Stage 1 Audit: Documentation Review and Readiness Assessment

Key Takeaways

  • The primary purpose of a Stage 1 audit under ISO/IEC 17021-1 is to evaluate the organization's ISMS documented information, assess site-specific conditions, and determine readiness for the Stage 2 audit.
  • Mandatory documentation required at Stage 1 includes the ISMS scope statement, information security policy, risk assessment procedure/report, risk treatment plan, Statement of Applicability (SoA), internal audit records, and management review minutes.
  • Stage 1 provides a vital gateway decision: if critical mandatory requirements (such as internal audit execution or SoA approval) are missing, Stage 2 must be postponed until corrective action is completed.
  • Auditors evaluate the organization's understanding of ISO/IEC 27001 requirements, statutory/regulatory compliance obligations, operational locations, and multi-site sampling feasibility during Stage 1.
  • The formal Stage 1 report details findings, identifies potential areas of concern for Stage 2, and establishes agreement on logistics, resources, and timing for the Stage 2 audit.
Last updated: July 2026

Stage 1 Audit: Documentation Review and Readiness Assessment

In third-party ISO/IEC 27001 certification auditing, the initial certification process is partitioned into two distinct phases as mandated by ISO/IEC 17021-1:2015 (Clause 9.3.1): Stage 1 and Stage 2. The Stage 1 audit—frequently referred to as the documentation review or readiness assessment—acts as the foundational gatekeeper. Its primary objective is not to verify operational effectiveness across all controls, but rather to determine whether the organization’s Information Security Management System (ISMS) has been sufficiently designed, documented, and prepared to justify proceeding to the intensive Stage 2 evaluation.

Performing an effective Stage 1 audit prevents premature, costly, and unproductive Stage 2 on-site audits. If an organization has failed to complete fundamental requirements—such as conducting an internal audit or formalizing its Statement of Applicability—proceeding directly to Stage 2 would inevitably lead to certification failure. The Lead Auditor's role during Stage 1 is to rigorously review documented information, evaluate site logistics, assess understanding of ISO/IEC 27001 requirements, and establish a clear path forward.


1. Objectives of the Stage 1 Audit

According to ISO/IEC 17021-1 Clause 9.3.1.2, the Stage 1 audit must be performed to achieve specific objectives:

  1. Review Documented Information: Inspect the client's ISMS documentation to confirm compliance with ISO/IEC 27001:2022 Clauses 4 through 10.
  2. Evaluate Site Conditions and Logistics: Assess the client's location, operational boundaries, remote infrastructure, and site-specific conditions to plan the Stage 2 audit.
  3. Assess Scope and Requirements: Review the organization's ISMS scope definition, including exclusions, boundaries, interested parties, and legal/regulatory compliance obligations.
  4. Evaluate Internal Audit and Management Review Readiness: Verify that internal audits and management reviews have been planned and performed, and that the level of implementation demonstrates readiness for Stage 2.
  5. Gather Information for Stage 2 Planning: Obtain necessary information regarding the scope of the ISMS, processes, locations, equipment, security controls, and applicable statutory/regulatory requirements to select the audit team and allocate audit days.
  6. Identify Areas of Concern: Provide feedback to the client regarding gaps or areas of concern that could be classified as nonconformities during Stage 2.

2. Reviewing Mandatory Documented Information

The Lead Auditor must systematically verify that all mandatory documented information required by ISO/IEC 27001:2022 is established, documented, approved, and maintained. Missing mandatory documentation during Stage 1 constitutes a significant gap that usually prevents progression to Stage 2.

Mandatory ISMS Documentation Checklist

  • ISMS Scope (Clause 4.3): Documented scope defining organizational boundaries, physical/logical perimeters, operational facilities, and justified exclusions.
  • Information Security Policy (Clause 5.2): Top-management-approved policy statement establishing information security objectives and commitment to continuous improvement.
  • Information Security Risk Assessment Process & Report (Clause 6.1.2): Formal methodology for identifying risks, defining risk criteria, estimating risk levels, and documenting assessment results.
  • Information Security Risk Treatment Process & Statement of Applicability (Clause 6.1.3): Risk treatment methodology and the Statement of Applicability (SoA) detailing which of the 93 Annex A controls are selected, their implementation status, and justification for inclusion or exclusion.
  • Information Security Objectives (Clause 6.2): Measurable security objectives aligned with policy goals.
  • Operational Planning and Control Procedures (Clause 8.1): Documented processes necessary to meet information security requirements.
  • Results of Risk Assessment and Treatment (Clause 8.2 & 8.3): Outputs demonstrating that risk assessments and treatments were executed according to the documented methodology.
  • Evidence of Internal Audit (Clause 9.2): Internal audit program, audit plan, records of auditor objectivity, and audit report detailing findings.
  • Evidence of Management Review (Clause 9.3): Minutes and decisions from top management reviews evaluating ISMS performance and risk treatment status.
  • Evidence of Nonconformities and Corrective Actions (Clause 10.2): Records of identified nonconformities, root cause analyses, and corrective actions taken.

