How an Axipro audit works
ISO 27001 and SOC 2 run on different tracks. This page walks through both: who audits you, who issues the certificate, how long each stage takes, and what you’ll need to show.
ISO Audit Process
Our audit team is separate from the consultants who help you implement, which is what ISO/IEC 17021-1 requires. We don’t issue the certificate ourselves either. That decision sits with an independent certification body, TNV Global Ltd or Guardian Assessment Ltd, and they run their own impartiality and technical review before making it.
United Accreditation Foundation (UAF)
International Accreditation Services (IAS)
You pick the certification body and the accreditation route, and you sign off on both before we start.
UAF
United Accreditation Foundation. Included by default.
IAS
International Accreditation Services. Available at no additional cost.
UKAS
Available for an additional fee.
Anyone can check your certificate
Every certificate is listed on IAF CertSearch. You get a unique certificate number and a QR code, so a customer or prospect who asks can verify it themselves in seconds.
Scope first, then the clock starts
Before the audit starts, we finalize your ISO application form and lock down the certification scope. Whatever goes in that field is the wording printed on your certificate, word for word, so it has to match what you actually do. Changing it after the certificate is issued costs extra in administrative charges.
What each step takes
The audit checks your Information Security Management System (ISMS) against ISO 27001, in two stages.
Stage 1 audit
Stage 2 audit
Interview session
Certificate issuance after successful audit completion (working days)
Documentation Review & Readiness Assessment
A desk review. The auditor is checking whether your management system is designed and documented properly. Nobody is looking at implementation yet.
- Scope and context. Your defined ISMS scope is clear and covers all relevant services, locations, and personnel.
- Risk management framework. Your Risk Assessment Methodology and Risk Treatment Plan show you’ve identified and planned to manage information security risks.
- Statement of Applicability (SoA). Every Annex A control has been considered and applicable controls are documented.
- Policies and procedures. Core security policies, such as Access Control, Incident Management, and Third-Party Security, are in place and aligned with your objectives.
- Internal audits and management review. Records prove you’re already monitoring and improving your system.
Outcome: You get a Stage 1 report. If it lists major non-conformities, you fix them before we book Stage 2.
Implementation & Effectiveness Verification
A hands-on audit. The auditor checks that what your documentation describes is what actually happens day to day, and that it works.
- Technical control verification. Evidence of implemented controls: network diagrams, access logs, IDS reports, vulnerability scan results.
- Operational process audits. Detailed walkthroughs of selected processes, such as an incident response drill or backup and disaster recovery testing.
- Staff interviews. Employees at every level, from IT to management, on their security roles and awareness of ISMS policies.
- Evidence of compliance. Objective proof of effectiveness: dashboard screenshots, maintenance records, log files, meeting minutes.
SOC 2 Audit Process
We run SOC 2 attestations alongside licensed CPA firms that meet AICPA professional standards.
Enrolled in peer review program
Peer review passed
Readiness & Type 1
Design of Controls
Check that your security program is designed to meet the AICPA Trust Services Criteria (TSC).
- Scoping and TSC selection. Security is mandatory; Availability, Confidentiality, Processing Integrity, and Privacy are optional.
- Gap assessment. We map existing controls against the TSC and identify missing policies or configurations.
- Remediation. Hands-on support to close gaps, from MFA to change management and incident response plans.
- Type 1 readiness review. A point-in-time examination of your control design.
- Type 1 report issuance. System description and design suitability documented as of a specific date, typically within 2 to 3 weeks.
Type 2 Observation Period
Operating Effectiveness
Show that the controls designed in Phase 1 held up consistently over time.
- Observation kickoff. Review period defined: minimum 3 months, typically 6 to 12 months.
- Continuous monitoring. GRC tools (Drata, Vanta, or custom) alert you the moment a control breaks.
- Evidence sampling. Complete populations collected for the period: change tickets, new hires, firewall logs.
- Testing of effectiveness. Walkthroughs verify every sampled control was followed correctly.
Quality Assurance & Peer Review
Internal safety net
Catch problems in the audit file before the CPA signs anything.
- Internal file assembly. The lead auditor compiles the workpapers behind every control.
- Independent peer review. A senior auditor not involved in the original audit checks control mapping accuracy, sufficiency of evidence, and compliance with AICPA standards.
- Deficiency clearing. Every peer review note is resolved before the file moves forward.
AICPA Attestation & Final Issuance
Signing and delivery
Sign the report and get it into your hands.
- Draft report generation. The four-part SOC 2 report: Independent Service Auditor’s Report, Management’s Assertion, System Description, and the Trust Services Criteria with controls and test results.
- Management representation letter. You confirm in writing that all necessary information was provided.
- Final CPA signing. The licensed CPA firm, Next Gen Assure, issues the signed PDF carrying the AICPA logo.
- Client delivery. Handover of the final report with advice on sharing it with your customers.
What you end up with
SOC 2 Type 1
Point-in-time verification that your controls are correctly designed against the AICPA Trust Services Criteria.
SOC 2 Type 2
Proof your controls operated effectively over a defined window (minimum 3 months).
Internal peer review
A rigorous quality check by senior audit leads before finalization.
AICPA attestation
Your formal report, signed by a licensed CPA.