ISO 27001 Internal Auditor
A two-day workshop for the people who will have to satisfy clause 9.2. Every certified ISMS must be internally audited at planned intervals, and in most Malaysian organisations that duty lands on someone with an audit title and no information security background, or someone with a security background and no audit training. Both produce the same result: an internal audit that finds nothing, followed by a certification audit that finds plenty.
The programme follows ISO 19011 auditing guidance applied to an ISO 27001 management system. It is built around practice: participants plan an audit, write checklists, run interview role plays, gather and test evidence, grade findings and write nonconformities that would survive review. Day two runs a full simulated internal audit against a case organisation. This is a competency workshop rather than a certified lead auditor qualification; participants seeking a registered lead auditor credential should take an accredited course from a certification body, and the session says where that line falls.
HRD Corp SBL-Khas Claimable
Programme Agenda
Day 1, 9:00 AM - 9:15 AM
Welcome and Programme Overview
Objectives, the case organisation used throughout, and confirming participants' own audit context.
Day 1, 9:15 AM - 10:30 AM
The Standard From an Auditor's Seat
Rapid consolidation of clauses 4 to 10 and Annex A, read the way an auditor reads them: what is a requirement, what is guidance, and what wording creates an auditable obligation. Shall versus should. Identifying the objective evidence each clause implies. Where the scope statement and the Statement of Applicability define the boundary of your audit.
Day 1, 10:30 AM - 10:45 AM
Break
Day 1, 10:45 AM - 12:00 PM
Audit Principles and the Audit Programme
ISO 19011 principles: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach and the risk-based approach. Establishing an audit programme, setting objectives and frequency, and covering the whole ISMS across a cycle rather than auditing the easy parts repeatedly. Auditor competence, impartiality, and the practical problem of auditing your own colleagues in a small organisation.
Day 1, 12:00 PM - 1:00 PM
Planning an Audit
Defining the objective, scope and criteria for a single audit. Document review before fieldwork. Risk-based sampling and how to decide what to look at when you cannot look at everything. Building an audit plan and an agenda. Writing a working checklist that prompts open questions rather than yes or no answers. Participants draft a plan and checklist for the case organisation.
Day 1, 1:00 PM - 2:00 PM
Lunch
Day 1, 2:00 PM - 3:15 PM
Conducting the Audit: Interview and Evidence
The opening meeting. Interview technique: open questions, following the thread, and staying quiet. Auditing by trace, forward from a policy to its evidence and backward from a record to its authority. Sources of evidence: documents, records, system configuration, observation and interview. Testing whether a control is designed adequately and whether it operates. Sufficiency and appropriateness of evidence. Handling an auditee who is defensive, evasive, or more senior than you.
Day 1, 3:15 PM - 3:30 PM
Break
Day 1, 3:30 PM - 5:00 PM
Interview Practice
Role-played audit interviews against the case organisation, rotating auditor and auditee, with structured feedback on questioning, note taking and evidence capture.
Day 2, 9:00 AM - 9:15 AM
Day 1 Review
Day 2, 9:15 AM - 10:30 AM
Findings, Nonconformities and Grading
Classifying findings: major nonconformity, minor nonconformity, observation and opportunity for improvement, and why inconsistent grading destroys the credibility of an audit programme. Writing a nonconformity that states the requirement, the evidence and the failure, without prescribing the fix. Common bad nonconformities and how to rewrite them. Auditing the Statement of Applicability and challenging an unjustified exclusion.
Day 2, 10:30 AM - 10:45 AM
Break
Day 2, 10:45 AM - 12:30 PM
Simulated Internal Audit
Teams run a full internal audit against the case organisation covering an assigned set of clauses and Annex A controls: opening meeting, evidence gathering from a supplied document and record pack, and finding development.
Day 2, 12:30 PM - 1:30 PM
Lunch
Day 2, 1:30 PM - 2:45 PM
Simulated Audit: Findings and Closing Meeting
Teams grade their findings, draft nonconformities and deliver a closing meeting to the case organisation's management, played by the facilitator. Structured challenge and defence of each finding.
Day 2, 2:45 PM - 3:00 PM
Break
Day 2, 3:00 PM - 4:00 PM
Reporting, Corrective Action and Follow-Up
Writing an audit report management will act on. Root cause analysis and the difference between a correction and a corrective action, which is where most corrective action plans fail. Evaluating and verifying corrective action, and closing a nonconformity properly. Feeding audit results into management review under clause 9.3.
Day 2, 4:00 PM - 4:45 PM
Preparing for the Certification Audit
How an external stage 1 and stage 2 audit differs from yours, what certification auditors consistently find, and how to use the internal audit programme to make sure they do not find it. Managing the audit relationship and what not to volunteer.
Day 2, 4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Read ISO 27001 as auditable requirements and identify the objective evidence each clause implies
- Establish an audit programme that covers the whole ISMS across a cycle
- Plan an individual audit with defined objective, scope, criteria and risk-based sampling
- Conduct audit interviews and gather sufficient, appropriate evidence by forward and backward trace
- Grade findings consistently and write nonconformities that state requirement, evidence and failure
- Report results, evaluate corrective action against root cause, and close findings properly
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Intermediate. Suitable for internal auditors, ISMS managers, information security and compliance staff, and quality practitioners extending into information security. ISO 27001 awareness or equivalent working knowledge is assumed.
Duration 2 Days (16 Hours) | 9:00 AM to 5:00 PM daily
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A complete audit plan and checklist, assessed role-played interviews, and a set of written nonconformities from the simulated audit
Certificate Certificate of Completion issued to all participants upon full attendance