ISO 27001 audit: every kind, who runs it and the rule behind it
ISO/IEC 17021-1 clause 3.4: an “audit carried out by an auditing organization independent of the client and the parties that rely on certification, for the purpose of certifying the client’s management system”.
“ISO 27001 audit” can mean three different things: the audits you run on yourself, the audits your customers run on you, and the audits a certification body runs to certify you. They have different rules, different people and different consequences. This page sets out every kind, with the clause that governs it, and links to the page that covers it in detail.
Every kind of ISO 27001 audit
| Audit | Carried out by | Rule | Detail |
|---|---|---|---|
| Internal audit | You, or someone you appoint | Harmonized structure 9.2, applied by ISO/IEC 27001 | Internal audit |
| Customer (second-party) audit | A customer, or an auditor it mandates | Your contract; for processors, UK GDPR Art. 28(3)(h) | Article 28 |
| Stage 1 | Certification body | ISO/IEC 17021-1 9.3.1.2 | Stage 1 and Stage 2 |
| Stage 2 | Certification body | ISO/IEC 17021-1 9.3.1.3 | Stage 1 and Stage 2 |
| Surveillance audit | Certification body | ISO/IEC 17021-1 9.1.3.3, 9.6.2 | Surveillance audits |
| Recertification audit | Certification body | ISO/IEC 17021-1 9.6.3 | Recertification |
| Special audit: scope extension | Certification body | ISO/IEC 17021-1 9.6.4.1 | This page |
| Special audit: short notice | Certification body | ISO/IEC 17021-1 9.6.4.2 | This page |
Audits you run: internal audit
“The organization shall conduct internal audits at planned intervals to provide information on whether the [information security] management system: a) conforms to: the organization’s own requirements for its [information security] management system; the requirements of this document; b) is effectively implemented and maintained.” That is the harmonized-structure text ISO/IEC 27001 applies. “The organization shall plan, establish, implement and maintain (an) audit programme(s), including the frequency, methods, responsibilities, planning requirements and reporting.”
Objectivity
For each audit the organisation shall “select auditors and conduct audits to ensure objectivity and the impartiality of the audit process”. An internal audit can be done by staff or by an outside auditor you hire; what it cannot be is an audit of your own work that nobody else checks. Evidence of it must exist: “Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results.”
Who cannot do it for you
Your certification body. ISO/IEC 17021-1 bars it from providing internal audits to its certified clients, and doing so would stop it certifying you for two years. Detail on internal audit.
Audits your customers run: second-party audits
A customer auditing its supplier is not certifying anything; it is checking a contract. In UK data protection law there is one place this is a right rather than a favour. A processor's contract must say the processor “makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller” (UK GDPR Article 28(3)(h)).
Does a certificate replace a customer audit?
Not by law. Article 28 lets the controller audit or mandate an auditor. A current ISO/IEC 27001 certificate, with a scope covering the service, is evidence a customer can choose to accept instead — our reading; the choice is the customer's. How to check a certificate is on certificate verification.
Audits a certification body runs
“In the definitions which follow, the term “audit” has been used for simplicity to refer to third-party certification audit.” “Certification audits include initial, surveillance, re-certification audits, and can also include special audits.”
The three-year programme
“The audit programme for the initial certification shall include a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year prior to expiration of certification.” And: “Surveillance audits shall be conducted at least once a calendar year, except in recertification years. The date of the first surveillance audit following initial certification shall not be more than 12 months from the certification decision date.”
Stage 1 and Stage 2
The initial audit is in two stages. “The purpose of stage 2 is to evaluate the implementation, including effectiveness, of the client’s management system. The stage 2 shall take place at the site(s) of the client.” Stage 1 decides whether you are ready for it. See Stage 1 and Stage 2.
Surveillance and recertification
Surveillance audits sample the system in the two years between; the recertification audit looks at it whole: “The purpose of the recertification audit is to confirm the continued conformity and effectiveness of the management system as a whole, and its continued relevance and applicability for the scope of certification.” See surveillance audits and recertification.
Special audits
Extending the scope
“The certification body shall, in response to an application for expanding the scope of a certification already granted, undertake a review of the application and determine any audit activities necessary to decide whether or not the extension may be granted. This may be conducted in conjunction with a surveillance audit.”
