Establishing an Audit Program
Establishing an audit program is the foundational step in managing ISO/IEC 27001 audits. It follows the guidance of ISO 19011 (Clause 5), supplemented by ISO/IEC 27007 for information security management system (ISMS) auditing. An audit program is the set of one or more audits planned for a specifi… Establishing an audit program is the foundational step in managing ISO/IEC 27001 audits. It follows the guidance of ISO 19011 (Clause 5), supplemented by ISO/IEC 27007 for information security management system (ISMS) auditing. An audit program is the set of one or more audits planned for a specific time frame and directed toward a specific purpose. It ensures that audits are systematic, consistent and aligned with organizational goals rather than conducted ad hoc. The process begins with defining audit program objectives. These should be consistent with the organization's strategic direction, information security policy and objectives, and ISMS requirements. Typical objectives include verifying conformity with ISO/IEC 27001, evaluating the effectiveness of controls selected through the risk treatment process, and identifying opportunities for improvement. Objectives should consider stakeholder needs, legal, regulatory and contractual obligations, and the organization's risk appetite. Next, the individuals managing the program must determine and evaluate risks and opportunities that could affect it. Risks may include insufficient resources, poor planning, inadequate auditor competence, ineffective communication, or limited access to information. Opportunities might include combining audits or using remote auditing techniques. The program is then established by defining roles and responsibilities, particularly for the audit program manager, who must possess competence in audit principles, ISMS concepts, risk management and relevant legal requirements. The extent of the program is determined by factors such as the size, complexity and maturity of the ISMS, the number and criticality of processes and sites, previous audit results, significant changes, and information security risk levels. Resources must then be identified, including competent auditors and technical experts, budget, time, travel, and tools such as information and communication technologies. Confidentiality and information security requirements for handling audit evidence must also be addressed. Finally, the program is documented, including audit scope, criteria, methods, frequency and schedules. A well-established audit program supports continual improvement by following the Plan-Do-Check-Act cycle, enabling implementation, monitoring, review and enhancement of auditing activities over time.
Establishing an Audit Program: ISO/IEC 27001 Lead Auditor Guide
Establishing an Audit Program: A Complete Guide for ISO/IEC 27001 Lead Auditor Candidates
1. Introduction
Establishing an audit program is one of the foundations of managing ISO/IEC 27001 audits. Before any single audit is planned or carried out, an organization (or a certification body) must set up a structured, risk-based framework. That framework decides what will be audited, when, by whom, how, and why.
The main guidance comes from ISO 19011:2018 (Guidelines for auditing management systems), clause 5. Further requirements come from ISO/IEC 27001:2022 clause 9.2 (Internal audit), which requires organizations to plan, establish, implement and maintain an audit programme(s). For third-party certification, ISO/IEC 17021-1 and ISO/IEC 27006 govern how certification bodies build their audit programs.
2. Why Establishing an Audit Program Is Important
• Strategic alignment: The program connects audit activity to the organization's objectives, information security risks and the needs of interested parties. Audits stop being isolated, ad hoc events.
• Compliance requirement: ISO/IEC 27001 clause 9.2.2 explicitly requires an audit program. Its absence is a nonconformity.
• Full coverage of the ISMS: A program makes sure all clauses (4–10), the applicable Annex A controls, processes, locations and functions are audited over a defined period, typically the three-year certification cycle.
• Risk-based prioritization: High-risk areas, critical assets and processes with previous nonconformities receive more frequent or deeper audits.
• Efficient use of resources: Planning ahead allows sensible allocation of competent auditors, time, budget and tools.
• Consistency and objectivity: Defined methods, criteria and auditor selection rules support impartiality and repeatable results.
• Continual improvement: Program outputs feed management review (clause 9.3) and corrective action (clause 10).
3. What an Audit Program Is
ISO 19011 defines an audit programme as arrangements for a set of one or more audits planned for a specific time frame and directed towards a specific purpose.
It is important to distinguish these related terms:
• Audit program: A set of audits over a period, such as annual internal audits or a three-year certification cycle. It is managed by the audit program manager.
• Audit plan: The description of activities and arrangements for one individual audit. It is prepared by the audit team leader.
• Audit scope: The extent and boundaries of an audit, such as locations, units, activities and processes.
• Audit criteria: The set of requirements used as a reference, such as ISO/IEC 27001, policies, procedures, legal and contractual requirements.
4. How It Works: The Process of Establishing an Audit Program (ISO 19011 Clause 5)
ISO 19011 structures audit program management on the PDCA cycle:
• Plan: Establish objectives (5.2), determine and evaluate risks and opportunities (5.3), and establish the program (5.4).
• Do: Implement the program (5.5).
• Check: Monitor the program (5.6).
• Act: Review and improve the program (5.7).
