What is the difference between a Stage 1 and Stage 2 ISO 27001 audit?
A Stage 1 ISO 27001 audit is a preliminary documentation review and readiness assessment, evaluating the design and completeness of the Information Security Management System (ISMS) against the standard's requirements. Conversely, a Stage 2 audit is the main assessment, verifying the ISMS's full implementation, operational effectiveness, and adherence to policies and procedures through on-site evidence collection and interviews. Stage 1 identifies gaps before the comprehensive Stage 2 evaluation, which determines certification eligibility.
The Stage 1 audit, often referred to as a 'readiness review' or 'documentation review', primarily focuses on the adequacy and completeness of the organisation's ISMS documentation. Auditors assess whether the ISMS scope is clearly defined, the risk assessment and treatment methodology is appropriate, and all mandatory clauses of ISO 27001 have been addressed in principle. This stage typically involves reviewing policies, procedures, risk registers, and the Statement of Applicability (SoA) to ensure the ISMS is designed to meet the standard's requirements. Practitioners should view this as a critical checkpoint to identify and rectify any significant gaps in their ISMS design or documentation before the more intensive Stage 2 audit, thereby reducing the risk of major nonconformities later.
The Stage 2 audit is the comprehensive on-site assessment where the certification body verifies the effective implementation and operation of the ISMS. Auditors will seek objective evidence that the documented policies and procedures are being followed in practice, that controls are operating as intended, and that the ISMS is achieving its stated security objectives. This involves interviewing personnel at various levels, observing processes, reviewing records (e.g., incident logs, access reviews, training records), and testing the effectiveness of selected controls. Successful completion of Stage 2, with resolution of any identified nonconformities, leads to the recommendation for ISO 27001 certification, demonstrating the organisation's commitment to information security management.
Sources
- ISO/IEC 17021-1:2015, Clause 9.3.1.2 (Initial Audit - Stage 1)
- ISO/IEC 17021-1:2015, Clause 9.3.1.3 (Initial Audit - Stage 2)