✔ CQI and IRCA Certified Course ✔ CQI IRCA Approved Training Partner ★ PR373 · Globally Recognised

ISO 27001 Lead Auditor Training Online — CQI IRCA Approved

CQI IRCA approved training to build information security auditing skills and pass with confidence — a 40-hour, 100% online, live virtual instructor-led course aligned with ISO 19011.

★★★★★  4.9 Google Rating · 1000+ reviews ·  Live instructor-led via Zoom ·  Certificate via Accredible within 3 working days of passing
×

ISO/IEC 27001:2022 ISMS Lead Auditor

Live online · CQI & IRCA certified · next cohort enrolling now.

Register Now Enquire Enquire Now ▸
40 Hrs
Live VILT Training
5
Exam Domains
ISO 19011
Aligned Methodology
100%
Online Delivery
Course Overview

Lead information security audits with confidence

3FOLD Training's CQI and IRCA certified ISO/IEC 27001:2022 ISMS Lead Auditor Course (PR373, Course Approval No. 2889) is a comprehensive 5-day training programme delivered on consecutive days, over weekends, or in evening blocks. It uses auditing role-plays, a realistic audit simulation and hands-on exercises that reflect real-world audit experience.

The course aims to provide delegates with the knowledge and skills required to perform first, second and third-party audits of information security management systems against ISO/IEC 27001:2022, in accordance with ISO 19011 and ISO/IEC 17021-1.

Delegates who successfully complete this course (within the five years before applying to become a certificated auditor) satisfy the training requirement for initial certification as an IRCA ISMS auditor.

Reserve Your Place

What You'll Achieve

Learning outcomes

OUTCOME 1

Explain the purpose of information security management system (ISMS) standards, management-system audit and third-party certification, and the business benefits of effective information security management.

OUTCOME 2

Explain the role of an auditor to plan, conduct, report and follow up an information security management system audit, in accordance with ISO 19011 and ISO/IEC 17021-1.

OUTCOME 3

Plan, conduct, report and follow up an audit of an ISMS to establish conformity, or otherwise, with ISO/IEC 27001:2022, and in accordance with ISO 19011.

Skills You'll Gain

Practical, job-ready auditing skills

By the end of the course you'll be able to run a full information security management system audit with confidence — these are the competencies you'll build and practise.

Audit planning & programme management Stage 1 & Stage 2 ISMS auditing Gathering objective audit evidence Interviewing & questioning techniques Evaluating information security controls Grading findings (Major / Minor / OFI) Writing defensible nonconformities Audit reporting & conclusions Leading opening & closing meetings Corrective action evaluation & follow-up Auditor ethics & impartiality Applying ISO 19011 & ISO/IEC 17021-1
Career Outcomes

Where this qualification can take you

As cyber and information security risk climbs every boardroom agenda, demand for qualified ISMS auditors keeps growing. A globally recognised CQI/IRCA lead auditor qualification positions you for first-, second- and third-party auditing, consulting and GRC management roles.

Step 1

Internal ISMS Auditor

Audit your own organisation's information security management system and prepare it for certification.

Step 2

ISMS Lead Auditor

Lead audit teams and conduct first-, second- and third-party audits, including for certification bodies.

Step 3

GRC / InfoSec Consultant

Advise organisations on ISO/IEC 27001 implementation, or manage information security and compliance programmes.

Curriculum

Course content — five focused modules

Each module blends short input with hands-on activities and a formative assessment, building one continuous audit of the case-study organisation.

1

Foundations of ISO/IEC 27001:2022 ISMS Auditing

The ISO/IEC 27001:2022 ISMS standard and the ISO 19011 auditing guidelines — what an ISMS is and why organisations operate one, the clause structure (4–10), Annex A and the Statement of Applicability, the types of audit and the audit process.

2

ISO/IEC 27001:2022 Audit Planning & Preparation through ISO 19011

Assessing the readiness of the ISMS from the Stage 1 review, then preparing a risk-based Stage 2 audit plan, building an audit checklist and sampling plan, and preparing effective opening meetings.

3

Conducting the Audit & Gathering Objective Evidence

Practising interviewing, following audit trails and corroborating evidence, and auditing the ISMS requirements across Clauses 4–10 and a risk-based sample of Annex A controls.

4

Audit Findings, Grading & Nonconformity Reporting

Evaluating evidence to determine conformity and nonconformity, grading findings as major or minor with justification, and writing clear, accurate nonconformity reports.

5

Finalising the Audit — Closing, Reporting & Follow-Up

The closing meeting, presenting conclusions and recommendations, and post-audit activities — evaluating corrective action, root-cause analysis and audit follow-up.

