What is ISO 27001 stage 1 audit?

Asked by: Zella Barrows V  |  Last update: September 18, 2026
Score: 4.4/5 (69 votes)

An ISO 27001 Stage 1 audit, or "documentation review," is the initial phase of the certification process where an external auditor evaluates an organization's Information Security Management System (ISMS) documentation. It determines if policies, procedures, and scope align with the ISO 27001 standard and prepares the organization for the Stage 2 implementation audit.

What is the Stage 1 audit of ISO 27001?

The Stage 1 audit, often termed the "Documentation Review," serves as an initial assessment of an organization's readiness for ISO 27001 certification. Its primary focus lies in evaluating the organization's ISMS documentation against the requirements of ISO 27001.

What is the difference between ISO 27001 Stage 1 and Stage 2 audit?

Stage 1 ensures that your ISMS is designed to meet ISO 27001:2022, while Stage 2 confirms that it functions effectively in practice. Together, they provide a complete review of your ISMS, ensuring compliance and reducing the risk of nonconformities.

What are 1st, 2nd, and 3rd party audits?

1st, 2nd, and 3rd party audits categorize audits by who performs them and their purpose: First-party (internal) audits are self-assessments for improvement; Second-party audits are by customers or partners on suppliers to check compliance; and Third-party audits are by independent, external bodies for certification (like ISO) or validation, offering the highest objectivity.

What is the main objective of stage 1 audit?

It's performed at the main location for the organisation or, if feasible, may be conducted remotely. The objective of a Stage 1 audit is to determine whether an organisation has completed the foundations of their management system.

ISO 27001 Stage #1 & Stage #2 Audits - Explained

44 related questions found

What is the difference between stage 1 and stage 2 audit?

Key Differences:

Objectives: The primary objective of the Stage 1 audit is to evaluate the organization's management system's readiness for the Stage 2 audit. The objective of the Stage 2 audit is to evaluate the implementation and effectiveness of the organization's management system.

What are the 5 stages of audit?

What happens during an audit? Internal audit conducts assurance audits through a five-phase process which includes selection, planning, conducting fieldwork, reporting results, and following up on corrective action plans.

What is a stage 3 audit?

Stage 3 Road Safety Audits should be undertaken when the highway scheme construction is complete and preferably before the works are opened to road users. All highway improvement schemes should be subjected to a Stage 3 Road Safety Audit within one month of opening.

Who are SOC 2 auditors?

SOC 2 audits can only be conducted by a licensed CPA firm or agency accredited by the American Institute of Certified Public Accountants (AICPA). In addition, the auditor or auditing firm must be a completely independent CPA, which means they have no relationship with the service organization they're auditing.

What are the 4 categories of ISO 27001?

ISO 27001, the international standard for information security management systems (ISMS), provides a structured approach to safeguarding data. Central to this framework are the 93 controls in Annex A, which are divided into four categories: organizational, people, physical, and technological.

What are the 4 types of auditors?

The four common types of auditors are Internal Auditors (evaluate company operations for management), External Auditors (independent review of financial statements for outside parties), Government Auditors (ensure compliance with laws for public agencies like the IRS), and Forensic Auditors (investigate financial fraud for legal proceedings). These roles focus on different areas, from internal controls and risk management to financial reporting accuracy and fraud detection.
 

What are the three types of ISO audits?

There are three types of ISO audits: internal audits (first-party audits), supplier audits (second-party audits), and external audits (third-party audits). Your choice of audit type will alter depending on your compliance and certification goals, scope, scale, and budget.

What is the salary for an ISO 27001 auditor?

ISO 27001 Lead Auditor Salary

According to salary surveys: US: $100,000 to $135,000 per year on average.

What is a Stage 1 document review?

An ISO 9001 stage-1 audit, also known as a document review, is the initial audit that a company undergoes as part of the ISO 9001 certification process. The purpose of this audit is to assess the company's readiness for a full ISO 9001 certification audit.

What are the 7 steps in the audit process?

The 7 steps in the audit process generally cover Planning, Risk Assessment, Internal Control Testing, Fieldwork/Evidence Collection, Reporting, and Follow-Up, focusing on a systematic review from initial engagement to ensuring corrective actions are taken for operational improvement. This framework ensures comprehensive evaluation, from understanding the client's business to delivering actionable insights and ensuring accountability for identified issues. 

What are the 4 levels of audit?

4 levels of audit opinions

  • Unqualified.
  • Qualified.
  • Adverse.
  • Disclaimer.
  • Beyond the opinion.

How many stages are in an ISO audit?

The ISO assessment is conducted in two parts, the Stage 1 and Stage 2 Certification Audits, and followed by Surveillance Audits. In this article we'll explain why, and what it means for your business. We'll also take a look at Pre-Certification Assessment and discuss whether they're necessary.

What is L1 and L2 audit?

A Level 2 audit begins with everything in a Level 1 audit but takes the data collection and final reporting a step farther. The building's energy consumption is broken down by end-use, helping to identify the areas with the greatest opportunities for improved efficiency.

What are the 4 C's of auditing?

A successful internal audit function relies on four fundamental pillars, often referred to as the “4 C's”: Competence, Confidentiality, Communication, and Collaboration. These principles guide auditors in delivering meaningful and impactful results. Let's explore each of these elements in detail.

What are the big 5 of audit?

Big Five

  • Arthur Andersen.
  • Deloitte & Touche.
  • Ernst & Young.
  • KPMG.
  • PricewaterhouseCoopers.

What are the four stages of an audit?

Although every audit is unique, the audit process usually consists of four stages: Planning, Field work, Reporting and (for some audits) Follow-up. Engagement of the client, or the area being audited, is critical at every stage of the audit process.

What are the 5 C's of audit?

The 5 Cs of audit (Criteria, Condition, Cause, Consequence, Corrective Action) are a framework for structuring clear, actionable audit findings, explaining what should be (Criteria), what is found (Condition), why it happened (Cause), what the impact is (Consequence/Effect), and how to fix it (Corrective Action/Recommendation) to drive organizational improvement and compliance.

What is the first stage of an audit?

The first stage is the planning stage. In this stage, a corporation engages with the auditing firm to establish details, such as the level of engagement, procedures, and objectives. The second stage is the internal controls stage.

What are the three main types of audit?

The three main types of audits, focusing on who performs them, are Internal Audits (by employees for improvement), External Audits (by independent CPAs for stakeholders), and Government Audits/IRS Audits (by tax authorities). Alternatively, focusing on the purpose, they can be categorized as Financial Audits (financial statements), Compliance Audits (rules/regulations), and Operational Audits (efficiency/effectiveness).