Audit plan
Scope, criteria, timetable, and a pre-audit list of the evidence needed.
Audits are performed in line with ISO 19011, with lead auditor training in ISO/IEC 27001 and ISO 9001, backed by hands-on IT, information security, and quality-management experience.

A clear process, traceable evidence, and output that can support real improvement.
Scope, criteria, timetable, and a pre-audit list of the evidence needed.
Each finding is linked to a criterion, evidence, and risk assessment.
Clear recommendations and corrective-action guidance for the real context.
A structured outcome for management and the people responsible for the system.
Business Key Consult delivers internal and GAP audits with a consulting nature, with a primary focus on ISO/IEC 27001 and complementary work across ISO 9001 and related standards.
Audit services follow ISO 19011 and are delivered from Sofia, Bulgaria, backed by hands-on experience in IT, cybersecurity, IAM, and cloud environments.
Our team has 6+ years of hands-on experience across cybersecurity and IT, including participation in internal and external audits of management systems.
Publicly stated credentials include ISO 19011 audit methodology, ISO/IEC 27001 and ISO 9001 lead auditor training, and CCSK cloud-security knowledge.
We combine:
This approach allows us to assess not only formal compliance, but the real effectiveness of controls and processes.
Audits and assessments are performed against:
Our audit approach is aligned to your context and applicable requirements.
Business Key Consult holds CCSK (Certificate of Cloud Security Knowledge) by Cloud Security Alliance, confirming deep knowledge in cloud security.
This enables audits and assessments in public and hybrid cloud environments, focusing on:
CCSK complements our ISO/IEC 27017 and ISO/IEC 27018 audit capability.
We have practical experience with organisations across:
This helps us apply an audit approach tailored to your environment and risk profile.
We work closely with clients while remaining professional, independent, and confidential.
We focus on:
Audits are delivered 100% remotely, without compromising quality or objectivity.
All audit activities follow the principles of:
Audits are internal/GAP in nature with a consulting orientation and are not certification audits or certification body activities.
These are internal and GAP audits with a consulting nature and do not represent a certification audit or the activity of a certification body.