How You'll Learn

100% online, virtual instructor-led

The course is 80% learning-by-doing — role-play, audit simulation, preparing audit reports and checklists — delivered as "virtual interactive sessions," same as a physical classroom environment, and better. It runs on Zoom, Nearpod and the 3FOLD LMS (Moodle).

Live virtual instructor-led training (VILT) with experienced lead auditors
One continuous case study — audit an ISMS end to end
Downloadable templates and working documents you complete and discuss live
Choice of a weekend batch (5 Sundays, 9:00 AM–5:00 PM GST) or a weekday evening batch (13 sessions, 7:00 PM–10:00 PM GST) — identical content
Assessment & Certification

How you're assessed

Continuous evaluation across the course, plus a final open-book examination set by CQI/IRCA, sat online within 30 days of the course.

Exam: 1 hour 45 minutes — extended to 2 hours 15 minutes for non-native English speakers, applied automatically by 3FOLD
40 questions / 80 marks across five domains; open book — course notes and a clean copy of the ISO standards permitted
Pass: minimum total of 40 out of 80 marks (50%), plus the minimum pass mark in each domain
First exam attempt included; Certificate of Achievement via Accredible within 3 working days
The Exam

Five domains, one open-book exam

The exam covers 40 questions worth 80 marks in total, split across five domains — you must reach the minimum pass mark in every domain as well as 50% overall.

D1

Concepts & Principles

8 marks — management systems and ISMS concepts.

D2

Audit Concepts & Responsibilities

8 marks — the auditor's role and responsibilities.

D3

Planning the Audit

8 marks — risk-based audit planning through ISO 19011.

D4

Conducting the Audit

36 marks — gathering evidence and forming findings.

D5

Reporting & Closing

20 marks — nonconformities, reporting and follow-up.

Open-Book Exam Format

What you can and can't use

Permitted: notes from your training course, and a clean copy (paper or PDF) of the ISO standards.

Your course notes
A clean copy (paper or PDF) of the ISO standards
Not allowed: internet access, search engines or online resources; mobile phones, smart watches, earphones; dictionaries, calculators; blank paper or unauthorised books
Certificate Types

Achievement vs. Attendance

Learners who pass the continuous assessment and the CQI/IRCA examination receive a Certificate of Achievement; those who attend but do not pass receive a Certificate of Attendance. Only the Certificate of Achievement qualifies you to apply for CQI/IRCA auditor membership.

Attempt Condition Fee
1stIncluded in course fee, within 30 daysFREE
2ndMissed or failed 1st attempt, resit onlyAED 125 / USD 35
3rd, 5th, 7th…Must re-attend courseLevy + Exam: AED 310 / USD 85
4th, 6th, 8th…Resit after re-attendanceAED 125 / USD 35

If you don't take the exam within 30 days, the attempt is marked DNS (Did Not Submit) and no extensions are allowed. You remain eligible for a second attempt within 1 year of course completion.

Official Certification

An officially certified CQI and IRCA course

This is not a generic information security awareness workshop. 3FOLD Training is a CQI IRCA Approved Training Partner, and this programme is an officially CQI and IRCA certified course — so your training and certificate are recognised worldwide.

  • Course reference: PR373: ISMS ISO/IEC 27001:2022 Lead Auditor
  • CQI/IRCA Course Approval Number: 2889
  • Delivered by 3FOLD Training — a CQI IRCA Approved Training Partner

Click the certificate to view it full size.

× CQI and IRCA official course certification — PR373 ISO/IEC 27001:2022 ISMS Lead Auditor, awarded to 3FOLD Training
Why Train With 3FOLD

A CQI IRCA Approved Training Partner you can trust

Officially Approved

An audited CQI IRCA Approved Training Partner delivering certified lead auditor courses across ISO 9001, 14001, 45001 and 27001.

Expert Tutors

Led by practising, experienced information security lead auditors who bring real-world audit judgement to every session.

Up to Date

Course materials fully aligned with the ISO/IEC 27001:2022 revision and the current CQI/IRCA exam format.

Full Support

End-to-end guidance — from a free ISMS Foundation module to exam registration and a fast certificate turnaround.

Real Practice

A complete case-study company and simulated audit give you genuine experience, not just theory.

Globally Recognised

An internationally respected qualification that opens doors to first-, second- and third-party auditing roles worldwide.

Is This Course For You?

