ISO 27001 Audit: Types, Stages, and How to Prepare

An ISO 27001 audit is a systematic, evidence-based review of your Information Security Management System (ISMS) to confirm it conforms to the requirements of ISO/IEC 27001:2022. In practice, “audit” covers several related activities: the internal audit your own organization runs under clause 9.2, the two-part certification audit (Stage 1 and Stage 2) carried out by an independent certification body, and the ongoing surveillance and recertification audits that keep your certificate valid over its three-year cycle. Understanding how each audit works — and what an auditor actually looks for — is the difference between a smooth assessment and a list of nonconformities.

This guide explains each audit type, what auditors check against clauses 4 to 10 and the applicable Annex A controls, how to prepare, and the auditor competence that sits behind a credible result. For the full certification journey from application to certificate, see our ISO 27001 certification process guide.

Why the ISO 27001 audit matters

The audit is the mechanism that turns a documented ISMS into a trusted one. Anyone can write a security policy; an audit tests whether that policy is implemented, followed, and effective. For your organization, audits surface gaps before an attacker or a regulator does, drive continual improvement, and provide the independent assurance that customers and partners increasingly demand in contracts and vendor questionnaires.

It is worth being precise about what gets certified. ISO 27001 certification is awarded to organizations, not to individuals. People earn qualifications — through ISO 27001 lead auditor training or ISO 27001 internal auditor training — so they can competently plan and conduct audits, but the certificate itself belongs to the ISMS of the organization that meets the standard.

The different types of ISO 27001 audit

There are two broad families of ISO 27001 audit: internal (first-party) audits that you run on yourself, and external (third-party) audits conducted by an accredited certification body. The external family then breaks into Stage 1, Stage 2, surveillance, and recertification assessments.

1. ISO 27001 internal audit (clause 9.2)

The internal audit is a mandatory requirement of ISO 27001. Clause 9.2 requires your organization to conduct internal audits at planned intervals to determine whether the ISMS conforms both to the organization’s own requirements and to the requirements of the standard, and whether it is effectively implemented and maintained.

Two principles matter here. First, internal audits must be planned against a program that considers the importance of the processes and the results of previous audits. Second, auditors must be selected to ensure objectivity and impartiality — auditors should not audit their own work. A member of the security team can audit HR or IT operations, but ideally should not audit the controls they personally designed and run. Many organizations build this independence by training several staff through internal auditor training so they can audit across departments.

The internal audit is your dress rehearsal. Done honestly, it finds the weaknesses a certification auditor would find — while you still have time to fix them.

2. Stage 1 certification audit (documentation and readiness review)

Once your ISMS has been operating for a reasonable period, an accredited certification body conducts the Stage 1 audit. This is a documentation and readiness review. The auditor confirms that the mandatory ISMS documentation exists and is coherent: the ISMS scope, the information security policy, the risk assessment and risk treatment methodology, the Statement of Applicability (SoA), the risk treatment plan, and records of internal audit and management review.

Stage 1 has two purposes: to verify that you are ready for the more rigorous Stage 2, and to plan that assessment. The auditor also checks that your SoA justifies the inclusion or exclusion of each of the 93 Annex A controls, organized across the four themes — organizational, people, physical, and technological. A weak or contradictory SoA is one of the most common Stage 1 findings.

3. Stage 2 certification audit (implementation and effectiveness)

The Stage 2 audit is where certification is genuinely earned. Conducted on-site or remotely, it assesses whether your ISMS is actually implemented and effective — not just documented. The auditor gathers objective evidence by sampling records, observing processes, and interviewing staff, then evaluates conformity against clauses 4 to 10 of the standard and every Annex A control you declared applicable in your SoA.

Expect the auditor to trace threads end to end: from a risk identified in your assessment, to the control chosen to treat it, to evidence that the control operates as intended. Access reviews, change records, incident logs, supplier assessments, backup and restore tests, and awareness training records are all typical sampling points. If the auditor finds nonconformities, they are classified as major or minor; majors must be resolved before a certificate can be recommended.

4. Surveillance audits

Certification is not a one-time event. After your certificate is issued, the certification body conducts surveillance audits, usually annually, to confirm that the ISMS remains conforming and continues to improve. Surveillance audits are narrower than the full Stage 2 assessment — the auditor samples a subset of the ISMS each visit — but they always review core areas such as internal audit, management review, corrective actions, complaints, and any changes to scope or risk.

5. Recertification audit

Because an ISO 27001 certificate is valid for three years, a recertification audit takes place before it expires. This is a comprehensive reassessment, similar in depth to Stage 2, that evaluates the continued conformity and effectiveness of the whole ISMS and considers its performance across the full certification cycle. A successful recertification renews the certificate for another three years.

