Stage 1 Audit Objectives and Activities
In ISO/IEC 27001 certification, the Stage 1 audit is the first part of the initial certification audit. It is governed by ISO/IEC 17021-1 and ISO/IEC 27006. Its main purpose is to decide whether the organization is ready for the Stage 2 audit, where the actual effectiveness of the information secur… In ISO/IEC 27001 certification, the Stage 1 audit is the first part of the initial certification audit. It is governed by ISO/IEC 17021-1 and ISO/IEC 27006. Its main purpose is to decide whether the organization is ready for the Stage 2 audit, where the actual effectiveness of the information security management system (ISMS) is evaluated. Stage 1 does not award certification. Key objectives include: (1) Reviewing the auditee's documented information, such as the ISMS scope, information security policy and objectives, risk assessment and risk treatment methodology and results, the Statement of Applicability (SoA), and the documentation required by clauses 4 to 10. (2) Evaluating site-specific conditions and holding discussions with personnel to judge preparedness for Stage 2. (3) Reviewing the organization's understanding of the standard's requirements, especially the identification of key performance, significant aspects, processes, objectives and how the ISMS operates. (4) Collecting information on scope, locations, processes, technologies, and applicable legal, regulatory and contractual requirements. (5) Confirming that internal audits and management reviews are planned or have been performed, and that the level of implementation shows readiness. (6) Reviewing resource allocation and agreeing on the details of Stage 2. Typical activities include an opening meeting, document review, interviews with top management and the ISMS manager, a review of the scope boundaries and justified exclusions of Annex A controls, verification that the SoA is consistent with the risk treatment plan, and sometimes a site tour. Stage 1 may be performed on site or remotely, depending on risk and complexity. The output is a documented Stage 1 report. It identifies areas of concern that could be classified as nonconformities during Stage 2, confirms or adjusts the scope, and supports planning of the Stage 2 audit, including duration, team competence and sampling. The lead auditor also decides whether to proceed to Stage 2 or to postpone it until concerns are resolved. The time between Stage 1 and Stage 2 should allow these issues to be addressed.
Stage 1 Audit Objectives and Activities: ISO/IEC 27001 Lead Auditor Guide
Introduction
In ISO/IEC 27001 certification, the initial certification audit has two parts: Stage 1 and Stage 2. The requirements for both come from ISO/IEC 17021-1 (requirements for certification bodies) and ISO/IEC 27006 (additional requirements for ISMS certification bodies). Stage 1 is the foundation of the whole certification process. If you understand its objectives and activities, you can answer a large share of lead auditor exam questions about audit planning, readiness and the transition into Stage 2.
Why Stage 1 Is Important
Stage 1 matters for both the auditee and the certification body.
1. It confirms readiness. It checks that the organization is prepared for Stage 2. This avoids wasted time and cost if the ISMS is not mature enough.
2. It reduces audit risk. Early understanding of the organization's context, scope, processes and risks lets the audit team plan Stage 2 well. Resources and sampling go to the areas that matter most.
3. It surfaces major gaps early. Missing mandatory documents, an incomplete risk assessment or an undefined scope can be found before Stage 2. The organization then has time to fix them.
4. It validates scope and boundaries. The certification scope must be clear, justified and properly bounded. This is especially important under ISO/IEC 27006, where scope statements need careful review.
5. It ensures fairness and credibility. A structured Stage 1 shows the certification body is acting competently, impartially and consistently. This supports trust in the certificate that is eventually issued.
What Stage 1 Is
Stage 1 is the first phase of the initial certification audit. It is mainly a review of the ISMS design, documentation and readiness.
It is not a full evaluation of whether controls are implemented and effective. That is the purpose of Stage 2.
Under ISO/IEC 27006, Stage 1 for an ISMS should normally include at least some activity at the client's premises. Where justified, part of it may be done remotely or off-site.
