Product
ISO 27001 internal audit, ISO 27001 external audit
Industry
AI governance and secure AI access software
Engagement Length
Under four weeks
Location
Smørum, Denmark
Outcome
Two independent ISO 27001 audit reports on its ISMS, internal and external, in under four weeks
Key Performance Metrics
Completed in 8 days (June 29 to July 6, 2026)
Closed on July 8, 2026
Completed in 5 days (July 20 to July 24, 2026)
In under four weeks
At a Glance
- Challenge: Haime, a young company selling AI governance tooling to compliance-conscious buyers, needed independent ISO 27001 internal and external audits of its own ISMS.
- Solution: Axipro ran the internal audit and the external audit with separate auditors, keeping the two independent.
- Results: Both audits completed within four weeks, from June 29 to July 24, 2026, giving Haime two audit reports on its ISMS.
The Company
Haime is a Danish software company that gives business teams a single, controlled way to use ChatGPT, Claude, Gemini and Mistral at work. The platform sits between employees and the AI models, stripping personal data before prompts leave the company’s environment and giving administrators a dashboard of who is using AI, how often, and through which models. It’s EU-hosted and built around GDPR reporting needs like DPAs, DPIAs and audit trails.
That positioning cuts both ways. Haime sells to organizations whose compliance teams need to approve any new AI tool, and those buyers apply the same scrutiny to Haime itself. A company promising to protect sensitive data has to show it manages its own information security to a recognized standard. ISO 27001 is the standard those buyers ask about first.
01- THE CHALLENGE
Building an Independent Audit Process
Like most companies under 50 people, it didn’t have a dedicated internal audit function, and an internal audit performed by the same people who built the ISMS doesn’t carry much weight with an external auditor or a customer.
Haime needed both audits done independently, and done close together so the findings from the first could feed the second.
02- THE ENGAGEMENT
Internal Audit First, External Audit Two Weeks Later
● Two audits, two independent auditors
Axipro ran both audits for Haime. To keep them properly separated, different auditors handled each stage: Shailee Manandhar on the internal audit and Sherharbano on the external audit, with Ikponke Godwin leading the internal audit engagement. That separation matters. An internal audit should find the problems before the external auditor does, and the external auditor should come to the evidence fresh. The engagement covered the audits only. Certification by an accredited body was not part of the scope.
● Internal audit: June 29 to July 6
Fieldwork for the internal audit ran over eight days, from June 29 to July 6, 2026. The engagement closed on July 8, two weeks before the external audit began, which gave Haime a short window to act on what the internal audit surfaced.
● Working around the platform
The one real snag came from tooling rather than from Haime’s ISMS. Haime managed its compliance documentation in CyberJuice, and many of the documents it had already uploaded there weren’t accessible to the audit team, so gathering evidence took longer than it should have. The team worked through it and stayed on schedule for the external audit.
● External audit: July 20 to July 24
The external audit ran over five days, from July 20 to July 24, 2026, conducted by a different Axipro auditor with no involvement in the internal audit.
03- THE RESULTS
Two Independent Audit Reports in Under Four Weeks
Haime went from the start of internal audit fieldwork to the end of the external audit in under four weeks.
It came out with two independent audit reports on its ISMS: one internal, one external, each from a different auditor. For a company under 50 people selling into compliance teams, that’s the evidence base that turns “we take security seriously” into something a buyer can check.