Stage 2 Audit Objectives and Activities
In ISO/IEC 27001 certification, the Stage 2 audit is the main assessment that follows the Stage 1 readiness review. It is guided by ISO/IEC 17021-1 and ISO/IEC 27006. Its central objective is to evaluate the implementation and effectiveness of the organization's Information Security Management Syst… In ISO/IEC 27001 certification, the Stage 2 audit is the main assessment that follows the Stage 1 readiness review. It is guided by ISO/IEC 17021-1 and ISO/IEC 27006. Its central objective is to evaluate the implementation and effectiveness of the organization's Information Security Management System (ISMS), confirming that it conforms to all requirements of ISO/IEC 27001 and achieves the organization's information security policy and objectives. Whereas Stage 1 focuses on documentation and preparedness, Stage 2 verifies that documented processes are actually practiced, maintained and producing intended results. Key objectives include: confirming adherence to the organization's own policies, objectives and procedures; verifying that the ISMS meets clauses 4 to 10 of the standard; assessing whether risk assessment and risk treatment processes are applied consistently; confirming that controls in the Statement of Applicability are implemented effectively; and determining whether the ISMS can be recommended for certification. Typical activities begin with an opening meeting to confirm scope, audit plan, methods and logistics. Auditors then gather objective evidence through interviews with top management and staff, observation of activities, and review of records. They examine information security objectives, performance monitoring and measurement, internal audit results, management review outputs, incident handling, and corrective actions. Sampling is used to test Annex A controls, such as access control, supplier security, cryptography and business continuity arrangements. Auditors also confirm that issues identified in Stage 1 have been addressed and evaluate leadership commitment and continual improvement. Findings are classified as major nonconformities, minor nonconformities, observations or opportunities for improvement. Major nonconformities must be corrected, and their correction verified, before certification can be granted. Minor nonconformities normally require an accepted corrective action plan. The audit concludes with a closing meeting presenting findings and the recommendation, followed by a formal audit report submitted to the certification body for an independent certification decision.
Stage 2 Audit Objectives and Activities: A Complete Guide for ISO/IEC 27001 Lead Auditors
Introduction
In the ISO/IEC 27001 certification process, the initial certification audit is split into two stages. Stage 1 checks documentation and readiness. Stage 2 is the main event: the auditor checks whether the Information Security Management System (ISMS) is actually implemented and working effectively. For a Lead Auditor candidate, Stage 2 is one of the most frequently examined topics, because it is where audit evidence is gathered, conformity is judged and the certification recommendation is formed.
Why Stage 2 Is Important
1. It confirms reality, not just intent. Stage 1 shows that the organization has designed an ISMS on paper. Stage 2 proves that the design is in operation, is followed by people, and produces the intended results.
2. It is the basis for the certification decision. The certification body relies on Stage 2 findings and the audit team's recommendation to grant, defer or refuse certification (ISO/IEC 17021-1, clause 9.3.1.3).
3. It provides assurance to stakeholders. Customers, regulators and partners trust an ISO/IEC 27001 certificate because an independent auditor has verified effective implementation of risk-based controls.
4. It drives improvement. Nonconformities and opportunities for improvement raised at Stage 2 push the organization toward a more mature ISMS.
5. It protects the credibility of certification. Weak Stage 2 audits produce certificates that mean little. The standards (ISO/IEC 17021-1, ISO/IEC 27006-1 and ISO 19011) set strict expectations to keep certification meaningful.
What Stage 2 Is
ISO/IEC 17021-1 clause 9.3.1.3 states that the purpose of the Stage 2 audit is to evaluate the implementation, including effectiveness, of the client's management system. Stage 2 takes place at the site(s) of the client, either on-site or remotely where justified. It follows Stage 1, which decides whether the organization is ready for Stage 2.
Core Objectives of Stage 2
The Stage 2 audit must include, at minimum, the following:
- Information and evidence of conformity to all requirements of ISO/IEC 27001 (clauses 4 to 10) and other applicable normative documents.
- Performance monitoring, measuring, reporting and reviewing against key information security objectives and targets (clause 9.1).
- The ability of the management system to meet legal, regulatory and contractual requirements. The auditor evaluates whether the organization has a system to identify and comply with these. The auditor does not perform a legal compliance audit.
- Operational control of the client's processes, including the information security risk treatment and implementation of controls (clause 8).
- Internal auditing and management review (clauses 9.2 and 9.3).
- Management responsibility for the client's policies (leadership, clause 5).
For ISMS audits specifically, ISO/IEC 27006-1 adds that Stage 2 must cover:
- The information security risk assessment and risk treatment, and the outputs they produce.
- The Statement of Applicability (SoA) and the controls selected, including the justification for inclusions and exclusions of Annex A controls.
- Information security objectives and performance.
