23
**Next review:** 2027-09-23
**Owner:** Yaroslav Shmarov, operator
**Version:** 1.0

Clause 9.2 of ISO/IEC 27001:2022 requires internal audits at planned intervals, to determine whether the information security management system conforms to the organization's own requirements and to the standard, and whether it is effectively implemented and maintained. This page is the programme and the record of audits performed against it.

**Current position.** One audit has been performed, in September 2026, across the full management system. It found **no control failures**. It raised six findings, all of them defects in how a control was described rather than in how it operates, and all six were corrected before the audit closed. Three opportunities for improvement remain open and are listed with their status.

---

## Independence of this audit

Clause 9.2 requires that auditors be selected and audits conducted in a way that ensures the objectivity and impartiality of the audit process. A single-operator organization cannot meet that requirement: the person auditing the system is the person who designed and operates it, and no choice of auditor changes that.

This is why [Annex A control A.5.35](/iso-27001/) (independent review of information security) is recorded as **In treatment** and [Clause 9.2](/iso-27001/) as **Partial**. An independent external review is what closes both. The audit is still performed and published, because a dated pass over the published claims against the running system catches defects that would otherwise reach a customer. The same limit applies to [self-conducted security testing](/security-testing/).

---

## Audit programme

| Element | Definition |
|---|---|
| Frequency | Annually, and additionally on any material change to architecture, sub-processors, or the regulatory obligations the Service is built against |
| Scope | The full ISMS: Clauses 4--10 and all 93 Annex A controls as published in the [ISO/IEC 27001:2022 self-assessment](/iso-27001/), together with the [information security policy](/policies/information-security/), [business continuity plan](/policies/business-continuity/), and [risk register](/policies/risk-register/) |
| Criteria | ISO/IEC 27001:2022; the commitments EthicsPortal has published on its own Trust surfaces; and the [DPA](/dpa/) |
| Method | Every published claim is checked against the running code and deployed configuration, not against sibling documents or plausible behaviour. Infrastructure claims are checked against deployed state --- the continuously running production check set at [secure.ethicsportal.eu/up](https://secure.ethicsportal.eu/up) queries the database for the presence of the append-only audit triggers rather than inferring them from migration history |
| Auditor | The operator. See the impartiality limitation above |
| Reporting | Findings are published on this page. Corrections are recorded in the [corrective-action log](/iso-27001/) of the document they change, and their status is reviewed at the next [management review](/policies/management-review/) |
| Classification | **Finding** (a *nonconformity* in the standard's own vocabulary) --- a published claim that is inaccurate or unsupported, or a requirement of the standard that is not met. **Observation** --- a conformity that holds but rests on weaker evidence than it should. **Opportunity for improvement** --- no finding, but a gap worth closing |

A finding that would leave a customer or regulator misinformed about the security of their data is material, and is corrected before the audit closes rather than scheduled.

---

## Audit 2026-09 --- first full audit

**Conducted:** 2026-09-23 · **Scope:** full ISMS as defined above · **Result:** no control failures. Six findings raised, all corrected before close; three opportunities for improvement, one of them since closed.