3. Comparing Stage 1 and Stage 2 Audit Focus

Understanding the boundary between Stage 1 and Stage 2 is a core competency evaluated on the PECB ISO/IEC 27001 Lead Auditor examination.

Audit AttributeStage 1 Audit (Readiness Assessment)Stage 2 Audit (On-Site/Operational Audit)
Primary FocusSystem design, documentation adequacy, and operational readiness.Practical implementation, operational effectiveness, and control compliance.
LocationTypically conducted off-site (desk review) and/or limited on-site/remote initial visit.Conducted on-site at operational locations, data centers, and active remote work environments.
Main OutputStage 1 Audit Report with readiness decision and list of areas of concern.Stage 2 Audit Report detailing conformity, nonconformities, and certification recommendation.
TimingPerformed weeks or months prior to Stage 2 to allow gap remediation.Scheduled after Stage 1 gaps are resolved; forms the basis for initial certification.
Sampling DepthHigh-level review of governance framework, policies, and management cycle evidence.In-depth technical sampling of operational logs, user accounts, physical barriers, and Annex A controls.
Key Decision"Is the organization ready to proceed to Stage 2?""Does the ISMS conform to ISO/IEC 27001 and warrant certification?"

4. Assessing Site Conditions and Operational Scope

During Stage 1, the Lead Auditor must evaluate operational logistics to ensure the Stage 2 audit plan is accurate and feasible:

  1. Physical and Logical Perimeters: Verifying data center locations, corporate offices, operational branches, cloud tenancies, and teleworking environments included in the scope.
  2. Multi-Site Assessment: Determining whether the organization qualifies for multi-site sampling under IAF MD 1 (International Accreditation Forum Mandatory Document for Audit and Certification of Management Systems Operated by a Multi-Site Organization).
  3. Regulatory Framework Identification: Identifying mandatory legal requirements (e.g., GDPR, HIPAA, PCI-DSS, local data protection acts) that apply to the organization's information assets and operations.
  4. Security and Safety Protocols: Obtaining necessary security clearances, safety inductions, non-disclosure agreements (NDAs), and remote access authorizations required for auditors during Stage 2.

5. Worked Scenario: Stage 1 Readiness Decision at CloudTech Solutions

Background

CloudTech Solutions, a software-as-a-service (SaaS) provider with 250 employees, applied for ISO/IEC 27001:2022 certification. Lead Auditor Sarah executed the Stage 1 audit. During the documentation review, Sarah identified the following state of affairs:

  • The Information Security Policy, Scope Document, and Risk Assessment methodology were well-documented and approved by executive management.
  • The Statement of Applicability (SoA) listed all 93 Annex A controls as "Applicable," but lacked written justifications for why specific physical security controls were marked applicable for fully remote engineering teams.
  • CloudTech conducted an internal audit three weeks prior; however, the internal audit only covered Clause 6 (Planning) and Clause 8 (Operation). Annex A controls, Clause 9 (Performance Evaluation), and Clause 10 (Improvement) were omitted from the internal audit scope.
  • A formal Management Review meeting had not been held; executive management planned to hold the review after the Stage 2 audit.

Auditor Analysis & Decision

Under ISO/IEC 17021-1 and PECB Lead Auditor standards, Sarah cannot approve CloudTech to proceed directly to Stage 2:

  1. Incomplete Internal Audit: Clause 9.2 requires a complete internal audit covering all ISO/IEC 27001 requirements and selected Annex A controls prior to certification.
  2. Missing Management Review: Clause 9.3 mandates that top management review the ISMS prior to Stage 2 to ensure its continuing suitability, adequacy, and effectiveness.
  3. Deficient SoA: Clause 6.1.3 requires clear justifications for inclusions and exclusions.

Conclusion & Outcome

Sarah issued a formal Stage 1 Audit Report documenting two major Areas of Concern: failure to execute a complete internal audit across the full scope, and absence of top management review. Sarah recommended postponing the Stage 2 audit by 60 days to allow CloudTech to perform a comprehensive internal audit, conduct a full management review, update the SoA, and submit evidence of completion for auditor verification.

Test Your Knowledge

What is the primary objective of a Stage 1 audit in ISO/IEC 27001 third-party certification?

A
B
C
D
Test Your Knowledge

During a Stage 1 audit, an auditor discovers that the client has not conducted a management review or a complete internal audit. How should the Lead Auditor proceed?

A
B
C
D
Test Your Knowledge

Which document is MANDATORY for review during the Stage 1 audit to verify control selection and exclusion justifications?

A
B
C
D