ISO 27001 Internal Auditor (2 Day) - Antaris Consulting

Antaris Academy launch offer. Save 15% on all available public courses at checkout until 27/05/26. View courses

Information Security

ISO 27001 Internal Auditor (2 Day)

Develop critical auditing skills aligned with ISO 19011 and ISO 27001
* This course runs in-house only.

Introduction

The ISO 27001:2022 Internal Auditor (ISMS) course is designed to equip learners with the essential knowledge and practical skills to audit Information Security Management Systems effectively. This CQI and IRCA certified programme offers participants a comprehensive understanding of ISO 27001:2022 requirements and the auditing process based on ISO 19011.

With evolving cyber threats and the critical importance of safeguarding information, this training helps organisations assess, improve, and maintain their ISMS frameworks. Through practical exercises and expert instruction, learners gain the confidence to conduct meaningful audits that drive continuous improvement and compliance.

ISO/IEC 27001:2022 introduced significant updates, including a streamlined set of 93 controls in Annex A (down from 114), now aligned with ISO/IEC 27002:2022. These changes reflect a more flexible and risk-focused approach to information security.

Course Overview

Who Should Attend?

This course is ideal for individuals responsible for conducting ISO 27001 internal audits or supporting ISMS implementation and improvement.

It is especially relevant to:

  • ISMS internal auditors
  • IT security professionals
  • Compliance and risk officers
  • Quality and governance managers
  • Information security or data protection officer/manager.

Learning Outcomes

On successful completion of this course, learners will be able to:

  • Explain the principles and requirements of ISO 27001:2022
  • Describe the roles and responsibilities of internal auditors
  • Plan and prepare internal ISMS audits using audit checklists
  • Conduct audits using effective questioning and evidence-gathering techniques
  • Report findings clearly and objectively
  • Follow up on corrective actions
  • Apply ISO 19011 auditing guidelines within an ISO 27001 context

These outcomes ensure learners can immediately contribute to ISMS auditing and improvement within their organisations.

Course Contents

This course provides a blend of theoretical and hands-on learning aligned with the auditing of ISMS under ISO 27001. Topics include:

  • Introduction to ISO 27001 and Annex A
  • Understanding Annex A Information security controls
  • Terminology and definitions
  • ISMS context, leadership, planning and operations
  • Statement of Applicability and risk assessment
  • Awareness, training, and continuous improvement
  • Internal audit process and ISO 19011
  • Competencies and responsibilities of internal auditors
  • Audit planning, preparation, checklists
  • Interviewing and evidence collection
  • Reporting, follow-up, and corrective actions

Learners participate in a practical internal audit exercise using realistic scenarios. Content can be tailored for in-company delivery.

Course Tutors

This course is delivered by experienced tutors with deep industry knowledge and auditing expertise. Each tutor brings real-world auditing experience, sector-specific insights, and a passion for practical training. Their focus is on building learner confidence through engaging, hands-on exercises and personalised support.

Tutors Include:

  • Gerry Higgins

Entry Requirements

CQI IRCA recommend learners have the following prior knowledge:

  • Understanding of the Plan-Do-Check-Act (PDCA) cycle
  • Basic knowledge of ISO 27001 concepts and terminology
  • Familiarity with the requirements of ISO 27001

These foundational concepts are essential for keeping pace with the course content. Without them, learners may struggle to engage fully with the material and audit methodologies introduced throughout the programme.

English Language Competency

A good standard of written and spoken English is important to engage effectively with this programme. While formal certification (e.g. IELTS) is not required, learners whose first language is not English should have a self-assessed proficiency equivalent to IELTS 5.5–6.0 or CEFR level B2.

This level of competence will support learners in understanding course materials, contributing to discussions, and completing assessments where applicable.

Assessment

Learners are assessed through continuous participation and an end-of-course multiple-choice assessment. Assessment includes:

  • Role-plays and simulations
  • Case studies and documentation review
  • Practical audit exercises
  • Final knowledge check via multiple-choice questions

Full attendance and active engagement are essential for successful completion.

