ISO 27001 Lead Auditor Training
Lead certification audits of an information security management system against ISO/IEC 27001:2022 — clauses 4 to 10, the Statement of Applicability, the 93 Annex A controls, and the Stage 1 to certification-decision process.
29
Lessons
~15h
Study time
30
Exam questions
Earns a QR-verifiable Certificate of Training
Overview
About this course
An ISMS certification audit succeeds or fails on two things: whether the auditor can read the Statement of Applicability against the risk assessment and see whether the two actually agree, and whether the auditor can tell the difference between a control that is documented and a control that is operating. This course is built around both. It works through ISO/IEC 27001:2022 clauses 4 to 10 at the depth an auditor needs — not a summary of what each clause says, but what evidence satisfies it, what a weak answer looks like, and how the resulting finding is written and graded.
Annex A is treated precisely for what it is: a normative reference set of 93 controls in four themes, used as a check against omission, governed by the organisation's own risk treatment decisions and recorded in the SoA. The course covers the 2022 restructuring from 114 controls in fourteen clauses, the eleven new controls and the evidence each demands, and the tell-tale signs of a system retro-fitted from the 2013 edition during the transition that closed on 31 October 2025. Three modules then address lead auditor practice: Stage 1 and Stage 2 under ISO/IEC 27006-1:2024, audit time and multi-site sampling, testing technical controls, team leadership, grading findings, the report and the certification recommendation.
It is written for auditors working for or towards a certification body, internal audit leads and ISMS consultants who already understand information security management and need audit-grade command of the standard. Prior familiarity with ISO management system structure is assumed; deep technical security expertise is not, though the course is explicit about where technical competence must be brought into the team.
Assessment is a 30-question online exam covering all nine modules, with a 70% pass mark. Successful learners receive a verifiable SKEDMIA certificate. Approximately 15 hours of self-paced study.
Practise the audit before you do it for real
Reading a clause and auditing against it are different skills. Enrol on this course and you also get 6 months of AuditVerse, our interactive practice platform — you work through ISO audit scenarios, decide what to sample, and see how a finding holds up when it is challenged.
Sign in with the same email address and password you use here. Access runs for 6 months from the day you enrol, and there is nothing to buy or activate.
Open AuditVerseWhat you earn
A certificate anyone can verify in seconds
Score 70% or better on the final exam and Skedmia issues your Certificate of Training with a unique certificate number. Every certificate carries a QR code that resolves to our public register, so an employer or auditor can confirm it is genuine without contacting anyone.
Verified at skedmia.com/verify
Syllabus
Course content
10 modules · 29 lessons · ~15h
01Module 1 — Foundations — The Standard, the Audit Framework and the Auditor3 lessons
- ISO/IEC 27001:2022 — Structure, Scope and What Certification Actually CertifiesPreview35 min
- The Audit Framework — ISO 19011:2018, ISO/IEC 17021-1 and ISO/IEC 27006-135 min
- Competence, Roles and Professional Conduct of the ISMS Lead Auditor30 min
02Module 2 — Context, Scope and Leadership — Auditing Clauses 4 and 53 lessons
- Clauses 4.1 and 4.2 — Context, Interested Parties and Climate Change32 min
- Clauses 4.3 and 4.4 — Determining and Auditing the ISMS Scope36 min
- Clause 5 — Leadership, Policy and Assigned Roles32 min
03Module 3 — Planning — Risk Assessment, Risk Treatment and the Statement of Applicability3 lessons
- Clause 6.1.2 — Auditing the Information Security Risk Assessment Process38 min
- Clause 6.1.3 — Risk Treatment and the Statement of Applicability38 min
- Clauses 6.2 and 6.3 — Objectives and Planning of Changes30 min
04Module 4 — Support and Operation — Auditing Clauses 7 and 83 lessons
- Clauses 7.1 to 7.4 — Resources, Competence, Awareness and Communication32 min
- Clause 7.5 — Documented Information and How Auditors Sample It30 min
- Clause 8 — Operational Planning and Control34 min
05Module 5 — Performance Evaluation and Improvement — Auditing Clauses 9 and 103 lessons
- Clause 9.1 — Monitoring, Measurement, Analysis and Evaluation32 min
- Clauses 9.2 and 9.3 — Internal Audit and Management Review36 min
- Clause 10 — Nonconformity, Corrective Action and Continual Improvement30 min
06Module 6 — Annex A Restructured — 93 Controls, Four Themes and the Transition3 lessons
- Annex A 2022 — Four Themes, 93 Controls and the Attribute Model34 min
- The Eleven New Controls — What They Require and What Evidence Looks Like38 min
- The 2013-to-2022 Transition — Auditing a Retro-Fitted ISMS32 min
07Module 7 — Auditing the Controls — Testing That a Claimed Control Actually Operates3 lessons
- From SoA Claim to Audit Test — Designing Control Tests36 min
- Auditing Organisational and People Controls — A.5 and A.636 min
- Auditing Physical and Technological Controls — A.7 and A.838 min
08Module 8 — The Certification Audit — Stage 1, Stage 2 and the Three-Year Cycle3 lessons
- Stage 1 — Readiness, Documentation Review and Scope Confirmation34 min
- Stage 2 — Audit Time, Sampling and Multi-Site Arrangements36 min
- The Certification Cycle — Surveillance, Recertification and Change30 min
09Module 9 — Leading the Audit — Team, Findings, Report and Recommendation3 lessons
- Leading the Audit Team on Site32 min
- Grading Findings — Writing Nonconformities That Survive Review34 min
- Closing Meeting, Report and Certification Recommendation34 min
10Course materials & downloads2 lessons
- Annex A 2013 to 2022 — Control Mapping and New-Control Chart (PDF)
- SoA and Risk Treatment Audit Checklist — Clause 6.1.3 Traceability Test (PDF)
Keep browsing
More it, security & ai training

ISO 27001 (The International Information Security Standard)
ISO 27001 2013 VS 27001 2022

IT Courses
Internet Of Things
NewISO 27001Internal AuditorInformation Security