- The links between policy, objectives, risk assessment results, control implementation, monitoring and results. The auditor checks that the chain is coherent and traceable.
- Implementation of controls, sampled from the SoA, taking into account how the organization monitors and measures their effectiveness.
- Programmes, processes, procedures, records, internal audits and reviews of ISMS effectiveness.
How Stage 2 Works: Key Activities
1. Preparation and planning
- Review Stage 1 findings and confirm that any areas of concern identified at Stage 1 have been addressed. Unresolved concerns may become nonconformities at Stage 2.
- Confirm the audit scope, audit criteria and audit objectives.
- Prepare the audit plan, covering the schedule, sites, auditees, processes, controls to be sampled and the assignment of audit team members. Share it with the auditee in advance.
- Determine audit time using ISO/IEC 27006-1 tables, based on the number of persons doing work under the organization's control and on complexity factors.
- Plan multi-site sampling where applicable.
- Prepare work documents, such as checklists, sampling plans and evidence-recording forms.
2. Opening meeting
The opening meeting is chaired by the audit team leader. It is used to:
- Introduce participants and their roles.
- Confirm the audit objectives, scope, criteria, plan and logistics.
- Explain the methods, confidentiality arrangements, the grading of findings (major or minor nonconformity) and the conditions for terminating an audit early.
- Confirm communication channels, guides and observers, and the appeals and complaints process.
3. Collecting and verifying information
Evidence is gathered through three main methods:
- Interviews with top management, process owners, risk owners, IT staff and end users.
- Observation of activities, for example physical security, clear desk practices, access to server rooms and change management in action.
- Review of documented information, such as risk registers, the SoA, logs, incident records, training records, supplier agreements, internal audit reports and management review minutes.
Technical verification may also be used where appropriate, for example viewing access control configurations or backup logs. Evidence is collected through sampling, because the auditor cannot check everything. Only verifiable information becomes audit evidence. The auditor triangulates evidence, meaning that interviews, records and observation are cross-checked to confirm consistency.
4. Audit trails
Auditors follow trails that connect ISMS elements. A typical trail runs:
Risk identified → risk treatment decision → control in the SoA → control implemented → monitoring of effectiveness → internal audit → management review → corrective action.
A broken link in this chain often reveals a nonconformity.
5. Generating audit findings
Audit evidence is evaluated against the audit criteria and produces findings:
- Conformity: the requirement is fulfilled.
- Major nonconformity: the absence of, or total breakdown in, a system element, or a situation that raises significant doubt about the ability of the ISMS to achieve its intended outcomes. Several minor nonconformities on the same requirement may also add up to a major one.
- Minor nonconformity: a nonconformity that does not affect the capability of the ISMS to achieve its intended results.
- Opportunity for improvement (OFI): a suggestion only. It is not a requirement, and the certification body must not give consultancy.
Each nonconformity must be written clearly and include:
- the requirement (the audit criterion),
- the objective evidence found,
- a statement of the nonconformity.
6. Team meetings and communication
- The audit team meets regularly to review progress, share evidence and agree on findings.
- The team leader keeps the auditee informed of progress and any concerns.
- Any urgent risk or significant issue is reported immediately.
- If the audit objectives become unattainable, the team leader reports the reasons and determines appropriate action, which may include changing the plan or terminating the audit.
7. Preparing audit conclusions
Before the closing meeting, the team:
- Reviews all findings against the audit objectives.
- Agrees on audit conclusions, including the extent of conformity, the effectiveness of the ISMS and its continual improvement capability.
- Decides the certification recommendation. The recommendation may be conditional on corrective actions for nonconformities.
8. Closing meeting
The closing meeting is chaired by the team leader. It is used to:
- Present the findings and conclusions.
- Remind the auditee that audit evidence is based on a sample, so some uncertainty remains.
- Explain the timeframes for corrections and corrective action plans. Major nonconformities typically require verified correction and corrective action before certification is granted, which may involve a follow-up audit. Minor nonconformities typically require an accepted action plan.
- Explain the post-audit activities and the right to appeal.
- Discuss and, where possible, resolve diverging opinions. Unresolved disagreements are recorded.
9. Audit report and follow-up
- The team leader issues the audit report, covering scope, objectives, criteria, findings, conclusions, recommendation, and any unresolved issues or limitations.
- The organization submits its root cause analysis and corrective actions.
- The auditor reviews and verifies the corrective actions.
- A separate, independent certification decision is made by the certification body, not by the audit team.
Stage 1 vs Stage 2: Quick Comparison
- Stage 1: documentation review, understanding of context and scope, readiness check, and planning for Stage 2. Its output is a readiness report with areas of concern.
- Stage 2: evaluation of implementation and effectiveness at the client's premises. Its outputs are findings, nonconformities and a certification recommendation.