Key Objectives of Stage 1
Based on ISO/IEC 17021-1 clause 9.3.1.2 and ISO/IEC 27006, the objectives include:
a) Audit the client's ISMS documented information. Review the information required by ISO/IEC 27001, such as:
• ISMS scope (clause 4.3)
• Information security policy (5.2)
• Risk assessment and treatment processes and results (6.1.2, 6.1.3, 8.2, 8.3)
• Statement of Applicability (SoA)
• Information security objectives (6.2)
• Evidence of competence, monitoring and measurement results
• Internal audit programme and results
• Management review results
• Nonconformities and corrective actions
b) Evaluate site-specific conditions. Look at the client's location(s) and hold discussions with personnel to judge readiness for Stage 2.
c) Review the client's status and understanding of the standard. In particular, identify key performance indicators, significant aspects, processes, objectives and how the ISMS operates.
d) Obtain information about the scope. This includes the locations, processes, equipment, controls applied and the applicable legal, regulatory and contractual requirements.
e) Review resource allocation for Stage 2. Agree the details of Stage 2 with the client.
f) Provide a focus for planning Stage 2. Build enough understanding of the ISMS, information security risks and site operations to plan Stage 2 effectively.
g) Evaluate whether internal audits and management review are planned and performed. Also check that the level of ISMS implementation shows the client is ready for Stage 2.
ISMS-Specific Emphasis (ISO/IEC 27006)
For ISMS audits, Stage 1 pays particular attention to:
• Understanding the ISMS in the context of the organization's security policy and objectives
• The organization's preparations for the audit
• The adequacy of the risk assessment methodology
• Whether controls have been chosen based on risk treatment decisions, as reflected in the SoA
• Justification for any exclusions of Annex A controls
How Stage 1 Works: Typical Activities
1. Pre-Stage 1 preparation
• The certification body confirms the application review and audit time calculation, including the ISO/IEC 27006 audit time tables.
• An audit team is appointed with suitable competence and is checked for impartiality.
• A Stage 1 plan is communicated to the client.
2. Opening meeting
The team introduces itself and confirms scope, objectives, methods, confidentiality and logistics.
3. Documentation review
The team examines mandatory documented information. It checks consistency between the scope, risk assessment, risk treatment plan and SoA.
4. Interviews with key personnel
Typical interviewees include top management, the ISMS manager or CISO, risk owners and internal auditors. These conversations show how well the organization understands and operates its ISMS.
5. Site understanding
The team may do a brief tour or walkthrough to understand physical boundaries, critical facilities and site-specific risks.
6. Evaluation of readiness
The team decides whether the ISMS is ready for Stage 2. It checks that:
• Internal audits have been performed
• Management review has occurred
• The ISMS has been operating for long enough to produce records
7. Identification of areas of concern
Findings that could be classified as nonconformities in Stage 2 are recorded and reported to the client.
8. Closing meeting and Stage 1 report
The documented conclusions are communicated to the client. They include:
• Fulfilment of the Stage 1 objectives
• Readiness for Stage 2
• Any areas of concern
9. Determining the interval between Stage 1 and Stage 2
The interval depends on how long the client needs to resolve the areas of concern. If significant changes are needed, the certification body may need to repeat all or part of Stage 1.
Typical Outcomes of Stage 1
• Ready for Stage 2: proceed as planned, possibly with minor concerns to address.
• Ready with concerns: proceed after the client resolves them. Stage 2 may be delayed.
• Not ready: major gaps exist, such as no internal audit, no management review or no risk assessment. Stage 2 is postponed, and Stage 1 may need to be repeated.
Stage 1 vs Stage 2: Key Differences
Stage 1:
• Focus: design, documentation, readiness, scope and planning
• Outputs: areas of concern and a Stage 2 plan input
• Does not grant certification
Stage 2:
• Focus: implementation and effectiveness of the ISMS, including controls
• Outputs: nonconformities, conclusions and a recommendation for certification
• Takes place at the client's site(s)
Common Areas of Concern at Stage 1
• Scope statement is vague or excludes interfaces without justification
• Risk assessment methodology lacks defined criteria, such as risk acceptance criteria
• SoA lacks justification for inclusions or exclusions, or is inconsistent with the risk treatment plan
• No full internal audit cycle completed
• Management review not yet held, or missing required inputs
• Information security objectives not measurable
• Legal, regulatory and contractual requirements not identified
Exam Tips: Answering Questions on Stage 1 Audit Objectives and Activities
Tip 1: Know the purpose. Stage 1 is about readiness, understanding and planning. Stage 2 is about implementation and effectiveness. If an answer option says Stage 1 verifies control effectiveness through extensive sampling, it is likely wrong.
