What happens in an ISO 27001 audit
By Eoghan Kenny · 5 October 2026
ISO 27001 certification involves two audits. Stage 1 reviews your documentation and determines whether you are ready. Stage 2 tests whether the system you documented is the system you actually operate.
Stage 2 usually follows stage 1 by six to eight weeks, and by then your management system should have been running for around three months, because the auditor needs records to examine.
Stage 1: the readiness review
The auditor examines your scope statement, your Statement of Applicability, your risk assessment and your documented policies. They are answering one question: is there enough here to assess?
They will raise findings. That is what the visit is for, and receiving them is not a failure. Stage 1 exists so that problems surface while they are still cheap to fix.
What tends to come up: a scope that does not match what the organisation does, a Statement of Applicability whose exclusions cannot be traced to the risk assessment, and policies that describe a process nobody follows.
Stage 2: the full assessment
Interviews, evidence inspection, and observation of how the work is actually done.
An auditor is not primarily checking whether you have documents. They are checking whether the documents describe reality. Which is why the most common failure is a thorough policy nobody follows, and a short policy that reflects actual practice passes comfortably.
What auditors tend to open first: the Statement of Applicability, because it maps everything else. Then the internal audit report and the management review minutes, because those show whether the organisation examines itself. Then a sample of controls, traced from the policy through to the evidence that it operated.
Every auditor is working to the same standard, but their methods differ. Some start with risk and work outward. Some go straight through the clauses in order. Others start with the management review, because it gives them context on the organisation before anything else. What makes the biggest difference is agreeing the audit plan and schedule in advance, and lining up the right people for each part of it. An auditor's day is wasted if they are sitting there waiting for someone to track down whoever can actually answer a question, because it is rarely one person the whole time. Different parts of the business need to be represented at different points, and the organisations that map that out beforehand get a noticeably smoother audit than the ones who just wait to see what gets asked.
Non-conformities: major and minor
A non-conformity is a failure to meet a requirement of the standard.
A major non-conformity is a systemic failure, an absent requirement, or a breakdown significant enough to cast doubt on the system. It has to be resolved before a certificate is issued, usually with evidence submitted and accepted.
A minor non-conformity is an isolated lapse that does not undermine the system. It is normally addressed through a corrective action plan with an agreed timescale, and certification can proceed.
Alongside these, an auditor may record observations or opportunities for improvement. These are not findings and do not require action, though ignoring them repeatedly tends to be noticed.
The closing meeting, and what follows
At the closing meeting the auditor summarises their findings and tells you whether they are recommending certification.
That recommendation then goes to someone else inside the certification body, who reviews it independently before a certificate is issued. The auditor recommends. The certification body decides.
The surveillance audits
The certificate lasts three years, and it is conditional.
A surveillance audit takes place in year one, typically six to twelve months after certification, and another in year two. These are shorter than the initial assessment and they sample rather than cover everything. Before the three years are up, a recertification audit starts the cycle again.
The first surveillance audit is usually straightforward. The system is fresh and the people who built it are still there. The second one is where decay shows: review cycles that stopped, a risk register nobody updated, policies that no longer describe how the team works after two rounds of hiring.
Year two is where the gap shows. The team that got you certified worked hard on it for a year, hit their date, and understandably wanted to walk away from it for a while. The first surveillance audit usually goes fine because everything is still fresh and the same people are around. By year two, if nobody has kept the system running with a proper monthly cadence, an email arrives from the auditor giving two months' notice, and it turns into a scramble to reconstruct nine months of evidence that was never captured. The organisations that check in on it every month never have that problem.
How to prepare without preparing
The organisations that find audits uneventful are not the ones that prepare hardest. They are the ones with less to prepare, because the evidence already exists as a by-product of the work.
That is the practical difference between a management system and an audit project. One produces evidence continuously. The other produces it in the six weeks before someone asks.
For ISO 27001 certification support, see how 3Be supports regulated SaaS organisations.
Common questions
What is the difference between a stage 1 and stage 2 audit?
Stage 1 is a documentation and readiness review that determines whether you are ready for full assessment. Stage 2 tests whether the system you documented is the system you operate, through interviews, evidence inspection and observation.
How long between stage 1 and stage 2?
Usually six to eight weeks. The certification body will also expect your management system to have been operating for around three months before stage 2, because they need records to examine.
What is a major non-conformity?
A systemic failure or an absent requirement significant enough to cast doubt on the management system. It must be resolved before a certificate is issued.
What do auditors look at first?
Typically the Statement of Applicability, because it maps the whole system, followed by the internal audit report and management review minutes.
What happens after certification?
Surveillance audits in years one and two, then a recertification audit before the three-year certificate expires.
Get started
How mature is your compliance today?
Our team built a free, practical health check so you can see your maturity across governance, risk, evidence, ownership and operations, which one is holding you back, and what to do about it first. Start the Health Check.