Key details

Cost: $3,150 GST exempt

Duration: 5 Days

CPD Points: 40

Qualifications: Exemplar Global AU26 TL26 IS and BSBSS00128 Lead Auditor Skill Set 

About the course

This 5-day Lead Auditor course provides a comprehensive and practical foundation for professionals responsible for managing or auditing information security systems.

You’ll learn how ISO/IEC 27001 supports strong security processes, safeguards data, and ensures compliance with customer, supplier, and regulatory requirements. Gain insight into the 2022 update, including the changes to Annex A, the integration of ISO/IEC 27002:2022 controls, and revisions to management system clauses aligned with Annex SL. You will also build the confidence to plan, conduct, and report ISMS audits in line with ISO 19011:2028 guidelines. The course also focuses on practical application, showing how a well-implemented ISMS can safeguard critical assets, including customer records, financial information, and intellectual property, against cyber threats.

Plus, you receive a complimentary licensed copy of:

  • ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements.

Earn 40 CPD points and take the next step in your information security career. Enrol today!

Whilst this training package uses the word “audit” and its derivatives, this does not equate with the terms audit, review, or assurance in accordance with Pronouncements or Standards issued by the Australian Auditing and Assurance Standards Board. References to the term “audit” and similar terminology within this training relate to the process of auditing in accordance with ISO 19011:2026.

Logo of the Australian Association for Quality


AOQ Certified Quality Practitioner Recognition

This course has been recognised by the Australian Organisation for Quality (AOQ) as contributing towards the AOQ Certified Quality Practitioner (CQP) programme.

Successful completion may contribute recognised learning hours towards your CQP pathway.

Learn more about AOQ-CQP →


 

Bundle your courses and save!

Bundle this course with Business Continuity to blend resilience strategies with information security practices and auditing know-how. 

Learn more and save!

Explore our bundles

Our training is different because

Streamlined assessment process with support available. 

We offer nationally and internationally recognised courses and qualifications. 

Trainers are practising risk, audit, and systems experts.

Access a suite of downloadable resources and refresher learning bursts upon completion of the course.

Certificates are issued promptly.

We never cancel a course - enrol with confidence.

Secure your place now and give your organisation a competitive edge

Course overview

Understand how to initiate, participate in, lead, and report on audits, aligned with the guidance provided in ISO 19011, including:

  • Audit planning requirements, such as undertaking the document review and developing the audit plan and timetable
  • Delivering a successful, risk-based audit program using appropriate auditing techniques, including evidence collection, sampling, and verification
  • Conducting and leading audit meetings, including opening, closing, and team meetings
  • Collating audit findings, understanding and identifying key risks and documenting nonconformances
  • Creating, reviewing, and issuing the audit report, including audit findings and outcomes.
  • Understand the structure and requirements of an ISMS in alignment with ISO/IEC 27001:2022 and its relationship with ISO/IEC 27002:2022
  • Identify and evaluate the application of Information Security Management principles from ISO/IEC 27002:2022, aligned with an organisation’s threat and risk environment, including organisational, people, physical, and technological controls

Apply the ISO/IEC 27001 and 27002 standards to design and assess ISMS controls and processes within an organisational context, and to establish conformity with the standard.

This course is divided into two flexible modules, enabling you to attend both modules in the same week or spread across different sessions. The first 2-day module is equivalent to our Becoming a Skilled Lead Internal/External Auditor course, where you learn how to conduct an audit of any management system in accordance with ISO 19011. The remaining 3-day module covers the requirements of the updated ISMS standard, ISO/IEC 27001:2022. 

Timetable

Day 1 – Monday

Preparing for a management systems audit

  • Introduction to auditing
  • 7 fundamental audit principles
  • Roles and responsibilities of an auditor
  • Setting appropriate audit objectives, scope, and criteria
  • Undertaking the document review
  • Audit planning, including effective timetabling
  • Checklist generation and review
  • Conducting an opening meeting

Day 2 – Tuesday

Conducting a management systems audit

  • Communication skills and interview techniques
  • Effective audit practices, evidence and sampling
  • Determining conformance and an evidence-based approach
  • Conducting a closing meeting
  • Developing the audit report and writing audit findings
  • Reviewing corrective action.

Day 3 – Wednesday

Information security management systems

  • Introduction to information security
  • Context of information security
  • Information security management systems requirements
  • Risk-based approach to information security
  • Structure of information security controls and control attributes.

Day 4 – Thursday

Information security controls

  • Information security controls – organisational, people, physical, technological
  • Information classification
  • Documentation requirements of an information security management system.

Day 5 – Friday

Application of information security management systems 

  • Statement of applicability
  • Information security audit scenarios
  • Course review.

Upon successful completion of the course, you will receive a Certificate of Attainment with 3 Exemplar Global competencies:

  • Exemplar Global AU26 – Auditing management systems 
  • Exemplar Global TL26 – Lead audit teams 
  • Exemplar Global IS – Auditing information security management systems

 

Upon successful completion of the course and all required assessment items, you will receive a Statement of Attainment for BSBSS00128 Lead Auditor Skill Set, consisting of: 

  • BSBAUD411 Participate in quality audits  
  • BSBAUD511 Initiate quality audits 
  • BSBAUD512 Lead quality audits 
  • BSBAUD513 Report on quality audits

Nationally Recognised Training assessment components are to be completed within 6 months.

