The Five CQI IRCA ISO 27001 Exam Domains Explained (and Where the Marks Are)
The CQI and IRCA ISO 27001 Lead Auditor exam has five domains carrying 8, 8, 8, 36 and 20 marks. Domain 4, conducting the audit, is worth 36 of the 80 marks on its own. Domains 4 and 5 together decide 70 per cent of the paper.
The CQI and IRCA ISO 27001 Lead Auditor exam has five domains carrying 8, 8, 8, 36 and 20 marks. Domain 4, conducting the audit, is worth 36 of the 80 marks on its own. Domains 4 and 5 together decide 70 per cent of the paper.
Every domain has a published question count, a mark allocation, a minimum mark you must reach, and a fixed level of thinking it tests. Knowing all four is the difference between revising and revising usefully.
The “where candidates lose marks” notes below are 3FOLD TRAINING's teaching observations, not CQI guidance.
| Domain | Area | Questions | Marks | Min. mark | Scope | Level tested | Time |
|---|---|---|---|---|---|---|---|
| 1 | Concepts and principles of management standards and systems | 6 | 8 | 3 | Generic and scheme-specific | Understand | 10 min |
| 2 | Audit concepts and auditor responsibilities | 6 | 8 | 3 | Generic | Apply | 10 min |
| 3 | Planning the audit | 6 | 8 | 3 | Scheme-specific | Apply | 10 min |
| 4 | Conducting the audit | 14 | 36 | 14 | Generic and scheme-specific | Apply and evaluate | 45 min |
| 5 | Reporting and closing out the audit | 8 | 20 | 8 | Scheme-specific | Evaluate | 30 min |
| Total | 40 | 80 | — | — | — | 105 min | |
Why are the domains weighted this way?
Read the “level tested” column. Domain 1 sits at understand. Domains 2 and 3 test apply. Domain 4 tests apply and evaluate. Domain 5 tests evaluate alone, the highest level on the paper. No domain is set at the level of simple recall.
The weighting follows the thinking, not the syllabus: the parts that ask you to make a judgement carry the marks. That is also why Domains 4 and 5 use scenarios exclusively. You cannot test a judgement without giving someone a situation to judge.
Domain 1 — Concepts and principles of management standards and systems
6 questions, 8 marks, minimum 3. Two 2-mark questions and four 1-mark questions.
The foundation domain. It covers what a management system is, why an organisation runs an ISMS, what confidentiality, integrity and availability mean in practice, how ISO/IEC 27001 is put together, and what certification is for. It is the shallowest domain on the paper.
It mixes generic and scheme-specific content, so expect both general management-system questions and questions that only make sense for information security. Situations may be used; scenarios are not.
Where candidates lose marks: treating Annex A as a mandatory checklist. It is a set of controls selected on the basis of risk and recorded in the Statement of Applicability. That misunderstanding costs marks here and again in Domain 4.
Domain 2 — Audit concepts and auditor responsibilities
6 questions, 8 marks, minimum 3. Two 2-mark questions and four 1-mark questions.
The auditing discipline itself. It covers the principles of auditing, the stages of an audit, the difference between first-, second- and third-party audits, and who does what on an audit team. It also covers the impartiality and confidentiality obligations that make an audit valid.
This is the only fully generic domain on the paper. Nothing in it is specific to information security — it is the ISO 19011 content that applies to any management-system audit. If you already hold a lead auditor qualification in another scheme, this is the domain you have already covered. It is also why the Auditor Conversion exam, for auditors moving between schemes, removes Domain 2 entirely.
Where candidates lose marks: confusing the audit client with the audit team leader, and treating a guide as a source of audit evidence. A guide arranges access and contacts. They are not someone you audit through.
Domain 3 — Planning the audit
6 questions, 8 marks, minimum 3. Two 2-mark questions and four 1-mark questions.
Everything before the audit starts:
- initiating the audit and confirming you can proceed
- establishing scope, objectives and criteria
- judging feasibility
- determining audit time on a reasoned basis
- the Stage 1 review
- building a risk-based Stage 2 plan and checklist
This domain is wholly scheme-specific. The planning questions are set in an ISMS context, so a generic answer about audit planning will not always be the best answer available.
Where candidates lose marks: treating Stage 1 as a formality.It is a genuine checkpoint used to assess readiness for Stage 2 and to plan the subsequent audit; significant issues identified at Stage 1 may need to be addressed before Stage 2 proceeds. It is also not a smaller version of Stage 2.
Domain 4 — Conducting the audit
14 questions, 36 marks, minimum 14. Eight 3-mark questions and six 2-mark questions. Suggested time: 45 minutes.
