ISO 27001 Lead Auditor Domain 3 Practice Questions: Planning the Audit
Domain 3 of the CQI and IRCA ISO 27001 Lead Auditor exam is six questions worth eight marks, with a minimum of three. It covers everything that happens before the Stage 2 audit begins. These six practice questions match that count, with an explanation for every option.
Domain 3 of the CQI and IRCA ISO 27001 Lead Auditor exam is six questions worth eight marks, with a minimum of three. It covers everything that happens before the Stage 2 audit begins. These six practice questions match that count, with an explanation for every option.
Every question below was written for this page by 3FOLD TRAINING's tutors. None is a real CQI and IRCA examination question, and none is taken from 3FOLD TRAINING's own graded mock exams. Real exam questions cannot lawfully be published, and any site offering them is offering you something it should not have.
What does Domain 3 cover?
Domain 3 is planning the audit. It covers initiating the audit and confirming you can proceed, establishing scope, objectives and criteria, and judging feasibility. It then covers determining audit time on a reasoned basis, the Stage 1 review, and building a risk-based Stage 2 plan and checklist.
| Questions | Marks | Minimum mark | Scope | Level tested | Suggested time |
|---|---|---|---|---|---|
| 6 | 8 | 3 | Scheme-specific | Apply | 10 minutes |
This domain is wholly scheme-specific, and that changes how you answer. The planning questions are set in an information security context, so a generally sensible answer about audit planning will not always be the best answer available. The best answer is the one an ISMS auditor would give.
It is also set at apply. You are not asked what Stage 1 is; you are asked what to do with what Stage 1 found.
How should you use this set?
Before you look at any answer, write one word beside each question: Stage 1 or Stage 2. Most of this domain resolves to that boundary, and seeing your own answer written down next to the right one tells you more than the explanation does. Then read the explanations for everything you got wrong and everything you guessed.
None of them predicts what you will be asked. They test the same understanding, in the two formats that carry most of the paper, so working through them shows you where you are weak while there is still time to act on it.
Every question below carries its mark value, and here the values are 1 and 2. With only eight marks available, one 2-mark question is a quarter of the domain, so score in marks rather than in questions right. Where a question asks for more than one answer, select exactly the number asked for: partial marks are given on all questions, and nothing CQI publishes says a wrong selection is deducted from a right one.
The real paper allows no backward navigation: answer, click Next, and it stands. Planning questions are where candidates most want a second look, because two options often both describe reasonable practice. Decide which the requirement demands, and move on. See CQI and IRCA on online exams.
The questions
Where do marks actually go in Domain 3?
Four errors account for most of them.
- Treating Stage 1 as a formality. It is a genuine checkpoint with defined outputs, and the one candidates forget is the decision it exists to take. A significant gap found there can delay or stop Stage 2.
- Treating Stage 1 as a small Stage 2. Stage 1 reviews documented information. Stage 2 tests whether the system works in practice. Options that put live evidence-gathering into Stage 1 are wrong for that reason.
- Basing audit time on the wrong thing. Audit time is driven by the effective number of personnel in scope, together with scope, complexity and sites, then adjusted for risk. It is not driven by the number of controls, documents or incidents.
- Writing a flat plan. A risk-based Stage 2 plan does not give every area the same time, and a checklist earns its place by asking something that can actually be tested, rather than by repeating the heading of the clause it came from.
There is a fifth that is really a Domain 2 principle showing up here: an auditor who helps the auditee fix a gap has crossed into consultancy, and a certification body must not provide consultancy to an organisation it certifies.
Domain 3 questions almost always resolve to one question: is this a Stage 1 activity or a Stage 2 activity? Get that boundary clear and most of the domain follows.
The other habit worth building is asking what a plan is for. It schedules the work; it does not confine the audit. You still follow audit trails wherever the evidence leads.
Frequently asked questions
How many Domain 3 questions are on the real ISO 27001:2022 lead auditor exam?
Six, worth eight marks — two 2-mark questions and four 1-mark questions. You need at least three of those eight marks.
What is reviewed at Stage 1?
The documented information: the scope statement, the ISMS policy and objectives, the risk assessment, the Statement of Applicability, the risk treatment plan, and the records of internal audit and management review.
What determines how long an ISMS audit takes?
Principally the effective number of personnel in scope, together with the scope and complexity of the ISMS and the number of sites, then adjusted for risk. The precise figure comes from the published audit-time table and the certification body's calculator.
Can an auditor help the auditee close a gap found at Stage 1?
No. That is consultancy, and a certification body must not provide consultancy to an organisation it certifies. The auditor records the area of concern and feeds it into the Stage 2 plan.
Where to go next
Planning is the last of the three small domains. Next is the one that decides most results:
- Domain 1 practice questions — concepts and principles, 6 questions, 8 marks.
- Domain 2 practice questions — audit concepts and auditor responsibilities, 6 questions, 8 marks.
- Domain 4 practice questions — conducting the audit, 14 scenario questions, 36 marks.
- The sample exam questions and answers — ten questions weighted across all five domains, if you want a spread rather than a domain.
The complete CQI IRCA ISO 27001 Lead Auditor exam guide covers the format, the timing and how the sitting itself works.
3FOLD TRAINING is a CQI and IRCA Approved Training Partner, ATP number 6039853. Its ISO 27001 Lead Auditor training course is the CQI and IRCA Certified ISO/IEC 27001:2022 ISMS Lead Auditor (PR373). The course identification number is 2889. Both the partner approval and the course certification are on 3FOLD TRAINING's Approved Training Partner record, and any provider's certified courses can be looked up in CQI and IRCA's own directory of certified courses and approved training partners. The ISO 27001 Lead Auditor training course page carries the schedule and what the course includes. If you would rather ask a person first, use the course enquiry form.
Booking a PR373 course? See the schedule, trainers and what's included.
View the course






Leave a Reply
Your email is safe with us.