Skedmia
ISO 27001Internal Auditor

ISO 27001 Internal Auditor Training

Plan, conduct, report and follow up ISO/IEC 27001:2022 internal audits — clauses 4 to 10, the 93 Annex A controls in four themes, and auditing against the Statement of Applicability rather than a checklist.

29

Lessons

~15h

Study time

30

Exam questions

Earns a QR-verifiable Certificate of Training

Overview

About this course

ISO/IEC 27001:2022 has been the only valid edition since the transition window closed on 31 October 2025, and internal audit is the mechanism by which a certified organisation demonstrates — to its own management, to management review and to its certification body — that the information security management system actually works rather than merely exists on paper. This course qualifies IT and security staff, ISMS managers and internal auditors to plan, conduct, report and follow up internal audits against clauses 4 to 10 and against the controls the organisation has declared in its Statement of Applicability.

The programme follows the order an auditor meets the work: the mandate and purpose of clause 9.2; the audit cycle, programme management and auditor competence requirements of ISO 19011:2018; clause-by-clause audit approaches for context, leadership, planning, risk assessment and risk treatment, support, operation, performance evaluation and improvement; and then the Annex A reference set as restructured in 2022 — 93 controls in four themes, including the eleven new controls — together with the evidence that organisational, people, physical and technological controls are genuinely operating. One discipline runs through the whole course: Annex A is a reference control set filtered by the Statement of Applicability, never a checklist of mandatory requirements.

The closing module is deliberately practical: building the audit plan and working documents, running the opening meeting, interviewing and sampling, following an audit trail to its end, writing nonconformities in problem–location–requirement form, grading major against minor defensibly, and verifying corrective action for root cause and effectiveness rather than accepting a promise.

Assessment is a 30-question online exam with a 70% pass mark. Successful learners receive a verifiable SKEDMIA certificate. Approximately 15 hours of self-paced study.

Included free · 6 months

Practise the audit before you do it for real

Reading a clause and auditing against it are different skills. Enrol on this course and you also get 6 months of AuditVerse, our interactive practice platform — you work through ISO audit scenarios, decide what to sample, and see how a finding holds up when it is challenged.

Sign in with the same email address and password you use here. Access runs for 6 months from the day you enrol, and there is nothing to buy or activate.

Open AuditVerse
CertificateOF TRAINING

What you earn

A certificate anyone can verify in seconds

Score 70% or better on the final exam and Skedmia issues your Certificate of Training with a unique certificate number. Every certificate carries a QR code that resolves to our public register, so an employer or auditor can confirm it is genuine without contacting anyone.

Verified at skedmia.com/verify

Syllabus

Course content

10 modules · 29 lessons · ~15h

01Module 1 — The ISMS and the Internal Audit Mandate — Standard, Structure and Purpose3 lessons
  • ISO/IEC 27001:2022 in 2026 — Structure, Amendment 1 and the Standards FamilyPreview30 min
  • What Internal Audit Is For — Clause 9.2 and the First-Party Mandate30 min
  • The Auditor's Frame of Reference — Terms, Evidence and the Burden of Proof30 min
02Module 2 — The Audit Cycle under ISO 19011:2018 — Principles, Programme and Competence3 lessons
  • The Seven Audit Principles and Risk-Based Auditing30 min
  • Managing the Audit Programme — ISO 19011 Clause 535 min
  • Auditor Competence, Independence and Evaluation — ISO 19011 Clause 730 min
03Module 3 — Context, Leadership and Planning — Auditing Clauses 4, 5 and 63 lessons
  • Auditing Context, Interested Parties and Scope — Clause 435 min
  • Auditing Leadership, Policy and Roles — Clause 530 min
  • Auditing Objectives and Planning of Changes — Clauses 6.2 and 6.330 min
04Module 4 — Information Security Risk — Auditing Assessment, Treatment and Acceptance3 lessons
  • Auditing the Risk Assessment Process — Clause 6.1.235 min
  • Auditing Risk Treatment and the Determination of Controls — Clause 6.1.335 min
  • Auditing Risk in Operation — Clauses 8.2 and 8.330 min
05Module 5 — Support and Operation — Auditing Clauses 7 and 83 lessons
  • Resources, Competence, Awareness and Communication — Clauses 7.1 to 7.430 min
  • Documented Information — Clause 7.5 and the Mandatory Records30 min
  • Operational Planning and Control — Clause 8.1 and External Providers30 min
06Module 6 — Performance Evaluation and Improvement — Auditing Clauses 9 and 103 lessons
  • Monitoring, Measurement, Analysis and Evaluation — Clause 9.130 min
  • Management Review — Clause 9.3 and its Inputs and Outputs30 min
  • Nonconformity, Corrective Action and Continual Improvement — Clause 1030 min
07Module 7 — Annex A and the Statement of Applicability — The Reference Control Set3 lessons
  • The 2022 Restructure — 93 Controls, Four Themes, Five Attributes35 min
  • The Eleven New Controls and What They Demand35 min
  • Auditing Against the SoA, Not Against Annex A35 min
08Module 8 — Auditing the Control Themes — What Operating Evidence Looks Like3 lessons
  • Organisational Controls (A.5) — Policy, Suppliers, Cloud, Incidents and Continuity35 min
  • People and Physical Controls (A.6 and A.7) — Screening to Perimeter30 min
  • Technological Controls (A.8) — Access, Logging, Configuration and Development40 min
09Module 9 — Conducting the Internal Audit in Practice — Planning to Follow-Up3 lessons
  • Planning the Audit and Building the Working Documents35 min
  • Fieldwork — Opening Meeting, Interviewing, Sampling and Trails35 min
  • Findings, the Report and Corrective Action Verification35 min
10Course materials & downloads2 lessons
  • ISMS Internal Audit Evidence Checklist — Clauses 4 to 10 and the SoA (PDF)
  • Nonconformity and Corrective Action Verification Template (Problem–Location–Requirement) (PDF)
Final Exam30 questions · pass 70% → certificate