ISO 27001 Lead Auditor Training
CQI IRCA approved training to build information security auditing skills and pass with confidence.


Join the Next Cohort
September – October 2026
Dates to be announced
Prefer weekends? Enquire below and we'll notify you the moment the next weekend batch opens.
Join the waitlistISO/IEC 27001:2022 ISMS Lead Auditor Online Course Key Features
100% Online
Complete your ISO/IEC 27001:2022 ISMS Lead Auditor course from the comfort of your home or office, including the final eAssessment.
Virtual Interactive Sessions
Same as a physical classroom environment, and better. Live, recorded, interactive, Q&A, discussions, polls and breakout sessions.
Guaranteed Quality
This course is validated and certified by CQI IRCA, UK. Rest assured of high quality training and course resources.
World-class Resources
Pre-course video lessons, knowledge-check quiz, recorded video lessons, mock and specimen exams, activities workbook and more.
Quick Turnaround
Get your Certificate of Achievement within 3 working days of successfully passing the continuous evaluation and final examination.
Learning-by-doing
80% of the course focuses on role-play, audit simulation, preparing audit reports, checklists and more.
ISO/IEC 27001:2022 ISMS Lead Auditor Online Training Course Summary
3FOLD Training's CQI IRCA Certified ISO/IEC 27001:2022 ISMS Lead Auditor Online Course is a comprehensive 5-day training programme delivered on consecutive days, over weekends, or in evening blocks. Designed on the pedagogy of learning by doing and accelerated-learning techniques, it uses auditing role-plays, a realistic audit simulation and hands-on exercises that reflect real-world audit experience.
The aim of the course is to provide delegates with the knowledge and skills required to perform first, second and third-party audits of information security management systems against ISO/IEC 27001:2022, in accordance with ISO 19011 and ISO/IEC 17021-1, as applicable.
Delegates who successfully complete this CQI and IRCA Certified ISO/IEC 27001:2022 Lead Auditor (ISMS) Online Training course — within the five years prior to making an application to become a certificated auditor — will satisfy the training requirements for initial certification as an IRCA ISMS auditor.
By the end of this course you will be able to
- 1
Explain the purpose of information security management system (ISMS) standards, management-system audit and third-party certification, and the business benefits of effective information security management.
- 2
Explain the role of an auditor to plan, conduct, report and follow up an information security management system audit, in accordance with ISO 19011 and ISO/IEC 17021-1.
- 3
Plan, conduct, report and follow up an audit of an ISMS to establish conformity, or otherwise, with ISO/IEC 27001:2022, and in accordance with ISO 19011.
What You Will Learn in the ISO/IEC 27001:2022 ISMS Lead Auditor Online Course
Foundations of ISO/IEC 27001:2022 ISMS Auditing
You will build a solid foundation in the ISO/IEC 27001:2022 ISMS standard and the ISO 19011 auditing guidelines — what an ISMS is and why organisations operate one, the clause structure (4–10), Annex A and the Statement of Applicability, the types of audit and the audit process. You will meet the realistic case-study auditee, initiate the audit, and begin reviewing documented information for a Stage 1 audit, with hands-on activities and a Q&A to consolidate your foundation.
ISO/IEC 27001:2022 Audit Planning & Preparation through ISO 19011
You will judge the readiness of the ISMS from the Stage 1 review, then prepare a risk-based Stage 2 audit plan, build an audit checklist and sampling plan, and prepare effective opening meetings. Through role-play you will simulate audit activities, exploring the organisation's context, interested parties and information security risk, before a review discussion to reinforce your planning skills.
Conducting the Audit & Gathering Objective Evidence
The focus shifts to conducting the Stage 2 audit. You will practise interviewing, following audit trails and corroborating evidence, and audit the ISMS requirements across Clauses 4–10 and a risk-based sample of Annex A controls — including risk assessment and treatment, the Statement of Applicability, access control, cryptography, supplier and cloud security, and incident management — through hands-on simulation and discussion.
Audit Findings, Grading & Nonconformity Reporting
A practice-rich lesson: you will evaluate evidence to determine conformity and nonconformity, grade findings as major or minor with justification, and write clear, accurate nonconformity reports using the three-part structure. You will also form the audit conclusions and structure the audit report, with practice questions to reinforce your findings and reporting skills.