What an ISO 27001 auditor checks

Across all of these audits, the auditor is testing the same fundamental question in different depths: does the ISMS meet the requirements, and does it work? Concretely, an auditor examines:

  • Clauses 4 to 10 — context of the organization, leadership, planning (including risk assessment and treatment), support, operation, performance evaluation, and improvement.
  • Applicable Annex A controls — the subset of the 93 controls your SoA declares relevant, with evidence that each operates.
  • The Statement of Applicability — that every control is justified as included or excluded and mapped to your risk treatment.
  • Records and evidence — sampled, not exhaustively reviewed, to form a representative picture of conformity.
  • Effectiveness, not just existence — whether controls achieve their intended information security outcomes.

Auditors do not check every record; they sample. That means consistent, well-organized evidence matters more than volume. A tidy control that produces reliable records will outperform an elaborate control with patchy documentation.

How to prepare for an ISO 27001 audit

Preparation is mostly about closing the gap between what your documents say and what your people do. A practical checklist:

  1. Run a genuine internal audit first. Treat clause 9.2 seriously and audit the full ISMS against clauses 4 to 10 and your applicable controls. Use an ISO 27001 audit checklist built from the standard and your SoA.
  2. Clean up your SoA and risk treatment plan. Ensure every Annex A control has a clear applicability decision and a rationale that matches your risk assessment.
  3. Complete a management review. Leadership must demonstrably review ISMS performance, resources, and improvement opportunities.
  4. Close corrective actions. Open nonconformities from previous internal audits should be resolved, with evidence of root-cause analysis.
  5. Organize your evidence. Make records for access control, incident management, supplier security, backups, and training easy to retrieve — auditors sample, and slow retrieval erodes confidence.
  6. Brief your people. Staff should be able to explain, in their own words, the parts of the ISMS they own. Interviews are a core evidence source at Stage 2.

For the broader picture of how assessments are planned and conducted across management systems, our ISO audit procedure overview is a useful companion.

The ISO 19011 approach and auditor competence

ISO 27001 audits are conducted in line with the principles of ISO 19011, the international guidance for auditing management systems. ISO 19011 sets out the discipline behind a credible audit: integrity, fair presentation, due professional care, confidentiality, independence, and an evidence-based approach. It also frames the audit as a managed program — planning, conducting, reporting, and following up — rather than a single visit.

Competence is central to that approach. An audit is only as reliable as the auditor performing it, which is why formal training matters. Individuals who will lead certification-style assessments typically complete ISO 27001 lead auditor training, while those maintaining an in-house program take ISO 27001 internal auditor training. You can view upcoming sessions on the IAS training schedule.

Certification and training roles should be described accurately and separately. IAS provides certification within its applicable UQAS accreditation scope and markets applicable Lead Auditor training in association with EAS. EAS holds JAS-ANZ accreditation for applicable certification activities and is a CQI and IRCA Approved Training Partner for applicable certified Lead Auditor courses. EAS handles the applicable candidate evaluation, training and assessment for those programmes. Keeping these roles distinct supports clear communication about impartiality and responsibility.

If you are ready to plan your ISMS assessment or enroll your team in auditor training, contact us to discuss the right path. You can also explore full ISO 27001 certification in the USA or browse the wider range of standards on our ISO certification hub.

Frequently Asked Questions

What is the difference between an internal audit and a certification audit for ISO 27001?
An internal audit (clause 9.2) is conducted by your own organization to check that your ISMS conforms to the standard and is effective — it is a required, self-managed activity. A certification audit is conducted by an independent, accredited certification body in two stages (Stage 1 and Stage 2) and results in the ISO 27001 certificate. The internal audit is preparation; the certification audit is the formal assessment.
What happens in a Stage 1 versus a Stage 2 ISO 27001 audit?
The Stage 1 audit is a documentation and readiness review: the auditor checks that your ISMS scope, policy, risk assessment, Statement of Applicability, and required records exist and are coherent, and then plans Stage 2. The Stage 2 audit assesses whether the ISMS is actually implemented and effective by sampling evidence and interviewing staff against clauses 4 to 10 and your applicable Annex A controls.
How often are ISO 27001 surveillance audits conducted?
Surveillance audits are usually carried out annually during the three-year certification cycle. They confirm the ISMS remains conforming and continues to improve, and they typically focus on core areas such as internal audit, management review, corrective actions, complaints, and any changes to scope or risk.
What does an ISO 27001 auditor check?
An auditor checks conformity to clauses 4 to 10 of ISO/IEC 27001:2022 and to the Annex A controls you have declared applicable in your Statement of Applicability. They verify that controls are not only documented but implemented and effective, gathering objective evidence by sampling records, observing processes, and interviewing staff.
Who can conduct an ISO 27001 internal audit?
Anyone with suitable competence and objectivity can conduct an internal audit, provided they do not audit their own work. Many organizations train several staff through internal auditor courses so that auditors can assess departments other than their own, preserving the impartiality that ISO 27001 and ISO 19011 require.
How do I prepare my ISMS to pass an ISO 27001 audit?
Run a thorough internal audit against the full standard, ensure your Statement of Applicability and risk treatment plan are current and justified, complete a management review, close outstanding corrective actions, organize your evidence for easy retrieval, and brief staff on the parts of the ISMS they own. This closes the gap between documentation and day-to-day practice, which is exactly what auditors sample for.