What the work actually looked like
Engagement records from Aegentra’s assurance practice — the scope tested, the method used, every finding, and how each was closed out.
Engagement records from Aegentra’s assurance practice — the scope tested, the method used, every finding, and how each was closed out. Written so a reader can judge the method rather than take a claim on trust.
No client is named. Aegentra publishes no client name without written approval on file, so each record is stated in terms of what was audited, what was found and how it was reported.
A Clause 9.2 internal audit, met with evidence
ISO 27001 · Clause 9.2 · July 2026
A small Australian technology company certified to ISO/IEC 27001:2022 needed an independent internal audit before its first surveillance audit, and could not run one in-house without breaching the impartiality requirement. All of Clauses 4 to 10 and a risk-based sample of 47 Annex A controls were audited across 73 lines of enquiry.
- 0 — Nonconformities
- 73 — Lines of enquiry
- 47 — Annex A controls
- 4 days — To final report
Read the full a clause 9.2 internal audit, met with evidence. Service: ISO 27001 internal audit.
How these are written — what you should be able to check
The scope is stated, not implied
What was in scope, what was sampled and on what basis. A result means nothing without the scope it was measured over — "no findings" across two controls is not the same claim as "no findings" across forty-seven.
Figures come from the report, not the pitch
Every number is the audited total from the engagement record. Where a figure would be an estimate, it is not published.
Method over outcome
Outcomes belong to the client and the day they were measured. What an engagement can genuinely demonstrate is method — the evidence obtained, the reasoning recorded, and whether matters raised were tested before being reported.
No client is named
Aegentra publishes no client name, logo or identifying detail without written approval on file. Anonymity is the default, not a gap.
The engagements behind these records come from Aegentra’s governance, risk and compliance practice — principally ISO 27001 implementation, ISO 27001 internal audit, ISO 42001 and SOC 2 readiness.
Want an engagement that reads like these? Fixed fee, scope agreed before the work starts, and a report you can hand to your certification body — talk to a senior consultant, or start with governance, risk and compliance.