Steps and Activities to Prepare an ISMS Audit
Preparing an ISMS audit follows the audit process in ISO 19011 and ISO/IEC 17021-1, as covered in the PECB ISO/IEC 27001 Lead Auditor course. Preparation turns the audit objectives into a realistic, risk-based plan. Step 1, Initiating the audit: The audit team leader is appointed and contacts the a… Preparing an ISMS audit follows the audit process in ISO 19011 and ISO/IEC 17021-1, as covered in the PECB ISO/IEC 27001 Lead Auditor course. Preparation turns the audit objectives into a realistic, risk-based plan. Step 1, Initiating the audit: The audit team leader is appointed and contacts the auditee. This contact confirms communication channels and the auditee's authority. It also requests access to documented information, confirms the audit objectives, scope and criteria, and identifies site-specific security, confidentiality and health and safety requirements. Step 2, Determining audit feasibility: The leader checks whether there is enough information, enough cooperation from the auditee, and enough time and resources. If the audit is not feasible, an alternative is proposed to the audit client. Step 3, Stage 1 audit and documentation review: The auditor reviews the ISMS documentation. This includes the scope, information security policy, risk assessment and treatment methodology, Statement of Applicability, objectives, and results of internal audits and management reviews. The review helps the auditor understand the organization's context, processes, assets and readiness for Stage 2. It also identifies areas of concern, which are documented in a Stage 1 report. Step 4, Audit planning: The team leader prepares an audit plan using a risk-based approach. The plan defines objectives, scope, criteria, locations, dates, duration, audit methods, sampling, roles and responsibilities, and logistics. It is communicated to the auditee, and any objections are resolved. Step 5, Assigning work to the audit team: Tasks are allocated according to each auditor's competence, independence and the need to avoid conflicts of interest. Technical experts and guides are assigned where needed. Step 6, Preparing work documents: Auditors develop checklists, audit test plans, sampling plans, interview guides and forms for recording evidence, findings and meetings. These documents support consistent evidence collection but must stay flexible. Together, these activities ensure the audit is efficient, objective, evidence-based and properly aligned with ISO/IEC 27001 requirements.
Steps and Activities to Prepare an ISMS Audit: A Complete Guide for the ISO/IEC 27001 Lead Auditor Exam
Introduction
Preparing an ISMS audit means doing the planning and groundwork before any on-site or remote audit work begins. Every successful ISO/IEC 27001 audit, whether internal, second-party or third-party (certification), depends on how well this phase is done. In the ISO/IEC 27001 Lead Auditor syllabus, this topic sits in the domain Preparing an ISO/IEC 27001 audit. It draws mainly on ISO 19011:2018 (clauses 6.2 and 6.3), ISO/IEC 17021-1 (clause 9), ISO/IEC 27006-1 and ISO/IEC 27007.
This guide explains why preparation matters, what it involves, how each step works, and how to answer exam questions on it.
1. Why Audit Preparation Is Important
Preparation determines the quality, credibility and efficiency of the audit. Key reasons:
• It confirms the audit can achieve its objectives. A feasibility check shows whether the information, cooperation, time and resources are adequate before effort is spent.
• It supports a risk-based approach. ISO 19011 requires auditors to consider risks and opportunities to the audit itself. Examples include unavailable personnel, restricted access to confidential information, or an incomplete ISMS.
• It focuses effort where it matters. Reviewing the ISMS scope, risk assessment and Statement of Applicability (SoA) beforehand lets auditors concentrate on high-risk processes and important Annex A controls.
• It protects impartiality and competence. Selecting the audit team during preparation means conflicts of interest and competence gaps are handled early.
• It avoids surprises for the auditee. Agreeing the audit plan in advance means the right people, records and facilities are available.
• It supports reliable conclusions. Good sampling plans and work documents lead to objective, traceable evidence.
• It meets accreditation requirements. Certification bodies must show that audits were planned according to ISO/IEC 17021-1 and ISO/IEC 27006-1. Poor preparation can lead to non-conformities against the certification body itself.
