CTDISR-2025 Section 17 requires an internal audit function for cybersecurity and continuous compliance monitoring. The internal audit is not just a preparatory exercise for the external PTA audit: it is an ongoing compliance control in its own right, and evidence of its conduct and findings is itself an audit evidence item.

An internal audit conducted rigorously, with genuine findings and documented remediation, demonstrates a compliance programme that functions between external audit cycles rather than one that activates only in response to external scrutiny. Auditors can distinguish the two: a compliance programme with clean internal audit records that perfectly match the external audit's findings is less credible than one that has found and addressed its own gaps.

The Internal Audit Methodology

The internal audit uses the same assessment approach as the external audit: for each CTDISR control, review whether the control exists, whether it is functioning, and whether evidence of its operation is available and current. The three-part test of implementation, currency, and accountability applies identically.

The difference from the external audit is scope and frequency: the internal audit does not need to cover all 104 controls in exhaustive depth every cycle. A risk-based approach covers the highest-priority controls (those with previous findings, those under active remediation, and those where new risks have emerged) in every cycle, and rotates through the lower-priority controls on a longer cadence.

An annual internal audit cycle that covers all 104 controls, with higher-priority controls reviewed quarterly, is the operational standard. This means the internal audit is not a single annual event but a rolling programme of review activities that together cover the full framework.

Conducting the Audit

Start with a preparation phase: gather the current state of evidence for each control being reviewed in this cycle. For governance controls, this means ISSC minutes, board reports, risk register versions. For technical controls, this means configuration extracts, scan reports, access review records. For training controls, this means completion records and simulation results.

The review phase examines each evidence item against the three-part test. For each control, document: the evidence reviewed, the assessment of implementation status, any gaps or deficiencies identified, and the recommended action.

The evidence review must be independent of the function being reviewed. Whoever manages the RADIUS server should not conduct the internal audit of access controls on the RADIUS server. In small ISPs where separation is difficult, the CISO reviews operational team controls, and the CEO or a designated board member reviews CISO-level governance controls.

Documenting Findings

Internal audit findings should be documented using the same classification as external findings: Critical (control absent), Major (control partial or undocumented), Minor (control present but documentation or review cadence incomplete). This consistency means the internal and external audit findings are directly comparable, which is useful for tracking whether internal remediation activities are closing the gaps external auditors would find.

For each finding, the documentation records: the control reference (CTDISR section and control number), the finding description, the finding classification, the recommended remediation, the responsible owner, and the target remediation date.

Internal audit findings are not failures to be hidden: they are the evidence that the internal audit programme is functioning. An internal audit report with no findings is less credible than one that identifies a handful of minor gaps and tracks their remediation. The value of the internal audit is precisely that it finds gaps before the external auditor does.

Feeding Into External Audit Preparation

The internal audit is the primary input to external audit preparation. An operator who conducts quarterly internal audit reviews has a continuously updated view of compliance posture, and when the external audit cycle approaches, preparation is a matter of closing known gaps and assembling already-maintained evidence rather than constructing a compliance picture from scratch.

Set the internal audit cycle such that a full-scope internal review is completed 60-90 days before the expected external audit date. This gives time to remediate any significant findings the internal audit surfaces before the external auditor arrives.

ISP Audit provides a scored self-assessment across all 104 CTDISR controls that serves the same diagnostic function as a structured internal audit, with the added benefit of weighted scoring across the high-priority sections. For operators who need the internal audit function owned and operated by the CISO, CISO-as-a-Service covers Section 17 as part of the governance remit. For managing internal audit findings and remediation tracking alongside all CTDISR evidence, ComplianceIQ provides the platform structure.