ISO 27001·10 min read

ISO 27001 Audit: What to Expect at Stage 1 and Stage 2

An ISO 27001 audit is not one event. It is an internal audit programme you run yourself, a two-stage certification audit, and then a three-year cycle of surveillance and recertification visits.

This post walks each of those in the order you will meet them, including what auditors actually test, how nonconformities are graded, and what drives the cost. For the control work that comes before any of it, see the ISO 27001 checklist.


The Two Kinds of ISO 27001 Audit

Teams preparing for certification often conflate these, and the confusion causes real scheduling problems.

Internal audit is a requirement of the standard itself. Clause 9.2 obliges you to run an audit programme against your own information security management system (ISMS), using auditors who are objective and impartial with respect to what they are auditing. You can staff it internally, provided the auditor is not auditing their own work, or outsource it.

Certification audit is performed by an accredited certification body and produces the certificate. It comes in two stages the first time, then repeats as surveillance and recertification.

The dependency matters: you cannot pass Stage 2 without having already completed an internal audit and a management review. Both are explicit clause requirements, and both are among the first records a certification auditor asks for. Teams that leave internal audit until after booking the certification visit lose weeks.


Stage 1: The Documentation and Readiness Audit

Stage 1 answers one question. Is this organization ready to be audited properly?

What the auditor reviews:

  • Scope statement, and whether it is coherent and defensible given your business
  • Statement of Applicability (SoA), with justification for every Annex A control included or excluded
  • Risk assessment and risk treatment plan, and whether the methodology is documented and actually applied
  • Information security policy and the supporting policy set
  • Internal audit records, showing the programme has run
  • Management review minutes, showing top management engaged with the required inputs
  • Evidence that the ISMS has been operating, not just written

Stage 1 is frequently shorter than Stage 2 and is often conducted remotely. The output is a report listing areas of concern: things that are missing, unclear, or likely to become nonconformities at Stage 2.

Treat that report as a gift. It is a preview of the Stage 2 findings with time still on the clock.

Leave a real gap between the stages. Several weeks is typical, and it is there so you can close what Stage 1 surfaced.


Stage 2: The Implementation and Effectiveness Audit

Stage 2 is the real audit. The auditor is on site, sampling evidence and interviewing the people who own the controls.

What they actually check:

Clauses 4 to 10. Context and interested parties, leadership commitment and policy, risk planning and objectives, resources and competence, operational controls, monitoring and internal audit, nonconformity and improvement.

Annex A controls you declared applicable. The SoA is the map, and the auditor works from it. A control you marked applicable but cannot evidence is a finding. A control you excluded without adequate justification is also a finding.

Whether people know their part. Auditors interview control owners directly, not just the ISMS manager. If your access review is documented but the person who runs it cannot describe how, that gap shows.

Typical ISO 27001 audit questions in a Stage 2 interview:

  • Show me the last three access reviews and who approved them
  • Walk me through what happened with this specific incident ticket
  • How did this supplier get onto the approved list, and when was it last reviewed
  • Show me the offboarding record for someone who left last quarter
  • Where is the risk owner's sign-off on this treatment decision

Notice the shape. The questions are never "do you have a policy for X." They are "show me X happening, on a date, with a name attached."


Nonconformities: How Findings Are Graded

Three outcomes come out of an audit, and only two of them create obligations.

Major nonconformity. A required process is absent, a control has failed systemically, or a failure calls the ISMS as a whole into question. This blocks certification. You correct it, submit evidence, and the auditor verifies, sometimes with a return visit.

Minor nonconformity. A single lapse within an otherwise functioning control: one access review skipped, one training record missing. Certification usually still proceeds. You submit a corrective action plan and evidence within a defined window, commonly around 90 days.

Observation or opportunity for improvement. No obligation attached. Worth treating seriously anyway, because observations that go unaddressed have a way of returning as nonconformities at the next surveillance audit.

Corrective action means root cause, not patch. An auditor who sees "we did the missed access review" without any analysis of why it was missed will often reject the response.


