iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 lead auditor: the qualification, and what auditing for a certification body actually requires

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 10 min read
8 primary sources cited on this page. How we check what is on this site
The rule course pages leave out 10 on-site audit days, within 5 years

Before auditing ISMSs for a certification body, an auditor must have “gained experience of auditing ISMS” as an auditor-in-training — ISO/IEC 27006:2015/Amd 1:2020, 7.2.1.1 d). A lead auditor course is not that experience.

“ISO 27001 lead auditor” is sold as a course, but the phrase covers three different things, and they are governed by three different sets of rules. Knowing which one you need — for your career, for a job advert, or for your own organisation's internal audit — saves you buying the wrong one.

Three things called an “ISO 27001 auditor”

Personal credential, certification body auditor and internal auditor, compared
Lead auditor credentialCertification body auditorYour internal auditor
What it isA personal credential: a course, an exam, then experienceBeing allowed to audit ISO 27001 for an accredited certification bodyWhoever audits your own ISMS under clause 9.2
Who grants itA personnel certification body running a published schemeThe certification body, against ISO/IEC 17021-1 and ISO/IEC 27006You appoint them
The standard behind itISO/IEC 17024 (certification of persons)ISO/IEC 17021-1, and the ISMS rules in ISO/IEC 27006ISO/IEC 27001 clause 9.2
Experience requiredDepends on the grade — from none to ten yearsAt least 10 ISMS on-site audit days, as an auditor-in-training, within 5 yearsNot specified — objectivity and impartiality are
Does it certify an organisation?NoIt is how organisations get certifiedNo
Can your certification body do it for you?No — ISO/IEC 17021-1 clause 5.2.6

The first column is what most people mean. The second is what an organisation actually meets at Stage 1 and Stage 2. The third is what your organisation has to provide for itself every year. A single person can be all three at different times — but never the second and third for the same organisation, because a certification body may not provide internal audits to its certified clients.

The personal credential: how the grades work

A lead auditor credential is issued by a personnel certification body under a published scheme. We use PECB as the worked example because it publishes its grade rules in full on a public page; other scheme owners publish their own, and we do not rank them. Every PECB auditor grade starts from the same exam — “PECB Certified ISO/IEC 27001 Lead Auditor exam or equivalent” — and then differs by experience:

PECB ISO/IEC 27001 auditor grades, as published
CredentialProfessional experienceManagement system audit experience
PECB Certified ISO/IEC 27001 Provisional AuditorNoneNone
PECB Certified ISO/IEC 27001 AuditorTwo years: One year of work experience in Information Security ManagementAudit activities: a total of 200 hours
PECB Certified ISO/IEC 27001 Lead AuditorFive years: Two years of work experience in Information Security ManagementAudit activities: a total of 300 hours
PECB Certified ISO/IEC 27001 Senior Lead AuditorTen years: Seven years of work experience in Information Security ManagementAudit activities: a total of 1,000 hours

What counts as audit experience

PECB says the audits must follow best audit practice and include activities such as:

  • Audit planning
  • Audit interview
  • Managing an audit program
  • Drafting audit reports
  • Drafting non-conformity reports
  • Drafting audit working documents
  • Documentation review
  • On-site Audit
  • Follow-up on non-conformities
  • Leading an audit team

The course itself

The published PECB lead auditor course runs over five days:

PECB ISO/IEC 27001 Lead Auditor course agenda, as published
Content
Day 1Introduction to the information security management system (ISMS) and ISO/IEC 27001
Day 2Audit principles, preparation, and initiation of an audit
Day 3On-site audit activities
Day 4Closing the audit
Day 5Certification Exam

PECB also states that “Certification and examination fees are included in the price of the training course”. We do not publish course prices: they vary by provider and format, and we have no source we could keep current.

Other schemes, and moving between them

Schemes are not all built the same way. Exemplar Global, for instance, allows an audit log in place of a knowledge exam where no exam is available: “If a knowledge examination is not available, this may be substituted with an audit log showing relevant audit experience. If you choose this method, we require that you show evidence of 10 audit days reflecting the specific scheme (e.g, QMS, EMS, OHS, etc.) and grade (i.e., auditor or lead auditor) you wish to apply for.” — and adds: “Importantly, the audit dates captured in your log need to have been conducted within the past three years.” Schemes also recognise one another to some extent: “There are current agreements with IRCA/CQI, PECB, and the CCAA to recognize certification.”

