Audit Process

How an Axipro audit works

ISO 27001 and SOC 2 run on different tracks. This page walks through both: who audits you, who issues the certificate, how long each stage takes, and what you’ll need to show.

On this page
01 — ISO 27001

ISO Audit Process

Our audit team is separate from the consultants who help you implement, which is what ISO/IEC 17021-1 requires. We don’t issue the certificate ourselves either. That decision sits with an independent certification body, TNV Global Ltd or Guardian Assessment Ltd, and they run their own impartiality and technical review before making it.

Certification Body
Accreditation Body
TNV Global Ltd

United Accreditation Foundation (UAF)

Guardian Assessment Ltd

International Accreditation Services (IAS)

You pick the certification body and the accreditation route, and you sign off on both before we start.

Standard option

UAF

United Accreditation Foundation. Included by default.

Included

IAS

International Accreditation Services. Available at no additional cost.

Add-on

UKAS

Available for an additional fee.

Anyone can check your certificate

Every certificate is listed on IAF CertSearch. You get a unique certificate number and a QR code, so a customer or prospect who asks can verify it themselves in seconds.

Timeline

Scope first, then the clock starts

Before the audit starts, we finalize your ISO application form and lock down the certification scope. Whatever goes in that field is the wording printed on your certificate, word for word, so it has to match what you actually do. Changing it after the certificate is issued costs extra in administrative charges.

What each step takes

The audit checks your Information Security Management System (ISMS) against ISO 27001, in two stages.

1 day

Stage 1 audit

2–3 days

Stage 2 audit

1–2 hrs

Interview session

7–10 days

Certificate issuance after successful audit completion (working days)

Stage 1

Documentation Review & Readiness Assessment

A desk review. The auditor is checking whether your management system is designed and documented properly. Nobody is looking at implementation yet.

What the auditor reviews
  1. Scope and context. Your defined ISMS scope is clear and covers all relevant services, locations, and personnel.
  2. Risk management framework. Your Risk Assessment Methodology and Risk Treatment Plan show you’ve identified and planned to manage information security risks.
  3. Statement of Applicability (SoA). Every Annex A control has been considered and applicable controls are documented.
  4. Policies and procedures. Core security policies, such as Access Control, Incident Management, and Third-Party Security, are in place and aligned with your objectives.
  5. Internal audits and management review. Records prove you’re already monitoring and improving your system.

Outcome: You get a Stage 1 report. If it lists major non-conformities, you fix them before we book Stage 2.

Stage 2

Implementation & Effectiveness Verification

A hands-on audit. The auditor checks that what your documentation describes is what actually happens day to day, and that it works.

How the auditor verifies
  1. Technical control verification. Evidence of implemented controls: network diagrams, access logs, IDS reports, vulnerability scan results.
  2. Operational process audits. Detailed walkthroughs of selected processes, such as an incident response drill or backup and disaster recovery testing.
  3. Staff interviews. Employees at every level, from IT to management, on their security roles and awareness of ISMS policies.
  4. Evidence of compliance. Objective proof of effectiveness: dashboard screenshots, maintenance records, log files, meeting minutes.
Outcome: If there are no major non-conformities, your audit file goes to the certification body for independent review. The ISO 27001 certificate follows 7 to 10 working days later.
02 — SOC 2

SOC 2 Audit Process

We run SOC 2 attestations alongside licensed CPA firms that meet AICPA professional standards.

Firm Name
Peer Review Status
AT and F International

Enrolled in peer review program

Moiz Ezzi

Peer review passed

01

Readiness & Type 1

Design of Controls

Objective

Check that your security program is designed to meet the AICPA Trust Services Criteria (TSC).

  1. Scoping and TSC selection. Security is mandatory; Availability, Confidentiality, Processing Integrity, and Privacy are optional.
  2. Gap assessment. We map existing controls against the TSC and identify missing policies or configurations.
  3. Remediation. Hands-on support to close gaps, from MFA to change management and incident response plans.
  4. Type 1 readiness review. A point-in-time examination of your control design.
  5. Type 1 report issuance. System description and design suitability documented as of a specific date, typically within 2 to 3 weeks.
02

Type 2 Observation Period

Operating Effectiveness

Objective

Show that the controls designed in Phase 1 held up consistently over time.

  1. Observation kickoff. Review period defined: minimum 3 months, typically 6 to 12 months.
  2. Continuous monitoring. GRC tools (Drata, Vanta, or custom) alert you the moment a control breaks.
  3. Evidence sampling. Complete populations collected for the period: change tickets, new hires, firewall logs.
  4. Testing of effectiveness. Walkthroughs verify every sampled control was followed correctly.
03

Quality Assurance & Peer Review

Internal safety net

Objective

Catch problems in the audit file before the CPA signs anything.

  1. Internal file assembly. The lead auditor compiles the workpapers behind every control.
  2. Independent peer review. A senior auditor not involved in the original audit checks control mapping accuracy, sufficiency of evidence, and compliance with AICPA standards.
  3. Deficiency clearing. Every peer review note is resolved before the file moves forward.
04

AICPA Attestation & Final Issuance

Signing and delivery

Objective

Sign the report and get it into your hands.

  1. Draft report generation. The four-part SOC 2 report: Independent Service Auditor’s Report, Management’s Assertion, System Description, and the Trust Services Criteria with controls and test results.
  2. Management representation letter. You confirm in writing that all necessary information was provided.
  3. Final CPA signing. The licensed CPA firm, Next Gen Assure, issues the signed PDF carrying the AICPA logo.
  4. Client delivery. Handover of the final report with advice on sharing it with your customers.
Deliverables

What you end up with

SOC 2 Type 1

Point-in-time verification that your controls are correctly designed against the AICPA Trust Services Criteria.

SOC 2 Type 2

Proof your controls operated effectively over a defined window (minimum 3 months).

Internal peer review

A rigorous quality check by senior audit leads before finalization.

AICPA attestation

Your formal report, signed by a licensed CPA.

03 — Documentation

License copies

The credentials behind the attestation, if you want to check them yourself.

Peer review status

Current standing in the AICPA peer review program.

CPA license

Active license for the signing CPA firm.