Information Security
ISO/IEC 27001 Lead Auditor: leading ISMS audits
A course for professionals who want to plan, conduct, report and lead audits of an information security management system, following recognised audit principles.
Request this courseAt a glance
- Subject
- Auditing against ISO/IEC 27001
- Suited to
- Aspiring lead auditors and internal auditors
- Format
- Online, classroom or in-company
- Recognition
- CQI/IRCA Certified Training through a recognised training partner
About this course
A lead auditor plans and leads audits of a management system and makes sure findings are well founded, objective and useful. This course covers the full audit: from preparation and fieldwork to reporting and follow-up.
The course follows the guidelines for auditing management systems in ISO 19011 and looks at how certification bodies conduct audits. That makes it useful for internal and supplier audits as well as for those aiming at certification audits.
Courses are delivered by experienced professionals with relevant subject expertise and, where applicable, through specialised training partners.
Who it is for
Information security professionals who want to conduct or lead audits
Internal auditors aspiring to the lead auditor role
Quality and compliance managers
Consultants preparing organisations for audits
Auditors (in training) at certification bodies
What you will learn
Explain the purpose and requirements of ISO/IEC 27001 from an audit perspective
Apply audit principles and the guidelines of ISO 19011
Plan an audit: objective, scope, criteria and audit plan
Gather audit evidence through interviews, observation and document review, and justify sampling
Record and classify findings and nonconformities objectively
Lead an audit team, run opening and closing meetings and report
Assess the follow-up of corrective actions
Programme
ISO/IEC 27001 from an audit perspective
- Structure and requirements of the standard
- Risk assessment and Annex A as audit subjects
- What a working ISMS looks like
Audit principles and ISO 19011
- First-, second- and third-party audits
- Audit principles and auditor behaviour
- The audit programme
Certification audits
- The role of certification bodies and accreditation
- Stages of a certification audit
- Relevant standards such as ISO/IEC 17021-1 and ISO/IEC 27006
Preparing an audit
- Setting objective, scope and criteria
- Document review
- Audit plan and working documents
Conducting an audit
- The opening meeting
- Gathering and verifying evidence
- Interview techniques and sampling
Reporting and follow-up
- Writing findings and nonconformities
- Closing meeting and audit report
- Follow-up and effectiveness of actions
Format
Online
Live remote sessions, with room for questions and exercises.
Classroom
Together in a training room, with the trainer and other participants.
In-company
A closed course for your team, at your premises or online.
Depending on the course, schedule and group size, training can be organised online, in a classroom or as a closed in-company course.
Exam and certification
Participants are usually assessed during the course and through a final exam. The exact exam format and conditions are set by the training partner; we confirm them in the offer.
On successful completion you receive a certificate from the training partner.
This course is delivered as CQI/IRCA Certified Training through a training partner recognised for it.
Successfully completing a Lead Auditor course does not automatically mean registration as an IRCA auditor. Registration carries additional requirements, such as audit experience, set by CQI/IRCA itself.
In-company training
For teams, for example a group of internal auditors, the course can be organised as a closed in-company course. In a certified variant the programme is largely fixed; exercises can relate to your own context where possible.
Frequently asked questions
Is Vedeum itself CQI/IRCA accredited?
CQI/IRCA recognition belongs to the specific course and the training partner delivering it, not to Vedeum as the organiser. Vedeum organises this course through training partners that deliver it as CQI/IRCA Certified Training.
Will I be registered as an IRCA auditor after the course?
Not automatically. A certificate of successful completion is an important step, but registration as an IRCA auditor carries additional requirements, such as audit experience. CQI/IRCA sets those requirements.
Do I need prior knowledge?
Knowledge of ISO/IEC 27001 is recommended, for example through the ISO/IEC 27001 Training or practical experience with an ISMS. Exact entry requirements differ per training partner and are agreed with you in advance.
Can I use this course for internal audits?
Yes. The skills apply directly to internal and supplier audits, even if you do not intend to become a certification auditor.
Discuss your training needs
Tell us which course you are looking for, for whom and in what period. You will receive a tailored proposal.
Request a proposal