iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 audit: every kind, who runs it and the rule behind it

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 30 September 2026
By the iso27001partners.co.uk editorial team · Published 30 September 2026 · Last reviewed 30 September 2026 · 9 min read
6 primary sources cited on this page. How we check what is on this site
The certification audit Independent of you and your customers

ISO/IEC 17021-1 clause 3.4: an “audit carried out by an auditing organization independent of the client and the parties that rely on certification, for the purpose of certifying the client’s management system”.

“ISO 27001 audit” can mean three different things: the audits you run on yourself, the audits your customers run on you, and the audits a certification body runs to certify you. They have different rules, different people and different consequences. This page sets out every kind, with the clause that governs it, and links to the page that covers it in detail.

Every kind of ISO 27001 audit

Kinds of audit an ISO 27001 organisation meets, who carries them out, and the governing rule
AuditCarried out byRuleDetail
Internal auditYou, or someone you appointHarmonized structure 9.2, applied by ISO/IEC 27001Internal audit
Customer (second-party) auditA customer, or an auditor it mandatesYour contract; for processors, UK GDPR Art. 28(3)(h)Article 28
Stage 1Certification bodyISO/IEC 17021-1 9.3.1.2Stage 1 and Stage 2
Stage 2Certification bodyISO/IEC 17021-1 9.3.1.3Stage 1 and Stage 2
Surveillance auditCertification bodyISO/IEC 17021-1 9.1.3.3, 9.6.2Surveillance audits
Recertification auditCertification bodyISO/IEC 17021-1 9.6.3Recertification
Special audit: scope extensionCertification bodyISO/IEC 17021-1 9.6.4.1This page
Special audit: short noticeCertification bodyISO/IEC 17021-1 9.6.4.2This page

Audits you run: internal audit

“The organization shall conduct internal audits at planned intervals to provide information on whether the [information security] management system: a) conforms to: the organization’s own requirements for its [information security] management system; the requirements of this document; b) is effectively implemented and maintained.” That is the harmonized-structure text ISO/IEC 27001 applies. “The organization shall plan, establish, implement and maintain (an) audit programme(s), including the frequency, methods, responsibilities, planning requirements and reporting.”

Objectivity

For each audit the organisation shall “select auditors and conduct audits to ensure objectivity and the impartiality of the audit process”. An internal audit can be done by staff or by an outside auditor you hire; what it cannot be is an audit of your own work that nobody else checks. Evidence of it must exist: “Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results.”

Who cannot do it for you

Your certification body. ISO/IEC 17021-1 bars it from providing internal audits to its certified clients, and doing so would stop it certifying you for two years. Detail on internal audit.

Audits your customers run: second-party audits

A customer auditing its supplier is not certifying anything; it is checking a contract. In UK data protection law there is one place this is a right rather than a favour. A processor's contract must say the processor “makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller” (UK GDPR Article 28(3)(h)).

Does a certificate replace a customer audit?

Not by law. Article 28 lets the controller audit or mandate an auditor. A current ISO/IEC 27001 certificate, with a scope covering the service, is evidence a customer can choose to accept instead — our reading; the choice is the customer's. How to check a certificate is on certificate verification.

Audits a certification body runs

“In the definitions which follow, the term “audit” has been used for simplicity to refer to third-party certification audit.” “Certification audits include initial, surveillance, re-certification audits, and can also include special audits.”

The three-year programme

“The audit programme for the initial certification shall include a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year prior to expiration of certification.” And: “Surveillance audits shall be conducted at least once a calendar year, except in recertification years. The date of the first surveillance audit following initial certification shall not be more than 12 months from the certification decision date.”

Stage 1 and Stage 2

The initial audit is in two stages. “The purpose of stage 2 is to evaluate the implementation, including effectiveness, of the client’s management system. The stage 2 shall take place at the site(s) of the client.” Stage 1 decides whether you are ready for it. See Stage 1 and Stage 2.

Surveillance and recertification

Surveillance audits sample the system in the two years between; the recertification audit looks at it whole: “The purpose of the recertification audit is to confirm the continued conformity and effectiveness of the management system as a whole, and its continued relevance and applicability for the scope of certification.” See surveillance audits and recertification.

Special audits

Extending the scope

“The certification body shall, in response to an application for expanding the scope of a certification already granted, undertake a review of the application and determine any audit activities necessary to decide whether or not the extension may be granted. This may be conducted in conjunction with a surveillance audit.”