Lead auditor vs lead implementer

Same scheme owner, same experience ladder, different job. The implementer grades mirror the auditor grades exactly, but count project activities rather than audit activities:

PECB ISO/IEC 27001 implementer grades, as published
CredentialProfessional experienceISMS project experience
PECB Certified ISO/IEC 27001 Provisional ImplementerNoneNone
PECB Certified ISO/IEC 27001 ImplementerTwo years: One year of work experience in Information Security ManagementProject activities: a total of 200 hours
PECB Certified ISO/IEC 27001 Lead ImplementerFive years: Two years of work experience in Information Security ManagementProject activities: a total of 300 hours
PECB Certified ISO/IEC 27001 Senior Lead ImplementerTen years: Seven years of work experience in Information Security ManagementProject activities: a total of 1,000 hours

What each is trained to do

The implementer course, over the same five days, covers:

PECB ISO/IEC 27001 Lead Implementer course agenda, as published
Content
Day 1Introduction to ISO/IEC 27001 and initiation of an ISMS implementation
Day 2Implementation plan of an ISMS
Day 3Implementation of an ISMS
Day 4ISMS monitoring, continual improvement, and preparation for the certification audit
Day 5Certification exam

And the project experience PECB counts for an implementer includes:

  • Drafting an ISMS implementation business case
  • Managing an ISMS implementation project
  • Implementing the ISMS
  • Managing documented information
  • Implementing corrective actions
  • Monitoring the ISMS performance
  • Managing an ISMS implementation team

If your aim is to get your own organisation certified, the implementer route is the closer fit. If your aim is to run internal audits or to audit other organisations, the auditor route is. Neither certifies your organisation.

Auditing for a certification body: what ISO/IEC 27006 requires

The auditor who arrives for your Stage 2 is not there because of a course certificate. Certification bodies are assessed against ISO/IEC 17021-1, and for information security against ISO/IEC 27006, which requires that each ISMS auditor:

d) “has gained experience of auditing ISMS prior to acting as an auditor performing ISMS audits. This experience shall be gained by performing as an auditor-in-training monitored by an ISMS evaluator (see ISO/IEC 17021-1:2015, 9.2.2.1.4) in at least one ISMS initial certification audit (stage 1 and stage 2) or re-certification and at least one surveillance audit. This experience shall be gained in at least 10 ISMS on-site audit days and performed in the last 5 years. The participation shall include review of documentation and risk assessment, implementation assessment and audit reporting.”

g) “has competence in auditing an ISMS in accordance with ISO/IEC 27001.”

ISO/IEC 27006:2015/Amd 1:2020, 7.2.1.1, quoted verbatim

How the auditor-in-training rule works

The route in is supervised audit work. ISO/IEC 17021-1: “Auditors-in-training may participate in the audit, provided an auditor is appointed as an evaluator. The evaluator shall be competent to take over the duties and have final responsibility for the activities and findings of the auditor-in-training.” So when a certification body brings an extra person to your audit, it may be exactly this — and the evaluator, not the trainee, carries final responsibility for the findings.

What a certification body must define for its auditors

“Table A.1 specifies the knowledge and skills that a certification body shall define for specific certification functions.” For the people auditing and leading the audit team, the table lists knowledge and skills including:

  • Knowledge of business management practices
  • Knowledge of audit principles, practices and techniques
  • Knowledge of specific management system standards/normative documents
  • Knowledge of certification body’s processes
  • Knowledge of client’s business sector
  • Knowledge of client products, processes and organization
  • Language skills appropriate to all levels within the client organization
  • Note-taking and report-writing skills
  • Presentation skills
  • Interviewing skills
  • Audit-management skills

Sector knowledge is on that list for a reason: it is why the auditor assigned to a fintech and the one assigned to a manufacturer may be different people. And “The necessary knowledge and skills of the audit team leader and auditors may be supplemented by technical experts, translators and interpreters who shall operate under the direction of an auditor.”

Worth asking your certification body

Who will lead our audit, and do they meet the ISO/IEC 27006 experience requirement for ISMS audits? It is a fair question, and the answer should be yes.

Your internal auditor

ISO 27001 requires every certified organisation to audit its own management system. The harmonized-structure text that the standard is built on — ISO/IEC 27001:2022 says it applies its “identical text” — sets the requirement:

“The organization shall conduct internal audits at planned intervals to provide information on whether the [information security] management system: a) conforms to: the organization’s own requirements for its [information security] management system; the requirements of this document; b) is effectively implemented and maintained.”

Harmonized structure for management system standards, 9.2.1 — the common text, not ISO/IEC 27001 itself; [information security] marks where the common text has a placeholder

And for the programme, the organisation shall:

Internal audit programme (harmonized structure 9.2.2), verbatim
The organisation shall
adefine the audit objectives, criteria and scope for each audit
bselect auditors and conduct audits to ensure objectivity and the impartiality of the audit process
censure that the results of audits are reported to relevant managers

We measured how closely ISO/IEC 27001:2022 follows the current harmonized text in the clauses we can read side by side (4.1 to 6.3): 79–100% of each common clause's wording appears, in order, in the standard, with small differences such as “outcome(s)” for “result(s)”. Read the quotes above as the common requirement, not as ISO 27001's exact wording.