Step 1: Establish the audit program objectives (5.2)
Objectives must align with the auditee's strategic direction and ISMS policy. When setting them, consider:
• needs and expectations of interested parties;
• process characteristics and requirements;
• information security risks and opportunities;
• legal, regulatory and contractual obligations;
• the level of ISMS maturity and previous audit results;
• changes to the organization or its context.
Examples of objectives:
• verify conformity with ISO/IEC 27001;
• evaluate the effectiveness of controls;
• prepare for certification;
• assess supplier security;
• identify opportunities for improvement.
Step 2: Determine and evaluate audit program risks and opportunities (5.3)
Risks to the program itself may relate to:
• Planning: setting unrealistic objectives, or failing to define the extent, number or duration of audits.
• Resources: insufficient time, equipment or training.
• Audit team selection: lack of competence in information security.
• Communication: ineffective internal or external channels.
• Implementation: poor coordination, or not considering information security and confidentiality of audit data.
• Control of documented information: records not retained or protected.
• Monitoring: failure to review and improve the program.
• Auditee availability and cooperation: including availability of evidence.
Opportunities include combining audits (integrated audits with ISO 9001 or ISO 22301), using remote auditing, and reducing travel or duplication.
Step 3: Establish the audit program (5.4)
This covers several elements.
a) Roles and responsibilities of the audit program manager (5.4.2). The manager should:
• determine the extent of the program;
• identify and evaluate program risks;
• establish responsibilities;
• establish procedures;
• determine resources;
• ensure implementation, including objectives, scope and criteria for each audit;
• select audit methods and team composition;
• ensure records are managed;
• monitor, review and improve the program.
b) Competence of the audit program manager (5.4.3). This includes knowledge of:
• audit principles and methods;
• management system standards;
• the auditee's context and activities;
• applicable legal requirements;
• risk management, project management, and information technology and security as appropriate.
c) Establishing the extent of the program (5.4.4). Extent is influenced by:
• size, nature and complexity of the auditee;
• number, importance, complexity and similarity of locations;
• the subject and scope of each audit;
• frequency and duration of audits;
• results of previous audits;
• significant changes;
• availability of ICT for remote auditing;
• legal requirements;
• interested party expectations;
• information security and confidentiality concerns.
For certification bodies, ISO/IEC 27006 Annex B and its audit time tables help determine audit duration based on number of employees and ISMS complexity.
d) Determining resources (5.4.5). Resources include:
• financial and time resources;
• audit methods;
• competent auditors and technical experts;
• the extent of the program and its risks;
• travel and accommodation;
• the impact of time zones;
• availability of ICT;
• required tools, technology and equipment;
• documented information.
Step 4: Implement the audit program (5.5)
The program manager:
• communicates the program to relevant parties;
• defines objectives, scope and criteria for each individual audit;
• selects and determines audit methods (on-site, remote, or a combination);
• selects audit team members and appoints the team leader;
• assigns responsibility for individual audits to the team leader;
• manages program outcomes;
• manages and maintains program records.
Step 5: Monitor the audit program (5.6)
Monitoring evaluates:
• whether schedules are being met;
• the performance of audit team members;
• the ability of teams to implement audit plans;
• feedback from auditees, auditors and other interested parties;
• the sufficiency and adequacy of documented information.
Step 6: Review and improve the audit program (5.7)
The review assesses:
• whether objectives were achieved;
• trends and lessons learned;
• conformity with procedures;
• evolving needs of interested parties;
• program records;
• alternative or new audit methods;
• auditor competence and evaluation;
• the effectiveness of risk treatment.
Results feed into improvements and management review.
5. ISO/IEC 27001 Specific Considerations
• Clause 9.2.1 requires internal audits at planned intervals. They determine whether the ISMS conforms to the organization's own requirements and to ISO/IEC 27001, and whether it is effectively implemented and maintained.
• Clause 9.2.2 requires the program to include frequency, methods, responsibilities, planning requirements and reporting. It must take into consideration the importance of the processes concerned and the results of previous audits.
• The organization must define audit criteria and scope for each audit.
• Auditors must be selected to ensure objectivity and impartiality. Auditors must not audit their own work.
• Results must be reported to relevant management.
• Documented information must be retained as evidence of the program and its results.
6. Third-Party Certification Audit Program (ISO/IEC 17021-1 and ISO/IEC 27006)
A certification audit program covers a three-year cycle:
• Initial certification audit: Stage 1 reviews documentation and readiness. Stage 2 evaluates implementation and effectiveness.
• Surveillance audits: at least annually in years 1 and 2. The first surveillance audit must take place no later than 12 months after the certification decision.
• Recertification audit: before certificate expiry, in year 3.
• Special audits where needed, such as scope extensions or short-notice audits.
