Skip to content

Internal Audit Policy

This policy defines how Cadence OneFive conducts internal audits of the ISMS, in accordance with ISO 27001:2022 clause 9.2.

Cadence OneFive engages Kirkpatrick Price to conduct an annual internal audit of the ISMS. The audit covers ISMS clauses (4–10) and a sample of applicable Annex A controls as documented in the Statement of Applicability.

Using an external firm satisfies the auditor independence requirement — the auditor does not audit their own work.

The CISO coordinates with Kirkpatrick Price to define the audit scope, criteria, and schedule each year. The plan is approved by the Head of Platform.

Auditor access to production systems and source code is read-only and time-limited. Audit evidence is gathered from exports, logs, and screenshots rather than direct interaction with live services.

Kirkpatrick Price delivers an audit report with findings classified as major nonconformity, minor nonconformity, observation, or conformity. Nonconformities are tracked through the Corrective Action Procedure. Audit results are reported during management review per ISMS Manual §9.3.

Audit reports and evidence are retained for a minimum of 3 years.

Role Responsibility
Head of Platform Approves audit plan and auditor access to systems; reviews audit results
CISO Coordinates audit logistics; tracks findings to closure; reports results in management review
Kirkpatrick Price Conducts audit independently; documents findings and evidence
All Personnel Cooperate with auditors; provide requested evidence
  • This policy will be reviewed annually and updated as necessary to reflect changes in audit requirements, ISMS scope, or organizational context.
  • Last reviewed/updated: 2026-08-25

Internal & Confidential: This page is only available in the internal handbook and contains confidential information.