ISO 27001 Lead Auditor - Domain 5 Study Guide
Conducting an ISO/IEC 27001 Audit
1. STAGE 1 vs STAGE 2 AUDIT
Stage 1 Audit (Document Review/Readiness Assessment)
Objectives:
Evaluate the auditee's documented information and readiness for Stage 2
Review ISMS scope, policies, and procedures
Verify understanding of ISO/IEC 27001 requirements
Plan the Stage 2 audit
Key Activities:
Review Statement of Applicability (SoA)
Evaluate risk assessment and treatment methodology
Check information security policy and objectives
Review organizational context and interested parties analysis
Assess internal audit and management review records
Verify locations, processes, and controls to be audited
Identify potential nonconformities or concerns
Confirm audit resources and timing for Stage 2
Documented Information Evaluation Criteria:
Completeness - All required documents present per ISO/IEC 27001
Accuracy - Information is correct and current
Consistency - No contradictions between documents
Accessibility - Documents available to relevant personnel
Traceability - Links between risks, controls, and requirements clear
Approval - Proper authorization and version control
Stage 2 Audit (Implementation Assessment)
Objectives:
Verify effective implementation of the ISMS
Assess conformity with ISO/IEC 27001 requirements
Evaluate the ISMS's ability to achieve objectives
Determine recommendation for certification
Key Activities:
Conduct opening meeting
Verify implementation of controls from SoA
Interview personnel at all levels
Observe processes and practices in action
Sample evidence across different areas
Test effectiveness of controls
Review records and logs
Assess compliance with legal/regulatory requirements
Conduct closing meeting
Report findings and conclusions
2. THE OPENING MEETING
Objectives
Introduce audit team and establish rapport
Confirm audit scope, objectives, and criteria
Review audit plan and schedule
Establish communication channels
Address logistics and safety requirements
Clarify roles and responsibilities
Content/Agenda
1. Introductions - Audit team, auditee representatives, observers
2. Confirmation of audit scope - Boundaries, sites, processes included/excluded
3. Review of audit plan - Schedule, areas to be covered, timing
4. Audit methods - Sampling approach, evidence collection techniques
5. Communication protocols - How findings will be shared, escalation procedures
6. Confidentiality and ethics - Code of conduct, information handling
7. Roles and responsibilities - Who will be interviewed, guides, observers
8. Safety and security - Site-specific requirements, access procedures
9. Reporting - Daily debriefs, closing meeting timing
10. Questions and clarifications - Address concerns from auditee
Best Practices
Keep it concise (30-45 minutes typically)
Set a collaborative tone, not adversarial
Confirm attendance of key personnel
Document attendees and key agreements
Use clear, jargon-free language
3. ROLES AND RESPONSIBILITIES DURING AUDIT
Lead Auditor
Overall audit responsibility and coordination
Final decisions on audit findings and conclusions
Communication with auditee management
Audit report approval
Audit Team Members
Conduct interviews and collect evidence
Document findings in working papers
Report to lead auditor
Contribute to audit conclusions
Guides
Responsibilities:
Facilitate access to locations and personnel
Arrange interviews and meetings
Provide local knowledge and context
Clarify questions about processes
Limitations:
Should not influence audit evidence
Cannot answer on behalf of auditees
Should remain neutral observers
Observers
Responsibilities:
Learn from the audit process
May be regulators, customers, or trainees
Must sign confidentiality agreements
Limitations:
Cannot interfere with audit activities
Cannot influence audit findings
Typically cannot ask questions directly
Auditee Representatives
Provide requested information and evidence
Arrange access to facilities and personnel
Clarify processes and procedures
Respond to audit findings
4. COMMUNICATION BEST PRACTICES
During Interviews
Open-ended questions - "How do you...?" "Can you describe...?"
Active listening - Paraphrase to confirm understanding
Non-leading questions - Avoid suggesting desired answers
Probing techniques - "Can you give me an example?" "What happens when...?"
