Roadmaps / ISO/IEC 27001 — Lead Auditor
🔍
advanced Roadmap #15

ISO/IEC 27001 — Lead Auditor

This roadmap prepares you for ISO/IEC 27001:2022 Lead Auditor certification exams. Where Foundation taught what the standard requires and Implementer taught how to build it, this roadmap is about independently verifying it — planning an audit program, preparing and conducting an audit, collecting and evaluating evidence, classifying findings, writing a defensible audit report, and understanding how certification bodies themselves are held accountable under ISO/IEC 17021-1. Exam preparation only — official certification is issued exclusively by an accredited body (PECB, BSI, IRCA), never by VigilForge.

📚 13 lessons ⏱ ~40h 📊 advanced

Create a free account to track your progress and unlock all features.

Get Started Free Sign In
ISO 19011 Principles Audit Programs Evidence Collection Nonconformity Classification Audit Reporting ISO/IEC 17021-1

📋 Lessons (13 total)

1
Foundations of Auditing & ISO 19011 Principles Medium

Learn the seven auditing principles behind every credible management system audit, why they exist, and how violating any one of them can invalidate an otherwise technically correct audit finding.

⏱ 55m
2
Establishing and Managing an Audit Program Medium prereq required

Learn how an audit program manager plans a multi-year cycle of audits, allocates competent auditors to each one, and monitors the program itself for effectiveness — the layer of management above any single audit.

⏱ 55m
3
Audit Planning: Objectives, Scope, and Criteria Medium prereq required

Learn the three defining parameters of any single audit — objectives, scope, and criteria — and why confusing 'criteria' with 'the standard' produces an audit no one can actually be held to.

⏱ 55m
4
Preparing the Audit: Document Review & Audit Plan Medium prereq required

Learn how to review an organization's documented information before ever setting foot on-site, and how to turn objectives/scope/criteria into a concrete, working audit plan and checklist.

⏱ 55m
5
The Opening Meeting & On-site Audit Activities Medium prereq required

Learn what a real opening meeting needs to establish before any evidence-gathering begins, and how to keep on-site activities aligned to the audit plan as the day unfolds.

⏱ 50m
6
Audit Techniques: Interviewing, Sampling, and Evidence Collection Medium prereq required

Learn the core techniques for actually gathering audit evidence — asking effective interview questions, sampling records credibly, and triangulating between what people say, what documents show, and what direct observation reveals.

⏱ 60m
7
Evaluating Audit Evidence & Determining Findings Medium prereq required

Learn how to move from collected evidence to a defensible audit finding — separating a fact from an inference, checking evidence against criteria rather than personal opinion, and recognizing when evidence is too thin to support a conclusion either way.

⏱ 55m
8
Classifying Nonconformities: Major, Minor, and Observation Medium prereq required

Learn how certification audits classify findings into major nonconformity, minor nonconformity, and observation — and why this classification, not just the finding itself, is what actually determines the consequences for certification.

⏱ 55m
9
Writing the Audit Report Medium prereq required

Learn what a defensible audit report actually contains, why every finding must be traceable back to its evidence, and how to write a report that survives scrutiny from someone who wasn't in the room.

⏱ 55m
10
The Closing Meeting & Follow-up Actions Medium prereq required

Learn how to present findings at the closing meeting without ambush, handle a disputed finding professionally, and verify that corrective actions actually close a nonconformity rather than just paper over it.

⏱ 50m
11
Auditor Competence, Evaluation, and Ethics Medium prereq required

Learn what specific competencies an auditor actually needs beyond knowing the standard, how auditors themselves are evaluated and maintained, and how to reason through ethical situations that don't have a clean rule to fall back on.

⏱ 50m
12
The Certification Body Perspective: ISO/IEC 17021-1 & Accreditation Medium prereq required

Learn how certification bodies themselves are held accountable — accreditation, impartiality safeguards, audit duration and multi-site sampling rules, and what happens when a certificate is suspended or withdrawn.

⏱ 55m
13
Auditor Practice Exam Hard prereq required

A comprehensive review and 20-question practice exam covering everything from lessons 1-12 — ISO 19011 principles, audit programs and planning, evidence collection, findings and classification, reporting, closure, auditor ethics, and the ISO/IEC 17021-1 certification body perspective.

⏱ 90m
🔍

From Building to Verifying

Implementer taught you how to build an ISMS. This roadmap is about independently verifying one — the skill a certification body auditor, or your own internal audit function, actually needs.

Prerequisite

This roadmap assumes Foundation's clauses/Annex A/SoA concepts and Implementer's practical control implementation throughout — complete both first if you haven't.

Go to Implementer roadmap →

Recommended Before

Complete earlier roadmaps in the sequence for best results.

View all roadmaps →

What You'll Learn

  • Apply the seven ISO 19011 auditing principles to real scenarios
  • Plan and prepare a management system audit from scope to checklist
  • Collect and evaluate audit evidence through interviews and sampling
  • Classify nonconformities and write a defensible audit report
  • Understand how certification bodies themselves are accredited under ISO/IEC 17021-1