2. What Audit Preparation Is
ISO 19011:2018 divides the audit into stages. Preparation covers the first two:
• 6.2 Initiating the audit
• 6.2.1 General (the audit team leader takes responsibility)
• 6.2.2 Establishing contact with the auditee
• 6.2.3 Determining the feasibility of the audit
• 6.3 Preparing audit activities
• 6.3.1 Performing review of documented information
• 6.3.2 Audit planning (6.3.2.1 risk-based approach to planning; 6.3.2.2 audit planning details)
• 6.3.3 Assigning work to the audit team
• 6.3.4 Preparing documented information for the audit
The later stages are 6.4 Conducting audit activities, 6.5 Preparing and distributing the audit report, 6.6 Completing the audit, and 6.7 Conducting audit follow-up.
In third-party certification, the certification body adds steps before and around these. These include application review, determining audit time, the Stage 1 audit and preparing the Stage 2 audit (ISO/IEC 17021-1, clauses 9.1 to 9.3). Many training courses treat Stage 1 as part of audit preparation, because its outputs feed directly into planning Stage 2.
Key terms to know (ISO 19011 / ISO 9000):
• Audit objectives: what the audit is meant to achieve.
• Audit scope: the extent and boundaries of the audit, such as locations, organizational units, activities, processes and time period.
• Audit criteria: the requirements used as a reference, such as ISO/IEC 27001 clauses 4 to 10, applicable Annex A controls, policies, and legal and contractual requirements.
• Audit plan: a description of the activities and arrangements for one audit.
• Audit programme: arrangements for a set of audits over a time frame (managed by the audit programme manager, not the team leader).
3. How It Works: Step-by-Step Activities
Step 1: Receive the audit mandate (objectives, scope and criteria)
The audit programme manager, or the certification body after application review, gives the audit team leader the audit objectives, scope and criteria. For a certification audit, the application review confirms:
• the ISMS scope;
• the number of sites;
• the number of effective personnel;
• the complexity of the ISMS and its technology;
• outsourced processes;
• the legal and regulatory context.
The certification body then calculates audit time using ISO/IEC 27006-1 (based on effective personnel, adjusted for ISMS complexity and other factors) and IAF Mandatory Documents. These include IAF MD1 for multi-site sampling, IAF MD4 for the use of ICT, and IAF MD5 for audit duration in other management system schemes.
Step 2: Select and appoint the audit team
The team is selected based on:
• the competence needed to achieve the audit objectives;
• the size and complexity of the audit;
• the audit method (on-site or remote);
• the need for impartiality and objectivity (for example, no consultancy for the auditee in the past two years under certification rules);
• language and cultural needs;
• the need for technical experts (for example in cryptography, cloud or OT security), auditors in training, observers or guides.
Technical experts give knowledge but do not act as auditors. They work under the direction of an auditor.
Step 3: Establish initial contact with the auditee
The audit team leader, or the programme manager, contacts the auditee formally or informally to:
• confirm communication channels with the auditee's representatives;
• confirm the authority to conduct the audit;
• share information on objectives, scope, criteria, methods and team composition, including technical experts;
• request access to relevant documented information for planning, such as the ISMS scope, policy, risk assessment, risk treatment plan and SoA;
• identify applicable legal, statutory, regulatory and contractual requirements;
• confirm confidentiality arrangements, which are critical in ISMS audits;
• agree the dates, duration, locations and schedule;
• agree access, health and safety, security and other arrangements, such as visitor badges, NDAs and clean-desk rules;
• agree the use of observers and guides;
• identify areas of interest, concern or risk;
• agree whether remote audit methods (ICT) will be used and which platforms.
ISMS-specific point: ISO/IEC 27006-1 and ISO/IEC 27007 recognize that the auditee may refuse to disclose some information because it is confidential or sensitive. For example, it may refuse to share detailed vulnerability reports or classified data. The certification body must decide whether the ISMS can still be audited adequately without that information. If it cannot, the audit may not be feasible until access arrangements are agreed.
Step 4: Determine the feasibility of the audit
ISO 19011 (6.2.3) says feasibility depends on three factors:
• sufficient and appropriate information for planning and conducting the audit;
• adequate cooperation from the auditee;
• adequate time and resources.
