Skedmia
ISO 27001Lead Auditor

ISO 27001 Lead Auditor Training

Lead certification audits of an information security management system against ISO/IEC 27001:2022 — clauses 4 to 10, the Statement of Applicability, the 93 Annex A controls, and the Stage 1 to certification-decision process.

29

Lessons

~15h

Study time

30

Exam questions

Earns a QR-verifiable Certificate of Training

Overview

About this course

An ISMS certification audit succeeds or fails on two things: whether the auditor can read the Statement of Applicability against the risk assessment and see whether the two actually agree, and whether the auditor can tell the difference between a control that is documented and a control that is operating. This course is built around both. It works through ISO/IEC 27001:2022 clauses 4 to 10 at the depth an auditor needs — not a summary of what each clause says, but what evidence satisfies it, what a weak answer looks like, and how the resulting finding is written and graded.

Annex A is treated precisely for what it is: a normative reference set of 93 controls in four themes, used as a check against omission, governed by the organisation's own risk treatment decisions and recorded in the SoA. The course covers the 2022 restructuring from 114 controls in fourteen clauses, the eleven new controls and the evidence each demands, and the tell-tale signs of a system retro-fitted from the 2013 edition during the transition that closed on 31 October 2025. Three modules then address lead auditor practice: Stage 1 and Stage 2 under ISO/IEC 27006-1:2024, audit time and multi-site sampling, testing technical controls, team leadership, grading findings, the report and the certification recommendation.

It is written for auditors working for or towards a certification body, internal audit leads and ISMS consultants who already understand information security management and need audit-grade command of the standard. Prior familiarity with ISO management system structure is assumed; deep technical security expertise is not, though the course is explicit about where technical competence must be brought into the team.

Assessment is a 30-question online exam covering all nine modules, with a 70% pass mark. Successful learners receive a verifiable SKEDMIA certificate. Approximately 15 hours of self-paced study.

Included free · 6 months

Practise the audit before you do it for real

Reading a clause and auditing against it are different skills. Enrol on this course and you also get 6 months of AuditVerse, our interactive practice platform — you work through ISO audit scenarios, decide what to sample, and see how a finding holds up when it is challenged.

Sign in with the same email address and password you use here. Access runs for 6 months from the day you enrol, and there is nothing to buy or activate.

Open AuditVerse
CertificateOF TRAINING

What you earn

A certificate anyone can verify in seconds

Score 70% or better on the final exam and Skedmia issues your Certificate of Training with a unique certificate number. Every certificate carries a QR code that resolves to our public register, so an employer or auditor can confirm it is genuine without contacting anyone.

Verified at skedmia.com/verify

Syllabus

Course content

10 modules · 29 lessons · ~15h

01Module 1 — Foundations — The Standard, the Audit Framework and the Auditor3 lessons
  • ISO/IEC 27001:2022 — Structure, Scope and What Certification Actually CertifiesPreview35 min
  • The Audit Framework — ISO 19011:2018, ISO/IEC 17021-1 and ISO/IEC 27006-135 min
  • Competence, Roles and Professional Conduct of the ISMS Lead Auditor30 min
02Module 2 — Context, Scope and Leadership — Auditing Clauses 4 and 53 lessons
  • Clauses 4.1 and 4.2 — Context, Interested Parties and Climate Change32 min
  • Clauses 4.3 and 4.4 — Determining and Auditing the ISMS Scope36 min
  • Clause 5 — Leadership, Policy and Assigned Roles32 min
03Module 3 — Planning — Risk Assessment, Risk Treatment and the Statement of Applicability3 lessons
  • Clause 6.1.2 — Auditing the Information Security Risk Assessment Process38 min
  • Clause 6.1.3 — Risk Treatment and the Statement of Applicability38 min
  • Clauses 6.2 and 6.3 — Objectives and Planning of Changes30 min
04Module 4 — Support and Operation — Auditing Clauses 7 and 83 lessons
  • Clauses 7.1 to 7.4 — Resources, Competence, Awareness and Communication32 min
  • Clause 7.5 — Documented Information and How Auditors Sample It30 min
  • Clause 8 — Operational Planning and Control34 min
05Module 5 — Performance Evaluation and Improvement — Auditing Clauses 9 and 103 lessons
  • Clause 9.1 — Monitoring, Measurement, Analysis and Evaluation32 min
  • Clauses 9.2 and 9.3 — Internal Audit and Management Review36 min
  • Clause 10 — Nonconformity, Corrective Action and Continual Improvement30 min
06Module 6 — Annex A Restructured — 93 Controls, Four Themes and the Transition3 lessons
  • Annex A 2022 — Four Themes, 93 Controls and the Attribute Model34 min
  • The Eleven New Controls — What They Require and What Evidence Looks Like38 min
  • The 2013-to-2022 Transition — Auditing a Retro-Fitted ISMS32 min
07Module 7 — Auditing the Controls — Testing That a Claimed Control Actually Operates3 lessons
  • From SoA Claim to Audit Test — Designing Control Tests36 min
  • Auditing Organisational and People Controls — A.5 and A.636 min
  • Auditing Physical and Technological Controls — A.7 and A.838 min
08Module 8 — The Certification Audit — Stage 1, Stage 2 and the Three-Year Cycle3 lessons
  • Stage 1 — Readiness, Documentation Review and Scope Confirmation34 min
  • Stage 2 — Audit Time, Sampling and Multi-Site Arrangements36 min
  • The Certification Cycle — Surveillance, Recertification and Change30 min
09Module 9 — Leading the Audit — Team, Findings, Report and Recommendation3 lessons
  • Leading the Audit Team on Site32 min
  • Grading Findings — Writing Nonconformities That Survive Review34 min
  • Closing Meeting, Report and Certification Recommendation34 min
10Course materials & downloads2 lessons
  • Annex A 2013 to 2022 — Control Mapping and New-Control Chart (PDF)
  • SoA and Risk Treatment Audit Checklist — Clause 6.1.3 Traceability Test (PDF)
Final Exam30 questions · pass 70% → certificate