Services
Audit Support
An internal audit programme that exists purely to tick a clause off the standard tells you nothing useful. A good one surfaces the issues that would otherwise only appear during a certification audit, or worse, during an incident.
Hillscom covers the full cycle: designing an audit schedule that reflects your risk profile, training internal auditors so the skill stays in-house rather than depending on outside help indefinitely, and leading audits directly where independence or specialist knowledge of a standard is needed. The aim is assurance you can act on, not a folder of completed checklists.
Reviewing what is in place
A typical engagement starts with the existing programme. If one exists, it is assessed for whether it tests the right things, rather than cycling through clauses on a fixed schedule regardless of where the risk sits. The 2026 edition of ISO 14001 makes the point explicit, requiring audit programmes to have defined objectives.
Risk-based scheduling
A risk-based schedule looks different from a calendar that visits every process once a year in turn. Areas with a history of problems, processes that are new or recently changed, and functions where failure would have serious consequences are audited more often than stable, low-risk areas. This is not about auditing less. It is about directing effort where it will catch something before it becomes a bigger problem.
Training internal auditors
Over the long term, training internal auditors is often the highest-value part of the service. A well-trained team can maintain assurance year-round without relying on an outside consultant for every cycle, which keeps costs down and keeps audit knowledge inside the organisation. Training covers the mechanics of planning and conducting an audit, and the harder skill of asking the right questions and recognising when a confident answer does not hold up under a little more scrutiny.
When an external auditor adds value
Even with a capable internal team, an outside auditor is worth having in some situations: auditing a process where the usual auditor is too close to it to be independent, bringing specialist knowledge of a standard such as AS9100 or ISO 27001 that the internal team has not audited against before, or providing an outside view ahead of an important certification or recertification. These engagements are scoped specifically rather than replacing the internal programme. Before a first certification, a mock audit is often the most useful form this takes.
Findings that get closed
Whatever the audit uncovers, the output is written to be used, not filed. Findings are linked to a root cause where one can be identified, framed in terms of the risk they represent, and followed up to confirm corrective action closes them rather than just being marked complete on a spreadsheet.
Reports are concise and readable rather than padded to look thorough. A forty-page report that buries the three findings that matter serves nobody. Reports are structured so senior management can see the overall picture in a few minutes, while process owners still have the detail they need to fix things. Recurring themes are tracked across cycles, since a finding that keeps reappearing in a different guise usually points to a root cause further upstream, and that pattern is often more valuable than any single result.
Get in touch to talk through your internal audit needs.
Start a conversation
Talk to Hillscom
Tell us a little about your organisation and what you are trying to achieve. The first conversation is free and straightforward.