If the audit is not feasible, the team leader proposes an alternative to the audit client after consulting the auditee. Alternatives include changing the scope, postponing the audit or adding resources. The team leader does not simply cancel the audit alone.
Step 5: Review documented information (including Stage 1 for certification)
The auditee's ISMS documented information is reviewed to:
• gather information to prepare audit activities and working documents;
• get an overview of the extent of documented information and spot possible gaps;
• understand the context of the organization.
Typical items reviewed for ISO/IEC 27001:2022 include:
• ISMS scope (clause 4.3), interested parties and context;
• information security policy (5.2) and roles and responsibilities (5.3);
• risk assessment and risk treatment methodology and results (6.1.2, 6.1.3, 8.2, 8.3);
• Statement of Applicability, with justifications for inclusions and exclusions (6.1.3 d);
• risk treatment plan and risk owner approval;
• information security objectives (6.2);
• evidence of competence (7.2);
• monitoring and measurement results (9.1);
• internal audit programme and results (9.2);
• management review outputs (9.3);
• nonconformities and corrective actions (10.2).
Stage 1 objectives (ISO/IEC 17021-1, 9.3.1.2) include:
• reviewing documented information;
• evaluating site-specific conditions;
• checking understanding of the requirements;
• collecting information on scope, processes, locations and legal aspects;
• reviewing the allocation of resources for Stage 2;
• focusing the planning of Stage 2;
• checking whether internal audits and management reviews have been planned and performed;
• judging whether the organization is ready for Stage 2.
Stage 1 findings, including areas of concern that could become nonconformities, are documented and shared with the client. ISO/IEC 27006-1 also requires that, for ISMS audits, documented information is reviewed before Stage 2.
Step 6: Prepare the audit plan using a risk-based approach
The audit team leader prepares the audit plan. Its level of detail should match the scope, complexity and risk of not achieving the audit objectives. When planning, the team leader considers:
• the composition and competence of the audit team;
• suitable sampling techniques;
• chances to improve audit effectiveness and efficiency;
• risks created by ineffective planning.
The audit plan typically includes:
• audit objectives;
• scope, including organizational and functional units, processes and sites;
• audit criteria and reference documents;
• locations, dates, expected times and duration, including meetings with auditee management;
• audit methods, including sampling and the use of remote techniques;
• roles and responsibilities of team members, guides and observers;
• allocation of resources based on the risks of the activities;
• other items as needed: auditee representative, language, report topics, logistics, confidentiality and information security, follow-up and coordination with other audits (integrated audits).
The plan should be flexible. It may change during the audit, but changes must be agreed with the auditee. The plan is presented to the auditee, and any objections are resolved between the team leader, the auditee and, if needed, the audit client before the audit starts.
Step 7: Assign work to the audit team
The audit team leader, consulting the team, assigns each member responsibility for specific processes, functions, sites, areas or activities. Assignments consider:
• independence: auditors should not audit their own work;
• competence;
• efficient use of resources;
• the different roles of auditors, auditors in training and technical experts.
Team briefings may be held to share information and assign work. Assignments can change during the audit.
Step 8: Prepare documented information (work documents) for the audit
Team members collect and review the information relevant to their assignments and prepare work documents such as:
• checklists, for example built from ISO/IEC 27001 clauses and the applicable Annex A controls in the SoA;
• audit sampling plans, which may be judgement-based or statistical, for example sampling access-rights reviews, change records or incident tickets;
• audit test plans for technical controls;
• audio-visual or ICT tools;
• forms for recording evidence, findings and meeting records.
Important: work documents must not restrict the extent of audit activities. They can change as new information arises during the audit. They must be retained at least until the audit is completed and, where they contain confidential or proprietary information, protected appropriately.
Step 9: Final logistics and confirmation
Before the audit, the team leader confirms:
• the final plan and the attendees for the opening meeting;
• access permissions, guides and safety or security briefings;
• that ICT tools have been tested for remote sessions;
• the rules for capturing or transmitting evidence, such as whether screenshots of sensitive data are allowed;
• the protection of audit records.
