Skip to main content
GDPR & privacy

ISO 27701 Lead Auditor

ISO 27701 Lead Auditor. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBLead Auditor5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Auditors who intend to conduct or lead PIMS certification audits
  • Managers or consultants aiming to master the PIMS audit process
  • Professionals responsible for maintaining ongoing PIMS conformance within their organisation
  • Technical experts preparing to support or participate in a PIMS audit
  • Privacy advisors specialising in the protection of personally identifiable information

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Individuals with no prior background in information security or privacy who may find the technical content difficult to follow
  • Those looking for a PIMS implementation course rather than an audit-focused programme
  • Beginners seeking an introductory overview of privacy concepts without audit application

What you'll be able to do

  • 1Describe the fundamental concepts and principles underpinning a privacy information management system (PIMS) as defined by ISO/IEC 27701
  • 2Interpret ISO/IEC 27701 PIMS requirements from an auditor's perspective
  • 3Assess PIMS conformity against ISO/IEC 27701 requirements using established audit concepts and principles
  • 4Plan, execute, and formally close an ISO/IEC 27701 compliance audit in line with ISO/IEC 17021-1 requirements and ISO 19011 guidelines
  • 5Manage a structured ISO/IEC 27701 audit programme across its full lifecycle
  • 6Apply best-practice auditing techniques to evaluate how an organisation protects personally identifiable information (PII)
  • 7Produce audit findings and conclusions that meet recognised certification audit standards

Day by day

Day 1Introduction to the privacy information management system and ISO/IEC 27701
  • PIMS concepts and the ISO/IEC 27701 standard

    Participants examine the structure, purpose, and core principles of ISO/IEC 27701 and understand how a PIMS extends an existing information security management system to address privacy requirements.

  • PII protection principles and regulatory context

    This module explores the key privacy principles relating to personally identifiable information and how they align with international regulatory expectations.

By end of day

  • Articulate the purpose and scope of ISO/IEC 27701 in relation to privacy management
  • Distinguish PIMS requirements from those of ISO/IEC 27001
Day 2Audit principles and preparation for audit initiation
  • Fundamental audit concepts and principles

    Participants review core auditing concepts including independence, evidence-based auditing, and the ethical conduct expected of a lead auditor.

  • Audit programme planning and initiation

    This module covers how to plan an audit programme, define its scope, establish audit objectives, and formally initiate an ISO/IEC 27701 audit in line with ISO/IEC 17021-1 requirements.

By end of day

  • Apply recognised audit principles when designing an ISO/IEC 27701 audit approach
  • Draft an audit plan that meets ISO/IEC 17021-1 requirements
Day 3On-site audit activities
  • Evidence gathering and interviewing techniques

    Participants practise collecting objective evidence through document review, observation, and structured interviews with PIMS stakeholders.

  • Evaluating PIMS controls and conformity

    This module focuses on assessing whether implemented PIMS controls conform to ISO/IEC 27701 requirements and recording findings accurately.

By end of day

  • Conduct on-site audit activities that produce reliable, objective evidence
  • Identify and document nonconformities against specific ISO/IEC 27701 clauses
Day 4Closing the audit
  • Communicating audit findings and closing meetings

    Participants learn how to present audit findings to auditee management, facilitate a closing meeting, and agree on corrective action timelines.

  • Audit reporting and follow-up

    This module addresses the preparation of a formal audit report and the follow-up process for verifying that nonconformities have been addressed effectively.

By end of day

  • Produce a structured audit report that clearly communicates findings and conclusions
  • Manage corrective action follow-up to close identified nonconformities
Day 5Audit programme management and certification exam preparation
  • Managing an ISO/IEC 27701 audit programme

    Participants examine how to oversee a multi-audit programme, allocate auditor resources, maintain programme records, and drive continual improvement of the audit function.

  • Exam competency domain review

    A structured review session consolidates knowledge across all seven exam competency domains, from PIMS fundamentals through to audit programme management.

By end of day

  • Design and govern a sustainable ISO/IEC 27701 audit programme
  • Identify personal knowledge gaps across the seven exam competency domains before sitting the assessment

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of a Privacy Information Management System (PIMS)
  • Domain 2: Privacy Information Management System (PIMS) requirements
  • Domain 3: Fundamental audit concepts and principles
  • Domain 4: Preparing an ISO/IEC 27701 audit
  • Domain 5: Conducting an ISO/IEC 27701 audit
  • Domain 6: Closing an ISO/IEC 27701 audit
  • Domain 7: Managing an ISO/IEC 27701 audit program

Certification Rules and Policies

  • Certification and examination fees are included in the price of the training course.
  • Participants will be provided with training course materials containing over 400 pages of information, practical examples, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • Candidates who have completed the training course but failed the exam are eligible to retake the exam once for free within a 12 month period from the initial date of the exam.

Education approach

  • This training is based on both theory and best practices used in PIMS audits
  • Lecture sessions are illustrated with examples based on case studies
  • Practical exercises are based on a case study which includes role-playing and discussions
  • Practice tests are similar to the Certification Exam

Building Digital Trust through Privacy Audits

digital trust

Buyers always ask

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

Which exam competency domains does the PECB ISO/IEC 27701 Lead Auditor exam cover?+

According to PECB, the exam addresses seven domains: fundamental principles and concepts of a PIMS, PIMS requirements, fundamental audit concepts and principles, preparing an ISO/IEC 27701 audit, conducting an ISO/IEC 27701 audit, closing an ISO/IEC 27701 audit, and managing an ISO/IEC 27701 audit programme.

For details on exam format, available languages, and scheduling, refer directly to PECB's List of Exams and Exam Rules and Policies.

How does ISO/IEC 27701 relate to ISO/IEC 27001, and why does that matter for auditors?+

ISO/IEC 27701 is an extension to ISO/IEC 27001 and ISO/IEC 27002 that adds requirements and guidance specifically for managing privacy information. An auditor therefore needs to understand how the PIMS builds on an existing information security management system rather than operating independently.

During the course, participants learn to evaluate PIMS conformity in the context of both the parent standards and the additional privacy-specific requirements introduced by ISO/IEC 27701.

Is prior audit experience necessary to benefit from this course?+

PECB states that a fundamental understanding of information security and privacy, together with a comprehensive knowledge of audit principles, is expected before attending. The course is therefore best suited to individuals who already have some grounding in audit practices rather than complete beginners.

Participants without any audit background may find the pace of Days 2 through 4, which focus on planning, conducting, and closing audits, difficult to follow.

What type of professional would find this course most directly applicable to their day-to-day work?+

The course is most directly applicable to practising auditors who want to add PIMS certification audits to their portfolio, privacy consultants who advise organisations on ISO/IEC 27701 readiness, and managers responsible for maintaining ongoing PIMS conformance.

Technical experts preparing to support a PIMS audit and expert advisors specialising in PII protection will also find the content highly relevant to their roles.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.