Stage 2 Audit: Opening Meeting and On-Site Execution

Key Takeaways

  • The Stage 2 audit evaluates the actual implementation, operational effectiveness, and conformity of the ISMS against ISO/IEC 27001 requirements and Annex A controls.
  • The formal Opening Meeting sets the operational foundation for Stage 2, establishing audit scope, introduced team roles, schedule confirmation, confidentiality protocols, and safety procedures.
  • Clear communication channels must be maintained throughout Stage 2 execution, including daily interim debriefings with auditee management to review progress and preliminary findings.
  • Audit guides assist the audit team with navigation, introductions, and safety, but must remain neutral observers without answering questions or influencing auditee responses.
  • The Lead Auditor is responsible for managing audit plan adjustments when operational constraints, unannounced incidents, or system unavailability arise during execution.
Last updated: July 2026

Stage 2 Audit: Opening Meeting and On-Site Execution

The Stage 2 audit is the core operational phase of the third-party ISO/IEC 27001 certification process. While Stage 1 evaluates system design and documented information, Stage 2 evaluates the actual implementation, operational compliance, and effectiveness of the Information Security Management System (ISMS). Conducted on-site at the organization’s facilities, data centers, and active remote work environments, Stage 2 requires auditors to gather empirical evidence verifying that documented policies and controls function effectively in practice.

Executing Stage 2 demands meticulous organization, adherence to ISO 19011 auditing principles, robust project management, and strict maintenance of auditor objectivity and professional independence.


1. Objectives of the Stage 2 Audit

In accordance with ISO/IEC 17021-1 Clause 9.3.1.3, the Stage 2 audit evaluates:

  1. Information Security Performance: Verification that the ISMS operates effectively in conformity with ISO/IEC 27001:2022 Clauses 4–10.
  2. Control Implementation: Empirical verification of the 93 Annex A controls selected within the Statement of Applicability (SoA).
  3. Operational Consistency: Evidence that operational procedures, technical controls, and physical safeguards function consistently across shifts, locations, and departments.
  4. Performance Monitoring and Measurement: Demonstration that security objectives are monitored, measured, analyzed, and evaluated (Clause 9.1).
  5. Legal and Regulatory Compliance: Verification that the organization adheres to applicable statutory, regulatory, and contractual security obligations.
  6. Continuous Improvement: Operational proof of internal audits, management reviews, and corrective action management driving ongoing ISMS enhancement.

2. Conducting the Formal Opening Meeting

Every Stage 2 audit must formally commence with an Opening Meeting chaired by the Lead Auditor. Governed by ISO 19011 Clause 6.4.3, the purpose of the Opening Meeting is to confirm the audit plan, introduce audit team members, establish formal communication channels, and ensure all administrative and safety arrangements are understood.

Mandatory Opening Meeting Agenda

  1. Introductions: Introduce the Lead Auditor, audit team members, auditee management, key process owners, guides, and observers.
  2. Confirmation of Audit Scope: Formally review and confirm the ISMS scope, including physical boundaries, business units, technology stacks, and justified control exclusions.
  3. Review of Audit Plan: Re-confirm the audit timetable, target departments, interview schedules, and logistics for multi-site or remote sampling.
  4. Audit Methods and Sampling: Explain that the audit is based on sampling verifiable evidence, which inherently introduces sampling risk.
  5. Communication Channels: Establish formal lines of communication between the Lead Auditor and the auditee's designated contact person (e.g., CISO or ISMS Manager).
  6. Language and Logistics: Confirm working language, workspace availability, network access, and meeting facilities for auditors.
  7. Safety, Security, and Confidentiality Protocols: Confirm site safety rules, emergency evacuation procedures, physical security restrictions, and non-disclosure commitments.
  8. Roles of Guides and Observers: Clarify the specific boundaries of assigned audit guides and observers.
  9. Reporting and Finding Categorization: Explain how findings will be reported, categorized (Major Nonconformity, Minor Nonconformity, Opportunity for Improvement), and presented during daily debriefings and the Closing Meeting.
  10. Questions and Clarifications: Provide an opportunity for auditee management to ask questions.