Short-notice and unannounced audits
“It may be necessary for the certification body to conduct audits of certified clients at short notice or unannounced to investigate complaints, or in response to changes, or as follow up on suspended clients.” A complaint about a certified supplier, or a significant change at the client, can therefore bring the auditor back between scheduled visits.
Joint, combined and integrated audits
ISO/IEC 17021-1's notes to the definition name three arrangements:
| Note | Text |
|---|---|
| Note 4 | A joint audit is when two or more auditing organizations cooperate to audit a single client. |
| Note 5 | A combined audit is when a client is being audited against the requirements of two or more management systems standards together. |
| Note 6 | An integrated audit is when a client has integrated the application of requirements of two or more management systems standards into a single management system and is being audited against more than one standard. |
If you hold ISO 9001 or another management system standard alongside ISO 27001, the combined or integrated audit is where audit days can be saved. The rules are on integrated management systems.
How long certification audits take
Audit time starts from ISO/IEC 27006-1:2024 Table C.1, by the number of people doing work under the organisation's control, and is then adjusted. Four rows of it:
| People in scope | Initial audit (Stage 1 + 2) | Each surveillance audit | Recertification |
|---|---|---|---|
| 1–10 | 5 | 1.67 | 3.33 |
| 26–45 | 8.5 | 2.83 | 5.67 |
| 126–175 | 13 | 4.33 | 8.67 |
| 426–625 | 16.5 | 5.50 | 11.00 |
The full table and what those days cost are on the cost calculator.
On site or remote
““On-site” audits can include remote access to electronic site(s) that contain(s) information that is relevant to the audit of the management system.” Stage 2, though, “shall take place at the site(s) of the client”.
Three audits, three questions
Internal audit: is the system working, in our own judgement? Customer audit: does this supplier meet our contract? Certification audit: does the system conform to ISO/IEC 27001, in an independent body's judgement? Only the last produces a certificate.
We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The rules are quoted from ISO/IEC 17021-1, the harmonized structure and UK GDPR; points marked as our reading are ours.
Where this fits
Common questions
What is an ISO 27001 audit?
Any audit of an information security management system against ISO/IEC 27001. The certification audit is defined in ISO/IEC 17021-1 as an “audit carried out by an auditing organization independent of the client and the parties that rely on certification, for the purpose of certifying the client’s management system”. Your own internal audits and your customers' audits of you are audits too, but they do not lead to a certificate.
What are the types of ISO 27001 audit?
Internal audits you run yourself; audits by customers; and certification audits by a certification body. ISO/IEC 17021-1: “Certification audits include initial, surveillance, re-certification audits, and can also include special audits.”
How often is an ISO 27001 audit?
Internal audits “at planned intervals”. Certification: “The audit programme for the initial certification shall include a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year prior to expiration of certification.” And “Surveillance audits shall be conducted at least once a calendar year, except in recertification years. The date of the first surveillance audit following initial certification shall not be more than 12 months from the certification decision date.”
What is an external audit for ISO 27001?
Usually the certification body's audit: Stage 1 and Stage 2 for the first certificate, then surveillance and recertification. A customer's audit of you is also external to you, but it is a second-party audit and cannot lead to certification.
How long does an ISO 27001 certification audit take?
It depends on the number of people in scope. ISO/IEC 27006-1:2024 Table C.1 sets the starting point: for example 5 auditor days for 1–10 people and 8.5 for 26–45, before adjustments. Surveillance is a third of that and recertification two thirds.
Can an ISO 27001 audit be done remotely?
Partly. ISO/IEC 17021-1 notes: ““On-site” audits can include remote access to electronic site(s) that contain(s) information that is relevant to the audit of the management system.” Stage 2 “shall take place at the site(s) of the client”.
What is a combined or integrated audit?
“A combined audit is when a client is being audited against the requirements of two or more management systems standards together.” “An integrated audit is when a client has integrated the application of requirements of two or more management systems standards into a single management system and is being audited against more than one standard.”
Sources cited on this page
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
- BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
- ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025
- UK GDPR Article 28 (Processor), legislation.gov.uk
- ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
An audit coming up?
Say which kind, when, and the number of people in scope.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.