ISO 27701 Lead Auditor Training
Lead audits of a privacy information management system built on ISO/IEC 27701 as an extension of ISO/IEC 27001 — the additional clauses, the controller and processor control sets, and how to plan, evidence and report a combined audit.
29
Lessons
~16h
Study time
30
Exam questions
Earns a QR-verifiable Certificate of Training
Overview
About this course
ISO/IEC 27701 turns an information security management system into a privacy information management system. It adds requirements to the ISO/IEC 27001 clauses, adds privacy guidance to the ISO/IEC 27002 controls, and introduces two role-specific control sets — Annex A for PII controllers and Annex B for PII processors. This course teaches that structure from the auditor's seat. It assumes you already know ISO/IEC 27001 and extends your competence rather than repeating it.
The programme is organised around what a lead auditor must get right: which edition you are auditing against, and whether the PIMS can be certified in its own right or only as an extension to a valid ISO/IEC 27001 certificate; the precise use of PII, PII principal, controller, processor and joint controller; and how a dual-role organisation decides that both Annex A and Annex B apply, and shows it in the Statement of Applicability. It then works through the substance an auditor tests — records of processing, lawful basis and consent, purpose limitation and minimisation, PII principal rights handled end to end, privacy by design, privacy impact assessment, retention and disposal, breach notification, international transfers, and processor obligations including sub-processors — and maps the control sets to GDPR articles, saying plainly where the mapping is genuine and where it is only approximate.
The closing modules cover audit practice to ISO 19011:2018: planning a combined ISMS and PIMS audit, sampling processing activities, testing evidence for a claimed privacy control, interviewing a DPO, grading findings, writing nonconformities and making the certification recommendation.
Assessment is a 30-question online exam with a 70% pass mark. Successful learners receive a verifiable SKEDMIA certificate. Approximately 15 hours of self-paced study.
Practise the audit before you do it for real
Reading a clause and auditing against it are different skills. Enrol on this course and you also get 6 months of AuditVerse, our interactive practice platform — you work through ISO audit scenarios, decide what to sample, and see how a finding holds up when it is challenged.
Sign in with the same email address and password you use here. Access runs for 6 months from the day you enrol, and there is nothing to buy or activate.
Open AuditVerseWhat you earn
A certificate anyone can verify in seconds
Score 70% or better on the final exam and Skedmia issues your Certificate of Training with a unique certificate number. Every certificate carries a QR code that resolves to our public register, so an employer or auditor can confirm it is genuine without contacting anyone.
Verified at skedmia.com/verify
Certified by
Syllabus
Course content
10 modules · 29 lessons · ~16h
01Module 1 — ISO/IEC 27701 and the PIMS — Purpose, Editions and Certifiability3 lessons
- From ISMS to PIMS — What ISO/IEC 27701 Adds and Why34 min
- Extension or Standalone — the Relationship to ISO/IEC 27001 Across EditionsPreview40 min
- Reading the Standard — Clauses 5 to 8 and Annexes A to F35 min
02Module 2 — Privacy Terminology and Roles — Getting the Definitions Right3 lessons
- PII, PII Principal and Identifiability33 min
- Controller, Processor, Joint Controller and Sub-processor35 min
- Dual-role Organisations — Applying Annex A and Annex B Together35 min
03Module 3 — Extending the ISMS Clauses — ISO/IEC 27701 Clause 53 lessons
- Context, Roles and the Scope of the PIMS (5.2)34 min
- Leadership, Policy and Planning — Privacy Risk and the SoA (5.3–5.4)40 min
- Support, Operation, Performance Evaluation and Improvement (5.5–5.8)30 min
04Module 4 — The Control Layer — Clause 6 Privacy Guidance on ISO/IEC 270023 lessons
- How Clause 6 Works — and the 2013 to 2022 Numbering Problem34 min
- Organisational and People Controls with Privacy Guidance35 min
- Physical and Technical Controls with Privacy Guidance35 min
05Module 5 — Controller Obligations — Clause 7 and Annex A3 lessons
- Conditions for Collection and Processing (A.7.2)32 min
- Obligations to PII Principals and Handling a Request End to End (A.7.3)40 min
- Privacy by Design, Retention and Transfers (A.7.4–A.7.5)40 min
06Module 6 — Processor Obligations — Clause 8 and Annex B3 lessons
- Processing on Instructions — Conditions for Collection and Processing (B.8.2)33 min
- Obligations to the Customer, Temporary Files and Disposal (B.8.3–B.8.4)35 min
- Sub-processors, Transfers and Disclosure Requests (B.8.5)35 min
07Module 7 — Mapping to Law — GDPR and Other Regimes, Genuine and Approximate3 lessons
- Where the Mapping Is Genuine — Annex A and B Against GDPR Articles33 min
- Where It Is Only Approximate — and the Certification Myth35 min
- Beyond the GDPR — Sector Standards and Multi-jurisdiction PIMS30 min
08Module 8 — Auditing the PIMS — Planning, Sampling and Evidence to ISO 19011:20183 lessons
- Audit Programme, Competence and the Combined Audit Plan33 min
- Sampling Processing Activities and Testing a Claimed Control40 min
- Findings, Grading, Report and Certification Recommendation35 min
09Module 9 — Leading the Audit in Practice — Judgement, Cases and Follow-up3 lessons
- Leading the Team and the Client Through a PIMS Audit30 min
- Worked Cases and the Nonconformities That Recur40 min
- After the Audit — Corrective Action, Surveillance and Change30 min
10Course materials & downloads2 lessons
- Annex A and Annex B Control Map with GDPR Article Cross-reference (PDF)
- Combined ISMS/PIMS Audit Evidence Checklist (PDF)
Keep browsing
More it, security & ai training

ISO 27001 (The International Information Security Standard)
ISO 27001 2013 VS 27001 2022

IT Courses
Internet Of Things
NewISO 27001Internal AuditorInformation Security