Audit Frequency and the Three-Year Cycle

The certification cycle is fixed and predictable.

YearAuditScope
0Stage 1 and Stage 2Full ISMS
1SurveillanceSample of clauses and controls, plus mandatory areas
2SurveillanceDifferent sample, plus mandatory areas
3RecertificationFull ISMS again

Surveillance audits are shorter, typically around a third of the initial audit effort, and they sample rather than cover everything. Certain items appear every time regardless: internal audit, management review, corrective actions from the previous visit, complaints, and use of the certification mark.

Internally, ISO 27001 audit frequency is your own decision within one constraint. The internal audit programme must cover the entire ISMS across the cycle. Most organizations run quarterly or half-yearly internal audits, splitting the clauses and controls into blocks so the full set is covered by the time recertification comes around.


What Drives ISO 27001 Audit Cost

Certification bodies do not quote a flat fee. They calculate audit days, then apply a day rate.

Audit day count is driven by:

  • Number of people in scope, which is the dominant factor
  • Number of sites, and whether sampling across sites is permitted
  • Complexity of the ISMS scope, including the technology and regulatory environment
  • Whether the audit is combined with another standard

Audit day rate is driven by the certification body, geography, and travel.

Two practical implications. First, ask for day count and day rate separately when comparing certification bodies, because the day count follows accreditation rules and should be broadly similar between them, while the day rate is where the actual price competition sits. Second, scope discipline is the biggest lever you control. A tightly drawn scope covering the product and the teams that build it costs less to audit than a scope that reflexively includes the whole company.

If you already hold another ISO certificate, a combined audit reduces total days, because the shared Annex SL clauses are assessed once. See integrated management systems for how that works.


Preparing: The Two Weeks Before

  • Get the audit plan and confirm every named control owner is available
  • Pre-stage evidence against your SoA, one folder per control, with dates intact
  • Re-read your own internal audit findings and confirm each has a closed corrective action
  • Brief control owners on the shape of the questions, so nobody freezes when asked to show rather than describe
  • Have the management review minutes, risk assessment, and SoA ready in their current versions

The failure mode is almost never a genuinely absent control. It is a real control nobody can evidence on the day.


For the control build itself, use the ISO 27001 checklist. If you are early-stage and sizing the effort, read ISO 27001 for startups. For how the certification compares to an attestation, see ISO 27001 vs SOC 2. If you hold other management system certificates, integrated management systems covers combined audits. Service detail lives on the ISO 27001 page.


Frequently Asked Questions

How often should you audit ISO 27001? Internally, on a programme that covers the whole ISMS across the three-year cycle, usually quarterly or half-yearly. Externally, Stage 1 and Stage 2 for certification, surveillance in each of the next two years, and recertification in year three.

What is an ISO 27001 audit plan? The schedule the auditor issues before the visit, listing clauses and controls in scope, sites, interview slots by role, and meeting times. Ask for it two weeks ahead so you can flag conflicts and pre-stage evidence.

How much does an ISO 27001 audit cost? Certification bodies price by audit days multiplied by a day rate. Day count follows accreditation rules based on headcount, sites, and complexity. Ask for the two numbers separately when comparing quotes.

What is an ISO 27001 audit checklist? A working document listing clauses 4 to 10 and every Annex A control marked applicable in your Statement of Applicability, with the evidence and owner recorded against each line.

What is the difference between Stage 1 and Stage 2? Stage 1 reviews documentation and readiness and is often remote. Stage 2 tests whether the system operates, through evidence sampling and interviews, and is where nonconformities and the certification decision happen.

What happens if the auditor raises a nonconformity? A minor nonconformity gets a corrective action window, commonly around 90 days, and certification usually proceeds. A major nonconformity blocks certification until corrected and verified.


Preparing for an ISO 27001 Audit?

ShieldKey Solutions runs internal audits and pre-certification readiness for ISO 27001, including the Statement of Applicability review and evidence staging that Stage 2 turns on. We audit the way a certification body will, so the findings arrive while you still have time to fix them.

Schedule a scoping call →