4. ISMS-Specific Preparation Considerations (ISO/IEC 27007 and 27006-1)
• Scope boundaries: check that the ISMS scope is clearly defined. This includes interfaces and dependencies with activities outside the scope, such as outsourced cloud services.
• Risk-driven controls: plan to check that controls in the SoA trace back to the risk assessment and treatment, and that exclusions are justified.
• Technical controls: decide whether technical review or testing is needed and whether technical experts must be added.
• Confidential information: plan how to verify controls without accessing classified data, for example by viewing records under supervision.
• Multi-site organizations: plan site sampling according to IAF MD1 and ISO/IEC 27006-1, considering the risk and complexity of each site.
• Remote auditing: assess the risks of ICT use (IAF MD4), such as connectivity, authentication of participants and recording permissions.
• Integrated audits: coordinate with other management system audits, such as ISO 9001 or ISO/IEC 20000-1, if combined.
5. Roles and Responsibilities During Preparation
• Audit programme manager / certification body: sets objectives, scope and criteria; selects the team; determines audit time; manages application review.
• Audit team leader: contacts the auditee (or confirms contact); determines feasibility; leads documented information review; prepares the audit plan; assigns work; resolves plan objections.
• Audit team members: review information for their assignments; prepare checklists, sampling plans and other work documents.
• Technical experts: give specific knowledge under an auditor's direction.
• Auditee: provides information, access and cooperation; nominates guides; reviews and accepts the plan.
• Audit client: requests the audit; decides on alternatives if the audit is not feasible.
6. Common Pitfalls
• Starting fieldwork without confirming access to key documents or people.
• Using generic checklists that ignore the organization's SoA and risk profile.
• Treating the checklist as a limit on what can be audited.
• Not checking impartiality, for example when an auditor previously consulted for the auditee.
• Making the plan too rigid, or changing it without the auditee's agreement.
• Ignoring confidentiality constraints that block evidence collection.
• Allocating too little time to complex or high-risk processes.
7. Worked Example
Scenario: A certification body is asked to audit a fintech company with 180 employees across two offices and a cloud-hosted platform. During initial contact, the company says it will not show penetration-test reports because of their sensitivity.
Preparation response:
1. Confirm objectives (initial certification), scope (both offices and the platform) and criteria (ISO/IEC 27001:2022, the SoA, PCI DSS contractual obligations).
2. Calculate audit time using ISO/IEC 27006-1. Decide whether both sites must be visited.
3. Select a team with fintech and cloud-security competence and check impartiality.
4. Assess feasibility. Propose an alternative to the client, such as viewing the reports on-site under supervision without taking copies.
5. In Stage 1, review the scope, risk assessment, SoA and internal audit results. Identify that the supplier security controls (Annex A 5.19 to 5.23) are high-risk.
6. Prepare a Stage 2 plan that gives extra time to cloud-supplier management and vulnerability management.
7. Assign the cloud specialist to technical controls and the lead auditor to clauses 4 to 10.
8. Prepare sampling plans, for example 10 of 120 change tickets and 5 supplier contracts, and a checklist based on the SoA.
8. Exam Tips: Answering Questions on Steps and Activities to Prepare an ISMS Audit
Tip 1: Memorize the sequence.
Mandate (objectives, scope, criteria) → team selection → initial contact → feasibility → documented information review (Stage 1) → audit plan → work assignment → work documents. Many questions ask what the auditor should do first or next. Initial contact and feasibility always come before detailed planning.
Tip 2: Know the three feasibility factors.
Sufficient and appropriate information, adequate cooperation from the auditee, and adequate time and resources. If an option mentions any other condition (for example, 'the auditee has no nonconformities'), it is a distractor.
Tip 3: When an audit is not feasible, propose alternatives.
The correct answer is usually to propose an alternative to the audit client, in consultation with the auditee. Answers saying the auditor should cancel unilaterally, proceed anyway or issue a nonconformity are usually wrong.
Tip 4: Separate the audit plan from the audit programme.
The plan covers one audit and is prepared by the audit team leader. The programme covers several audits over time and is managed by the audit programme manager. Exam questions often mix up these two.
