ISO 27001 Audit Preparation: What Your Lead Auditor Will Examine
ISO/IEC 27001:2022 is the international standard for information security management systems (ISMS). Organizations certified to the 2013 version had until October 31, 2025 to transition. Whether you are preparing for initial certification, surveillance, or an audit after a security incident, here is what an ISO 27001 lead auditor will examine.
Stage 1 and Stage 2
Initial certification happens in two stages. Stage 1 reviews documentation and readiness: scope, policy, risk methodology, and the Statement of Applicability. Stage 2 evaluates whether the ISMS is implemented and effective, through interviews, observation, and records.
The Core Clauses (4 to 10)
- Scope (4.3): clearly defined boundaries, interfaces, and dependencies.
- Leadership and policy (5.1, 5.2): top management commitment and an information security policy.
- Risk assessment and treatment (6.1.2, 6.1.3): a repeatable method, identified risk owners, and a risk treatment plan.
- Statement of Applicability (6.1.3 d): every Annex A control listed, with justification for inclusion or exclusion and implementation status.
- Objectives (6.2): measurable information security objectives.
- Competence and awareness (7.2, 7.3): evidence people are trained and understand their role.
- Operation (8.1 to 8.3): risk assessments performed at planned intervals and treatment carried out.
- Performance evaluation (9.1 to 9.3): monitoring, internal audit, and management review.
- Improvement (10.1, 10.2): nonconformities corrected with root cause analysis.
Annex A
The 2022 version contains 93 controls in four themes: organizational (37), people (8), physical (14), and technological (34). Auditors sample controls from your Statement of Applicability and ask for evidence that each is operating.
If You Have Had an Incident
An incident does not automatically mean a failed audit. Auditors look at how you responded: whether the incident was handled under your incident management process, evidence was preserved, root cause was identified, risks were reassessed, and corrective actions were taken and verified. Missing or damaged records should be documented honestly, with a record of what was lost and how it is being rebuilt. Talk to your certification body early.
Preparation Checklist
- Complete an internal audit covering all clauses and applicable controls
- Hold a management review with all required inputs
- Confirm the Statement of Applicability matches reality
- Close or plan all open nonconformities
- Prepare control owners for interviews
Compliance Fortress includes a qualified ISO 27001 lead auditor who can perform gap and internal audits to prepare you for certification. Related reading: CMMC Level 2 vs ISO 27001.
How Compliance Fortress Solves This: The Exceleor Path
- Discovery: understand the problem, measure where things stand today, and agree on what success looks like.
- Define the engagement path: most organizations don't know the path. We do. A proven method, tailored to your situation.
- Training: bring your people to a clear understanding of the requirements.
- Implement and engage: carry out the work jointly, with your people involved from day one.
- Verify: confirm the work was done and meets the requirement.
- Validate: confirm the original problem is actually solved, measured against the success measures from Discovery.
- Transfer ownership: we collaborate throughout, so your team can run it without us.
- Sustain and grow: we stay close, check in, and catch the next need early. We're here to make sure you succeed.
Is this your situation? See how we approach it on the Malware Sabotaged Our Data page, or request a Situation Review. You can also email [email protected].
Need an EHS Audit?
Veteran-led, certified lead auditors covering ISO 14001, ISO 45001, RC14001, CFATS and more. Get a tailored proposal within 24 hours.
Request Your AssessmentFree EHS Compliance Checklist
Download our 50-point EHS Audit Readiness Checklist — the same framework our auditors use.
Download Free ChecklistMore Free Resources
Fortify Your Compliance Today
Don't wait for an audit finding to reveal your gaps. Partner with the Southeast's most comprehensive EHS and security audit team.