PECB Certified ISO/IEC 27001 Lead Auditor
Five days on auditing information security management systems against ISO/IEC 27001, using the ISO 19011 and ISO/IEC 17021-1 principles that certification bodies audit by.
Total price, all inclusive
$1,495per seat
Exam, one retake and first-year certification included.
- Official PECB participant materials and case studies
- 3-hour PECB certification exam voucher included
- One free exam retake if you do not pass first time
- First-year certification application fee covered
- 31 CPD credits on completion
No payment is taken online. We confirm your seat and dates by email, then invoice. Questions?
About this course
ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system. It is the most widely recognised security certification in the world, and the one most often written into enterprise contracts, tender requirements and supplier assurance questionnaires.
This is the official PECB Lead Auditor scheme for ISO/IEC 27001, delivered over 5 days and worth 31 CPD credits. On completion and after passing the examination you are awarded the PECB Certified ISO/IEC 27001 Lead Auditor credential.
Why this certification is worth holding
- Named directly in enterprise procurement and vendor due-diligence questionnaires
- Maps cleanly onto SOC 2, NIS 2, DORA and GDPR control expectations
- The single most requested credential on information security job listings
What you will be able to do
- 01Explain the fundamental concepts of information security management systems and of ISO/IEC 27001
- 02Apply the audit principles, procedures and techniques of ISO 19011 and ISO/IEC 17021-1
- 03Plan and lead an audit, from the audit programme to the closing meeting
- 04Gather and evaluate audit evidence, and grade findings defensibly
- 05Draft nonconformity reports and manage audit follow-up and closure
Day-by-day agenda
5 days of instruction and case-study work, following the official PECB curriculum.
- 1
Introduction to ISO/IEC 27001 and audit principles
- Training objectives and the auditor certification path
- Information security management system — concepts and requirements
- Fundamental audit concepts and principles
- The audit approach based on evidence and risk
- Initiating the audit and establishing first contact with the auditee
- Stage 1 audit: documentation review and readiness assessment
- 2
Audit preparation
- Preparing the stage 2 audit and confirming the audit objectives
- Reviewing the ISMS documentation and the Annex A information security controls
- Building the audit plan and allocating work to the audit team
- Designing audit test plans, checklists and sampling strategy
- Drafting working documents and the opening meeting agenda
- 3
Conducting the audit
- Opening meeting and managing the auditee relationship
- Communication and coordination during the audit
- Audit procedures: observation, interview, sampling, corroboration
- Creating audit test plans and documenting evidence
- Drafting audit findings and nonconformity reports
- 4
Closing the audit and managing an audit programme
- Audit documentation and quality review of the file
- Closing meeting, conclusions and the certification decision
- Evaluating corrective action plans and verifying closure
- Managing an internal audit programme and surveillance audits
- Auditor competence, ethics and closing the training
- 5
Certification exam
- Exam-technique clinic: how the essay-type domains are marked
- Timed mock questions with model answers walked through
- Sitting the official PECB examination (online-proctored or paper)
- Submitting the certification application and evidencing experience
Exam and certification
Exam duration
3 hours
Exam format
Essay-type · open book
Delivery
Online-proctored or paper-based
CPD credits
31 credits
To be awarded PECB Certified ISO/IEC 27001 Lead Auditor
- Pass the PECB Lead Auditor examination
- Five years of professional experience, two of them in the relevant field
- 300 hours of audit activities
- Sign the PECB Code of Ethics
If you do not pass first time
One retake is included at no extra cost, and PECB does not require you to repeat the training. We run a focused review session with you first to work out where the marks went, then rebook the sitting.
Exam duration and format follow PECB’s published examination rules, which we confirm with you before you sit.
Who it is for
Built for
- Auditors seeking to lead certification audits of a management system
- Security and IT managers responsible for conformity with ISO/IEC 27001
- Internal auditors expanding into information security
- Consultants and advisors preparing clients for external audits
Prerequisites
A working knowledge of ISO/IEC 27001 and a general understanding of audit principles. The Foundation course covers this if you are new to the standard.
See the Foundation courseWhat is included
- Official PECB participant materials and case studies
- 3-hour PECB certification exam voucher included
- One free exam retake if you do not pass first time
- First-year certification application fee covered
- 31 CPD credits on completion
- Twelve months of access to the KATE learning app
- A 1:1 pre-enrolment call to confirm the course is right for you
Common questions
PECB is a global certification body that provides training and certification against ISO standards. Its personnel certification schemes are accredited to ISO/IEC 17024, the international standard for bodies certifying people — which is what makes a PECB credential recognised by employers, auditors and certification bodies worldwide rather than being a private certificate of attendance.
No. Foundation is not a formal prerequisite for Lead Implementer or Lead Auditor. It exists for people who are new to the standard and want the vocabulary and clause structure before the deeper course. If you already work with the standard day to day, go straight to the Lead course — we will tell you plainly on the pre-enrolment call which is right for you.
The official PECB participant materials and case studies, the certification exam voucher, one free retake if you do not pass first time, your first-year certification application fee, the CPD credits, twelve months of KATE app access, and a 1:1 call before you enrol. There are no separate exam fees added later.
Lead Implementer is for building the management system: scope, risk assessment, control selection, documentation and getting the organisation ready for its certification audit. Lead Auditor is for assessing one: audit planning, evidence gathering, findings, nonconformity reports and audit programme management. Implementers build, auditors verify. Consultants often hold both.
Foundation exams are one hour and multiple choice. Lead-level exams are three hours, essay-type and open book — you may bring the standard and your own notes. Exams can be sat online with remote proctoring or on paper at the end of a classroom session. Results are typically issued within four to six weeks, and your certification is then issued once your application is approved.
One retake is included in every price on this site, at no additional cost. PECB allows retakes without repeating the training, and we will run a focused review session with you first to work out what went wrong.
Often taken alongside this
ISO/IEC 27001 Foundation
A two-day grounding in ISO/IEC 27001 — the vocabulary, the structure of the standard and how information security management systems actually work in practice.
ISO/IEC 27001 Transition
Two days mapping what changed in the current edition of ISO/IEC 27001, and what your existing ISMS has to do about it before the next surveillance audit.
ISO/IEC 27001 Lead Implementer
Five days on leading an ISO/IEC 27001 implementation end to end — from gap assessment and scope through risk assessment, control selection and the Statement of Applicability, to the certification audit itself.