There are no prerequisites for this course.

You will complete a series of workshops during the course, which form part of the assessment. Upon the completion of each module there is a short multiple-choice quiz. You will receive continual assistance and feedback from the facilitator. 

To complete the Nationally Recognised Training units of competency and the BSBSS00128 Lead Auditor Skill Set, an additional assessment is required to be completed and submitted to RTP for review following the training, demonstrating your knowledge and understanding of the audit process. You will be provided with instructions to assist with the completion of the assessment, and templates are available for use, as required. Your trainer will explain the post-course assessment process during the training. 

Nationally Recognised Training assessment components are to be completed within 6 months. 

This course is ideal if you:

  • Are looking to become an internal auditor for an information security management system
  • Are developing or improving an ISMS 
  • Hold responsibility for auditing or managing information security within your organisation
  • Want to formalise your existing experience with a recognised qualification.
  • Looking to undertake formal professional development

A business background is recommended, though no prior experience in auditing or management systems is required.

This course is your first step to becoming a third-party ISMS auditor under the Exemplar Global scheme. Once you’ve achieved the required competencies, you can apply for auditor certification through Exemplar Global.

Visit the Exemplar Global website for full certification requirements and current fees.  

Expand your qualifications with the following courses:

Training available in a separate week:

If you’re looking for a foundation-level understanding of ISO standards and auditing skills, check out our library of eLearns, which includes our self-paced 45-minute Introduction to ISO/IEC 27001module.   

Price

The price of this course is $3,150 GST exempt.

Discounts for multiple attendees are available – please contact us to find out what discounts can be applied.

How to enrol

We offer an easy, streamlined enrolment process – you can either enrol directly into your course online or call us on 1300 95 96 92 to enrol over the phone.

How to pay

We offer a variety of payment methods:

  • Bank transfer
  • Credit card
  • Payment plans.

Payment plans

We can arrange flexible payment plans on an individual basis. Please be aware that your certificate will be held until full payment has been received.

Public – Virtual/Online

This course is delivered online via our virtual training platform. Our virtual courses are available to participants in Australia and New Zealand. They provide the same premium learning experience as our face-to-face sessions, with the added convenience of online learning. The virtual platform mimics in-person learning and aims to be engaging and interactive, with real-time group exercises, Q&A sessions, and online assessments. No matter your location, you can benefit from our expert-led training and become proficient in auditing an ISMS.

Please note: Due to licensing restrictions, our virtual courses are open to participants from Australia and New Zealand only.

In-house – Face-to-face or virtual

In-house training can provide a cost-effective training solution for organisations with a number of staff who require training. We can also customise a course to suit your own individual needs and include your own audit documentation. Call us on 1300 95 96 92 or complete the form below to request a quote.

Request an In-house quote

Training Course Locations

Course Dates

Sort Location Start Finish Duration
Virtual - AEST (AUST & NZ participants only) Mon 07 Sep 2026 Fri 11 Sep 2026 5 Days Enrol now

There are no search results in your chosen search.
Register and we'll be in touch when courses are available.

Register Now

FAQs

Do I need any prior knowledge?

No prior experience in auditing or management systems is required. This course is designed to support both new and experienced professionals. A business background is recommended to help you get the most out of the course, but it’s not essential.

Whether you’re stepping into an auditing role for the first time or looking to formalise your experience with a recognised qualification, this course will guide you through every step.

What is the purpose of an ISMS?

The purpose of an ISMS is to protect the confidentiality, integrity, and availability of information by applying risk management processes and robust security controls.

An ISMS provides a structured framework for managing sensitive information and reducing the risk of data breaches, cyber threats, and non-compliance.

Is the course suitable for people working outside of IT?

Yes. While many participants work in IT, information security is a broader issue that affects all departments. This course is suitable for professionals in governance, compliance, risk, HR, and executive roles.

Can I use this qualification to audit other management systems like ISO 9001 or ISO 14001?

Yes. The first module of this course covers auditing skills applicable to any ISO management system. You’ll also need to complete modules in the relevant standard to gain specific competencies in those standards.

Can't find course dates in your city?

Register and we'll be in touch when courses are available

Register Now

What our students say about our courses

“The virtual classroom coupled with an enthusiastic trainer made the course easy to run through and as good as any face-to-face courses I have ever attended.”

“Honestly thought it was gonna be boring. I was very wrong! Very engaging and informative. Loved all 5 days and will be back for more courses!”

“Let’s be honest – ISO standards aren’t exactly edge-of-your-seat material. But this course proved that with the right coach, even clauses and compliance can be compelling! Packed with real-world examples, well-paced sessions, and just the right amount of workshops, it was surprisingly enjoyable. Highly recommended!”

“It was clearly evident that the lead auditor trainer had significant industry-related experience in auditing. He was able to keep the class fully engaged with personal interaction and reinforce learnings. Getting full copies of the standards was amazing, the catering and the training location in Brisbane was perfect.”

“The trainer’s experience and real-life examples gave great context to the course material. The 5 days allowed the material to be digested in a way that was not overwhelming. I’d definitely recommend the course to others.”

Need help finding a course?

Speak directly with a member of the RTP team to decide which course is right for you.

×