3. Opening Meeting Checklist & Lead Auditor Script

Opening Meeting Protocol ElementLead Auditor Verification Requirement
Attendance RecordCirculate a formal attendance sheet capturing names, titles, departments, and contact details.
Scope AlignmentDisplay the exact scope statement to ensure no unauthorized changes occurred since Stage 1.
Confidentiality CommitmentReiterate that all client data, records, and findings are kept strictly confidential under ISO/IEC 17021-1.
Interim DebriefingsSchedule daily 15-to-30-minute end-of-day summary meetings with auditee management.
Dispute ResolutionOutline the mechanism for raising and resolving factual disagreements during the audit.

4. Role and Boundaries of Audit Guides and Observers

Audit guides are assigned by the auditee to assist the audit team. While their presence is vital for operational efficiency, the Lead Auditor must ensure that guides and observers do not compromise audit integrity.

Responsibilities of Audit Guides

  • Assisting auditors in locating personnel and establishing contact.
  • Escorting auditors through physical facilities and restricted security zones.
  • Ensuring site-specific health, safety, and security rules are observed by auditors.
  • Witnessing the audit interviews on behalf of the auditee.

Mandatory Boundaries (What Guides MUST NOT Do)

  • Answering for the Interviewee: Guides must never answer questions or prompt employees during interviews. The auditor requires direct evidence from process performers.
  • Influencing Auditor Judgement: Guides must not attempt to divert auditors away from selected sample areas or dispute findings during live interviews.
  • Interfering with Evidence Collection: Guides must not impede auditors from taking working notes, viewing system screens, or selecting sample records.

5. Executing On-Site Audit Activities & Daily Dynamics

Once the Opening Meeting concludes, the audit team executes the audit plan. Key operational activities include:

  1. Interviewing Process Owners: Engaging personnel across governance, IT engineering, HR, physical security, legal, and operational units.
  2. Observing Control Execution: Watching live operations, such as visitor registration, media disposal, incident response drills, and change control approvals.
  3. Inspecting Records: Reviewing sample batches of access request tickets, firewall rule reviews, patch logs, and backup restoration test results.
  4. Conducting Daily Interim Debriefings: At the end of each audit day, the Lead Auditor meets with auditee management to summarize progress, highlight positive observations, discuss preliminary findings, and resolve factual misunderstandings early.

6. Worked Scenario: Managing Guide Interference during Stage 2

Background

During a Stage 2 certification audit of FinTech Global, Lead Auditor Marcus was conducting an interview with a junior Database Administrator (DBA) regarding Annex A 8.18 (Use of privileged utility programs) and Annex A 8.2 (Privileged access rights). Marcus requested a live demonstration of how administrative access to production SQL databases was granted and reviewed.

As the junior DBA began opening the database administration console, the assigned audit guide—FinTech's Senior IT Compliance Manager—interrupted and stated: "Our DBA team follows strict ticket approvals. Let me answer that for him. Here is the written policy showing that all access requires CISO sign-off." The Compliance Manager then attempted to navigate the screen away from the DBA's live console.

Auditor Intervention

Marcus immediately applied ISO 19011 lead auditor control protocols:

  1. Polite Pause: Marcus politely thanked the Compliance Manager for referencing the written policy but firmly requested that the junior DBA demonstrate the actual operational procedure.
  2. Clarifying Guide Boundaries: Marcus gently reminded the Compliance Manager of the Opening Meeting agreement: "As agreed in our opening meeting, the purpose of Stage 2 is to verify operational implementation directly with the process executor. Please allow the DBA to explain his daily workflow."
  3. Resuming Evidence Collection: Marcus asked the DBA to continue displaying the live database logs for a random sample of five administrative log-ins.

Audit Finding Outcome

When the junior DBA executed the live database query, Marcus observed three active DBA accounts that had not been logged in the access ticket system, and one account belonging to an employee who had resigned two months prior. Because the Compliance Manager attempted to obscure operational reality with policy documentation, Marcus documented a Major Nonconformity against Clause 9.1 (Monitoring, measurement, analysis and evaluation) and Annex A 8.2 (Privileged access rights) due to lack of operational control over administrative accounts.

Test Your Knowledge

What is the main purpose of conducting a formal Opening Meeting at the beginning of a Stage 2 audit?

A
B
C
D
Test Your Knowledge

Which of the following actions is acceptable for an assigned audit guide during a Stage 2 interview?

A
B
C
D
Test Your Knowledge

Why are daily interim debriefings conducted between the Lead Auditor and auditee management during Stage 2 execution?

A
B
C
D