Professional demeanor - Respectful, objective, non-confrontational
Cultural sensitivity - Adapt to local communication styles
Throughout the Audit
Daily debriefs - Keep auditee informed of progress
Transparency - Share observations as they arise (no surprises)
Factual language - Objective descriptions, not opinions
Appropriate escalation - Critical issues to lead auditor immediately
Written confirmation - Document key agreements and decisions
Conflict Resolution Techniques
1. Active listening - Understand all perspectives fully
2. Seek common ground - Focus on shared objectives
3. Facts-based discussion - Reference objective evidence
4. Escalate appropriately - Involve lead auditor or management when needed
5. Maintain professionalism - Stay calm and respectful
6. Document disagreements - Record differing viewpoints in audit records
5. EVIDENCE COLLECTION PROCEDURES AND TOOLS
Interview
Purpose: Gather information about processes, knowledge, and practices
Best Practices:
Prepare questions in advance
Interview personnel at multiple levels
Verify competence and awareness
Cross-check information with other sources
Advantages: Rich contextual information, assess understanding Disadvantages: Subjective,
time-consuming, potential bias
Documented Information Review
Purpose: Verify policies, procedures, and records exist and are appropriate
What to Review:
Policies and procedures
Risk assessments and treatment plans
Statement of Applicability
Records (logs, incident reports, training records)
Contracts, agreements
Internal audit and management review minutes
Best Practices:
Check version control and approval
Verify accessibility to relevant personnel
Assess adequacy and currency
Look for consistency across documents
Observation
Purpose: See processes in action in their real environment
Best Practices:
Observe without interfering
Watch complete processes from start to finish
Note deviations from documented procedures
Verify physical and environmental controls
Advantages: Objective evidence, real-time verification Disadvantages: Hawthorne effect
(people behaving differently when observed)
Analysis
Purpose: Evaluate data and trends to assess effectiveness
Examples:
Incident trends over time
Key performance indicator (KPI) analysis
Vulnerability scan results
Compliance metrics
Sampling
Purpose: Draw conclusions about populations based on representative samples
When to Use:
Large volumes of similar transactions
Repetitive processes
Multiple similar controls
Limited audit time
Technical Verification
Purpose: Test technical controls and security measures
Examples:
Review system configurations
Examine access control settings
Test backup and recovery procedures
Verify encryption implementation
Check patch management status
6. AUDIT SAMPLING METHODS
Statistical Sampling
Definition: Uses mathematical probability to select samples
Characteristics:
Results can be extrapolated to entire population
Sample size based on confidence level and acceptable error
More defensible scientifically
Requires expertise in statistical methods
Types:
Random sampling - Every item has equal chance of selection
Systematic sampling - Select every nth item
Stratified sampling - Divide population into subgroups, sample from each
Non-Statistical (Judgmental) Sampling
Definition: Auditor uses professional judgment to select samples
Characteristics:
Based on risk, importance, or specific criteria
Cannot statistically extrapolate results
More flexible and practical
Relies on auditor experience
Approaches:
Risk-based - Focus on high-risk areas
Haphazard - Random selection without formal method
Block sampling - Select consecutive items
Judgmental - Select specific items of interest
Determining Sample Size
Factors to Consider:
Population size
Risk level
Variability in population
Desired confidence level
Available audit time
Previous audit results
Best Practices
Document sampling methodology in audit plan
Ensure samples are representative
Don't cherry-pick favorable results
Adjust sample size if initial results raise concerns
Record rationale for sample selection
7. AUDIT WORKING PAPERS
Purpose
Document evidence collected
Support audit findings and conclusions
Provide trail of audit activities
Enable quality review
Support certification decision
Essential Components
Audit identification - Audit reference, date, location
Auditor details - Who collected the evidence
Area/Process audited - Specific scope of investigation
ISO/IEC 27001 clause reference - Which requirement being audited
Evidence description - What was reviewed, observed, or tested
Findings - Conformities and nonconformities
Auditee comments - Responses or explanations
Supporting documentation - References, samples, photos
Best Practices for Development
Complete during the audit, not afterward
Be specific and detailed (who, what, when, where)
Include objective facts, not opinions
Reference source documents clearly
Use consistent format across team
Sign and date all working papers
Protect confidentiality
Retain per organizational requirements
Quality Characteristics
Complete - All necessary information present
