Internal Audit Policy
Purpose
Section titled “Purpose”This policy defines how Cadence OneFive conducts internal audits of the ISMS, in accordance with ISO 27001:2022 clause 9.2.
Audit Program
Section titled “Audit Program”Cadence OneFive engages Kirkpatrick Price to conduct an annual internal audit of the ISMS. The audit covers ISMS clauses (4–10) and a sample of applicable Annex A controls as documented in the Statement of Applicability.
Using an external firm satisfies the auditor independence requirement — the auditor does not audit their own work.
Audit Planning
Section titled “Audit Planning”The CISO coordinates with Kirkpatrick Price to define the audit scope, criteria, and schedule each year. The plan is approved by the Head of Platform.
Protection of Production Systems
Section titled “Protection of Production Systems”Auditor access to production systems and source code is read-only and time-limited. Audit evidence is gathered from exports, logs, and screenshots rather than direct interaction with live services.
Reporting and Follow-Up
Section titled “Reporting and Follow-Up”Kirkpatrick Price delivers an audit report with findings classified as major nonconformity, minor nonconformity, observation, or conformity. Nonconformities are tracked through the Corrective Action Procedure. Audit results are reported during management review per ISMS Manual §9.3.
Audit reports and evidence are retained for a minimum of 3 years.
Roles and Responsibilities
Section titled “Roles and Responsibilities”| Role | Responsibility |
|---|---|
| Head of Platform | Approves audit plan and auditor access to systems; reviews audit results |
| CISO | Coordinates audit logistics; tracks findings to closure; reports results in management review |
| Kirkpatrick Price | Conducts audit independently; documents findings and evidence |
| All Personnel | Cooperate with auditors; provide requested evidence |
Related Documents
Section titled “Related Documents”- ISMS Manual — ISMS governance and management review
- Statement of Applicability — Controls in scope for audit
- Corrective Action Procedure — Handling of audit nonconformities
- GitHub Access Policy — Auditor team access controls
Policy Review
Section titled “Policy Review”- This policy will be reviewed annually and updated as necessary to reflect changes in audit requirements, ISMS scope, or organizational context.
- Last reviewed/updated: 2026-08-25
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
