Skip to content

Information Security

ISO/IEC 27001 Lead Auditor: leading ISMS audits

A course for professionals who want to plan, conduct, report and lead audits of an information security management system, following recognised audit principles.

Request this course

At a glance

Subject
Auditing against ISO/IEC 27001
Suited to
Aspiring lead auditors and internal auditors
Format
Online, classroom or in-company
Recognition
CQI/IRCA Certified Training through a recognised training partner

About this course

A lead auditor plans and leads audits of a management system and makes sure findings are well founded, objective and useful. This course covers the full audit: from preparation and fieldwork to reporting and follow-up.

The course follows the guidelines for auditing management systems in ISO 19011 and looks at how certification bodies conduct audits. That makes it useful for internal and supplier audits as well as for those aiming at certification audits.

Courses are delivered by experienced professionals with relevant subject expertise and, where applicable, through specialised training partners.

Who it is for

  • Information security professionals who want to conduct or lead audits

  • Internal auditors aspiring to the lead auditor role

  • Quality and compliance managers

  • Consultants preparing organisations for audits

  • Auditors (in training) at certification bodies

What you will learn

  • Explain the purpose and requirements of ISO/IEC 27001 from an audit perspective

  • Apply audit principles and the guidelines of ISO 19011

  • Plan an audit: objective, scope, criteria and audit plan

  • Gather audit evidence through interviews, observation and document review, and justify sampling

  • Record and classify findings and nonconformities objectively

  • Lead an audit team, run opening and closing meetings and report

  • Assess the follow-up of corrective actions

Programme

  1. ISO/IEC 27001 from an audit perspective

    • Structure and requirements of the standard
    • Risk assessment and Annex A as audit subjects
    • What a working ISMS looks like
  2. Audit principles and ISO 19011

    • First-, second- and third-party audits
    • Audit principles and auditor behaviour
    • The audit programme
  3. Certification audits

    • The role of certification bodies and accreditation
    • Stages of a certification audit
    • Relevant standards such as ISO/IEC 17021-1 and ISO/IEC 27006
  4. Preparing an audit

    • Setting objective, scope and criteria
    • Document review
    • Audit plan and working documents
  5. Conducting an audit

    • The opening meeting
    • Gathering and verifying evidence
    • Interview techniques and sampling
  6. Reporting and follow-up

    • Writing findings and nonconformities
    • Closing meeting and audit report
    • Follow-up and effectiveness of actions

Format

  • Online

    Live remote sessions, with room for questions and exercises.

  • Classroom

    Together in a training room, with the trainer and other participants.

  • In-company

    A closed course for your team, at your premises or online.

Depending on the course, schedule and group size, training can be organised online, in a classroom or as a closed in-company course.

Exam and certification

Participants are usually assessed during the course and through a final exam. The exact exam format and conditions are set by the training partner; we confirm them in the offer.

On successful completion you receive a certificate from the training partner.

This course is delivered as CQI/IRCA Certified Training through a training partner recognised for it.

Successfully completing a Lead Auditor course does not automatically mean registration as an IRCA auditor. Registration carries additional requirements, such as audit experience, set by CQI/IRCA itself.

In-company training

For teams, for example a group of internal auditors, the course can be organised as a closed in-company course. In a certified variant the programme is largely fixed; exercises can relate to your own context where possible.

Discuss your training needs →

Frequently asked questions

Is Vedeum itself CQI/IRCA accredited?

CQI/IRCA recognition belongs to the specific course and the training partner delivering it, not to Vedeum as the organiser. Vedeum organises this course through training partners that deliver it as CQI/IRCA Certified Training.

Will I be registered as an IRCA auditor after the course?

Not automatically. A certificate of successful completion is an important step, but registration as an IRCA auditor carries additional requirements, such as audit experience. CQI/IRCA sets those requirements.

Do I need prior knowledge?

Knowledge of ISO/IEC 27001 is recommended, for example through the ISO/IEC 27001 Training or practical experience with an ISMS. Exact entry requirements differ per training partner and are agreed with you in advance.

Can I use this course for internal audits?

Yes. The skills apply directly to internal and supplier audits, even if you do not intend to become a certification auditor.

Discuss your training needs

Tell us which course you are looking for, for whom and in what period. You will receive a tailored proposal.

Request a proposal