Accurate - Facts correctly recorded
Legible - Readable by others
Objective - Free from bias
Sufficient - Enough detail to support conclusions
Traceable - Clear links to findings
8. AUDIT TEST PLANS
Purpose
Detail specific audit activities for each area
Ensure comprehensive coverage of requirements
Guide evidence collection systematically
Allocate audit resources effectively
Components
1. Audit area/process - What will be examined
2. ISO/IEC 27001 clauses - Specific requirements to verify
3. Annex A controls - Relevant controls from SoA
4. Audit objectives - What to determine
5. Evidence sources - Documents, systems, personnel
6. Audit methods - Interview, observation, review, testing
7. Personnel to interview - Roles and names
8. Sample size - Quantity of records to review
9. Time allocation - Duration for each activity
10. Auditor assignment - Who conducts each activity
Best Practices for Creation
Align with audit plan and scope
Focus on risk and importance
Be specific but flexible
Consider dependencies between activities
Allow time for unexpected findings
Review with audit team before execution
Update based on Stage 1 findings
Example Test Plan Elements
For Access Control (A.9):
Review access control policy
Sample 10 user access requests for approval evidence
Observe user provisioning process
Interview IT administrator about access review procedures
Test 5 user accounts for least privilege
Review last access rights review records
9. EVIDENCE ANALYSIS AND EVALUATION
Corroboration Techniques
Purpose: Verify evidence through multiple sources
Methods:
Cross-referencing - Compare information from different sources
Triangulation - Use three independent sources to confirm
Verification - Check claimed evidence actually exists
Confirmation - Ask multiple people same questions
Testing - Independently verify claims through direct testing
Example: Employee claims they completed security training
Interview confirms knowledge
Training records show completion
Manager confirms attendance
Test demonstrates competence
Evaluation Criteria
Evidence must be:
Sufficient - Enough to support findings
Reliable - Trustworthy and credible
Relevant - Relates to audit objectives and criteria
Factual - Based on observable, verifiable information
Objective - Free from bias or prejudice
Analysis Process
1. Collect - Gather evidence using various methods
2. Organize - Sort by audit area, requirement, or process
3. Corroborate - Verify through multiple sources
4. Evaluate - Assess against audit criteria
5. Identify gaps - Recognize missing or insufficient evidence
6. Draw conclusions - Determine conformity or nonconformity
7. Document - Record in working papers
10. DRAFTING AUDIT FINDINGS
Types of Findings
Conformity
Definition: Evidence demonstrates requirements are met Reporting: May highlight good
practices but not always documented
Nonconformity
Definition: Failure to fulfill a requirement
Major Nonconformity:
Complete absence of required system element
Systemic failure across multiple areas
Critical breakdown of ISMS
Significant risk to information security
Failure to achieve ISMS objectives
Repeated minor nonconformities showing systemic issue
Example: No risk assessment conducted for any information assets
Minor Nonconformity:
Isolated failure or lapse
Does not directly impact ISMS effectiveness
Single instance of non-implementation
Procedural deviation
Example: One employee's access rights not reviewed on schedule
Observation (Opportunity for Improvement)
Definition: Not a nonconformity but area for potential enhancement Example: Inconsistent
password complexity across different systems (if not required by policy)
Components of Well-Written Findings
1. Condition - What was found (the fact)
2. Criterion - The requirement (ISO/IEC 27001 clause or control)
3. Cause - Why the nonconformity occurred (if known)
4. Consequence - Actual or potential impact
5. Evidence - Specific objective proof
Writing Standards
Specific - Precise details, not generalizations
Factual - Observable evidence, not opinions
Clear - Unambiguous language
Complete - All necessary information
Traceable - Reference to working papers
Fair - Balanced and objective
Example of Poor Finding
"Security awareness training is inadequate."
Example of Good Finding
Nonconformity against ISO/IEC 27001 Clause 7.2 (Competence)
Condition: Five out of ten employees interviewed in the Finance Department could not identify
how to report a security incident or describe the organization's data classification scheme.
Evidence: Interviews conducted October 2, 2025, with employees E1, E2, E3, E4, E5 (see
working paper WP-15). Training records reviewed showed these employees completed online
security awareness training in January 2025 but received no follow-up or refresher.
Consequence: Personnel lack awareness necessary to protect sensitive information and respond
appropriately to security incidents, increasing organizational risk.
11. BENEFIT OF THE DOUBT
Concept
When evidence is ambiguous or could be interpreted multiple ways, the auditor should give the
benefit of the doubt to the auditee rather than assume nonconformity.
