Step 6 of 6 · Check · Act
Audit and improvement Prove it, then get better.
This is where the cycle closes. You record what internal and external audits found and follow the corrections through to the end.

What it is about
A management system lives on checking itself. That is why auditors look less at whether everything is perfect and more at whether deviations are spotted and fixed. If you document that properly, every audit becomes more relaxed.
How you go about it
- You plan internal audits and record the findings, including those from external audits.
- For each finding you create a corrective action with an owner and a deadline.
- Once everything is evidenced, you start the next round with the current status as the starting point.
What UniqSuite does for you
- Findings, corrections and evidence sit in one place. The auditor gets a report instead of a folder.
- Your history is kept. You see how the status develops from round to round.
What you end up with
An audit report with findings, corrective actions and their status.
Where the requirements come from
- ISO/IEC 27001, clauses 9.2 and 9.3: internal audit and management review
- ISO/IEC 27001, clause 10: continual improvement, nonconformity and corrective action
- BSIG section 30(2) no. 6: assessing the effectiveness of the measures
The references show where the requirements come from. They do not replace a legal assessment.
How far along are you with this step?
The quick check shows you in two minutes. Or let us show you UniqSuite with your own questions.
