EMStool LLC — Cadence MIH Scheduling Platform

Internal Audit Program

Policy #: IAP-2026-01 Effective Date: July 16, 2026 Version: 1.0 Next Review: July 16, 2027

1. Purpose

This program defines a recurring, scheduled review of access logs and policy compliance — the piece SOC2 5.36 / ISO 27001 identifies as missing beyond simply having audit logs available to review on request. It satisfies the requirement for a formal internal audit cadence, scoped appropriately for a one-engineer team (Security Officer self-review, not a separate audit department).

2. Schedule

Quarterly, on the 1st business day of January, April, July, and October. An automated reminder email fires on that schedule (see Section 4) so the review does not depend on manual tracking.

3. Review Checklist

4. Automated Reminder

An automated quarterly email reminder (Resend, same recipient list as the security-alert/inactive-user notifications) links to this checklist. Completion itself is manual — the Security Officer works through the checklist and notes findings below — but the schedule is enforced by automation, not memory.

5. Findings Log

QuarterReviewed ByFindingsActions Taken
No reviews conducted yet — first scheduled review is the next quarterly reminder after this program's effective date.