An ISO 27001 audit is a structured review of your information security management system (ISMS) to verify that it meets the requirements of the ISO 27001 standard. Auditors assess whether your organisation has identified its information security risks, put appropriate controls in place, and can demonstrate that those controls actually work. This article walks you through every key question about the ISO 27001 audit process, from what auditors look for to whether the whole thing can happen online.

What do ISO 27001 auditors actually look for?

ISO 27001 auditors look for evidence that your organisation has a functioning information security management system, not just documentation, but real, operational processes. They want to see that you have identified your information assets, assessed the risks to those assets, and implemented controls that are proportionate to those risks.

More specifically, auditors focus on several core areas:

  • Risk assessment and treatment: Have you systematically identified threats and vulnerabilities, and do you have a documented plan to address them?
  • Policies and procedures: Are your information security policies current, approved by management, and actually followed by staff?
  • Access controls: Who has access to what data, and how is that access managed and reviewed?
  • Incident management: Do you have a process for detecting, reporting, and responding to security incidents?
  • Internal audits and management reviews: Is your organisation actively monitoring and improving its ISMS over time?
  • Statement of Applicability (SoA): Have you documented which of the standard’s controls apply to your organisation, and justified any exclusions?

The key point is that auditors are not just checking whether documents exist. They verify that people in your organisation understand the policies, follow the procedures, and that the system is genuinely embedded in day-to-day operations.

How does the ISO 27001 audit process work, step by step?

The ISO 27001 audit process follows a clear two-stage structure. In Stage 1, the auditor reviews your documentation to check that your ISMS is designed correctly. In Stage 2, the auditor goes deeper, verifying that your system is actually implemented and working as described. If both stages are passed, you receive your ISO 27001 certification.

Here is a more detailed breakdown of the process:

  1. Stage 1 — Documentation review: The auditor examines your ISMS documentation, including your risk assessment, Statement of Applicability, policies, and objectives. The goal is to confirm that your system is complete and ready for a full audit.
  2. Stage 2 — Implementation audit: The auditor interviews staff, reviews records, and tests whether your controls are genuinely operational. This is where your system is put to the real test.
  3. Findings and nonconformities: The auditor documents any gaps. Minor nonconformities require a corrective action plan; major ones must be resolved before certification is granted.
  4. Certification decision: Once all major issues are resolved, the certification body issues your ISO 27001 certificate, which is valid for three years.
  5. Surveillance audits: In years two and three, shorter surveillance audits check that your ISMS remains effective and continues to meet the standard.

What’s the difference between an internal and external ISO 27001 audit?

An internal ISO 27001 audit is conducted by someone within your organisation, or an independent party you commission, to check your own ISMS before the official certification audit. An external audit is conducted by an accredited certification body and is the formal process that results in your ISO 27001 certificate.

Internal audits are a requirement of the standard itself. They help you identify gaps and fix them before an external auditor does. Think of them as a rehearsal: you walk through your own processes, test your controls, and document the results. This gives you a clear picture of where you stand.

External audits, by contrast, are conducted by independent, accredited auditors who have no stake in the outcome. Their findings carry formal weight and lead directly to certification, or to a list of nonconformities you need to address. For ISO 27001 certification, passing the external audit is what counts.

For small organisations, the internal audit does not need to be a massive undertaking. A structured self-assessment against the standard’s requirements, carried out honestly and documented properly, is sufficient to meet this obligation.

How long does an ISO 27001 audit take?

The duration of an ISO 27001 audit depends on the size and complexity of your organisation. For a small company with up to 50 employees, a Stage 1 audit typically takes one to two days, and a Stage 2 audit takes two to three days. The total audit time across both stages is usually three to five days for smaller organisations.

Preparation time is a separate matter. Traditionally, building an ISMS from scratch could take six to twelve months. With modern digital tools and structured guidance, this preparation phase can be compressed significantly, sometimes to a matter of days or weeks, depending on how focused your effort is.

Surveillance audits in years two and three are shorter, usually one to two days, since they focus on specific areas rather than the full system.

What happens if you fail an ISO 27001 audit?

If you fail an ISO 27001 audit, you receive a list of nonconformities rather than an outright rejection. Minor nonconformities require you to submit a corrective action plan within a set timeframe, typically 90 days. Major nonconformities mean certification cannot be granted until those issues are resolved and evidence of correction is reviewed.

Failing an audit is not the end of the road. It is a structured feedback process. Auditors document exactly what was missing or incorrect, which gives you a clear roadmap for what to fix. Most organisations that receive nonconformities resolve them and achieve certification in a follow-up review without needing to repeat the full audit.

The most common reasons organisations receive nonconformities include incomplete risk assessments, policies that exist on paper but are not followed in practice, missing records of management reviews, and gaps in the Statement of Applicability. Addressing these proactively before your audit significantly reduces the risk of findings.

Can an ISO 27001 audit be done fully online?

Yes, an ISO 27001 audit can be conducted fully online. Remote audits, where the auditor reviews documentation, conducts interviews, and examines evidence via video call and digital document sharing, are a recognised and accepted approach. For digital companies in particular, this is often the most practical and efficient route.

Remote audits work especially well when your organisation operates digitally, your documentation is stored in the cloud, and your team is comfortable with video-based communication. Auditors can review access logs, system configurations, and security records remotely just as effectively as they can on-site.

The shift toward fully digital audit processes has made ISO 27001 more accessible for small organisations that previously could not justify the cost and logistical complexity of in-person audits. If your business is digital-first, there is no reason the certification process needs to be anything other than fully online.

How DICIS AG helps you through the ISO 27001 audit process

We built our platform specifically for small digital companies that want ISO 27001 certification without the traditional overhead. Here is what working with us looks like in practice:

  • AI-supported ISMS setup: Our platform guides you through building your information security management system step by step, generating the documentation you need in hours rather than months.
  • Fully online audits: Both Stage 1 and Stage 2 audits happen entirely online, no travel, no scheduling headaches, no on-site visits required.
  • Built-in audit preparation: The platform helps you run your internal audit before the external one, so you arrive prepared and confident.
  • Fast certification timeline: Your ISMS can be set up and certified in days, not months, genuinely useful if you need certification to win a contract or meet a client requirement.
  • Transparent pricing: No hidden consultant fees or surprise costs. You know exactly what you are paying from the start.

If you are ready to get your ISO 27001 certification online, get in touch with us today and we will show you how quickly it can happen for your organisation.

Related Posts

There is no related posts