ISO 27001 lead auditor: the qualification, and what auditing for a certification body actually requires
Before auditing ISMSs for a certification body, an auditor must have “gained experience of auditing ISMS” as an auditor-in-training — ISO/IEC 27006:2015/Amd 1:2020, 7.2.1.1 d). A lead auditor course is not that experience.
“ISO 27001 lead auditor” is sold as a course, but the phrase covers three different things, and they are governed by three different sets of rules. Knowing which one you need — for your career, for a job advert, or for your own organisation's internal audit — saves you buying the wrong one.
Three things called an “ISO 27001 auditor”
| Lead auditor credential | Certification body auditor | Your internal auditor | |
|---|---|---|---|
| What it is | A personal credential: a course, an exam, then experience | Being allowed to audit ISO 27001 for an accredited certification body | Whoever audits your own ISMS under clause 9.2 |
| Who grants it | A personnel certification body running a published scheme | The certification body, against ISO/IEC 17021-1 and ISO/IEC 27006 | You appoint them |
| The standard behind it | ISO/IEC 17024 (certification of persons) | ISO/IEC 17021-1, and the ISMS rules in ISO/IEC 27006 | ISO/IEC 27001 clause 9.2 |
| Experience required | Depends on the grade — from none to ten years | At least 10 ISMS on-site audit days, as an auditor-in-training, within 5 years | Not specified — objectivity and impartiality are |
| Does it certify an organisation? | No | It is how organisations get certified | No |
| Can your certification body do it for you? | — | — | No — ISO/IEC 17021-1 clause 5.2.6 |
The first column is what most people mean. The second is what an organisation actually meets at Stage 1 and Stage 2. The third is what your organisation has to provide for itself every year. A single person can be all three at different times — but never the second and third for the same organisation, because a certification body may not provide internal audits to its certified clients.
The personal credential: how the grades work
A lead auditor credential is issued by a personnel certification body under a published scheme. We use PECB as the worked example because it publishes its grade rules in full on a public page; other scheme owners publish their own, and we do not rank them. Every PECB auditor grade starts from the same exam — “PECB Certified ISO/IEC 27001 Lead Auditor exam or equivalent” — and then differs by experience:
| Credential | Professional experience | Management system audit experience |
|---|---|---|
| PECB Certified ISO/IEC 27001 Provisional Auditor | None | None |
| PECB Certified ISO/IEC 27001 Auditor | Two years: One year of work experience in Information Security Management | Audit activities: a total of 200 hours |
| PECB Certified ISO/IEC 27001 Lead Auditor | Five years: Two years of work experience in Information Security Management | Audit activities: a total of 300 hours |
| PECB Certified ISO/IEC 27001 Senior Lead Auditor | Ten years: Seven years of work experience in Information Security Management | Audit activities: a total of 1,000 hours |
What counts as audit experience
PECB says the audits must follow best audit practice and include activities such as:
- Audit planning
- Audit interview
- Managing an audit program
- Drafting audit reports
- Drafting non-conformity reports
- Drafting audit working documents
- Documentation review
- On-site Audit
- Follow-up on non-conformities
- Leading an audit team
The course itself
The published PECB lead auditor course runs over five days:
| Content | |
|---|---|
| Day 1 | Introduction to the information security management system (ISMS) and ISO/IEC 27001 |
| Day 2 | Audit principles, preparation, and initiation of an audit |
| Day 3 | On-site audit activities |
| Day 4 | Closing the audit |
| Day 5 | Certification Exam |
PECB also states that “Certification and examination fees are included in the price of the training course”. We do not publish course prices: they vary by provider and format, and we have no source we could keep current.
Other schemes, and moving between them
Schemes are not all built the same way. Exemplar Global, for instance, allows an audit log in place of a knowledge exam where no exam is available: “If a knowledge examination is not available, this may be substituted with an audit log showing relevant audit experience. If you choose this method, we require that you show evidence of 10 audit days reflecting the specific scheme (e.g, QMS, EMS, OHS, etc.) and grade (i.e., auditor or lead auditor) you wish to apply for.” — and adds: “Importantly, the audit dates captured in your log need to have been conducted within the past three years.” Schemes also recognise one another to some extent: “There are current agreements with IRCA/CQI, PECB, and the CCAA to recognize certification.”
