An ISO 27001 audit for certification consists of two phases. In the first phase, the documentation is mainly assessed, while the second phase looks at the implementation and operation of the ISMS.
Do you want to succesfully complete both phases of the audit? In this blog article, we explain exactly what the ISO audit is, what it involves and offer some cost saving tips.
In this blog:
- What is an ISO 27001 audit?
- The two phases of an audit
- 10 tips for succesfully completing the ISO 27001 audit
- The costs of an ISO 27001 audit
What is an ISO 27001 audit?
An ISO 27001 audit is a formal process used to assess whether an organisation complies with the ISO 27001 standard for information security. This standard specifies the requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). Achieving the ISO 27001 certificate demonstrates that your organisation meets the required standards and requirements around information security, which builds trust among customers, partners and stakeholders.
An ISO 27001 audit determines whether your organisation qualifies for the ISO 27001 certificate. With an ISO 27001 certificate, your organisation demonstrates that it meets the required standards and requirements around information security. However, this certificate isn't easy to obtain; there are a great many guidelines you need to comply with.
The two phases of an audit
As mentioned earlier, an audit for obtaining an ISO 27001 certificate consists of two phases.
Phase 1: Documentation audit
The first phase is also known als the "documentation audit".
This phase focuses on assessing the status of documentation within the organisation, assessing the performance system and determining whether the organisation is ready for the next phase.

Phase 2: Compliance audit
The second phase is also know as the "compliance audit". During this phase, the functioning and implementation of the ISMS (Information Security Management System) is assessed:
- Does the ISMS meet the audit criteria, or the certification scheme?
- Doe the ISMS enable the organisation to safeguard information security in a way that the organisation meets its contractual obligations?
- Does the ISMS enable the organisation to safeguard information security in a way that the organisation meets the various laws and regulations?
- Is the ISMS effective, such that it can reasonably be expected that the organisation's stated objectives will be achieved?
- Can the ISMS potentially be improved in specific areas?
10 tips for succesfully completing the ISO 27001 audit
Would you like your organisation to succesfully complete both phases if an ISO 27001 audit? With these tips achieving the certification will be much easier:
1. Choose an accredited auditor
Choosing an auditor recognised by one of the members of the European co-operation for Accrediation ensures your certification is recognised worldwide.This gives your certification greater value and provides assurance that the audit is carried out idependently and objectively.
It's wise to contact potential auditors timely and check whether they have the right accreditations and experience to audit your specific industry.
2. Build internal knowledge
Within the organisation, it's important to put together a team that's well informed about all aspects of the ISMS and the ISO 27001 standard. This team needs to be able to answer all of the auditor's questions, both at a strategic and on an operational level.
This requires not only knowledge of the documentation, but also insight into the practical implementation of the information security countermeasures. Internal training and trial audits (simulated sessions) can help to ensure your team is well prepared.
Look within the organisation for employees who can answer all questions relating to information security. Having the right knowledge in place can have a significant impact on the outcome.
Think of questions that start with:
-
What do we do, and what not?
-
How do we do that?
-
When do we do that?
-
Why do we do that?
-
Can we show that?
-
How do we measure that?
3. Ensure complete documentation
One of the most common pifalls during an ISO 27001 audit is a lack of adequate documentation. Make sure all procedures, policies and risk assessments required by ISO 27001 are fully and accurately documented and kept up to date. This also include logs, reports and internal audits.
Keep in mind that the auditor may take samples, so make sure all documentation is kept systematically and easily accessible.
For this reason, search the standard for the word "documented" (or documentation). Anything that comes up needs to be documented. It would be unfortunate to get stuck on that point.
4. Create an overview of your documentation
Before the audit, create an overview of all documentation and the corresponding standards. Drawing up an overview of all relevant documentation an standards is an effective way to ensure the audit runs smoothly.
Consider creating a matrix or spreadsheet in which you record, for each standard, where the corresponding documentation can be found, what evidence exists for the implementation of the standard and how the control measure is checked. This makes it clear to both your team and the auditor where the required information can be found and prevents unnecessary delays.
Another option is to add three columns to your statement of applicability:
(1) Where can the policy be found?
(2) Where can evidence of implementing the standard be found?
(3) How is the control measure checked?
5. Carry out a test check
In addition to the administrative and technical aspects of information security, the auditor will also check the physical security of your organisation. This includes the security level of office spaces, data centres and archive rooms.
That's why it's smart to walk through the office and its various spaces at least once, asking questions such as: "What's in this cabinet?", "What's on this drive?", "Who has access to this?", "Who is responsible for that?", "How do we carry out maintenance?" and "What do we test?"
6. Ensure demonstrable compliance
Do what you've described, and make sure you can demonstrate it. Ultimately, it's not just about the auditor hearing the story, it's about your day to day practice showing it too.
It may go without saying, but its not enough to have procedures and policies on paper alone; your organisations actually needs to follow them. Use systems such as ticketing tools to document the implementation of procedures and processes.
This makes it clear to the auditor that your ISMS isn't just well designed, but is also applied effectively in daily practice. Make sure you can demonstrate operational processes with concrete examples and that all actions taken are traceable.
7. Focus on achieving objectives
The ISO 27001 standard doesn't prescribe how specific security countermeasures should be implemented, but instead focuses on achieving certain objectives. This gives your organisation the flexibility to choose the countermeasures best sutied for your business environment and risk profile. Make sure all mandatory elements from tips 4 to 10 are fully implemented and that annex A, which provides an overview of control measures, alligns well with the scope of your information security.
8. Implement improvements step by step
Rather than trying to implement all possible improvements at once, it's more effective to put a continuous improvement process in place. This also ties in with the PDCA model (Plan-Do-Check-Act), which is central to ISO 27001.
By carefully documenting and planning all improvements, you show the auditor that your organisation is actively working to improve its information security and that there's a structured approach to addressing risks.
9. Aks questions during the audit
Although an auditor isn't allowed to advise on specific solutions, they can offer clarification on how the standard should be interpreted. Take advantage of this by asking questions whenever you're unsure about something or want better understanding on how certain requirements are assessed. This can provide valuable insights you can use to further optimise your ISMS and ensure your organisation is fully compliant.
10. Also think about what comes after the ISO 27001 audit
Think about management after certification. How will you keep track of everything and continue the process?
The costs of an ISO 27001 audit
The costs of an ISO 27001 audit can vary significantly, depending on various factors such as the size and complexity of your organisation, the certification body chosen and the level of preparation within your organisation.
For smaller businesses, costs can range somewhere between € 5.000 and € 15.000, while larger or more complex organisations may face costs that can rise to € 30.000 or more. These costs include both preparatory costs, such as internal audits and any consultancy involved, and the actual audit fees charged by the certification body. It's important to take these variable costs into account when planning for an ISO 27001 certification.
Cost saving tip
Want to make sure you're well prepared for your adit? Try Base27, our ISMS, the first month for free. Base27 fully supports ISO 27001 and other key frameworks, and is alwats kept up to date. It helps your organisation comply with frameworks and carry out internal audits to achieve certification.
Nederlands




![Risk analysis for information security [with checklist] Risk analysis for information security [with checklist]](https://www.base27.eu/hubfs/Imported_Blog_Media/checklist%20risicoanalyse.jpg)