Audit Team Selection and Audit Time
Audit team selection and audit time determination are key planning activities when preparing an ISO/IEC 27001 certification audit. They are governed mainly by ISO/IEC 17021-1, ISO/IEC 27006 and the guidance in ISO 19011. Audit Team Selection: The certification body appoints an audit team leader, u… Audit team selection and audit time determination are key planning activities when preparing an ISO/IEC 27001 certification audit. They are governed mainly by ISO/IEC 17021-1, ISO/IEC 27006 and the guidance in ISO 19011. Audit Team Selection: The certification body appoints an audit team leader, usually a qualified ISO/IEC 27001 Lead Auditor. The team leader is responsible for planning, managing and reporting the audit. The team as a whole must have the competence needed to achieve the audit objectives. This includes knowledge of information security management, the Annex A controls, risk assessment and treatment, and relevant legal and regulatory requirements. It also includes familiarity with the auditee's sector and technologies, such as cloud services, software development or finance. Where gaps exist, technical experts may be added. Technical experts provide specialist knowledge but do not act as auditors. Auditors-in-training may join under supervision. Selection must also ensure impartiality and independence. Team members must not have provided consultancy to the auditee, typically within the previous two years, and must have no other conflicts of interest. Other factors include language skills, cultural awareness, security clearance requirements, availability and the size and complexity of the organization. Roles such as guides and observers should be agreed in advance. Audit Time: Audit duration is calculated using the audit time tables in ISO/IEC 27006. The starting point is the effective number of personnel within the ISMS scope, including part-time staff and contractors. This baseline is then adjusted for factors such as: - the complexity of the ISMS - the business type and its regulatory environment - the IT infrastructure - outsourcing arrangements - the number of sites - previous audit results Reductions are limited, commonly to no more than 30 percent of the table value, and every adjustment must be justified and recorded. The total time covers Stage 1, which reviews documentation and readiness, and Stage 2, which evaluates implementation and effectiveness. As a rule of thumb, surveillance audits take about one third of the initial audit time, and recertification audits about two thirds. Travel time is excluded. Multi-site sampling and remote auditing techniques may affect how the time is allocated, but they must still allow sufficient evidence to be gathered for a reliable audit conclusion.
Audit Team Selection and Audit Time in ISO/IEC 27001 Audits: A Complete Guide for Lead Auditors
Introduction
Before an ISO/IEC 27001 audit can begin, two decisions shape everything that follows: who will audit (audit team selection) and how long they will audit (audit time). If either is wrong, the audit cannot deliver reliable conclusions. A team without the right competence will miss risks. Too little time leads to superficial sampling. A team with conflicts of interest produces findings nobody can trust.
This topic sits in the Preparing an ISO/IEC 27001 audit domain of the Lead Auditor syllabus. It draws mainly on three standards:
• ISO 19011, the guidelines for auditing management systems.
• ISO/IEC 17021-1, the requirements for certification bodies.
• ISO/IEC 27006, the ISMS-specific requirements for certification bodies.
Accreditation guidance such as IAF MD 5 also applies the same audit time principles to other management systems.
1. Why It Is Important
• Credibility of certification: Accreditation bodies and the public trust a certificate only if a competent, impartial team carried out the audit with enough time to gather sufficient evidence.
• Effectiveness: ISMS audits cover technical controls (cryptography, access control, secure development, cloud, networks), legal requirements and business processes. Without the right mix of skills, important nonconformities go undetected.
• Impartiality: Conflicts of interest are among the biggest risks to certification integrity. A common example is an auditor who previously consulted for the auditee.
• Risk-based sampling: Audit time determines how many processes, sites, controls and records can be examined. Insufficient time increases audit risk, meaning the risk of reaching wrong conclusions.
• Commercial fairness: Standardised methods for calculating time stop certification bodies from competing by cutting audit days. Such cutting would erode the value of certification.
• Exam relevance: Scenario questions frequently test whether you can spot inadequate team competence, impartiality threats or unjustified reductions in audit time.
2. What It Is
2.1 Audit Team Selection
This is the process of appointing an audit team leader and team members who together have the competence needed to achieve the audit objectives. The team must also be independent of the activity being audited.
Typical roles:
• Audit team leader (lead auditor): Manages the audit, plans it, assigns tasks, communicates with the auditee and is responsible for the audit conclusions.
• Auditors: Collect and evaluate evidence within their assigned areas.
• Technical experts: Provide specific knowledge or expertise, for example in OT/ICS security, cloud architecture, healthcare data law or banking systems. They work under the direction of an auditor and do not act as auditors.
• Auditors-in-training: Take part under the direction and supervision of a qualified auditor. They are not relied upon independently.
• Observers: Accompany the team, for example from an accreditation body, a regulator or the client's consultant. They do not influence or interfere with the audit.
• Guides: Appointed by the auditee to help the team (escort, access, introductions). They do not audit.
• Interpreters/translators: Support communication. They should be independent of the auditee where possible.
2.2 Audit Time
Audit time is the time needed to plan and perform a complete and effective audit of the client's management system. It is usually expressed in auditor-days. An audit day is normally 8 hours, subject to local legal working-time rules.