Principles
Presumption of good faith - Assume organization intends to comply
Clarification first - Seek additional evidence before concluding nonconformity
Professional skepticism balanced with fairness - Be thorough but fair
Evidence threshold - Nonconformity requires clear, objective evidence
When to Apply
Minor documentation gaps with clear verbal evidence
Process variations that still achieve intended outcome
Ambiguous situations where intent and practice appear aligned
First-time audits where ISMS is maturing
When NOT to Apply
Clear evidence of nonconformity exists
Systemic patterns of non-compliance
Safety or critical security concerns
Willful disregard of requirements
Example
Situation: Procedure describes a 3-step approval process. Auditor observes 2-step process in
practice.
Application of Benefit of Doubt:
Interview involved personnel - they describe informal third approval via email
Check emails - confirmation approval exists
Conclusion: Process achieves requirement despite documentation gap
Result: Minor nonconformity for documentation accuracy, not for control absence
12. AUDIT CHECKLISTS
Purpose
Ensure consistent coverage of requirements
Prompt memory during audit
Record evidence systematically
Train less experienced auditors
Advantages
Comprehensive - Less likely to miss requirements
Consistent - Standardized approach across auditors
Efficient - Pre-prepared questions save time
Training tool - Helps new auditors understand requirements
Documentation - Can serve as working papers
Disadvantages
Inflexible - May miss organization-specific issues
Mechanical - Can discourage deeper investigation
Checkbox mentality - Focus on form over substance
Predictable - Organizations may prepare only for checklist items
Limits professional judgment - Discourages adaptive auditing
Best Practices
Use as guide, not script
Customize to organization context
Allow flexibility for follow-up questions
Combine with professional judgment
Don't let checklist limit inquiry
Adapt based on findings during audit
13. AUDIT PLAN PREPARATION
Purpose
Define audit scope, objectives, and criteria
Allocate resources and time
Coordinate with auditee
Provide framework for audit execution
Essential Elements
1. Audit objectives - What audit aims to achieve
2. Audit scope - Boundaries, locations, processes, departments
3. Audit criteria - ISO/IEC 27001, organization's own requirements
4. Audit dates and duration - Schedule
5. Audit team - Members, roles, responsibilities
6. Auditee contacts - Key personnel
7. Areas to be audited - Specific processes, controls, locations
8. Audit methods - Approach to evidence collection
9. Language and logistics - Communication needs, site requirements
10. Confidentiality requirements - Information security measures
11. Reporting requirements - Format and timing of report
Development Process
1. Review previous audit reports - Understand history
2. Analyze documented information - From Stage 1 or pre-audit review
3. Assess risks - Focus on high-risk areas
4. Consider scope complexity - Multi-site, various processes
5. Calculate audit duration - Based on scope and risk
6. Assign team members - Match expertise to audit areas
7. Create detailed schedule - Day-by-day, hour-by-hour
8. Coordinate with auditee - Confirm availability
9. Obtain approval - From lead auditor/audit program manager
10. Distribute to all parties - Ensure everyone has current plan
14. QUALITY REVIEWS OF AUDIT DOCUMENTATION
Purpose
Ensure audit evidence is sufficient and appropriate
Verify findings are supported by evidence
Confirm working papers meet quality standards
Validate conclusions before finalizing report
What to Review
Working papers - Completeness, accuracy, legibility
Evidence trail - Clear links from evidence to findings
Findings - Properly classified (major/minor), well-written
Sampling documentation - Methodology and results clear
Test plans - Coverage adequate, execution documented
Interview notes - Sufficient detail, properly attributed
Review Criteria
Completeness - All audit areas covered, no gaps
Sufficiency - Enough evidence to support conclusions
Accuracy - Facts correctly recorded
Objectivity - Free from bias
Traceability - Clear links between evidence, findings, conclusions
Consistency - Uniform standards applied
Compliance - Follows audit program requirements
Review Process
1. Self-review by auditor - First check of own work
2. Peer review - Cross-check by audit team member
3. Lead auditor review - Final approval before reporting
4. Technical review - Specialist review of complex areas if needed
Common Issues to Identify
Insufficient evidence supporting findings
Unclear or ambiguous findings
Missing working papers or references
Inconsistent classification of nonconformities
Opinions stated as facts
Missing signatures or dates
Confidential information not protected
15. COMPLETING AUDIT WORKING DOCUMENTS
Finalization Steps
1. Complete all fields - No blank sections
2. Cross-reference - Link findings to working papers clearly