Tip 2: Use the right terminology. Findings at Stage 1 are usually called areas of concern. These are issues that could become nonconformities in Stage 2. Formal major or minor nonconformity grading normally belongs to Stage 2. Exams often test this distinction.
Tip 3: Remember the mandatory documents. Expect questions on what is reviewed: scope, policy, risk assessment and treatment, SoA, objectives, internal audit and management review evidence. The SoA and risk assessment are the most frequently tested.
Tip 4: Watch for the management review and internal audit trigger. If a scenario says the organization has not yet done an internal audit or management review, the correct conclusion is usually that it is not ready for Stage 2. Clauses 9.2 and 9.3 must show evidence of operation.
Tip 5: Know who decides. The audit team recommends readiness. The certification decision is made later by the certification body, after Stage 2. No certificate is ever issued based on Stage 1 alone.
Tip 6: Understand the timing. The gap between Stage 1 and Stage 2 should be long enough for the client to address concerns, but not so long that Stage 1 information becomes outdated. If the gap is too long or significant changes occur, Stage 1 may need to be repeated.
Tip 7: Scenario questions. When given a case study, ask yourself:
(a) Is the scope clear and justified?
(b) Is the risk methodology defined and applied?
(c) Is the SoA consistent with risk treatment?
(d) Have internal audit and management review happened?
(e) Are legal and contractual requirements identified?
Any 'no' answer is an area of concern.
Tip 8: Location of activities. ISO/IEC 27006 expects at least part of Stage 1 to be performed on-site for ISMS audits. Be careful with options suggesting Stage 1 is always purely remote document review.
Tip 9: Elimination strategy. Discard options that:
• Claim Stage 1 results in certification
• Describe exhaustive control testing
• Describe surveillance audit activities
• Confuse Stage 1 with a gap analysis consultancy service, which would breach impartiality
Tip 10: Impartiality. Auditors must not offer solutions or consultancy during Stage 1. They identify concerns; the client decides how to fix them. Answers suggesting the auditor writes or corrects the client's documents are wrong.
Tip 11: Link to Stage 2 planning. A key output of Stage 1 is input into the Stage 2 audit plan. Examples include which processes to sample, which sites to visit, how much time to allocate and which auditor competencies are needed.
Tip 12: Essay-style answers. Structure your answer as Objective, then Activity, then Evidence, then Outcome. For example: 'To evaluate readiness, the auditor reviewed the SoA and risk treatment plan, interviewed the ISMS manager, and confirmed internal audit records. The conclusion was that the ISMS is ready for Stage 2 with two areas of concern.'
Sample Exam Question
During Stage 1, the auditor finds that the organization has completed its risk assessment and SoA but has not conducted any management review. What should the auditor do?
Best answer: Record this as an area of concern and report it in the Stage 1 report. Conclude that the organization is not yet ready for Stage 2 until a management review has been carried out. Agree an appropriate interval before Stage 2 so the client can resolve it.
Summary
Stage 1 is the readiness and planning phase of the initial ISO/IEC 27001 certification audit. It reviews ISMS documentation, scope, context, risk methodology, the SoA, internal audit and management review. It also gathers the information needed to plan Stage 2. In exams, keep three ideas in mind:
• Readiness, not effectiveness
• Areas of concern, not formal nonconformities
• Recommendation for Stage 2, never certification
Combine these with strong recall of the mandatory documented information and the ISO/IEC 17021-1 and ISO/IEC 27006 requirements, and you will handle Stage 1 questions with confidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!