Audit time covers:
• Planning.
• Document review.
• On-site or remote auditing.
• Reporting.
For initial certification, the total is split between Stage 1 and Stage 2. Surveillance and recertification audits have their own durations.
3. How It Works
3.1 Determining Competence Needs
ISO 19011 (clause 5.5.4) says the audit team should be selected considering the competence needed to achieve the audit objectives. Competence needs include:
• Knowledge of ISO/IEC 27001 requirements and the Annex A controls (aligned with ISO/IEC 27002).
• Information security principles: risk assessment and treatment (e.g., ISO/IEC 27005), incident management, business continuity.
• Technical knowledge of the client's environment: IT infrastructure, cloud, software development, networks, outsourcing.
• Sector knowledge: finance, health, telecom, government, manufacturing.
• Legal, regulatory and contractual requirements, such as data protection laws and sector regulations.
• Audit principles, methods and techniques.
• Language and cultural understanding.
ISO/IEC 17021-1 and ISO/IEC 27006 require the certification body to define competence criteria. They also require it to ensure that the team as a whole has the knowledge for the technical areas within the scope. Not every member needs every skill, but the team collectively must cover them.
3.2 Factors Influencing Team Selection
• Audit objectives, scope, criteria and estimated duration.
• Whether the audit is combined or integrated with other management systems.
• Overall competence needed and the competence of each member.
• Statutory, regulatory and contractual requirements.
• Independence and impartiality: no conflicts of interest.
• Ability of members to work together and interact with the auditee.
• Language, social and cultural characteristics of the auditee.
• Complexity, size and number of sites.
• Type of audit (first, second or third party), use of remote auditing and audit risk.
• Need for security clearance or confidentiality arrangements, for example in defence or government work.
3.3 Impartiality Rules (Third-Party Certification)
• An auditor who provided consultancy on the client's ISMS must not audit that client for a specified period. ISO/IEC 17021-1 uses two years as the typical benchmark.
• Internal auditors of the client, former employees in relevant roles, and people with financial or family ties are threats to impartiality.
• Rotation of auditors over successive cycles helps reduce familiarity threats.
• Members should declare any known conflicts before assignment.
3.4 Use of Technical Experts
A technical expert is used when the auditors lack specific competence. They:
• Brief the auditors.
• Accompany interviews.
• Help interpret technical evidence.
The auditor remains responsible for the findings. The technical expert must also meet impartiality requirements.
3.5 Calculating Audit Time for an ISMS
ISO/IEC 27006 provides the method. Its annex contains a table relating the number of persons doing work under the organization's control to a baseline number of auditor-days. The process works as follows.
Step 1: Determine the effective number of personnel.
• Count all people within the ISMS scope who do work under the organization's control.
• This includes full-time, part-time, temporary and contracted staff on site.
• Part-time staff may be converted to full-time equivalents.
• Shift workers are considered according to the activities covered.
• Personnel performing the same repetitive, low-risk tasks may justify consideration of a reduced effective number. This must be justified and recorded.
Step 2: Read the baseline audit time for the effective number of personnel from the table. The baseline is the time for an initial audit (Stage 1 + Stage 2).
Step 3: Adjust for complexity. ISO/IEC 27006 lists factors that increase or decrease time.
Factors that may increase time:
• Complex logistics or more than one building or location.
• Staff speaking multiple languages, which may require interpreters.
• A highly regulated sector or significant legal requirements.
• A high-risk business with critical information assets.
• Complex IT: many platforms, extensive outsourcing, in-house software development, cloud dependencies.
• Many interfaces with external parties.
• Many controls applicable in the Statement of Applicability.
Factors that may decrease time:
• Low-risk business.
• A very small or limited scope.
• Few processes with low complexity.
• Mature systems with prior certification, for example an integrated management system already certified.
• Limited IT complexity.
• Highly standardised processes.
ISO/IEC 27006 also categorises business complexity and IT complexity (low, medium, high) to guide the adjustment. Reductions must be justified and recorded. Accreditation practice, following IAF MD 5 principles, generally limits total reductions (commonly to 30% of the baseline).
Step 4: Allocate time.
• Split time between Stage 1 and Stage 2.
• Ensure the on-site or remote auditing portion is not eroded by planning and reporting. IAF MD 5 guidance states that planning and reporting should not reduce on-site time below about 80% of the total audit time.
Step 5: Exclude non-auditor time.
• Time spent by technical experts, translators, observers and auditors-in-training does not count towards the calculated audit time.
• An auditor-in-training cannot replace a qualified auditor's days.
3.6 Surveillance and Recertification Time
• Surveillance audits: Typically about one third of the initial audit time per year, adjusted for changes.
• Recertification audits: Typically about two thirds of the initial audit time, adjusted for changes in scope, size or complexity.
• Any significant change (new sites, mergers, large headcount growth, new technologies) triggers recalculation.
3.7 Multi-Site Organizations
ISO/IEC 27006 allows sampling of sites when the sites operate under the same ISMS, with central administration, internal audits and management review covering all sites.