Who should attend

This course suits anyone aiming to become a certified ISMS lead auditor or to strengthen their information security auditing capability, including:

  • Information security, IT, risk, GRC and compliance professionals
  • Internal auditors and management-system professionals moving into ISMS auditing
  • Consultants advising on ISO/IEC 27001 implementation
  • Anyone pursuing IRCA ISMS auditor certification
Answers

Frequently asked questions

What is the ISO 27001 Lead Auditor course?
It is a CQI/IRCA-certified training course that gives you the knowledge and skills to plan, conduct, report and follow up first-, second- and third-party audits of an information security management system (ISMS) against ISO/IEC 27001:2022, in accordance with ISO 19011.
Is the ISO 27001 Lead Auditor course CQI/IRCA approved?
Yes. 3FOLD Training is a CQI/IRCA Approved Training Partner and this ISO/IEC 27001:2022 ISMS Lead Auditor course is certified by CQI and IRCA, UK (Course Approval No. 2889).
How long is the course and how is it delivered?
It is a 40-hour course delivered 100% online (Virtual Instructor-Led Training). Choose a 5-Sunday weekend batch (9:00 AM–5:00 PM GST) or a weekday evening batch (7:00 PM–10:00 PM GST).
Do I need prior knowledge before the course?
Yes — the course assumes a working knowledge of information security management and ISO/IEC 27001. You complete a short self-paced ISMS Foundation module and readiness quiz on our LMS before the live sessions begin.
What certificate will I receive?
Learners who pass the continuous assessment and the CQI/IRCA examination receive a Certificate of Achievement; those who attend but do not pass receive a Certificate of Attendance. Only the Certificate of Achievement qualifies you to apply for CQI/IRCA auditor membership.
How is the CQI/IRCA exam structured and what is the pass mark?
The exam has 40 questions worth 80 marks across five domains. You must score at least 40% in each domain and at least 50% overall (40/80). It is taken online within 30 days of the course; duration is 1 hour 45 minutes, extended to 2 hours 15 minutes for non-native English speakers (3FOLD applies this automatically).
Is the ISO 27001 exam open book?
Yes. You may use your course notes and a clean copy of the ISO standards. Internet access and unauthorised items are strictly prohibited and treated as malpractice.
Who should attend the ISO 27001 Lead Auditor course?
Information security, IT, risk, GRC and compliance professionals; internal auditors and management-system professionals moving into ISMS auditing; consultants; and anyone pursuing IRCA ISMS auditor certification.
Flexible Schedule

Two flexible formats, one course

Choose the rhythm that fits your work. Both formats cover the same 40 hours and the same five modules.

Weekday Evenings
7:00 PM – 10:00 PM GST · 13 sessions · learn around work
  1. Sessions 1–3 — Foundations of ISO/IEC 27001:2022 ISMS auditing
  2. Sessions 4–6 — Audit planning & preparation through ISO 19011
  3. Sessions 7–9 — Conducting the audit & gathering objective evidence
  4. Sessions 10–11 — Findings, grading & nonconformity reporting
  5. Sessions 12–13 — Closing, reporting & follow-up
Weekends
9:00 AM – 5:00 PM GST · 5 Sundays · focused completion
  1. Sunday 1 — Foundations of ISO/IEC 27001:2022 ISMS auditing
  2. Sunday 2 — Audit planning & preparation through ISO 19011
  3. Sunday 3 — Conducting the audit & gathering objective evidence
  4. Sunday 4 — Findings, grading & nonconformity reporting
  5. Sunday 5 — Closing, reporting & follow-up
Upcoming Sessions

Upcoming live online sessions

Choose your preferred batch and reserve your place. All sessions are delivered live online via Zoom; times shown in Gulf Standard Time (GST). After you register, a member of the 3FOLD team will contact you within 24 hours with your Zoom joining instructions and LMS access — please ensure your email address is correct.

Live Online · Weekday Evenings
Sep 21 – Oct 7, 2026
Dubai (GST): 7:00 PM – 10:00 PM
Sep 21, 22, 23, 24, 25, 28, 29, 30 & Oct 1, 2, 5, 6, 7
13 sessions
AED 2020 / USD 550 Save 44% (reg. USD 990) · incl. VAT/GST
Pay in AED Pay in USD
Enrolling now · filling fast
Live Online · Weekends
Oct 4 – Nov 8, 2026
Dubai (GST): 9:00 AM – 5:00 PM
Oct 4, 18, 25 & Nov 1, 8
5 Sundays
AED 2020 / USD 550 Save 44% (reg. USD 990) · incl. VAT/GST
Pay in AED Pay in USD
Enrolling now · filling fast
Corporate · Group Training
Custom Schedule
Tailor-made schedules for your team or organisation
On Request group & corporate rates available
Request a Quote
Any team size — worldwide

Can't see a date that suits you? Message us on WhatsApp for the latest calendar and group-booking options.

Ready to become an ISO/IEC 27001:2022 ISMS Lead Auditor?

Reserve your place on the next live cohort, or talk to an advisor about dates and group bookings.