5.1 Stage 1 Audit and Documented Information Review

Key Takeaways

  • Stage 1 assesses ISMS design and readiness for Stage 2; Stage 2 evaluates implementation and effectiveness of controls and processes.
  • Core Stage 1 document checks include ISMS scope, information security policy, risk assessment and treatment, the Statement of Applicability (SoA), internal audit evidence, and management review outputs.
  • Missing or incomplete internal audits or management reviews are readiness failures that normally delay Stage 2 rather than proceed with cosmetic fixes.
  • Stage 1 findings are often recorded as areas of concern so the client can correct gaps before Stage 2 evidence collection begins.
Last updated: July 2026

Exam relevance

On the CQI IRCA ISMS Lead Auditor exam, Conducting the audit is the largest online exam domain at 14 of 40 questions. Pre-audit work—especially Stage 1 document review, readiness judgment, and how Stage 1 shapes Stage 2—sits squarely in that domain. Exam items often contrast Stage 1 (design and readiness) with Stage 2 (implementation and effectiveness), and they test whether you know which documents prove readiness: scope, Statement of Applicability (SoA), internal audit programme and reports, and management review records.

ISO/IEC 17021-1 drives third-party certification body practice for the two-stage initial audit. ISO 19011 provides the broader process guidance for planning and conducting management system audits. Do not confuse Stage 1 document review with a full effectiveness assessment of Annex A controls—that work belongs primarily in Stage 2.

Core rules: Stage 1 versus Stage 2

FocusStage 1Stage 2
Primary questionIs the ISMS designed and ready to be audited for certification?Does the ISMS operate effectively against criteria?
Evidence emphasisDocumented information, site context, understanding of requirementsProcess operation, control implementation, performance evidence
Typical outputsAreas of concern, readiness conclusion, Stage 2 plan confirmationConformities, nonconformities, certification recommendation inputs
Key readiness signalsScope clarity, SoA completeness, risk process defined, internal audit and management review performedEvidence that planned arrangements are implemented and effective

Stage 1 objectives typically include: reviewing ISMS documented information against ISO/IEC 27001 requirements; evaluating site-specific conditions and discussing preparedness with personnel; checking the client's understanding of the standard (including processes, performance aspects, and the SoA); collecting information on scope, locations, and applicable statutory or regulatory obligations; confirming resource allocation for Stage 2; and verifying that internal audits and management reviews support a claim of readiness.

Documented information the auditor must scrutinize

  • ISMS scope (Clause 4.3): Boundaries must be clear, justified, and consistent with context (4.1) and interested-party requirements (4.2). Interfaces with outsourced processes and third parties must be visible. Artificially narrow scopes that exclude high-risk activities without justification are a major readiness concern.
  • Information security policy: Must align with strategic direction, commit to meeting requirements and continual improvement, and be available/communicated as required.
  • Risk assessment methodology and results: Criteria for risk acceptance and consistent, comparable results must be evident. Incomplete risk assessment is a classic Stage 1 blocker.
  • Risk treatment plan and SoA: The SoA must list Annex A controls with inclusion/exclusion decisions and justifications, and link treatment decisions to residual risk acceptance.
  • Information security objectives: Measurable, consistent with policy, monitored, and updated as appropriate.
  • Internal audit programme and reports: Planned intervals, objectivity/impartiality, conformity to own and ISO/IEC 27001 requirements, and corrective action follow-up.
  • Management review inputs and outputs: Evidence that top management reviewed suitability, adequacy, and effectiveness, with decisions on improvement and needed changes.

Scenario: incomplete readiness package

An auditor arrives for Stage 1 at a mid-size SaaS provider. The documented scope names "all cloud product operations," but diagrams exclude the outsourced SOC and a contractor-run code repository. The SoA marks many Annex A controls as "implemented" without linking to risk treatment decisions. Internal audits covered only HR access provisioning; no audit touched change management or supplier security. Management review minutes exist, but they omit risk assessment results and information security performance feedback.

Lead Auditor judgment: Scope interfaces are unclear, SoA justification is weak, and mandatory monitoring mechanisms (internal audit breadth and management review content) do not demonstrate readiness. The auditor documents areas of concern, recommends delaying Stage 2 until the client completes a coherent SoA, expands the internal audit programme to critical processes, and holds a management review with complete mandatory inputs. Proceeding immediately would waste Stage 2 days on a system that is not yet auditable as an implemented ISMS.

How auditors evaluate the SoA during Stage 1

The Statement of Applicability is often the hinge document between risk treatment and Stage 2 sampling. During Stage 1, the auditor does not yet re-test every claimed control in depth, but does check whether the SoA is complete, internally consistent, and usable as an audit roadmap. Warning signs include: exclusions justified only by "not applicable" with no organizational rationale; controls marked implemented when related processes are clearly still in draft; missing linkage between high risks and selected treatments; and SoA versions that do not match the risk assessment date or scope boundaries. A coherent SoA lets the Lead Auditor plan Stage 2 competence (for example, cloud security or cryptography expertise) and timeboxes. A hollow SoA is a readiness defect.

Also confirm that documented information control (creation, update, availability, protection) appears workable. If policies exist only as uncontrolled email attachments with conflicting versions, Stage 2 evidence trails will collapse. Stage 1 is the moment to insist that the client can produce the authoritative versions auditors will sample later.

Interval and communication after Stage 1

After Stage 1, the auditor agrees Stage 2 timing with the client. The interval must allow correction of areas of concern, but an excessively long gap may require repeating parts of Stage 1 if the ISMS has changed materially. Communicate findings clearly in writing: which issues are readiness blockers, which are improvements that can be verified in Stage 2, and what evidence the client should prepare. Stage 1 outputs should shape Stage 2 sampling, team competence needs, and time allocation—especially where Stage 1 revealed high residual risk, complex outsourced interfaces, or thin evidence in critical processes.

Second scenario: strong documents, weak understanding

A manufacturing firm presents polished templates: scope, policy, risk methodology, SoA, internal audit schedule, and management review agenda all look complete. Interviews, however, show the ISMS manager cannot explain how risk acceptance criteria were set, and process owners treat the SoA as a consultancy deliverable they never use. Site walkthroughs reveal a newly opened warehouse storing customer data offline that is absent from the scope statement. Stage 1 still fails readiness—not because templates are missing, but because the organization does not understand or apply its own ISMS, and the physical boundary is wrong. Documented information without operational ownership is not Stage 2 readiness.

In short: Stage 1 is not a soft courtesy visit. It is the professional filter that protects audit integrity. If documented information, scope, SoA, internal audit, or management review evidence cannot support readiness—or if personnel cannot demonstrate understanding—Stage 2 should wait.

Test Your Knowledge

What is the primary purpose of a Stage 1 audit in an ISO/IEC 27001 certification context under ISO/IEC 17021-1?

A
B
C
D
Test Your Knowledge

During Stage 1 scope verification, which evaluation is most critical for the auditor?

A
B
C
D
Test Your Knowledge

If Stage 1 shows that management review has never been conducted, what is the most appropriate Lead Auditor response?

A
B
C
D