• The sample should be partly random and partly risk-based, taking into account incidents, complexity and differences in local regulation.
• The central function is always audited.
• Audit time is calculated per site and adjusted, never set lower than justified.
3.8 Remote Auditing
Remote techniques (video conferencing, screen sharing, remote access to records) may be used where risk-assessed and agreed. Remote audit time counts as audit time if it achieves equivalent effectiveness. Physical security and environmental controls may still require on-site verification.
3.9 Integrated or Combined Audits
When ISO/IEC 27001 is audited together with ISO 9001, ISO 22301 or ISO/IEC 27701, time may be reduced through integration. This depends on the degree of integration and must still allow adequate coverage of ISMS-specific requirements. The team must be competent in all the standards involved.
3.10 Documenting the Decision
The certification body must record:
• The calculation basis (number of personnel, factors applied).
• The justification for adjustments.
• The team composition with competence evidence.
Accreditation bodies review these records.
4. Worked Example
A software company has 180 people in scope across two sites. It develops software in-house, hosts a SaaS platform in the cloud, processes personal data under strict privacy law, and has no previous certification.
• Baseline: Use the ISO/IEC 27006 table for 180 persons.
• Adjustments: Increase for in-house development, cloud complexity, privacy regulation and two sites. Little or no reduction is justified.
• Team: A lead auditor with ISMS and software sector competence, plus a second auditor. A technical expert in cloud security may be added if the auditors lack that competence. The expert's time is not counted as audit time.
• Impartiality check: Confirm that no team member consulted for the company in the last two years.
• Allocation: Stage 1 reviews documentation and readiness. Stage 2 covers both sites, development, operations and privacy-related controls.
5. Common Pitfalls
• Reducing audit days because the client asks for a lower price. Commercial pressure is not a valid justification.
• Counting a trainee or technical expert as an auditor-day.
• Selecting an auditor who lacks sector knowledge without adding a technical expert.
• Ignoring outsourced or cloud-based processes when assessing IT complexity.
• Failing to recalculate audit time after significant changes.
• Allowing an auditor with prior consultancy, or a former employee, to audit.
• Letting observers or guides influence findings.
6. Exam Tips: Answering Questions on Audit Team Selection and Audit Time
Tip 1: Think competence of the team as a whole. If a scenario describes a specialised environment (OT/SCADA, medical devices, financial trading, cloud), the correct answer usually involves adding a competent auditor or a technical expert. Remember that technical experts do not act as auditors and do not issue findings.
Tip 2: Spot impartiality threats immediately. Look for these phrases in scenarios: previously provided consulting, former employee, helped implement the ISMS, relative works at the auditee, shares in the company. The correct response is to exclude or replace the person. Consultancy within roughly the last two years is the classic disqualifier.
Tip 3: Audit time is based on effective personnel, then adjusted. Answers that base time only on revenue, floor area or the client's wishes are wrong. The starting point is the number of persons doing work under the organization's control in the ISMS scope. After that, apply justified complexity factors.
Tip 4: Reductions need justification and have limits. Valid reasons include low risk, limited scope, prior certification or integration. Invalid reasons include a client's budget, a tight schedule or a desire for speed. Remember the general cap on reductions (commonly 30%) and that on-site time should not drop below about 80% of total audit time because of planning and reporting.
Tip 5: Know what does not count. Time spent by auditors-in-training, technical experts, observers, translators and guides is not counted as audit time.
Tip 6: Remember the cycle ratios.
• Surveillance is about one third of initial audit time.
• Recertification is about two thirds.
• Stage 1 and Stage 2 together equal the initial time.
Tip 7: Change triggers recalculation. If a scenario mentions an acquisition, new sites, a doubled workforce or a migration to cloud, the answer usually involves reviewing audit time and team competence.
Tip 8: Multi-site questions. The central function is always audited. Sampling is permitted only when there is one ISMS under central control. The sample should include risk-based selection, not just random selection.
Tip 9: Distinguish roles precisely.
• The lead auditor is accountable for the conclusions.
• Guides assist but do not audit.
• Observers do not interfere.
• Trainees work under supervision.
Many distractor answers swap these roles.
Tip 10: For essay or scenario answers, structure your response.
• (1) Identify the audit objectives and scope.
• (2) Determine the competence needed.
• (3) Check impartiality.
• (4) Calculate time from personnel and complexity.
• (5) Justify adjustments.
• (6) Assign roles and document the decision.
Quoting the relevant clause or standard (ISO 19011 5.5.4, ISO/IEC 17021-1, ISO/IEC 27006) strengthens your answer.
Tip 11: Choose the most risk-based answer. When two options seem correct, prefer the one that ensures sufficient evidence and maintains impartiality. Avoid options that favour convenience or cost.
Summary
Audit team selection ensures the right people audit: competent as a team, impartial and suited to the client's context. Audit time ensures they have enough time, calculated from the effective number of personnel and adjusted for business and IT complexity with documented justification. Mastering both lets a lead auditor plan audits that withstand accreditation scrutiny and produce trustworthy certification decisions. It also helps you answer exam questions with confidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!