If the period between Stage 1 and Stage 2 is long, or significant changes occur, Stage 1 may need to be repeated. ISO/IEC 17021-1 requires the certification body to consider the time needed to resolve Stage 1 concerns.
Common Practical Scenarios
- Excluded control: The SoA excludes a control without justification. This is a nonconformity against clause 6.1.3 d).
- Unclosed risk treatment: The risk treatment plan lists actions that are overdue, and there is no evidence of risk owner approval of residual risks. This is a nonconformity against clause 6.1.3 f) or 8.3.
- Incomplete internal audit: No internal audit has covered the full ISMS before Stage 2. This is typically a major nonconformity, because clause 9.2 requires it and certification bodies normally require at least one internal audit and management review before certification.
- Missing management review inputs: Minutes do not show the required inputs from clause 9.3.2. This is a nonconformity, usually minor.
- Contradictory evidence: The policy requires MFA, but the auditor observes accounts without it. Sample further to decide whether the problem is isolated (minor) or systemic (potentially major).
Exam Tips: Answering Questions on Stage 2 Audit Objectives and Activities
1. Know the core purpose by heart. When asked about the purpose of Stage 2, the answer is to evaluate the implementation, including effectiveness, of the ISMS. Do not confuse it with Stage 1's readiness and documentation focus.
2. Distinguish Stage 1 from Stage 2 clearly. Exam questions often present an activity and ask which stage it belongs to:
- Reviewing documented information, understanding the context and agreeing Stage 2 details are Stage 1.
- Verifying that controls operate, interviewing staff and sampling records are Stage 2.
3. Use the correct terminology. Write audit evidence, audit criteria, audit findings, audit conclusions, objective evidence, sampling, major/minor nonconformity and opportunity for improvement. Examiners reward precise ISO 19011 and ISO/IEC 17021-1 language.
4. Structure scenario answers logically. For essay or scenario questions, use this sequence:
(a) Identify the requirement (clause).
(b) Describe the evidence you would seek and how you would obtain it (interview, observation, document review).
(c) Evaluate whether it conforms.
(d) Grade the finding and justify the grade.
5. Write nonconformity statements in three parts. Each statement should give the requirement, the evidence and the statement of nonconformity. For example: Clause 9.2 requires internal audits at planned intervals. No evidence was provided of an internal audit covering Annex A control 8.13 backup processes within the audit programme. The organization has not fully implemented its internal audit programme.
6. Justify major versus minor grading. Always explain why:
- A major nonconformity involves a systemic failure, a missing ISMS element, or significant doubt about the ability of the ISMS to achieve its intended outcomes.
- A minor nonconformity is an isolated lapse with limited impact.
Examiners award marks for the reasoning, not just the label.
7. Remember the ISMS-specific elements. Mention the risk assessment, risk treatment, SoA, the justification of Annex A controls, and the traceability from policy to objectives to risks to controls to results. This shows ISO/IEC 27006-1 awareness.
8. Stay independent and do not consult. If a question tempts you to tell the auditee how to fix a problem, the correct answer is to report the finding and, where appropriate, note an OFI without prescribing a solution. The organization owns its corrective actions.
9. Know who decides. The audit team recommends. The certification body decides, independently. This is a classic trick question.
10. Apply sampling and risk-based thinking. Explain that you sample based on risk, significance and the Stage 1 results. If a sample reveals problems, explain that you would expand the sample to determine whether the problem is systemic.
11. Remember the legal compliance nuance. The auditor checks that the organization has a process for identifying and evaluating legal, regulatory and contractual requirements. The auditor does not act as a lawyer or regulator.
12. Handle obstacles correctly. If key personnel are unavailable, evidence is denied, or scope issues arise, the team leader communicates with the auditee and the certification body, records the limitation, and may adjust the plan or terminate the audit. Do not simply ignore the obstacle.
13. Watch the timeline wording. Corrective actions for major nonconformities must be verified before certification, typically within a period set by the certification body (often up to 90 days, depending on the scheme). If this cannot be done within six months after the last day of Stage 2, ISO/IEC 17021-1 requires a new Stage 2 to be conducted before certification can be recommended.
14. Read every scenario detail. Exam scenarios hide clues, such as an outdated risk assessment, a missing signature, or a policy not communicated. Each clue usually maps to a clause. Underline them and link each one to an ISO/IEC 27001 requirement.
15. Manage your time and be concise. Use short paragraphs or bullet-style answers, cite clauses where possible, and always link back to the audit objective being tested. That objective is effectiveness of implementation.
Summary
Stage 2 is where the ISMS is proven in practice. The auditor plans carefully, opens formally, collects and verifies evidence by sampling, follows audit trails across the risk-to-control chain, grades findings objectively, closes transparently and reports a recommendation. In the exam, show that you understand both what must be evaluated (the 17021-1 and 27006-1 requirements) and how a competent, independent auditor evaluates it (ISO 19011 methods).
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!