Information Security & AI
ISO 27001:2022 Internal Auditor Course

ISO 27001:2022 Internal Auditor Course requirements and overview
This ISO 27001 training course gives infosec auditors and risk managers a practical route into equip your team to audit complex information security controls and frameworks. Delegates work through auditing annex a controls, risk treatment review and reporting findings, with clear tutor-led guidance, usable workplace examples and flexible delivery options for IT, technology, professional services, manufacturing and regulated organisations.
Course outline
Module 1: ISO 27001 context and purpose
Understand how Information Security Management Systems, information security risk, Annex A controls and audit readiness connects to day-to-day work, certification expectations and business risk.
Module 2: Internal Auditor learning route
Build confidence in audit planning, evidence gathering, reporting and corrective action, using examples that suit infosec auditors and risk managers.
Module 3: Auditing Annex A controls
Apply auditing annex a controls to realistic workplace situations so delegates leave with practical points they can use immediately.
Module 4: Risk treatment review
Apply risk treatment review to realistic workplace situations so delegates leave with practical points they can use immediately.
Module 5: Reporting findings
Apply reporting findings to realistic workplace situations so delegates leave with practical points they can use immediately.
Delivery methods
2 days · Internal Auditor level · available through onsite, hybrid and online delivery. Pricing starts from £35, with options for individuals, teams and workplace delivery where available.
Delivered for up to 10 delegates
Blended delivery for teams
Remote delivery for individuals
What you will learn in this ISO 27001:2022 Internal Auditor
Who should attend
This course is suited to infosec auditors and risk managers working across IT, technology, professional services, manufacturing and regulated organisations. It is built for delegates who need clear, practical guidance on Information Security Management Systems, information security risk, Annex A controls and audit readiness without unnecessary jargon.
Accreditation and certification
The course is aligned with CQI / IRCA expectations where applicable. Delegates receive confirmation of completion and can use the learning to support internal competence, audit readiness and management system improvement.
Continue your ISO route
Use these routes to compare the course with the wider certification path and related training options.
Frequently asked questions
What is ISO 27001?
ISO 27001 covers Information Security Management Systems, information security risk, Annex A controls and audit readiness. This course explains the terminology, responsibilities and practical steps delegates need to understand before applying it inside a UK organisation.
Who should attend the ISO 27001:2022 Internal Auditor course?
This course is designed for infosec auditors and risk managers and teams working across IT, technology, professional services, manufacturing and regulated organisations.
How long is the ISO 27001:2022 Internal Auditor course?
The course runs for 2 days. Delivery is available through onsite, hybrid and online formats, depending on the needs of the delegate or organisation.
What does the ISO 27001:2022 Internal Auditor course cover?
The course covers auditing annex a controls, risk treatment review and reporting findings and gives delegates a practical understanding of Information Security Management Systems, information security risk, Annex A controls and audit readiness.
Is the ISO 27001:2022 Internal Auditor course accredited?
The course is aligned with CQI / IRCA expectations where applicable. Delegates receive confirmation of completion and can use the learning to support internal competence, audit readiness and management system improvement.
How much does the ISO 27001:2022 Internal Auditor course cost?
Pricing starts from £35. Exact pricing depends on the delivery format selected and whether the course is booked for an individual or a team.
Can NDC deliver ISO 27001:2022 Internal Auditor training for a team?
Yes. NDC can deliver this course for teams using onsite, hybrid or online formats where available.