How Do We Train to Support You?

Our training approach is practical, highly interactive, and discussion-based, with flexibility to meet organisational needs:

  • Pre-training consultation to align with your ISMS system (for in-company courses)
  • Where appropriate, exercises incorporate the organisation’s own ISMS documentation, offering learners the opportunity to practise audit techniques in a relevant and realistic setting. This hands-on approach culminates in a tutor-supervised internal audit, reinforcing practical application and embedding core learning outcomes.
  • Real-time support from expert tutors

Class sizes are generally limited to 10 – 12 to support personalised learning and individual support.

Accreditation

This course is certified by CQI IRCA and delivered by Antaris, a CQI IRCA Approved Training Partner. Course ID Number: 2140. Certification demonstrates ISO 27001 audit competence and supports professional recognition and organisational assurance.

Learner Pathway

This course forms part of a broader learning journey in auditing and information security. Possible next steps include:

  • ISO 27001:2022 Lead Auditor Training
  • ISO 27701 Data Privacy Extension Courses

Advance your capability and contribute to secure and compliant operations.

Upcoming Public Dates

Check out our public course dates below.

Public Course Dates

20-21 March 2026
19-20 JUNE 2026
16-17 JULY 2026
For upcoming public course dates please contact learning@antarisconsulting.com

Course Details

Duration:
2 Day
Accreditation:
CQI IRCA
Delivery Format:
Onsite or Virtual
Language:
English

What Our Students Say

Meet Our Tutors

Who We’ve Trained

Our training expertise has supported teams across a broad range of industries. Here you’ll find some of the organisations who have benefited from Antaris’ guidance and education.

Want to Get in Touch About Our Courses?

If you have questions about our courses or need support in determining the best pathway for your training objectives, please contact us.

Related Courses

Explore other courses that complement this training and support your professional development.

 

ISO 27001 Internal Auditor (2 Day)

The ISO 27001:2022 Internal Auditor (ISMS) course is designed to equip learners with the essential knowledge and practical skills to audit Information Security Management Systems effectively. This CQI and IRCA certified programme offers participants a comprehensive understanding of ISO 27001:2022 requirements and the auditing process based on ISO 19011.

With evolving cyber threats and the critical importance of safeguarding information, this training helps organisations assess, improve, and maintain their ISMS frameworks. Through practical exercises and expert instruction, learners gain the confidence to conduct meaningful audits that drive continuous improvement and compliance.

ISO/IEC 27001:2022 introduced significant updates, including a streamlined set of 93 controls in Annex A (down from 114), now aligned with ISO/IEC 27002:2022. These changes reflect a more flexible and risk-focused approach to information security.

ISO 27001 Internal Auditor (2 Day)

The ISO 27001:2022 Internal Auditor (ISMS) course is designed to equip learners with the essential knowledge and practical skills to audit Information Security Management Systems effectively. This CQI and IRCA certified programme offers participants a comprehensive understanding of ISO 27001:2022 requirements and the auditing process based on ISO 19011.

With evolving cyber threats and the critical importance of safeguarding information, this training helps organisations assess, improve, and maintain their ISMS frameworks. Through practical exercises and expert instruction, learners gain the confidence to conduct meaningful audits that drive continuous improvement and compliance.

ISO/IEC 27001:2022 introduced significant updates, including a streamlined set of 93 controls in Annex A (down from 114), now aligned with ISO/IEC 27002:2022. These changes reflect a more flexible and risk-focused approach to information security.

Download our brochure

Request Company Quote

Need In-Company Training? Please fill out the form below and a member of our team will be in touch with a company quote.

"*" indicates required fields

Consent
Consent

Download Course Brochure

Need In-Company Training? Please fill out the form below and a member of our team will be in touch with a company quote.

Download now