Skip to main content

ASSURE

Both management systems, audited together.

ISO 27001 and ISO 42001 share the same clause structure. Auditing them as one engagement rather than two removes duplicated fieldwork, produces a single coherent report, and costs less than running them separately.

Scoped on the free 45 minute diagnostic

ISO 42001 Lead Implementer (PECB)ISO 42001 Lead Auditor (PECB)ISO 27001 Senior Lead Implementer (PECB)ISO 27001 Lead Auditor (PECB)CISSP

THE ENGAGEMENT

One management system underneath, so one audit.

Organisations holding both certifications usually run two internal audits, at different points in the year, often with different auditors. The result is two reports describing overlapping governance in different language, with findings that do not reconcile and a management review that has to translate between them. That is a consequence of how the services are sold rather than how the standards are built.

Both standards follow the Annex SL harmonised structure, so clauses 4 through 10 cover the same management system architecture. Context, leadership, planning, support, operation, performance evaluation, and improvement are audited once, because there is one management system underneath rather than two. Only the Annex A control sets genuinely differ, and those are tested separately against each Statement of Applicability.

The practical consequence is fewer interviews, one document review, one examination of management review, and one set of findings that shows where a single weakness affects both scopes rather than surfacing twice with no connection drawn between the two.

INDEPENDENCE

Where we audit, and where we do not.

Goldline does not conduct internal audits of management systems it implemented. An internal audit that reports on the implementer's own work is not an audit, and a certification body reviewing your clause 9.2 evidence will see that immediately. In a combined engagement the rule applies to both scopes: if we built either the ISMS or the AIMS, we do not audit it.

That constraint is a strength rather than a limitation. It is the reason a Goldline audit report carries weight with a certification body, and it is why the findings in it can be relied on by your board. Preparation remains available for our own implementation clients, because a Pre-Certification Readiness Audit is a rehearsal rather than an assurance opinion, and the same party should not do both.

THE CREDENTIAL REQUIREMENT

Why almost nobody offers this.

A combined audit requires Lead Auditor competence in both standards held by the same practitioner. Splitting the work between two auditors reintroduces the problem the combined audit exists to solve, because the shared clauses get examined twice by people who did not sit in each other's interviews.

ISO 27001 Lead Auditors are common. ISO 42001 Lead Auditors are not, because the standard was published in December 2023 and the certification pathway is recent. Practitioners holding both are rarer still.

Goldline holds Lead Implementer and Lead Auditor credentials for both ISO 27001 and ISO 42001. That is what makes a genuinely combined audit possible rather than two audits scheduled close together.

DELIVERABLES

What you receive.

01

Single audit plan covering both scopes, agreed in advance against your ISMS and AIMS boundaries

02

Shared clause fieldwork conducted once, covering clauses 4 through 10 across both management systems

03

ISO 27001 Annex A control testing against your Statement of Applicability

04

ISO 42001 Annex A control testing against your Statement of Applicability

05

One audit report addressing both scopes, written to certification body evidence standard and structured so each certification body sees what it needs

06

Single nonconformity log with severity ratings, root cause, and explicit marking of findings that affect both scopes

07

Corrective action recommendations sequenced across both systems

08

Evidence pack retained for both surveillance audits

FIT

Who this is for.

  • You are certified to both ISO 27001 and ISO 42001.
  • You are certified to one and implementing the other, so the audit covers the certified scope and provides a readiness view on the second.
  • Your two internal audits currently run separately and produce findings that do not reconcile.
  • You are approaching surveillance audits for both certifications within the same window.

This is not for organisations holding only one certification. Where there is a single management system to audit, the single standard internal audit is the right service and the cheaper one.

Nor is it for organisations whose management systems Goldline implemented. We will say so at scoping and recommend an alternative auditor.

WHAT COMES NEXT

Where organisations go from here.

Where only one certification is held, the single standard internal audit covers the clause 9.2 obligation on its own terms, and the combined engagement becomes the right instrument once the second certificate is in place.

QUESTIONS

Common questions.

Two internal audits in the diary?

A 45 minute scoping call establishes both management system scopes, your surveillance dates, and the price. No sales pitch. Where independence rules out either scope, we will say so and recommend an alternative.

Prefer email? Write to info@goldlineconsultancy.co.uk.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.