Finalising the Audit — Closing, Reporting & Follow-Up
The lesson opens with a full course review, then covers the closing meeting, presenting conclusions and recommendations, and post-audit activities — evaluating corrective action, root-cause analysis and audit follow-up in line with ISO 19011. It concludes with exam preparation and guidance on your CQI/IRCA examination and IRCA registration.
ISMS Lead Auditor Course Delivery Format
At 3FOLD Training, our ISO/IEC 27001:2022 ISMS Lead Auditor course is designed to accommodate busy professionals through flexible online learning formats.
Weekend Batch (Sundays)
Attend live virtual classes every Sunday from 9:00 AM to 5:00 PM GST for five consecutive weeks — ideal for professionals who prefer to focus intensively on weekends.
Weekday Evening Batch
Join weekday evening sessions held from 7:00 PM to 10:00 PM GST, offering a more gradual learning pace suited for working individuals with daytime commitments.
Customised Schedule
We also customise the course schedule for corporate or group training, tailored to your team's availability.
Technology & Learning Tools
To deliver an engaging and effective online ISO/IEC 27001:2022 ISMS Lead Auditor course, we use a suite of proven digital platforms that support collaborative, interactive learning.
Zoom
All live sessions are delivered via Zoom, with breakout rooms used for group exercises and audit-simulation role-plays that replicate real-world audit environments.
Nearpod
We integrate Nearpod for interactive activities, live polls, quizzes and visual learning tools to keep sessions dynamic and aid retention.
3FOLD LMS (Moodle)
Learners access all learning resources — pre-course modules, materials, working documents and exam-preparation resources — through the 3FOLD Learning Management System (www.3foldlearn.com).
What's Inside the LMS for This Course
All learners enrolled in the ISO/IEC 27001:2022 ISMS Lead Auditor course receive full access to our LMS, designed to support your learning journey before, during and after the course.
What Happens After You Complete the Course
Once you complete the ISO/IEC 27001:2022 ISMS Lead Auditor course, your tutor submits your continuous assessment results, confirming your active participation and completion of all required activities. We then register your details on the CQI IRCA Authorized Training Partner Portal, and you receive access to two platforms.
Demo Exam Portal Access
Check your technical readiness for the actual exam — system compatibility, navigation and more — and take a practice exam that simulates the real test environment.
Final Exam Portal Access
After exploring the demo platform, you receive access to the official CQI IRCA Final Exam Portal, where you can take the exam at your own convenience once fully prepared.
CQI IRCA Exam Procedure
After completing the course, you have 30 days from the final day to sit the official CQI IRCA exam through the online testing platform. Before your exam, use the Demo Exam Portal to familiarise yourself with the system and question format, and practise with sample questions.
If you don't take the exam within 30 days
- Your first attempt is marked “DNS” (Did Not Submit). No extensions are allowed.
- You remain eligible for a second attempt within 1 year of course completion.
- To reschedule, contact 3FOLD and pay a resit fee of only AED 125 — no extra fee beyond the official CQI IRCA cost.
If you appear but fail
- You'll receive a section-wise performance report across the 5 exam domains.
- Retake the exam for the AED 125 resit fee.
- Attend the training again, free of cost, within 1 year of completing the course.
If you fail the second attempt
- CQI IRCA requires you to attend the full course again.
- A Levy + Exam fee totalling AED 310 applies for the third attempt.
- If you don't pass the third attempt, retake the exam again for AED 125 (resit fee).
- You can attend the training free of cost within 1 year of completing the course.
| Attempt | Condition | Fee |
|---|---|---|
| 1st | Included in course fee, within 30 days | FREE |
| 2nd | Missed or failed 1st attempt, resit only | AED 125 / USD 35 |
| 3rd, 5th, 7th… | Must re-attend course (Levy + Exam) | AED 310 / USD 85 |
| 4th, 6th, 8th… | Resit after re-attendance | AED 125 / USD 35 |
Exam Content Structure
The CQI IRCA Lead Auditor exam assesses your knowledge and practical auditing skills across five domains — 40 questions, 80 marks. Domain 4, Conducting the Audit, carries the heaviest weight.