3. Sign and date - Authenticate all documents
4. Organize systematically - Logical order for review
5. Create index - For easy navigation
6. Check legibility - Ensure readable by others
7. Verify confidentiality - Sensitive information protected
8. Obtain auditee sign-off - On key documents where appropriate
9. Archive properly - Per retention requirements
10. Restrict access - Maintain confidentiality
Final Documentation Package Should Include
Audit plan and any amendments
Opening meeting attendance and agenda
Daily audit schedules
Working papers for each audit area
Interview records
Document review checklists
Observation notes
Test results
Photographs or screenshots (if permitted)
Nonconformity reports
Closing meeting attendance
Audit report draft and final
Retention Requirements
Maintain per certification body requirements (typically 3-5 years)
Protect confidentiality during retention
Ensure retrievability for appeals or complaints
Dispose securely at end of retention period
KEY AUDIT PRINCIPLES (ISO 19011)
Integrity
Auditors act ethically and honestly
Professional conduct at all times
Resist pressure to compromise findings
Fair Presentation
Report truthfully and accurately
Present obstacles encountered
Include significant observations and findings
Due Professional Care
Diligence and judgment in auditing
Thorough within time constraints
Recognize significance of findings
Confidentiality
Discretion in handling information
Protect proprietary and sensitive data
Use information only for audit purposes
Independence
Auditors free from bias and conflict of interest
Objective throughout audit
Not auditing own work
Evidence-Based Approach
Conclusions based on verifiable evidence
Systematic evidence collection
Rational method to reach reliable conclusions
Risk-Based Thinking
Focus audit on areas of greatest risk
Consider context and likelihood
Prioritize significant matters
EXAM PREPARATION TIPS
Focus Areas
1. Understand Stage 1 vs Stage 2 - Different purposes, activities, outputs
2. Master evidence collection methods - When to use each, advantages/disadvantages
3. Practice writing findings - Condition, criterion, consequence, evidence
4. Know sampling methods - Statistical vs. judgmental, when to use
5. Memorize opening meeting content - Structure and purpose
6. Understand roles - Auditor, guide, observer limitations
7. Study communication techniques - Open questions, active listening
8. Review working paper requirements - What makes quality documentation
9. Understand benefit of the doubt - When and how to apply
10. Know major vs minor nonconformities - Clear distinction criteria
Practice Exercises
Write sample nonconformities from scenarios
Create audit test plans for various ISO/IEC 27001 clauses
Develop interview questions for different roles
Evaluate sample evidence for sufficiency and reliability
Design sampling approaches for given populations
Common Pitfalls to Avoid
Confusing Stage 1 and Stage 2 activities
Writing opinions instead of facts in findings
Insufficient evidence to support conclusions
Forgetting to corroborate evidence
Unclear classification of nonconformities
Poor documentation in working papers
Not applying benefit of the doubt appropriately
Resources to Review
ISO/IEC 27001:2022 standard (all clauses)
ISO/IEC 27002:2022 controls catalog
ISO 19011:2018 auditing guidelines
ISO/IEC 17021-1 conformity assessment requirements
PECB training materials and case studies
GLOSSARY OF KEY TERMS
Audit Criteria: Set of requirements used as reference against which objective evidence is
compared (ISO/IEC 27001 requirements)
Audit Evidence: Records, statements of fact, or other verifiable information relevant to audit
criteria
Audit Finding: Results of evaluation of collected audit evidence against audit criteria
Audit Plan: Description of activities and arrangements for an audit
Audit Scope: Extent and boundaries of an audit (locations, organizational units, processes)
Competence: Ability to apply knowledge and skills to achieve intended results
Conformity: Fulfillment of a requirement
Corroboration: Supporting evidence from multiple independent sources
Information Security Management System (ISMS): Management system with respect to
information security
Nonconformity: Non-fulfillment of a requirement
Objective Evidence: Data supporting existence or verity of something (quantitative or
qualitative)
Risk: Effect of uncertainty on objectives
Sampling: Selection of representative items from a population to conclude the whole
Statement of Applicability (SoA): Document stating which Annex A controls are applicable and
justification for inclusions and exclusions
Working Papers: Records of audit planning, evidence collected, and results of evaluation
Good luck with your exam! Focus on understanding concepts deeply rather than merely
memorizing them. Practice applying knowledge to realistic scenarios, as PECB exams often use
case studies and practical situations to test competency.