Lead auditor vs lead implementer
Same scheme owner, same experience ladder, different job. The implementer grades mirror the auditor grades exactly, but count project activities rather than audit activities:
| Credential | Professional experience | ISMS project experience |
|---|---|---|
| PECB Certified ISO/IEC 27001 Provisional Implementer | None | None |
| PECB Certified ISO/IEC 27001 Implementer | Two years: One year of work experience in Information Security Management | Project activities: a total of 200 hours |
| PECB Certified ISO/IEC 27001 Lead Implementer | Five years: Two years of work experience in Information Security Management | Project activities: a total of 300 hours |
| PECB Certified ISO/IEC 27001 Senior Lead Implementer | Ten years: Seven years of work experience in Information Security Management | Project activities: a total of 1,000 hours |
What each is trained to do
The implementer course, over the same five days, covers:
| Content | |
|---|---|
| Day 1 | Introduction to ISO/IEC 27001 and initiation of an ISMS implementation |
| Day 2 | Implementation plan of an ISMS |
| Day 3 | Implementation of an ISMS |
| Day 4 | ISMS monitoring, continual improvement, and preparation for the certification audit |
| Day 5 | Certification exam |
And the project experience PECB counts for an implementer includes:
- Drafting an ISMS implementation business case
- Managing an ISMS implementation project
- Implementing the ISMS
- Managing documented information
- Implementing corrective actions
- Monitoring the ISMS performance
- Managing an ISMS implementation team
If your aim is to get your own organisation certified, the implementer route is the closer fit. If your aim is to run internal audits or to audit other organisations, the auditor route is. Neither certifies your organisation.
Auditing for a certification body: what ISO/IEC 27006 requires
The auditor who arrives for your Stage 2 is not there because of a course certificate. Certification bodies are assessed against ISO/IEC 17021-1, and for information security against ISO/IEC 27006, which requires that each ISMS auditor:
d) “has gained experience of auditing ISMS prior to acting as an auditor performing ISMS audits. This experience shall be gained by performing as an auditor-in-training monitored by an ISMS evaluator (see ISO/IEC 17021-1:2015, 9.2.2.1.4) in at least one ISMS initial certification audit (stage 1 and stage 2) or re-certification and at least one surveillance audit. This experience shall be gained in at least 10 ISMS on-site audit days and performed in the last 5 years. The participation shall include review of documentation and risk assessment, implementation assessment and audit reporting.”
g) “has competence in auditing an ISMS in accordance with ISO/IEC 27001.”
ISO/IEC 27006:2015/Amd 1:2020, 7.2.1.1, quoted verbatim
How the auditor-in-training rule works
The route in is supervised audit work. ISO/IEC 17021-1: “Auditors-in-training may participate in the audit, provided an auditor is appointed as an evaluator. The evaluator shall be competent to take over the duties and have final responsibility for the activities and findings of the auditor-in-training.” So when a certification body brings an extra person to your audit, it may be exactly this — and the evaluator, not the trainee, carries final responsibility for the findings.
What a certification body must define for its auditors
“Table A.1 specifies the knowledge and skills that a certification body shall define for specific certification functions.” For the people auditing and leading the audit team, the table lists knowledge and skills including:
- Knowledge of business management practices
- Knowledge of audit principles, practices and techniques
- Knowledge of specific management system standards/normative documents
- Knowledge of certification body’s processes
- Knowledge of client’s business sector
- Knowledge of client products, processes and organization
- Language skills appropriate to all levels within the client organization
- Note-taking and report-writing skills
- Presentation skills
- Interviewing skills
- Audit-management skills
Sector knowledge is on that list for a reason: it is why the auditor assigned to a fintech and the one assigned to a manufacturer may be different people. And “The necessary knowledge and skills of the audit team leader and auditors may be supplemented by technical experts, translators and interpreters who shall operate under the direction of an auditor.”
Worth asking your certification body
Who will lead our audit, and do they meet the ISO/IEC 27006 experience requirement for ISMS audits? It is a fair question, and the answer should be yes.
Your internal auditor
ISO 27001 requires every certified organisation to audit its own management system. The harmonized-structure text that the standard is built on — ISO/IEC 27001:2022 says it applies its “identical text” — sets the requirement:
“The organization shall conduct internal audits at planned intervals to provide information on whether the [information security] management system: a) conforms to: the organization’s own requirements for its [information security] management system; the requirements of this document; b) is effectively implemented and maintained.”
Harmonized structure for management system standards, 9.2.1 — the common text, not ISO/IEC 27001 itself; [information security] marks where the common text has a placeholder
And for the programme, the organisation shall:
| The organisation shall | |
|---|---|
| a | define the audit objectives, criteria and scope for each audit |
| b | select auditors and conduct audits to ensure objectivity and the impartiality of the audit process |
| c | ensure that the results of audits are reported to relevant managers |
We measured how closely ISO/IEC 27001:2022 follows the current harmonized text in the clauses we can read side by side (4.1 to 6.3): 79–100% of each common clause's wording appears, in order, in the standard, with small differences such as “outcome(s)” for “result(s)”. Read the quotes above as the common requirement, not as ISO 27001's exact wording.
