ISO 27001 Audit Preparation: Stage 1 and Stage 2 Checklist
What auditors really check in Stage 1 and Stage 2, and how to prepare your ISMS without last-minute evidence hunting.
An ISO 27001 audit is not just a document review. The auditor wants to understand whether your information security management system works in daily practice: whether the scope is clearly bounded, risks are assessed in a traceable way, controls from the Statement of Applicability are actually implemented and responsible people can explain their processes.
Good preparation therefore does not start by collecting as many policies as possible. It starts with a simple question: can an external person follow the path from risk, to selected control, to concrete evidence? If that connection is clear, the audit becomes much calmer. If it is missing, questions, follow-up requests and findings become more likely.
This article first explains what Stage 1 and Stage 2 each focus on. Further down, you will find an Excel checklist for structuring readiness, evidence, actions and interview preparation.
Stage 1: demonstrate certification readiness
Stage 1 is the documentation and readiness review. The auditor wants to see whether the ISMS can be audited and whether Stage 2 can be planned sensibly. For ISO 27001, this especially means: the scope must be plausible, the risk method must be defined, the risk assessment must be traceable and the Statement of Applicability must not be an isolated document.
| Check point | What should be prepared | Typical gap |
|---|---|---|
| Scope | Sites, services, systems, interfaces and exclusions are justified. | The scope is written like marketing copy and cannot be technically bounded. |
| Context and requirements | Relevant customer, legal, contractual and internal requirements are recorded. | NIS2, customer requirements or processor topics are missing from the assessment. |
| Risk method | Criteria, scale, acceptance limits and responsibilities are approved. | Risks were assessed, but the method is not explained. |
| SoA | All 93 controls are assessed, justified and connected to implementation/evidence. | Controls are marked "applicable" without a defensible reference. |
| Audit programme | Internal audit and management review are planned or completed. | The internal check is improvised only after Stage 1. |
Example: what good Stage 1 evidence shows
Good Stage 1 evidence is not only present; it can be explained. Example scope: if a SaaS provider wants to certify only the product platform, it should be clear whether development, operations, support, cloud infrastructure, identity management and external providers are inside the scope. If customer support can access sensitive data, it cannot simply sit outside the scope because it belongs to a different team.
The same applies to risk assessment. An auditor does not necessarily expect a complex quantitative method. But criteria such as likelihood, impact, information value, risk acceptance and responsibility should be applied consistently. If two comparable risks are scored differently, the difference should be defensible.
Stage 2: show implementation and effectiveness
Stage 2 does not test whether the documentation looks tidy. The auditor follows processes, interviews responsible people and checks samples. The best preparation is therefore an evidence walkthrough: for every critical process, clarify where the evidence is stored, who can explain it and which open action still has to be closed.
Evidence that is often requested
- approved scope, information security policy and ISMS objectives,
- asset or information asset register with owners,
- risk register, risk treatment plan and accepted residual risks,
- Statement of Applicability with control status and evidence references,
- access reviews, backup tests, logging/monitoring evidence and incident records,
- supplier assessment, contractual security requirements and privacy/data processing references,
- awareness and training records, internal audit, management review and action tracking.
Example: from risk to evidence
An audit-ready evidence trail connects several levels. Example: the risk register lists "unauthorised access to customer data". That leads to controls such as access control, role model, access recertification, logging and offboarding. In Stage 2, it should be visible how these controls work in practice: a current access review, an offboarding ticket, an identity management export, a role description and evidence that deviations were tracked.
A folder with isolated policies is weak if it has no clear link to the risk assessment or SoA. Strong evidence shows: this risk was identified, this control was selected, this person is responsible, this record shows implementation, and this open deviation is being tracked.
Download: ISO 27001 Audit Checklist
Once the audit logic is clear, a structured working list helps. The Excel template contains four worksheets: Stage 1 readiness, Stage 2 evidence, action tracking and interview planning. It is designed as a working file, not as a generic tick-box list.
How to fill out the template
Use the template as a working list for the project team. The dropdowns in the status and priority columns keep the assessment consistent, while the free-text fields are for concrete evidence, owners and next steps.
