Skip to main content

How to Plan Internal Audits Across Multiple Standards

Managing ISO 27001, GDPR, NIS2, DORA, SOC 2 and others at the same time can feel impossible. Here’s how to build a single, efficient internal audit program that works across every framework.

Christophe MazzolaChristophe Mazzola· Practicing CISO · Founder of Cyber Academy4 min read
How to Plan Internal Audits Across Multiple Standards

Running internal audits for one standard is already a challenge. Running them for three, four, or five at once? That’s where most organisations burn out ; duplicated work, inconsistent findings, endless checklists, and “audit season” panic every quarter.

But the truth is simple:You don’t need multiple audit programs. You need one integrated engine.

Most organisations make the same mistake: They plan internal audits per standard.

ISO 27001 audit here. GDPR audit there. NIS2 gap check. DORA readiness review. SOC 2 control testing.

Different people. Different methodologies. Different reports. And 80% of the work overlaps.

The field-tested reality:You can audit multiple standards with one unified, risk-driven, evidence-focused program ; if you structure it properly.

Here’s how.

1. Start by Building a Single Control Library (Your Audit Backbone)

Before planning audits, unify the controls.

Most frameworks overlap heavily:

  • ISO 27001 ; security governance backbone
  • SOC 2 ; trust services criteria
  • GDPR ; privacy + accountability
  • NIS2 ; security + operational resilience
  • DORA ; ICT resilience + governance

What organisations don’t realise: They’re all asking the same questions, just using different vocabulary.

Your first task: Consolidate everything into one control library mapped to each framework.

Example unified control themes:

  • access management
  • incident management
  • change control
  • asset management
  • vendor risk
  • logging & monitoring
  • continuity & recovery
  • secure development
  • data protection
  • governance & accountability

Anecdote: A company we worked with reduced 147 required controls across four frameworks to 63 unified controls. The audit effort dropped by half.

Unified library → unified audits.

2. Audit the Controls, Not the Standards

Organisations fail when they audit compliance framework by framework. Internal audits should instead focus on control effectiveness.

Example: Instead of auditing “ISO A.9.2 – User Access Management,” audit your access management process once, then map results to:

  • ISO 27001
  • SOC 2 CC6
  • NIS2 Art. 21
  • DORA Article 10
  • GDPR (security of processing)

One test = many compliances.

This is how real GRC teams scale.

3. Prioritise Audits Based on Risk, Not Calendar Obligations

Many organisations run internal audits based on external audit deadlines.

Better approach: Plan based on:

  • business risk
  • regulatory impact
  • incident history
  • recent system changes
  • new vendors
  • new services
  • staffing changes
  • past audit issues

Anecdote: An organisation spent three months auditing low-risk HR processes because it was “on the calendar”, meanwhile, backups hadn’t been tested for over a year.

Risk > routine.

4. Build a Rolling 12-Month Audit Calendar (Quarterly Themes)

Forget the “big annual internal audit.” It’s outdated and ineffective.

Use a rolling 12-month plan with quarterly focus areas.

Example structure:

Q1 – Governance & Risk

  • leadership involvement
  • risk methodology
  • SoA alignment
  • policy governance
  • regulatory obligations

Q2 – Technical Controls

  • access reviews
  • vulnerability management
  • secure configuration

Q3 – Privacy & Third Parties

  • GDPR requirements
  • DPIAs
  • vendor assessments
  • third-party risk

Q4 – Resilience & Operations

  • incident response testing
  • crisis simulations
  • DORA/NIS2 operational checks

This ensures full coverage without overwhelming teams.

5. Use One Evidence Repository ; Tagged per Standard

You don’t need separate evidence folders for ISO, SOC 2, GDPR, NIS2, DORA.

You need one evidence library with tagging.

Example:

  • “Access Review Q1 2025” – ISO: A.5.18 – SOC 2: CC6.1 – NIS2: Art. 21 (2)(e) – DORA: Article 10 (2)(d)

One piece of evidence, many frameworks.

Anecdote: A client reduced audit preparation time by 70% after implementing tagging.

Unified evidence = unified audits.

6. Standardise Your Audit Checklist to 6 Universal Questions

Internal audits don’t need 60-page checklists per standard.

You need six universal audit questions:

  1. Does the process exist?
  2. Is it documented?
  3. Is it implemented as documented?
  4. Is evidence available and reliable?
  5. Is ownership clear?
  6. Does it effectively reduce risk?

These six questions apply to every framework.

Auditors don’t test standards. They test behaviour, consistency, and evidence.

7. Train Auditors to Think Systemically, Not Framework-by-Framework

The best internal auditors don’t say, “I’m here to check ISO clause A.8.12.”

They say: “I’m here to evaluate how you manage change, risk, and evidence.”

Internal auditors need to understand:

  • the business
  • the systems
  • the workflows
  • the culture
  • the real risk vs documented risk

Anecdote: We trained an internal audit team to audit by process instead of by clause. Suddenly, audits became useful ; because findings were actionable, not academic.

8. Document Findings in a Universal Format That Maps to All Frameworks

Stop writing separate findings per regulation. Write one finding and tag it.

Example finding:“Privileged access reviews are inconsistent across systems.”

Tags:

  • ISO A.5.18
  • SOC 2 CC6
  • DORA Art. 10
  • GDPR Art. 32 (security of processing)

One finding → multi-standard impact.

This improves reporting and simplifies management action plans.

9. Turn Internal Audits Into Decision Tools, Not Punishment Tools

Internal audits are not about “catching failures.” They are about informing leadership and improving resilience.

A good audit delivers:

  • clear business impact
  • cost implications
  • risk exposure
  • required decisions
  • prioritised recommendations

If your audit reports don’t lead to decisions, your program is noise ; not governance.

10. Use ISO 19011 as Your Master Methodology

ISO 19011 isn’t talked about enough. It’s the universal standard for auditing management systems.

It teaches:

  • planning
  • conducting audits
  • competence requirements
  • reporting
  • follow-up
  • ethical foundations

You can use it for ISO 27001 + GDPR + NIS2 + DORA + SOC 2. It’s the glue.

Anecdote: Every unified audit program that works long-term uses ISO 19011 as its backbone.

Final Thought

Internal audits don’t scale when you treat frameworks as separate worlds. They scale when you treat compliance as a single governance system with multiple outputs.

Unified audits:

  • reduce cost
  • reduce audit fatigue
  • improve evidence quality
  • shorten external audits
  • strengthen risk visibility
  • align leadership
  • protect the business

One system. Many frameworks. Zero duplication.

If you want to build a unified audit program across ISO 27001, GDPR, SOC 2, NIS2, and DORA ; simple, efficient, and evidence-driven ; that’s exactly what we teach in the Cyber Academy Lead Auditor Programs. Join the next session and transform the way your organisation audits.

Want the next field note in your inbox?

The GRC Brief newsletter. Five links and one short take, every Monday at 8am CET. Three-minute read.