An internal auditor writes a finding. Access reviews are not performed regularly.
The auditee reads it and asks three questions. Where does the standard say "regularly"? Which of our own documents defines the frequency? What did you look at to conclude we missed it?
The auditor has good instincts and no answers. The finding gets withdrawn.
The problem was real. Access reviews genuinely weren't happening. But the finding wasn't built, so it didn't survive first contact.
Anyone can spot a problem. A finding is a problem you can defend.
That gap is the entire Lead Auditor course.
This isn't the course you think it is
Lead Auditor used to be for people who wanted to work for a certification body. That hasn't been true for years, and it isn't why people sit in my room.
Three reasons show up now.
Clause 9.2 doesn't audit itself. Every certified organisation owes internal audits, and most of them are run by whoever got handed the job. They produce a document. They don't produce findings anyone acts on.
NIS2 and DORA turned supplier assessment into a full time occupation. If you're evaluating third parties, you're auditing. You just don't have a method, so you're doing it with a questionnaire and a gut feeling.
And some people come because they're tired of being surprised. You sit on the receiving end. The fastest way to stop collecting findings is to learn how they get written.
What you can do on the Friday that you couldn't on the Monday
Plan an audit that survives scope creep. Objectives, criteria, scope, sample. Written down before you walk in, because the moment you improvise, the auditee sets the agenda.
Sample, and defend the sample. The standard never tells you how much evidence is enough. That judgement is the job, and it's the thing nobody teaches. You'll learn how to size a sample and how to explain it when someone challenges you.
Tell a document from a record. A policy says what should happen. A record proves it did. Most wasted audit time is an auditor reading policies and calling it evidence.
Interview. Open questions. Silence. What to do when the answer doesn't match the record in front of you, which is the moment the audit actually starts.
Write a finding in three parts. Requirement, evidence, gap. Miss one and it gets withdrawn, exactly like the one above. You'll write real ones and I'll take them apart in front of the group.
Classify and hold the line. Major, minor, observation, opportunity for improvement. The classification is the argument, and it's where almost every dispute lands. Getting it wrong in either direction costs you credibility.
Use the Statement of Applicability as the spine. Excluded a control? Justify it. That column is the fastest route through any ISMS, from either chair.
Run a closing meeting when the room disagrees with you. Including when the disagreement is coming from someone considerably more senior than you.
The five days
PECB structure, and it's a sensible one. Day 1 covers the ISMS and ISO/IEC 27001 itself. Day 2 is audit principles, preparation and initiation. Day 3 is conducting the audit. Day 4 is closing it and managing an audit programme. Day 5 is the exam.
The method comes from ISO 19011 and ISO/IEC 17021-1, which is what certification bodies work to. So you learn the real rules, not a simplified version of them.
Day 1 is groundwork. Days 2 to 4 are the course.
The part nobody tells you before you pay
Passing the exam does not automatically make you a Lead Auditor.
PECB issues three credentials off this one exam: Provisional Auditor, Auditor, and Lead Auditor. Same exam, same training. What separates them is documented professional experience and logged audit hours.
Most people sitting their first ISMS audit exam come out as Provisional Auditor and move up as they log real audits.
That's not a catch and it isn't a downgrade. It's how a serious personnel certification scheme works, and you should hear it from me now rather than from the application form later. If you want to know which tier you'd qualify for, email me before you book and I'll tell you straight.
Six people, and that's deliberate
You can't learn to audit by watching slides.
Over the week you plan an audit, run interviews, collect evidence, and write findings on a case study. Then those findings get challenged, out loud, by me and by the room. That's the part that changes how you work, and it doesn't function with thirty people logged in.
So the cohort is capped at six. It's not a scarcity tactic. It's the maximum number of people whose findings I can properly tear apart in five days.
I'm also a practising CISO. I run implementations, I get audited, and I audit other people's systems. You'll get the standard, and you'll get what actually happens when the evidence doesn't exist and someone has to decide what that means.
Who shouldn't book this
If you've never seen an ISMS, start with Foundation or Lead Implementer. This course assumes you know what a Statement of Applicability is and why Clause 6.1.3 matters.
If you want a certificate for a profile page, there are cheaper ways to get one. This is five days of being asked to defend your reasoning.
The details
ISO/IEC 27001 Lead Auditor · 28 September - 2 October 2026
Five days. PECB certification. 31 CPD credits. €2,999 including the exam.
Six seats. Discounts start at three participants from the same organisation.
Certified or Refunded. Sit the exam, and if you fail it twice, you get your money back in full. Not a credit note. Not a free retake. Your money.
I can afford that guarantee because of how the week is run. Six people, real findings, and no one leaves a session with a misunderstanding I didn't catch.
"Show me where it says that" is the question that ends bad audits.
Spend five days learning to have the answer ready.
