In an ISO 27001 Stage 2 audit the auditor tests whether the ISMS lives in practice: the review starts from the Statement of Applicability and risk records, then samples operational evidence such as the screening records and access grants of recent hires. The opening requests follow a fixed logic: scope, risk method and the SoA come first because every later answer is measured against them. Then the sampling starts: internal audit, management review, corrective actions, personnel evidence, suppliers, incidents. Ten requests cover almost every opening move, and each has a recognizable weak answer.
What does a Stage 1 audit ask for on paper?
Stage 1 is the documentation audit, and it can stop the project before Stage 2 is ever booked. The certification body reviews ISMS documentation and readiness: scope plausibility, the ISMS policy, the risk assessment, the Statement of Applicability, internal audit results and management review. If readiness is not evident, the process ends there. Preparation means having the paper trail in order, not rehearsing answers for an interview that has not been scheduled. If you are earlier in the process, the ISO 27001 overview for regulated firms covers the full certification path.
Which documents does an ISO 27001 auditor ask for first?
Stage 2 moves from paper to practice: random samples, interviews with the information security lead, management, IT administrators and randomly selected employees, plus direct observation. The requests below open most Stage 2 audits, roughly in this order. Each item names what the auditor is testing and what a weak answer sounds like.
-
“Show me your ISMS scope statement.” The scope (clause 4.3) defines what the certificate will cover, and every later answer is measured against that boundary. Auditors open with it because a mismatch found late invalidates what came before; the BSI warns explicitly about scopes drawn too narrowly for regulated services. Weak: a template sentence listing offices and departments the documented processes do not cover.
-
“Walk me through your risk assessment method.” Before looking at any single risk, the auditor tests whether a documented method exists: criteria, scoring, owners, review rhythm. The method makes ratings comparable across years, which is why it comes before the register itself. Weak: a spreadsheet whose scores appear without criteria or dates, so the auditor cannot re-derive a single rating.
-
“Give me your Statement of Applicability.” The SoA is mandatory documented information under clause 6.1.3 d and the table of contents of the whole ISMS: which of the 93 Annex A controls apply, which are excluded, and why. Auditors open with it because every later control test hangs off this document. Weak: all 93 controls marked applicable without justification, or exclusions that no longer match reality.
-
“Show me your internal audit programme and its results.” An ISMS that never audits itself cannot demonstrate improvement, so the running programme under clause 9.2 is a prerequisite question. A superficial internal audit that only collects confirmations, mutual back-patting, is a classic Stage 2 finding. Weak: a single rushed audit weeks before Stage 2, an empty findings list, no evidence anything was followed up.
-
“When did management last review the ISMS, and what did it decide?” The management review under clause 9.3 tests whether leadership steers the system. The auditor reads the minutes for decisions, not for status prose, because dated decisions show that security carries authority. Weak: minutes that restate project status, name no decisions, and record no management involvement since the previous cycle.
-
“Show me the corrective actions from your last findings.” Nonconformities and corrective actions (clause 10) are where a paper ISMS falls apart. The auditor traces one finding from internal audit to its documented closure and checks whether the fix worked. Weak: findings open for months with no owner, or closure noted in the log without any evidence of effect.
-
“Show me the most recent new hires, their screening records and their access grants.” This documented Stage 2 example tests the People controls at their entry gate: was every person verified before receiving access, proportionate to the role, with a record to show? Weak: a signed CV offered as screening, an informal “I know him, he is trustworthy” answer, or no records at all for people who joined before the ISMS existed.
-
“Show me your awareness and training records.” Control A.6.3 is quick to sample and fast to expose a programme without substance: who was trained, when, and whether the content reached everyone in scope. Weak: a policy that promises annual training, participation lists from one session, and nothing that shows anyone learned anything since.
-
“Pick a critical supplier and show me its security arrangements.” Supplier security is tested by walking one relationship end to end: contract clauses, security requirements, review evidence, and what happens when the supplier fails. Weak: a supplier list with no security clauses in contracts, or annual supplier reviews that exist as templates but were never filled with results.
-
“Show me your incident and event records.” A silent incident log is itself a warning sign: events happen in every organization, and the question is whether they get reported, triaged and documented. The auditor picks one event and follows it through to the lessons learned. Weak: an empty log explained with “nothing happened”, or incidents solved in a chat channel that never entered the ISMS.
Why auditors sample personnel evidence early
Auditors reach the personnel sample early in Stage 2 for a practical reason: the records are fast to verify and unusually telling about ISMS maturity. Screening records of recent hires under A.6.1, signed employment terms and NDAs under A.6.2 and A.6.6, training evidence under A.6.3, a communicated disciplinary process under A.6.4: each is a short document that either exists, dated and traceable, or does not. For regulated firms the questions go deeper: what was checked for whom, before which access was granted, and how rescreening is triggered when roles change.
This is the seam where employee background verification becomes ISMS evidence. Structured, documented, reviewable verification of key personnel, drawn from registry data, sanctions and adverse media checks and employment history, and closed with a human final review, produces records with exactly the properties auditors and data protection officers look for: traceable sources, dates, a documented decision, retention that respects the BDSG. The Indicium report is built for this class of evidence. The control itself, including its exact wording, is covered in ISO 27001 A.6 personnel security.
Frequently asked questions
What is the difference between Stage 1 and Stage 2?
Stage 1 reviews ISMS documentation and readiness and can stop the process if the system is not ready. Stage 2 is the on-site effectiveness audit with document sampling, interviews and direct observation. The certification decision follows only after Stage 2 and after all nonconformities are resolved.
Do I need an internal audit before the certification audit?
In practice yes. Internal audit results and the management review are among the first things a Stage 1 reviewer asks to see, because they prove the ISMS evaluates itself. A programme that exists only on paper will surface as a finding in Stage 2.
What happens if the auditor finds a nonconformity?
Findings are classified by severity. A major nonconformity blocks the certificate until a follow-up audit confirms the correction; minor nonconformities receive a correction deadline, in practice commonly around 90 days. The certificate is issued only after every nonconformity has been corrected or accepted, so weak evidence costs time exactly where it looks harmless.
How often do surveillance audits take place?
At least once per calendar year during the three-year certificate period, with the first surveillance no later than twelve months after certification. Surveillance audits are sample-based and revisit previous findings, so unresolved weaknesses reappear. Book capacity early: Stage 2 slots at large certification bodies have filled months ahead as NIS2 and DORA projects queue, and the body should hold DAkkS accreditation for ISO/IEC 27001.
This article provides general information about ISO 27001 audits and audit preparation; it does not constitute legal advice.