- Learn
- Align
- Perform
- Review
Review5 min read
The Internal Audit Is a Protective Control
By J Damien Scott, Trusted Advisor
Operations cannot see its own gaps from inside. An internal audit against a standard and the organization's own documented practice finds what daily work hides, and the closing meeting is where leadership decides what to do about it. Six ISO/IEC 27001 Clause 9.2 audits delivered for client organizations show how the method works, and why protective programs, which are almost never audited this way, need it most.
What Clause 9.2 asks, and why operations cannot answer it from inside
ISO/IEC 27001:2022 requires an organization to conduct internal audits at planned intervals to determine whether its information security management system conforms to the organization's own requirements and to the standard, and whether it is effectively implemented and maintained. The standard's own description of its purpose is establishing, implementing, maintaining, and continually improving a management system. The internal audit is the mechanism that tests the maintaining and the improving. Without it, the system is a set of documents and a belief.
The reason an audit has to come from outside daily operations is not a question of competence. People inside a function see their controls as they intend them, and intention is invisible to an auditor. Guidance on auditing management systems, ISO 19011, sets out principles that include independence and an evidence-based approach; the 2018 edition has been withdrawn in favour of ISO 19011:2026, and the principles carried over. The Institute of Internal Auditors makes the same point structurally in its Three Lines Model, which separates the people who own and manage risk from the people who provide independent assurance over them. A control owner reviewing a control owner is a status report, not an audit.
The NIST Cybersecurity Framework 2.0 places the same expectation under its Identify function. Outcome ID.IM-01 reads: improvements are identified from evaluations. An evaluation that only ever confirms what the team already believed has not evaluated anything.
“An audit does not ask whether the team is working hard. It asks whether the documented control exists, operates, and produces evidence.”
What six client audits taught about findings
I delivered six ISO/IEC 27001 Clause 9.2 internal audits for external client organizations. Each was planned and executed as a full-scope audit against two things at once: the standard, and the client's own documented information. That second reference matters more than people expect. A client rarely fails the standard outright. A client fails its own policy, because the policy was written for a certification project two years earlier and operations have moved on.
The most common pattern was a control that existed on paper, was believed to operate, and produced no evidence. Access reviews that were scheduled quarterly and last performed eleven months before. A supplier register that listed every vendor except the two added since the last audit. An incident log that recorded the incidents somebody thought were serious and none of the near misses. None of this is negligence. It is what happens when a control has no owner watching the evidence trail rather than the activity.
The second pattern was scope drift. The management system said it covered a defined set of assets and locations, and the business had quietly added a site, a cloud service, or a client category that nobody had brought inside the boundary. An audit that starts by re-reading the scope statement against the current org chart finds this in the first hour. An audit that starts with the control checklist finds it never.
Severity, and the closing meeting
Every finding in those six audits was classified by severity before it was presented. A major nonconformity is a control that is absent or has failed in a way that defeats the objective it serves. A minor nonconformity is a lapse in a control that otherwise operates. An observation is a weakness that has not yet produced a lapse. The classification is not a courtesy to the client. It is what lets leadership allocate attention, because a list of forty undifferentiated findings produces forty shrugs.
The closing meeting is the point of the audit. Findings were presented to client leadership, with the evidence behind each one, and with the corrective action inputs the client would need to proceed. My part ended there in every case: the clients took certification in-house afterwards, and the certification outcomes are not known to me. That boundary is worth stating plainly, because an internal auditor who also claims the certificate has stopped being independent.
What leadership owes the closing meeting is a decision on each major finding: fix it, accept the risk in writing, or dispute the finding with evidence. What they do not owe is agreement. ISO 31000:2018 describes monitoring, reviewing, and continually improving risk management as criteria, not aspirations, and a closing meeting that ends without decisions has failed the criterion.
Why physical security programs escape audit
Information security has a certification industry that forces the audit habit. Physical security and executive protection have inspections, walk-throughs, and client satisfaction reviews, which are not the same thing. An inspection checks whether the guard is at the post. An audit checks whether the post order exists, whether it matches the risk assessment that justified the post, whether the officer was trained to it, whether the training record exists, and whether anyone reviewed the post order after the last incident.
At a national security services firm I led, the organization held an ISO/IEC 27001 certificate, built from inception in 2020 and sustained through the standard's revision to 2024, with a certified scope covering federal and government contracts and headquarters. The discipline that certificate imposed on the information domain had no natural counterpart on the protective side, and I ran it anyway: post orders, training expectations, escalation protocols, incident reports, and customer reporting held to standard across 238 sites in 28 states. In a later role, the licensing, training, personnel, incident, post coverage, payroll, and billing records were held audit-ready, because external audits, inspections, and regulatory review ask for them without notice.
The gap is closing. The ANSI-accredited executive protection standard, ANSI/BEP EPS 2026, gives a protective program a documented set of requirements to be audited against for the first time. I served on the Technical Committee of the Board of Executive Protection Professionals that authored it. A standard is only a shelf document until someone audits against it.
Running the same audit against a protective program
The method transfers without modification. Plan the audit against two references: the standard the program claims, and the program's own documents. Re-read the scope first, and look for the site, the principal, or the travel pattern that was added after the documents were written. Sample the evidence trail, not the activity: the training record, the advance report, the after-action note, the exception log. Classify each finding by severity. Present at a closing meeting with the corrective inputs attached, and get a decision on every major finding before the meeting ends.
Then leave. The auditor who stays to fix the findings has joined the second line and will not be able to audit the fix. The audit is a protective control because it is the one control in the program that is designed to find the program's own failures before an adversary or a regulator does. Review feeds Learn. The findings are the most reliable threat intelligence a program will ever receive about itself.
Field Notes · by email
One email when a new article publishes. Nothing else.
Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.
Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes
Related reading
More from Review
Review · 11 September 2026
Post Coverage Is a Protective Audit, Not a Finance Task
An unfilled post is an unprotected site, and the record that proves the post was filled is the same record that bills the client. Redesigning timekeeping controls, billing reconciliation, contract compliance, post coverage validation, and exception review cut revenue leakage by 95% at a 127-account security enterprise. The finance result was real. The protective result was larger, and it is the one most security leaders never claim.
5 min readReview · 10 September 2026
The After-Action Review Is Where Review Happens
Exercises produce findings. After-action reviews produce change, and only when the corrective action has an owner, a date, and a place in the next plan. Four conflict-affected operating environments, two country evacuations, and a post-earthquake recovery taught what a rigorous after-action review looks like, who has to own what comes out of it, and how findings feed threat intelligence rather than a filing cabinet.
5 min readReview · 9 September 2026
Three Numbers a Protective Program Must Report
Activity counts are not measures. A protective program that reports patrols completed and alerts reviewed is describing effort, and effort is not what leadership is paying for. Three numbers describe effectiveness: detection time, response time, and mitigation effectiveness. Each needs a defined clock and a defined denominator, or the number is theatre. This article sets out how each was defined and moved in practice.
5 min read