| Domain | Topic Area | Marks | Questions | Min Pass Marks | Rec. Time |
|---|---|---|---|---|---|
| 1 | Concepts & Principles of Management Systems | 8 | 6 | 3 | 10 minutes |
| 2 | Audit Concepts & Auditor Responsibilities | 8 | 6 | 3 | 10 minutes |
| 3 | Planning the Audit | 8 | 6 | 3 | 10 minutes |
| 4 | Conducting the Audit | 36 | 14 | 14 | 45 minutes |
| 5 | Reporting & Closing the Audit | 20 | 8 | 8 | 30 minutes |
Overall pass requirement: a minimum total of 40 out of 80 marks (50%), plus the minimum pass mark in each domain. Duration: 1 hour 45 minutes (2 hours 15 minutes for non-native English speakers — 3FOLD applies this automatically).
Open-Book Exam Format
What you can use
- Notes from your training course
- A clean copy (paper or PDF) of the ISO standards
Strictly not allowed
- Internet access, search engines or online resources
- Mobile phones, smart watches, earphones or other electronic devices
- Dictionaries, calculators (unless specifically allowed), blank paper, or unauthorised books and handouts
Possession of unauthorised items during the exam, even if unused, may be treated as malpractice.
What Happens After You Pass
CQI IRCA takes up to 10 working days to release your official result; 3FOLD notifies you immediately once it's available. If you pass, you receive a Certificate of Achievement within 3 working days via our digital credential partner, Accredible — digitally verifiable and globally recognised. If you don't pass and choose not to resit, you receive a Certificate of Attendance. Only the Certificate of Achievement qualifies you to apply for CQI/IRCA Auditor Membership.
Upcoming ISO/IEC 27001:2022 ISMS Lead Auditor Online Training Schedule
Choose your batch and pay in AED or USD to secure your seat in our CQI IRCA Approved ISO/IEC 27001:2022 ISMS Lead Auditor Online Course.
Weekday Evening Batch
Enrolling now · filling fast📧 Please ensure you provide your correct email address during payment — all future communication, including joining links and exam access, will be sent to this email.
ISO 27001 Lead Auditor Course — FAQ
It is a CQI/IRCA-certified training course that gives you the knowledge and skills to plan, conduct, report and follow up first-, second- and third-party audits of an information security management system (ISMS) against ISO/IEC 27001:2022, in accordance with ISO 19011.
Yes. 3FOLD Training is a CQI/IRCA Approved Training Partner and this ISO/IEC 27001:2022 ISMS Lead Auditor course is certified by CQI and IRCA, UK (Course Approval No. 2889).
It is a 40-hour course delivered 100% online (Virtual Instructor-Led Training). Choose a 5-Sunday weekend batch (9:00 AM–5:00 PM GST) or a weekday evening batch (7:00 PM–10:00 PM GST).
Yes — the course assumes a working knowledge of information security management and ISO/IEC 27001. You complete a short self-paced ISMS Foundation module and readiness quiz on our LMS before the live sessions begin.
Learners who pass the continuous assessment and the CQI/IRCA examination receive a Certificate of Achievement; those who attend but do not pass receive a Certificate of Attendance. Only the Certificate of Achievement qualifies you to apply for CQI/IRCA auditor membership.
The exam has 40 questions worth 80 marks across five domains. You must score at least 40% in each domain and at least 50% overall (40/80). It is taken online within 30 days of the course; duration is 1 hour 45 minutes, extended to 2 hours 15 minutes for non-native English speakers (3FOLD applies this automatically).
Yes. You may use your course notes and a clean copy of the ISO standards. Internet access and unauthorised items are strictly prohibited and treated as malpractice.
Information security, IT, risk, GRC and compliance professionals; internal auditors and management-system professionals moving into ISMS auditing; consultants; and anyone pursuing IRCA ISMS auditor certification.
Course Enquiry
Fill this form and we'll get back to you with complete course details, batch availability and pricing.
We respect your privacy. No spam. Your details are safe with us.
Ready to become a certified ISMS Lead Auditor?
Seats for the September–October 2026 weekday evening batch are limited and filling fast.
Reserve your seat nowHow can we assist you?



