The ISO 27001 Audit: Stage 1, Stage 2 and Internal Audits
There are two kinds of ISO 27001 audit, and they catch people out. Here is what each one checks, in order, without the jargon.
The short version
- There are two different audits: the internal audit you run on yourself (a mandatory requirement under clause 9.2), and the external certification audit run by an independent, UKAS-accredited certification body. They are not the same thing, and you need both.
- The certification audit has two stages: Stage 1 is a documentation and readiness review; Stage 2 is a deeper check that your management system is actually working, using evidence and interviews.
- It does not end at certification: the certificate typically lasts three years, with shorter surveillance audits in the intervening years and a fuller recertification audit at the end of the cycle.
- Findings are called nonconformities: classed major or minor. A minor one usually will not stop you certifying, provided you fix it. An audit is a conversation about evidence, not a trap.
If someone has told you an ISO 27001 audit is coming and your stomach dropped a little, this guide is for you. Most of the fear comes from not knowing what happens in the room. The reassuring truth is that an ISO 27001 audit is a structured, predictable conversation about evidence, and once you can see its shape it feels less like an ambush and more like a to-do list.
One thing trips up almost every SME, so let us clear it up first: there are two different kinds of audit under ISO 27001. One you run on yourself. One an outside body runs on you. We will walk through both, in the order you meet them.
Two kinds of audit (and why you need both)
ISO 27001 involves an internal audit you arrange yourself and an external certification audit run by an independent body, and they do genuinely different jobs.
The internal audit is your own check on your own system. You (or someone you appoint) look at your information security management system and ask honestly whether it is doing its job. This is not optional politeness; it is a mandatory requirement of the standard, under clause 9.2, which we return to below.
The external certification audit is the one people picture when they hear “audit”. It is carried out by a certification body, and in the UK you want one accredited by UKAS (the United Kingdom Accreditation Service, which oversees auditors). UKAS does not certify your business directly; it accredits the certification bodies, confirming they are competent and impartial. That external audit is what leads to the certificate on your wall.
You cannot skip the internal one and go straight to the external. The certification body expects to see that you already check your own house; if you have never run an internal audit, that itself is a finding.
The simplest way to remember it
Internal audit: you marking your own homework, honestly, before it is handed in. Certification audit: the examiner marking it for real. The first makes the second go far more smoothly.
Stage 1: the readiness review
Stage 1 is a documentation and readiness review, where the auditor checks your management system exists on paper and is likely to pass the deeper audit that follows.
The external certification audit is split into two stages, and Stage 1 is the gentler one. Sometimes called a documentation review or readiness review, it is not yet judging whether your security works in practice; the auditor is checking that you have built a genuine management system and written it down.
They will want the core documents of an ISO 27001-conformant system: your defined scope (what the ISMS actually covers), your risk assessment, your policies, and your Statement of Applicability (a document setting out which controls apply to you and why). They are gauging whether this is a coherent system that stands a reasonable chance at Stage 2.
Stage 1 is also where the auditor flags gaps, and you would far rather hear about a thin spot now, with time to fix it, than at Stage 2. Treat it as a friendly early warning, not a verdict. If you are still weighing whether the standard is right for you yet, our guide to ISO 27001 for SMEs is a good place to check first.
Stage 2: implementation and effectiveness
Stage 2 is the deeper audit that tests whether your management system is genuinely operating, using evidence, sampled records and interviews with your people.
Stage 2 is where the auditor moves from “is it written down?” to “is it actually happening?”. This is the detailed assessment against ISO/IEC 27001:2022, and it carries the weight.
The auditor collects objective evidence. They will not simply accept that a policy exists; they look for proof it is being followed. Expect them to sample records, ask to see logs or tickets, and talk to your people. Interviews are a normal, central part of Stage 2: the auditor might ask a staff member how they would report a suspected incident, or how access to a system gets granted and removed. They are checking that the way things work on paper matches the way they work in real life.
None of this is meant to catch anyone out. If your system is genuinely running, the evidence is there in the course of normal work. The businesses that find Stage 2 stressful are usually the ones that wrote their policies for the audit rather than for how they operate day to day, which is a sharp difference from a lighter scheme like Cyber Essentials.
What happens after: surveillance and recertification
Certification is not a one-off event; the certificate typically lasts three years, with shorter surveillance audits along the way and a recertification audit at the end.
Passing Stage 2 gets you the certificate, typically valid for three years. But ISO 27001 is deliberately not a set-and-forget badge. The standard runs on a three-year cycle, and the auditor comes back.