The largest domain by a wide margin. It covers:
- the opening meeting
- gathering objective evidence, following audit trails and corroborating what you are told
- interviewing and observation
- auditing the applicable requirements of ISO/IEC 27001 in the ISMS context
- auditing a risk-based sample of Annex A controls
- forming findings and grading them
Every question here is built on a scenario. It tests apply and evaluate. You are given a situation and asked what an auditor should do, what the evidence supports, or how a finding should be graded.
Where candidates lose marks: three things, consistently. Grading a finding on how serious it feels rather than on whether the evidence shows an isolated lapse or a systemic failure. Recognising a nonconformity without tying it to a specific requirement and specific objective evidence. And choosing the answer that sounds most thorough over the one the scenario's evidence actually supports.
One habit earns marks across this whole domain. Ask of every scenario: what is the requirement, and what does the objective evidence show? Answer those two and most Domain 4 questions resolve themselves.
With a minimum of 14 marks out of 36 and no way to compensate elsewhere, this is the domain a result is most likely to turn on. CQI and IRCA publish no outcome data, so that follows from the mark structure rather than from any statistic. See how the ISO 27001 Lead Auditor exam pass mark works.
Domain 5 — Reporting and closing out the audit
8 questions, 20 marks, minimum 8. Four 3-mark questions and four 2-mark questions. Suggested time: 30 minutes.
Writing nonconformity reports, producing the audit report and running the closing meeting. Then evaluating corrective action responses, deciding whether a finding can be closed, and understanding how the certification decision is taken.
Wholly scheme-specific, scenario-based, tested at evaluate. Questions here rarely have an obviously wrong answer; they have a best one.
Where candidates lose marks: confusing correction with corrective action. A correction addresses the detected nonconformity; corrective action addresses its cause so that the nonconformity does not recur or occur elsewhere, where action is needed. Note the wording: does not, not cannot — and 10.2 requires the organisation to evaluate the need for action, not to take it every time. The second trap is accepting a corrective action on a promise: without objective evidence of implementation, nothing is closed.
Where should your revision time go?
Follow the marks, and the published time guidance follows them too: 10 minutes each for Domains 1, 2 and 3, 45 for Domain 4 and 30 for Domain 5.
Three practical consequences:
- Domains 4 and 5 deserve the majority of your preparation. They are 56 of the 80 marks and they are the two you cannot rescue from elsewhere.
- Do not over-invest in Domain 1. It is 8 marks and the shallowest domain on the paper. It is also the easiest place to spend an hour feeling productive.
- Practise on scenarios, not definitions. 56 of the 80 marks are scenario-based. Reading the standard through again does not prepare you for a question that asks what you would do next.
Frequently asked questions
How many domains are on the CQI IRCA ISO 27001 Lead Auditor exam?
Five. They carry 8, 8, 8, 36 and 20 marks, from 6, 6, 6, 14 and 8 questions respectively, for 40 questions and 80 marks in total.
Which domain is worth the most marks on the ISO 27001 Lead Auditor exam?
Domain 4, conducting the audit, at 36 of 80 marks. It is worth more than Domains 1, 2 and 3 combined, which total 24 marks.
Do I have to pass every domain of the ISO 27001 Lead Auditor exam separately?
Yes. Each domain has a minimum mark you must reach — 3, 3, 3, 14 and 8 — on top of the 40-mark overall pass.
Why does the Auditor Conversion exam have fewer domains?
It removes Domain 2, because that domain covers generic ISO 19011 audit requirements a converting auditor has already been assessed on. The conversion paper is 34 questions and 72 marks.
Where to go next
The complete CQI IRCA ISO 27001 Lead Auditor exam guide sets out the sitting process and the rules on the day. There is a separate article on whether the ISO 27001 Lead Auditor exam is open book.
3FOLD TRAINING is a CQI and IRCA Approved Training Partner, ATP number 6039853. Its ISO 27001 Lead Auditor training course is the CQI and IRCA Certified ISO/IEC 27001:2022 ISMS Lead Auditor (PR373). The course identification number is 2889. Both the partner approval and the course certification are on 3FOLD TRAINING's Approved Training Partner record, and any provider's certified courses can be looked up in CQI and IRCA's own directory of certified courses and approved training partners. The ISO 27001 Lead Auditor training course page carries the schedule and what the course includes. If you would rather ask a person first, use the course enquiry form.
Booking a PR373 course? See the schedule, trainers and what's included.
View the course





Leave a Reply
Your email is safe with us.