Who can do it
The requirement is objectivity and impartiality, not a named qualification. A colleague from another team, a contractor, or a consultancy can all qualify; someone auditing their own work cannot. The one party the standard rules out entirely is your certification body:
“Therefore, the certification body and any part of the same legal entity and any entity under the organizational control of the certification body [see 9.5.1.2, bullet b)] shall not offer or provide internal audits to its certified clients. A recognized mitigation of this threat is that the certification body shall not certify a management system on which it provided internal audits for a minimum of two years following the completion of the internal audits.”
ISO/IEC 17021-1:2015, 5.2.6, quoted verbatim
Your internal audits are then examined twice at certification and again at every surveillance audit, where “internal audits and management review” is the first thing each one must include.
A credential for a person, a certificate for an organisation
Two different conformity assessment standards sit behind the two kinds of certificate, and they are easy to conflate:
| What is certified | Standard | Scope |
|---|---|---|
| Management system certification | ISO/IEC 17021-1 | Requirements for bodies providing audit and certification of management systems |
| Certification of persons | ISO/IEC 17024 | General requirements for bodies operating certification of persons |
An organisation with three qualified lead auditors on staff is not ISO 27001 certified, and an organisation with a certificate does not need any. Procurement questionnaires sometimes blur the two; the certificate that answers them is the organisation's, issued by an accredited certification body.
We do not train, examine, audit or certify, and we do not recommend course providers or scheme owners. The schemes named on this page are there because they publish their rules where anyone can read them.
Where this fits
- Stage 1 and Stage 2
- Surveillance audits
- Major and minor nonconformities
- Choosing a certification body
- Consultants
Common questions
What is an ISO 27001 lead auditor?
Usually, a person who has passed a lead auditor course and exam and holds a personal credential from a personnel certification scheme. The same words are also used for someone who leads audit teams for a certification body — a different thing, with different requirements, set out in ISO/IEC 17021-1 and ISO/IEC 27006. A lead auditor credential does not certify any organisation.
How do I become an ISO 27001 lead auditor?
Take a lead auditor course and pass the exam, then build the experience the scheme's grade requires. To take one published example, PECB's “Lead Auditor” grade asks for five years' professional experience, two of them in information security management, and 300 hours of audit activities; its “Provisional Auditor” grade asks for the exam alone. To audit for a certification body you also need the auditor-in-training experience ISO/IEC 27006 requires: at least 10 ISMS on-site audit days within 5 years.
How long is an ISO 27001 lead auditor course?
The PECB course, as one published example, runs over five days, the fifth being the exam. Other providers publish their own formats; we have not compared them and do not rank them.
Is ISO 27001 lead auditor the same as lead implementer?
No. One is trained to audit an ISMS, the other to build one. In the PECB scheme the grades mirror each other — the experience rules are the same — but the auditor grades count audit activities and the implementer grades count project activities.
Can an individual be ISO 27001 certified?
Not in the sense an organisation is. ISO/IEC 27001 certification is issued to an organisation's management system under ISO/IEC 17021-1. What an individual can hold is a personal credential — lead auditor, lead implementer, foundation — issued under a different standard, ISO/IEC 17024, for certification of persons.
Does a lead auditor qualification let me do our internal audit?
It helps, but it is not what the standard asks for. The harmonized-structure text that ISO 27001 is built on requires the organisation to “select auditors and conduct audits to ensure objectivity and the impartiality of the audit process”. Independence from the work being audited matters as much as the certificate. Your certification body cannot do it at all.
Can I audit for a certification body with just the lead auditor course?
Not on the course alone. ISO/IEC 27006 requires ISMS auditors to have audited as an auditor-in-training, monitored by an evaluator, in at least one initial certification or recertification audit and at least one surveillance audit — 10 on-site days within 5 years.
How much does an ISO 27001 lead auditor earn?
We have not found a source we are prepared to cite, so we do not give a figure. Salary surveys and job boards vary widely and rarely say how they were compiled.
Sources cited on this page
- PECB, ISO/IEC 27001 Lead Auditor — certification requirements
- PECB, ISO/IEC 27001 Lead Implementer — certification requirements
- Exemplar Global, Information Security Management System Auditor (ISO 27001)
- ISO/IEC 27006:2015/Amd 1:2020, Requirements for bodies providing audit and certification of information security management systems — Amendment 1
- BS EN ISO/IEC 17021-1:2015, clauses 3.11–3.13 and 9.4.5–9.5.3 (nonconformities, audit findings, the certification decision), full text
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025
- ISO/CASCO, Conformity assessment bodies and the standards that govern each type
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Need an independent internal audit?
If nobody in-house is independent of the ISMS, an external internal audit is the usual answer. Say when you need it.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.