01Audit typology: first, second and third party
ISO 19011 defines an audit as a systematic, independent and documented process in which audit evidence is objectively evaluated against audit criteria; the guideline was published in its fourth edition in May 2026 (ISO 19011:2026, a technical revision of the 2018 edition, including expanded guidance on remote audits). Three constellations are distinguished: first-party audits (internal audits) are conducted by the organization itself or on its behalf, for example to verify conformity with the standard or to prepare for certification. Second-party audits are carried out by interested parties such as customers – typically as supplier audits within third-party risk management. Third-party audits are conducted by independent bodies, in particular certification bodies and authorities; these certification audits are governed not by ISO 19011 but by ISO/IEC 17021-1.
02The certification process: Stage 1, Stage 2 and the 3-year cycle
Under ISO/IEC 17021-1, the initial certification audit takes place in two stages: Stage 1 assesses readiness for certification – documentation, scope, site-specific conditions and whether internal audits and the management review have already been planned and performed. Stage 2 then evaluates on site the implementation and effectiveness of the management system, including the controls from the Statement of Applicability (SoA). With the positive certification decision, the three-year certification cycle begins: surveillance audits take place at least once per calendar year – except in years with a recertification audit, with the first no later than twelve months after the certification decision – and examine selected areas on a sampling basis; in the third year, the recertification audit re-assesses the entire system before the certificate expires. Transitions to new versions of a standard follow their own rules – under IAF MD 26, the deadline for transitioning to ISO/IEC 27001:2022 ended on 31 October 2025, and older certificates to the 2013 edition have been invalid since then.
03The accreditation chain: who audits the auditors?
For a certificate to carry weight, the issuing certification body must itself be overseen. In Germany, this is the task of DAkkS as the sole national accreditation body, based on Regulation (EC) No 765/2008 and the German Accreditation Body Act (AkkStelleG); DAkkS itself operates in accordance with ISO/IEC 17011. Certification bodies for management systems are accredited to ISO/IEC 17021-1; for ISMS certifications, the requirements of ISO/IEC 27006-1:2024 apply in addition – including those on auditor competence and minimum audit time – whose transition period for certification bodies ended on 31 March 2026. For clients this means: the accreditation symbol should be visible on the certificate – a non-accredited certificate carries considerably less evidential weight.
04Internal audits: mandatory under Clause 9.2
In Clause 9.2, ISO/IEC 27001:2022 requires internal audits at planned intervals: they are intended to show whether the ISMS conforms to the organization's own requirements and to the requirements of the standard, and whether it is effectively implemented and maintained (9.2.1). Clause 9.2.2 requires an audit programme for this purpose, covering frequency, methods, responsibilities and reporting lines, which takes into account the importance of the processes concerned and the results of previous audits. The standard does not prescribe a fixed frequency; auditors must be selected in a way that preserves objectivity and impartiality – internal audits can therefore also be performed by external third parties on the organization's behalf. The results must be reported to the relevant level of management and retained as documented information; external auditors examine precisely this process in Stage 1 and again in every surveillance audit.
05Audit preparation: from gap assessment to evidence package
Solid preparation starts with a cleanly delimited scope and a gap analysis against the requirements of the standard and the control catalogue. This is followed by implementing the open measures and building up audit-ready evidence: risk assessment and risk treatment plan, Statement of Applicability, and operational records, for example on access reviews, training and security incidents. Before Stage 2, at least one complete internal audit cycle and one management review should be finished, because it is precisely this maturity that the auditor already evaluates in Stage 1; “Areas of Concern” identified there can be classified as nonconformities in Stage 2. It has proven effective to generate evidence where the work is actually done – documentation compiled retroactively shortly before the audit is regularly noticed in Stage 2.
06Common nonconformities and how to handle them
Certification auditors classify findings as major nonconformities – where the ability of the management system to achieve its intended results is in question – or as minor nonconformities; in addition, there are observations and opportunities for improvement. Recurring areas of findings in ISMS audits are gaps between documented processes and actual practice, a risk assessment without a traceable link to the Statement of Applicability, internal audits that do not cover the entire scope, incomplete management reviews, and corrective actions that are not followed up. Major nonconformities must be demonstrably closed before the certification decision; if the certification body cannot verify the corrections within six months of the end of Stage 2, ISO/IEC 17021-1 requires another Stage 2 audit. What matters is a systematic approach: root cause analysis, corrective action and verification of effectiveness instead of one-off symptom fixes.