Tip 5: Checklists support the audit but never limit it.
Any option stating that auditors must audit only what is on the checklist is incorrect. Work documents are flexible and must be retained and protected.
Tip 6: The audit plan is flexible but changes must be agreed.
Plan changes during the audit are acceptable if agreed with the auditee. The plan is communicated before the audit, and objections are resolved before fieldwork begins.
Tip 7: Understand Stage 1 versus Stage 2.
Stage 1 checks readiness, understanding of the requirements, documented information, scope and site conditions, and focuses Stage 2 planning. Stage 2 evaluates implementation and effectiveness. If a question asks which stage checks whether internal audits and management reviews have been planned and performed, the answer is Stage 1. Stage 2 then confirms their effectiveness.
Tip 8: Look for ISMS-specific clues.
Mentions of the SoA, risk treatment, confidential information or technical controls point to ISO/IEC 27006-1 and ISO/IEC 27007 considerations. For example, if the auditee refuses access to sensitive records, the auditor must judge whether the audit can still achieve its objectives. The auditor should not ignore the issue, and should not automatically raise a major nonconformity.
Tip 9: Impartiality and competence come first in team selection.
In scenarios where an auditor has a prior relationship with the auditee, the correct action is to replace or reassign the auditor. Technical experts give knowledge but do not audit on their own.
Tip 10: Use the risk-based approach in planning answers.
For essay or scenario questions, justify time allocation by risk and complexity, for example: 'More time is assigned to supplier relationships because the core platform is outsourced to a cloud provider.' Examiners reward answers that link planning decisions to the organization's context and risk assessment.
Tip 11: Structure essay answers clearly.
Use a numbered sequence of steps. Name the responsible party and the output of each step (for example, an agreed audit plan, a sampling plan or a feasibility decision). Cite the relevant clause where possible, such as ISO 19011 6.2.3 or ISO/IEC 17021-1 9.3.1.2. Connect each step to the scenario facts. Generic theory without application loses marks.
Tip 12: Watch absolute words.
'Always', 'never', 'must only' and 'all' often signal wrong options. Exceptions include true absolutes such as 'audit criteria must be defined' or 'auditors must not audit their own work'.
Sample exam questions and answers
Q1. During initial contact, the auditee says key staff will be unavailable during the planned dates. What should the audit team leader do?
Answer: Reassess feasibility (adequate cooperation and resources) and agree alternative dates or arrangements with the auditee and audit client. The audit plan is then updated.
Q2. Which document best helps the auditor determine which Annex A controls to include in the checklist?
Answer: The Statement of Applicability, supported by the risk assessment and risk treatment plan.
Q3. A junior auditor says the checklist does not include a process discovered during the audit, so it should not be examined. Is this correct?
Answer: No. Work documents must not restrict audit activities. If the process is within scope and relevant, it should be audited, and the plan adjusted with the auditee's agreement.
Q4. Who prepares the audit plan?
Answer: The audit team leader, who presents it to the auditee before the audit.
Q5. Name two outputs of the preparation phase.
Answer: Examples include an agreed audit plan, work assignments, checklists and sampling plans, a feasibility determination, and Stage 1 findings or a readiness decision.
9. Quick Reference Summary
• Why: ensures feasibility, risk-focused effort, impartiality, efficiency and credible conclusions.
• What: ISO 19011 clauses 6.2 (initiating) and 6.3 (preparing), plus certification steps from ISO/IEC 17021-1 and 27006-1 (application review, audit time, Stage 1).
• How: mandate → team → contact → feasibility → document review / Stage 1 → risk-based audit plan → work assignment → work documents → confirmation.
• Exam keys:
• the three feasibility factors;
• propose alternatives if the audit is not feasible;
• the team leader owns the plan;
• checklists never limit the audit;
• plan changes are agreed with the auditee;
• Stage 1 checks readiness, Stage 2 checks effectiveness;
• the SoA and risk assessment drive ISMS audit focus.
Master this sequence and link each step to the scenario facts, and you will be able to answer both multiple-choice and essay questions on ISMS audit preparation with confidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!