### Findings

| Ref | Clause | Finding | Correction | Verified |
|---|---|---|---|---|
| NC-01 | 4--10, 6.1.3 | The published ISO/IEC 27001 self-assessment covered Annex A only. Clauses 4--10 --- the mandatory requirements certification is awarded against --- were not assessed, and no Statement of Applicability existed under that name, so the link from assessed risk to selected control was not visible to a reviewer | Clauses 4--10 assessed sub-clause by sub-clause; the Annex A tables framed as the Statement of Applicability, with the basis for inclusion and the risk-to-control mapping stated | Published at [/iso-27001/](/iso-27001/) v3.0 |
| NC-02 | 7.2, A.6.1, A.6.3 | Screening and awareness were marked **Not applicable** on the grounds that there are no employees. Correct for a hiring process, wrong for the operator, whose competence Clause 7.2 requires irrespective of headcount | Both reclassified **Compensating** with the substitute assurance named; a competence basis recorded in [IS policy §8](/policies/information-security/) | [/iso-27001/](/iso-27001/) v3.0, [IS policy](/policies/information-security/) v1.1 |
| NC-03 | A.5.30, A.8.13 | [Business continuity plan §9](/policies/business-continuity/) stated the restore drill runs quarterly and [risk register R-05](/policies/risk-register/) stated "at least quarterly". The drill has been running monthly, so both documents understated a control that was stronger than claimed | Both corrected to monthly, matching what the [Security](/security/#backups-and-restore) page and risk register R-02 already stated | [BCP](/policies/business-continuity/) v1.1, [risk register](/policies/risk-register/) v1.3 |
| NC-04 | A.8.13 | The Annex A backup row described only the object-storage dump layer, omitting the host-snapshot layer and the continuous backup-freshness check, both already operating and already documented on [Security](/security/#backups-and-restore) | Row restated to cover both layers and the freshness check | [/iso-27001/](/iso-27001/) v3.0 |
| NC-05 | 6.2 | The three information security objectives were qualitative. Clause 6.2 requires objectives to be measurable where practicable, with the means of evaluation stated. As written, no management review could have concluded whether any of them had been met | Each objective given a measure, a target, and the source the result is read from | [IS policy §3](/policies/information-security/) v1.1 |
| NC-06 | A.5.3, A.8.15 | Four published surfaces stated that individual reads are not logged. Handler views of a report are logged, per handler, deduplicated to one entry per report per 24 hours, and reporter follow-up views with them. On the [Privacy notice](/privacy/) and [DPIA template](/dpia/) this was an under-disclosure of processing, not only an understated control | All four corrected to describe what is logged and what is not | [/iso-27001/](/iso-27001/), [Privacy notice](/privacy/), [DPIA](/dpia/), [DORA map](/dora/) |

### Opportunities for improvement

| Ref | Clause | Finding | Position |
|---|---|---|---|
| OFI-01 | 6.1.3, 8.3 | There is no consolidated risk treatment plan. Treatment is recorded per risk in the register, but the three risks carrying an **In treatment** residual position have no completion date against them | **Closed 2026-09-23.** A [treatment plan](/policies/risk-register/) now dates every open item, with a stated rule for a missed target. Clause 6.1.3 moves to Implemented and 8.3 off Partial |
| OFI-02 | 4.2 | Interested parties and their expectations are addressed per relationship --- controllers in the DPA, reporters in the privacy notice, authorities and sub-processors elsewhere --- rather than consolidated into a single view | Open. Low materiality; the distributed form serves the party reading it better |
| OFI-03 | 9.1 | The production check set runs continuously and alerts on failure, but no schedule defines when the collected data is *analysed*. Clause 9.1 asks when results are evaluated, not only when they are gathered | Open. The annual management review is the current analysis point |

### Areas examined with no finding

Tenant and role boundaries; the append-only audit trail and its database-level enforcement; the encryption boundary and what it does and does not cover; retention and erasure paths; the deploy gate and its enforcement of the automated suite; sub-processor disclosure against the published list; and the accuracy of the open gaps recorded on [Trust](/trust/) and [Self-conducted security testing](/security-testing/).

---

## Document control

| Field | Value |
|---|---|
| Document title | EthicsPortal Internal Audit Record |
| Version | 1.0 |
| Effective date | 2026-09-23 |
| Last reviewed | 2026-09-23 |
| Next scheduled review | 2027-09-23 |
| Review trigger (interim) | Material change to architecture, sub-processors, or regulatory obligations; a finding raised at [management review](/policies/management-review/) |
| Owner | Yaroslav Shmarov, operator |
| Distribution | Published on [ethicsportal.eu/policies/](/policies/) |

Signed: Yaroslav Shmarov, on behalf of EthicsPortal --- 2026-09-23.