In the years between certification and recertification, you have surveillance audits. These are shorter than the full Stage 2 (for a smaller organisation, often around half a day to a day) and sample a portion of your controls rather than re-examining everything.
At the end of the three years comes recertification: a fuller audit, closer in depth to your original Stage 2, that revisits the whole system and, if you pass, starts a fresh three-year cycle. Book it ahead of your certificate’s expiry so there is no awkward gap.
So ISO 27001 is a living commitment: the certificate reflects a system you keep running, and there is an ongoing cost to that in time and fees, which we cover in what ISO 27001 certification actually costs.
The internal audit (clause 9.2), run proportionately
Clause 9.2 makes the internal audit a mandatory requirement, but a small business can run one sensibly and in proportion to its size.
The internal audit is the part SMEs most often underestimate. Clause 9.2 of ISO 27001 requires you to conduct internal audits at planned intervals to check that your management system both meets the standard and is working effectively. You must complete at least one before your external certification audit, and keep doing them regularly afterwards, usually at least once a year.
That can sound heavy for a ten-person company, but it need not be. The standard asks you to plan a programme and cover your system over time, not to build a department. A proportionate approach for a small business looks like this:
- Plan it. Decide what you will audit and roughly when. You need not cover everything in one sitting; spread it across the year.
- Keep it independent. The one firm rule is that people cannot audit their own work. If your IT lead runs the access controls, someone else reviews them, whether a colleague or an outside pair of hands.
- Write down what you find. The output is a short record of what you checked, what was fine, and what needs attention. That record is itself evidence the certification body will want to see.
Why the internal audit is your friend
Every issue you catch in your own internal audit is one you fix on your own timetable, quietly, before it becomes a formal finding on someone else's report. It is the cheapest, calmest way to improve your odds at Stage 2, and it means the external auditor rarely tells you anything you did not already know.
Nonconformities, and what “failing” really means
Audit findings are recorded as nonconformities, classed major or minor, and most are a prompt for corrective action rather than a slammed door.
When an auditor finds that something does not meet a requirement, they record it as a nonconformity: a requirement of the standard, a control, or one of your own policies is not being met. Nonconformities come in two grades.
A minor nonconformity is an isolated slip or partial gap that does not undermine your system as a whole: a record left out of date, say, or a policy followed almost-but-not-quite. You can usually still certify, or stay certified, with minor nonconformities recorded against you, provided you commit to a clear plan and timeline to put them right.
A major nonconformity is more serious. It points to something systemic, or something that simply is not working, and it undermines the integrity of the management system. A major nonconformity will typically hold up certification until you have resolved it and the auditor has verified the fix.
Either way, the response is the same: corrective action. Find the genuine root cause, fix it so it does not happen again, and show the evidence. Avoid the cosmetic fix that leaves the real cause untouched, because a finding that recurs is treated more seriously than a first-time one. “Failing” in the dramatic sense is rare; what is common is a handful of findings and a to-do list, which is a normal, manageable outcome.
How to prepare, and what auditors want to see
Preparation is mostly about being able to show, quickly and honestly, that your system is real and running.
You do not prepare for an ISO 27001 audit by rehearsing answers, but by making the evidence of a working system easy to reach. A few practical pointers:
- Have your core documents to hand. Scope, risk assessment, policies and the Statement of Applicability. The auditor starts here, so know where they live and that they are current.
- Make evidence findable. For each control that matters, be able to point to proof it is operating: an access review, an incident record, a training log, a set of tickets. Fumbling for evidence reads as an absence of it.
- Brief your people gently. Anyone the auditor might speak to should understand that honesty is the point. “I am not certain, let me check” beats a confident wrong answer every time.
- Run your internal audit first, and act on it. Walking in with your own findings already in hand shows the self-awareness the standard is asking for.
Much of the underlying discipline carries over from Cyber Essentials, so our Cyber Essentials explained guide is a useful companion for the technical basics that feed into an ISMS. And the mindset that serves you best is simple: the auditor is not trying to fail you, but to confirm that what you have told the world about your security is true. If it is, the audit is mostly a matter of showing your working.
SecurSentry is launching soon to help UK SMEs build and keep the evidence and routines an ISO 27001 audit looks for, so the work you do once keeps paying off. Join the waitlist to be among the first to know when we open.
This article is for general information only and does not constitute legal or compliance advice. Audit scope and outcomes vary by organisation; where in doubt, consult a qualified professional or an accredited certification body.