The program must ensure all ISMS requirements and the applicable Annex A controls in the Statement of Applicability are covered over the cycle. Multi-site sampling must follow ISO/IEC 27006 rules.
7. Practical Example
A financial services company with three sites establishes its internal audit program:
• Objective: Ensure ISMS conformity and prepare for certification.
• Risk-based prioritization: Access control, cryptography and supplier management are high risk, so they are audited twice a year. HR security is lower risk, so it is audited annually.
• Resources: Two internal auditors are trained in ISO/IEC 27001. An external technical expert is engaged for cloud security.
• Impartiality: IT staff do not audit IT processes.
• Schedule: All clauses and applicable controls are covered within 12 months.
• Monitoring: Quarterly reviews of schedule adherence and auditee feedback.
• Review: Annual program review, with outputs sent to management review.
8. Common Pitfalls
• Confusing the audit program with the audit plan.
• Planning audits without considering risk or previous results.
• Assigning auditors who lack competence or impartiality.
• Failing to cover the whole ISMS scope over the cycle.
• Neglecting to monitor and improve the program.
• Not protecting the confidentiality of audit information.
Exam Tips: Answering Questions on Establishing an Audit Program
Tip 1: Know the difference between program and plan. Many questions test whether you can tell them apart. Use this rule of thumb:
• Program = multiple audits over a time frame, managed by the audit program manager.
• Plan = one audit, prepared by the audit team leader.
If a question asks who determines audit team composition or the objectives of individual audits within the program, the answer is usually the audit program manager.
Tip 2: Memorize the PDCA structure of ISO 19011 clause 5. Questions often ask what happens first or which activity belongs to which phase. Remember the order: objectives (5.2), then risks and opportunities (5.3), then establishing (5.4), implementing (5.5), monitoring (5.6), and reviewing and improving (5.7).
Tip 3: Always think risk-based. When a scenario asks how to prioritize audits or set frequency, choose the answer that reflects:
• importance of processes;
• information security risks;
• results of previous audits;
• organizational changes.
This links directly to ISO/IEC 27001 clause 9.2.2.
Tip 4: Watch for impartiality and objectivity traps. A scenario may describe an auditor auditing their own department or work. This violates the requirement for objectivity and impartiality. Identify it as a problem or nonconformity.
Tip 5: Recognize the factors that determine extent and resources. Expect lists in questions. Size, complexity, number of sites, previous results, legal requirements and confidentiality concerns are all valid factors. Eliminate options that are irrelevant, such as the auditor's personal preferences or the auditee simply wanting fewer audits.
Tip 6: Remember the certification cycle facts.
• The cycle lasts three years.
• Surveillance audits take place at least annually.
• The first surveillance audit occurs within 12 months of the certification decision.
• Recertification happens before expiry.
• Stage 1 and Stage 2 make up the initial audit.
Tip 7: Identify the competence of the program manager. Questions may ask what knowledge the program manager needs. Correct answers include:
• audit principles;
• management system standards;
• the auditee's context;
• legal requirements;
• risk management;
• information security knowledge.
Tip 8: Link outputs to improvement. Program review results feed management review (clause 9.3) and continual improvement (clause 10). If asked what happens with program review results, choose answers about improvement and management review.
Tip 9: Read scenario questions carefully. Identify:
• the role being described (program manager, team leader, auditor);
• the type of audit (first, second or third party);
• the stage of the process.
Then apply the correct clause. Words like planned intervals, programme, frequency and methods indicate audit program topics.
Tip 10: Structure essay-style answers. For open-ended questions, follow this pattern:
(1) define the audit program;
(2) cite ISO 19011 clause 5 and ISO/IEC 27001 clause 9.2;
(3) explain the PDCA steps;
(4) apply the steps to the scenario with risk-based reasoning;
(5) mention monitoring and improvement.
Use correct terminology, such as audit criteria, audit scope, audit objectives, competence and impartiality.
Tip 11: Eliminate extreme answers. Options saying the program must audit every control every month, or that frequency is fixed regardless of risk, are usually wrong. ISO standards favor flexible, risk-based and proportionate approaches.
Tip 12: Remember documented information. ISO/IEC 27001 requires documented information as evidence of the implementation of the audit program and the audit results. A missing program record is a common nonconformity in exam scenarios.
9. Summary
Establishing an audit program means defining objectives, evaluating risks and opportunities, setting roles, extent and resources, then implementing, monitoring and improving the program through PDCA. For the ISO/IEC 27001 Lead Auditor exam, master three things:
• the distinction between program and plan;
• the ISO 19011 clause 5 structure;
• the risk-based requirements of ISO/IEC 27001 clause 9.2.
Apply these with attention to competence, impartiality and the certification cycle, and you will be well prepared for questions on this topic.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!