ISO 27001 Internal Auditor

A two-day workshop for the people who will have to satisfy clause 9.2. Every certified ISMS must be internally audited at planned intervals, and in most Malaysian organisations that duty lands on someone with an audit title and no information security background, or someone with a security background and no audit training. Both produce the same result: an internal audit that finds nothing, followed by a certification audit that finds plenty.

The programme follows ISO 19011 auditing guidance applied to an ISO 27001 management system. It is built around practice: participants plan an audit, write checklists, run interview role plays, gather and test evidence, grade findings and write nonconformities that would survive review. Day two runs a full simulated internal audit against a case organisation. This is a competency workshop rather than a certified lead auditor qualification; participants seeking a registered lead auditor credential should take an accredited course from a certification body, and the session says where that line falls.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

Day 1, 9:00 AM - 9:15 AM

Welcome and Programme Overview

Objectives, the case organisation used throughout, and confirming participants' own audit context.

02

Day 1, 9:15 AM - 10:30 AM

The Standard From an Auditor's Seat

Rapid consolidation of clauses 4 to 10 and Annex A, read the way an auditor reads them: what is a requirement, what is guidance, and what wording creates an auditable obligation. Shall versus should. Identifying the objective evidence each clause implies. Where the scope statement and the Statement of Applicability define the boundary of your audit.

03

Day 1, 10:30 AM - 10:45 AM

Break

04

Day 1, 10:45 AM - 12:00 PM

Audit Principles and the Audit Programme

ISO 19011 principles: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach and the risk-based approach. Establishing an audit programme, setting objectives and frequency, and covering the whole ISMS across a cycle rather than auditing the easy parts repeatedly. Auditor competence, impartiality, and the practical problem of auditing your own colleagues in a small organisation.

05

Day 1, 12:00 PM - 1:00 PM

Planning an Audit

Defining the objective, scope and criteria for a single audit. Document review before fieldwork. Risk-based sampling and how to decide what to look at when you cannot look at everything. Building an audit plan and an agenda. Writing a working checklist that prompts open questions rather than yes or no answers. Participants draft a plan and checklist for the case organisation.

06

Day 1, 1:00 PM - 2:00 PM

Lunch

07

Day 1, 2:00 PM - 3:15 PM

Conducting the Audit: Interview and Evidence

The opening meeting. Interview technique: open questions, following the thread, and staying quiet. Auditing by trace, forward from a policy to its evidence and backward from a record to its authority. Sources of evidence: documents, records, system configuration, observation and interview. Testing whether a control is designed adequately and whether it operates. Sufficiency and appropriateness of evidence. Handling an auditee who is defensive, evasive, or more senior than you.

08

Day 1, 3:15 PM - 3:30 PM

Break

09

Day 1, 3:30 PM - 5:00 PM

Interview Practice

Role-played audit interviews against the case organisation, rotating auditor and auditee, with structured feedback on questioning, note taking and evidence capture.

10

Day 2, 9:00 AM - 9:15 AM

Day 1 Review

11

Day 2, 9:15 AM - 10:30 AM

Findings, Nonconformities and Grading

Classifying findings: major nonconformity, minor nonconformity, observation and opportunity for improvement, and why inconsistent grading destroys the credibility of an audit programme. Writing a nonconformity that states the requirement, the evidence and the failure, without prescribing the fix. Common bad nonconformities and how to rewrite them. Auditing the Statement of Applicability and challenging an unjustified exclusion.

12

Day 2, 10:30 AM - 10:45 AM

Break

13

Day 2, 10:45 AM - 12:30 PM

Simulated Internal Audit

Teams run a full internal audit against the case organisation covering an assigned set of clauses and Annex A controls: opening meeting, evidence gathering from a supplied document and record pack, and finding development.

14

Day 2, 12:30 PM - 1:30 PM

Lunch

15

Day 2, 1:30 PM - 2:45 PM

Simulated Audit: Findings and Closing Meeting

Teams grade their findings, draft nonconformities and deliver a closing meeting to the case organisation's management, played by the facilitator. Structured challenge and defence of each finding.

16

Day 2, 2:45 PM - 3:00 PM

Break

17

Day 2, 3:00 PM - 4:00 PM

Reporting, Corrective Action and Follow-Up

Writing an audit report management will act on. Root cause analysis and the difference between a correction and a corrective action, which is where most corrective action plans fail. Evaluating and verifying corrective action, and closing a nonconformity properly. Feeding audit results into management review under clause 9.3.

18

Day 2, 4:00 PM - 4:45 PM

Preparing for the Certification Audit

How an external stage 1 and stage 2 audit differs from yours, what certification auditors consistently find, and how to use the internal audit programme to make sure they do not find it. Managing the audit relationship and what not to volunteer.

19

Day 2, 4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Read ISO 27001 as auditable requirements and identify the objective evidence each clause implies
  • Establish an audit programme that covers the whole ISMS across a cycle
  • Plan an individual audit with defined objective, scope, criteria and risk-based sampling
  • Conduct audit interviews and gather sufficient, appropriate evidence by forward and backward trace
  • Grade findings consistently and write nonconformities that state requirement, evidence and failure
  • Report results, evaluate corrective action against root cause, and close findings properly

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate. Suitable for internal auditors, ISMS managers, information security and compliance staff, and quality practitioners extending into information security. ISO 27001 awareness or equivalent working knowledge is assumed.

Duration   2 Days (16 Hours)  |  9:00 AM to 5:00 PM daily

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A complete audit plan and checklist, assessed role-played interviews, and a set of written nonconformities from the simulated audit

Certificate   Certificate of Completion issued to all participants upon full attendance

EnquiriesContact us to register or discuss scheduling

Frequently Asked Questions

Yes. ISO 27001 Internal Auditor is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

ISO 27001 Internal Auditor runs for 2 days (16 hours) | 9:00 AM to 5:00 PM daily. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Intermediate. Suitable for internal auditors, ISMS managers, information security and compliance staff, and quality practitioners extending into information security. ISO 27001 awareness or equivalent working knowledge is assumed. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.