Who can do it

The requirement is objectivity and impartiality, not a named qualification. A colleague from another team, a contractor, or a consultancy can all qualify; someone auditing their own work cannot. The one party the standard rules out entirely is your certification body:

“Therefore, the certification body and any part of the same legal entity and any entity under the organizational control of the certification body [see 9.5.1.2, bullet b)] shall not offer or provide internal audits to its certified clients. A recognized mitigation of this threat is that the certification body shall not certify a management system on which it provided internal audits for a minimum of two years following the completion of the internal audits.”

ISO/IEC 17021-1:2015, 5.2.6, quoted verbatim

Your internal audits are then examined twice at certification and again at every surveillance audit, where “internal audits and management review” is the first thing each one must include.

A credential for a person, a certificate for an organisation

Two different conformity assessment standards sit behind the two kinds of certificate, and they are easy to conflate:

Which standard certifies what
What is certifiedStandardScope
Management system certificationISO/IEC 17021-1Requirements for bodies providing audit and certification of management systems
Certification of personsISO/IEC 17024General requirements for bodies operating certification of persons

An organisation with three qualified lead auditors on staff is not ISO 27001 certified, and an organisation with a certificate does not need any. Procurement questionnaires sometimes blur the two; the certificate that answers them is the organisation's, issued by an accredited certification body.

We do not train, examine, audit or certify, and we do not recommend course providers or scheme owners. The schemes named on this page are there because they publish their rules where anyone can read them.

Where this fits

Common questions

What is an ISO 27001 lead auditor?

Usually, a person who has passed a lead auditor course and exam and holds a personal credential from a personnel certification scheme. The same words are also used for someone who leads audit teams for a certification body — a different thing, with different requirements, set out in ISO/IEC 17021-1 and ISO/IEC 27006. A lead auditor credential does not certify any organisation.

How do I become an ISO 27001 lead auditor?

Take a lead auditor course and pass the exam, then build the experience the scheme's grade requires. To take one published example, PECB's “Lead Auditor” grade asks for five years' professional experience, two of them in information security management, and 300 hours of audit activities; its “Provisional Auditor” grade asks for the exam alone. To audit for a certification body you also need the auditor-in-training experience ISO/IEC 27006 requires: at least 10 ISMS on-site audit days within 5 years.

How long is an ISO 27001 lead auditor course?

The PECB course, as one published example, runs over five days, the fifth being the exam. Other providers publish their own formats; we have not compared them and do not rank them.

Is ISO 27001 lead auditor the same as lead implementer?

No. One is trained to audit an ISMS, the other to build one. In the PECB scheme the grades mirror each other — the experience rules are the same — but the auditor grades count audit activities and the implementer grades count project activities.

Can an individual be ISO 27001 certified?

Not in the sense an organisation is. ISO/IEC 27001 certification is issued to an organisation's management system under ISO/IEC 17021-1. What an individual can hold is a personal credential — lead auditor, lead implementer, foundation — issued under a different standard, ISO/IEC 17024, for certification of persons.

Does a lead auditor qualification let me do our internal audit?

It helps, but it is not what the standard asks for. The harmonized-structure text that ISO 27001 is built on requires the organisation to “select auditors and conduct audits to ensure objectivity and the impartiality of the audit process”. Independence from the work being audited matters as much as the certificate. Your certification body cannot do it at all.

Can I audit for a certification body with just the lead auditor course?

Not on the course alone. ISO/IEC 27006 requires ISMS auditors to have audited as an auditor-in-training, monitored by an evaluator, in at least one initial certification or recertification audit and at least one surveillance audit — 10 on-site days within 5 years.

How much does an ISO 27001 lead auditor earn?

We have not found a source we are prepared to cite, so we do not give a figure. Salary surveys and job boards vary widely and rarely say how they were compiled.

Sources cited on this page

  1. PECB, ISO/IEC 27001 Lead Auditor — certification requirements
  2. PECB, ISO/IEC 27001 Lead Implementer — certification requirements
  3. Exemplar Global, Information Security Management System Auditor (ISO 27001)
  4. ISO/IEC 27006:2015/Amd 1:2020, Requirements for bodies providing audit and certification of information security management systems — Amendment 1
  5. BS EN ISO/IEC 17021-1:2015, clauses 3.11–3.13 and 9.4.5–9.5.3 (nonconformities, audit findings, the certification decision), full text
  6. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  7. ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025
  8. ISO/CASCO, Conformity assessment bodies and the standards that govern each type

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Need an independent internal audit?

If nobody in-house is independent of the ISMS, an external internal audit is the usual answer. Say when you need it.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now