- Stage 1 Readiness: Start with scope, context, risk method, risk assessment, SoA, objectives and audit planning. Set the status via dropdown and record every gap with an owner and due date.
- Stage 2 Evidence: Link to or describe the actual evidence. The decisive point is not that a document exists, but that the responsible owner can explain it.
- Actions: Move all open points from Stage 1 and Stage 2 into one consolidated list. Priority and status are prepared as dropdowns.
- Interview Plan: Plan which roles the auditor is likely to interview, which questions may come up and which evidence each person should show.
Plan the audit days in practice
Even a technically solid ISMS can look unnecessarily weak if the organisation is not prepared for the audit day. Define in advance who receives the auditor, who follows the audit agenda, who retrieves evidence and who is allowed to make decisions. For remote audits, also clarify how screen sharing, document access and confidential evidence will be handled.
- Create a central evidence folder or link list with the most important records.
- Keep one internal contact available during the audit to retrieve missing evidence.
- Prepare short process overviews so interviews do not start from zero.
- Record audit questions, uncertainties and potential findings during the audit.
Prepare the interviews
Many organisations prepare only the document repository. That is not enough. Top management, IT, HR, procurement and process owners should briefly understand which questions may come up and which evidence they can show. The point is not scripted answers, but a consistent understanding of the ISMS.
| Role | Typical questions | Good preparation |
|---|---|---|
| Top management | Why this scope? Which risks do you accept? Which objectives apply? | Review scope, management review, ISMS objectives and residual risks together. |
| IT / Operations | How are access, vulnerabilities, backups and logs controlled? | Prepare samples and name system owners. |
| HR | How do onboarding, role changes, training and offboarding work? | Check onboarding/offboarding evidence and awareness records. |
| Procurement / supplier owner | How are critical suppliers assessed and monitored? | Prepare supplier list, criticality and contractual requirements. |
What should not happen
- Evidence is searched for during the audit.
- The SoA lists controls, but nobody can show implementation.
- Risks, controls and action lists contradict each other.
- Top management does not know the scope, objectives or residual risks.
- Open actions are not prioritised and not dated.
If the auditor raises a finding
A finding does not automatically mean the audit has failed. What matters is that you clarify which requirement the finding relates to, what objective evidence was missing or ineffective, and what correction is needed. Then assess the cause, define corrective action and track effectiveness.
Typical example: an access review was planned but not performed. Simply completing the spreadsheet afterwards only solves part of the problem. A stronger response is to perform the review, understand why it was missed, define ownership and frequency, and prove at the next review that the process is actually running.
ISO describes ISO/IEC 27001 as a management system standard for information security, cybersecurity and privacy protection. That is why audit preparation should connect management logic with technical evidence instead of collecting isolated IT controls: ISO/IEC 27001:2022 ISO overview.
How to use the checklist
- Start the readiness worksheet four to six weeks before Stage 1 and only mark an item as "Done" when the evidence can be found.
- Transfer every gap into the action list with owner, due date, priority and next step.
- Before Stage 2, review the evidence list by process and control. Add links to folders, tickets, minutes or screenshots.
- Plan short interview preparation sessions with the roles the auditor is likely to speak to.
Connect it with your ISMS
If you are still building the system, start with the overview of ISO 27001 certification for SMEs. For audit readiness, the articles on ISO 27001 risk assessment, the Statement of Applicability and ISO 27001 and NIS2 are also relevant.
How Sternberg Consulting supports you
We review scope, risk assessment, SoA, evidence and audit interviews before Stage 1 or Stage 2. Our ISO 27001 consulting covers gap analysis, ISMS implementation and concrete audit preparation.
Frequently asked questions
Does everything have to be implemented before Stage 1?
Not every operational record has to be complete. But scope, risk method, key documentation, SoA and audit planning must be robust enough for Stage 2 to make sense.
Is an ISO 27001 checklist enough?
No. A checklist helps with structure, but it does not replace assessment of scope, risks, control selection, implementation and effectiveness.
Who should participate in the audit?
In addition to the ISMS owner, usually top management, IT/Operations, HR, procurement or supplier owners and affected process owners.