Short-notice and unannounced audits

“It may be necessary for the certification body to conduct audits of certified clients at short notice or unannounced to investigate complaints, or in response to changes, or as follow up on suspended clients.” A complaint about a certified supplier, or a significant change at the client, can therefore bring the auditor back between scheduled visits.

Joint, combined and integrated audits

ISO/IEC 17021-1's notes to the definition name three arrangements:

Audit arrangements, ISO/IEC 17021-1:2015 clause 3.4 notes (verbatim)
NoteText
Note 4A joint audit is when two or more auditing organizations cooperate to audit a single client.
Note 5A combined audit is when a client is being audited against the requirements of two or more management systems standards together.
Note 6An integrated audit is when a client has integrated the application of requirements of two or more management systems standards into a single management system and is being audited against more than one standard.

If you hold ISO 9001 or another management system standard alongside ISO 27001, the combined or integrated audit is where audit days can be saved. The rules are on integrated management systems.

How long certification audits take

Audit time starts from ISO/IEC 27006-1:2024 Table C.1, by the number of people doing work under the organisation's control, and is then adjusted. Four rows of it:

Auditor days by people in scope (ISO/IEC 27006-1:2024 Table C.1; surveillance one third and recertification two thirds of initial)
People in scopeInitial audit (Stage 1 + 2)Each surveillance auditRecertification
1–1051.673.33
26–458.52.835.67
126–175134.338.67
426–62516.55.5011.00

The full table and what those days cost are on the cost calculator.

On site or remote

““On-site” audits can include remote access to electronic site(s) that contain(s) information that is relevant to the audit of the management system.” Stage 2, though, “shall take place at the site(s) of the client”.

Three audits, three questions

Internal audit: is the system working, in our own judgement? Customer audit: does this supplier meet our contract? Certification audit: does the system conform to ISO/IEC 27001, in an independent body's judgement? Only the last produces a certificate.

We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The rules are quoted from ISO/IEC 17021-1, the harmonized structure and UK GDPR; points marked as our reading are ours.

Where this fits

Common questions

What is an ISO 27001 audit?

Any audit of an information security management system against ISO/IEC 27001. The certification audit is defined in ISO/IEC 17021-1 as an “audit carried out by an auditing organization independent of the client and the parties that rely on certification, for the purpose of certifying the client’s management system”. Your own internal audits and your customers' audits of you are audits too, but they do not lead to a certificate.

What are the types of ISO 27001 audit?

Internal audits you run yourself; audits by customers; and certification audits by a certification body. ISO/IEC 17021-1: “Certification audits include initial, surveillance, re-certification audits, and can also include special audits.”

How often is an ISO 27001 audit?

Internal audits “at planned intervals”. Certification: “The audit programme for the initial certification shall include a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year prior to expiration of certification.” And “Surveillance audits shall be conducted at least once a calendar year, except in recertification years. The date of the first surveillance audit following initial certification shall not be more than 12 months from the certification decision date.”

What is an external audit for ISO 27001?

Usually the certification body's audit: Stage 1 and Stage 2 for the first certificate, then surveillance and recertification. A customer's audit of you is also external to you, but it is a second-party audit and cannot lead to certification.

How long does an ISO 27001 certification audit take?

It depends on the number of people in scope. ISO/IEC 27006-1:2024 Table C.1 sets the starting point: for example 5 auditor days for 1–10 people and 8.5 for 26–45, before adjustments. Surveillance is a third of that and recertification two thirds.

Can an ISO 27001 audit be done remotely?

Partly. ISO/IEC 17021-1 notes: ““On-site” audits can include remote access to electronic site(s) that contain(s) information that is relevant to the audit of the management system.” Stage 2 “shall take place at the site(s) of the client”.

What is a combined or integrated audit?

“A combined audit is when a client is being audited against the requirements of two or more management systems standards together.” “An integrated audit is when a client has integrated the application of requirements of two or more management systems standards into a single management system and is being audited against more than one standard.”

Sources cited on this page

  1. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  2. BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
  3. BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
  4. ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025
  5. UK GDPR Article 28 (Processor), legislation.gov.uk
  6. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

An audit coming up?

Say which kind, when, and the number of people in scope.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now