ISO 27001 Information Security Audit Practice Training Course
| Course code | SD-A-070 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Finance and accounting teams process payment files, payroll data, bank details, management accounts, tax records and investor information that must remain accurate, available and restricted to authorised users. When an ISO 27001 audit is planned, internal auditors and control owners need more than familiarity with the standard: they must be able to test whether access controls, reconciliations, change approvals, supplier arrangements and incident records operate as stated. This course addresses the practical gap between reading an information security management system (ISMS) and producing evidence-based audit conclusions that management can act on.
Participants learn to plan, perform, document and report ISO 27001 internal audits using ISO 19011 audit principles and the ISO/IEC 27001:2022 clause structure. The course focuses on audit trails relevant to finance and accounting, including segregation of duties, privileged access, payment-system interfaces, data retention, spreadsheet controls, third-party processors and business continuity arrangements. Participants practise building audit criteria, sampling evidence, interviewing process owners, testing control design and operation, grading nonconformities, and writing findings that distinguish isolated errors from systemic weaknesses.
Delivery combines instructor-led explanation with a running finance-sector case study, working papers, evidence packs and structured audit simulations. Teams conduct a mock audit of a finance operations process, review records in Excel, complete an audit checklist, and present findings at a closing meeting. Each participant leaves with an adaptable ISO 27001 audit pack containing an audit programme, process-based checklist, evidence log, sampling plan, nonconformity report and corrective-action follow-up tracker.
The course suits professionals moving into ISMS internal auditing as well as experienced finance, risk and compliance staff who need a disciplined method for examining information security controls in financially sensitive processes.
Course objectives
By the end of this course, participants will be able to:
- Interpret ISO/IEC 27001:2022 clauses and Annex A controls as auditable criteria for finance and accounting processes
- Build a risk-based ISO 27001 internal audit programme covering payment, payroll, close and reporting activities
- Create process-based audit checklists that test access control, segregation of duties, data handling and supplier controls
- Plan evidence sampling using populations, sample rationale, traceability and exception documentation
- Conduct structured audit interviews and corroborate statements against system records, approvals and retained evidence
- Evaluate control design and operating effectiveness using walkthroughs, reperformance and evidence triangulation
- Write objective nonconformity reports with requirement references, evidence statements, grading and corrective-action expectations
- Produce a complete audit file containing an audit plan, checklist, evidence log, findings register and follow-up tracker
Benefits of attending
For you
- Gain a repeatable method for auditing finance-system access, payment controls and sensitive data handling
- Build confidence conducting audit interviews with finance, IT and third-party process owners
- Create defensible findings that link observed evidence to ISO 27001 requirements and control objectives
- Strengthen eligibility for internal audit, ISMS, governance and assurance assignments
- Develop a reusable personal audit pack for planning and documenting future ISO 27001 audits
For your organisation
- Improve the quality and consistency of internal ISO 27001 audits affecting financial information
- Identify weak access, approval, retention and supplier controls before they create reporting or fraud exposure
- Reduce reliance on external auditors for routine ISMS evidence gathering and follow-up
- Produce clearer corrective-action records with accountable owners, due dates and verification evidence
- Give management better assurance that finance processes support ISMS scope, risk treatment and audit readiness
Target competencies
Who should attend
- Internal Auditors — who need to test ISO 27001 controls across finance and accounting processes
- Finance Managers — who own sensitive financial data and must prepare teams for ISMS audits
- Risk and Compliance Analysts — who map regulatory, control and ISMS requirements into auditable evidence
- Information Security Analysts — who support control testing and remediate audit findings in finance systems
- Financial Controllers — who oversee close, reporting and access-control practices affecting financial information
- External Audit and Assurance Associates — who need a structured method for evaluating information-security evidence
Requirements and prerequisites
Participants should understand the purpose of internal controls and be familiar with at least one finance or accounting process, such as accounts payable, payroll, financial close, treasury or management reporting. Basic awareness of information-security concepts—confidentiality, integrity, availability, access control, risk and incident management—is helpful. Participants should be comfortable reading policies, procedures, system reports and spreadsheet-based evidence. No prior ISO 27001 certification, lead auditor qualification, coding skill or specialist security-tool experience is required. Complete beginners should expect to spend time learning the ISO clause structure and audit terminology before progressing to evidence testing.
Training methodology
The instructor uses short clause-by-clause teaching segments followed by audit working sessions built around a finance operations case. Participants inspect policies, access extracts, approval records, supplier documents, incident logs and spreadsheet evidence; then decide what is sufficient, reliable and relevant. Small groups plan audit scopes, conduct role-play interviews, test selected controls and calibrate findings against ISO/IEC 27001:2022 criteria. Daily debriefs compare audit judgements, while the final session converts the case method into a 90-day application plan for each participant’s own audit environment.
Course outline
Day 1: ISO 27001 audit foundations for financial information
- ISMS purpose, scope and interested parties in finance operations
- ISO/IEC 27001:2022 clause structure and mandatory documented information
- Annex A control themes affecting accounting and payment environments
- Confidentiality, integrity and availability risks in financial data flows
- ISO 19011 audit principles, auditor conduct and evidence-based judgement
- First-party, second-party and certification audit distinctions
- Audit criteria, scope, objectives and process boundaries
Workshop: Participants map a procure-to-pay process, define its ISMS audit scope and identify the evidence needed to test three control objectives.
Day 2: Risk-based audit planning and evidence design
- Risk-based annual audit programme construction
- Audit universe mapping for payroll, treasury, close and reporting processes
- Linking risk treatment plans to audit priorities
- Process-based audit checklist design
- Evidence reliability, relevance, sufficiency and traceability
- Sampling methods for user access, payment approvals and change records
- Opening meeting agendas, audit plans and communication protocols
Workshop: Teams prepare an audit plan, sampling rationale and process-based checklist for a finance application access-control audit.
Day 3: Fieldwork: testing finance and accounting controls
- Walkthrough testing from transaction initiation to financial posting
- User access recertification and privileged-account evidence review
- Segregation-of-duties testing in payment and journal processes
- Spreadsheet control testing for financial reporting workbooks
- Supplier and cloud-service assurance evidence
- Change-management testing for finance-system configurations
- Interview techniques and evidence triangulation
Workshop: Participants conduct a simulated audit interview and test an evidence pack containing access reports, approval logs, spreadsheets and supplier records.
Day 4: Audit findings, reporting and corrective action
- Control design versus operating-effectiveness conclusions
- Classification of conformities, observations and nonconformities
- Writing factual evidence statements without unsupported judgement
- Referencing ISO clauses, Annex A controls and internal procedures
- Root-cause analysis using five whys and fishbone diagrams
- Corrective-action plans, ownership and target dates
- Closing meeting presentation and challenge handling
Workshop: Participants draft, peer-review and present nonconformity reports for deficiencies found in the finance case study.
Day 5: Audit follow-up and workplace application
- Corrective-action verification and closure criteria
- Tracking repeat findings and systemic control weaknesses
- Audit metrics for management review and ISMS improvement
- Reporting themes to finance leadership and information-security governance forums
- Audit-file quality review and working-paper retention
- Integrating ISO 27001 audits with internal control and financial audit cycles
- Personal 90-day ISO 27001 audit application planning
Workshop: Participants assemble a complete audit file and create a 90-day plan for applying the audit method to a live or proposed workplace process.
Tools & standards covered
ISO/IEC 27001:2022, ISO 19011:2018, Microsoft Excel, Jira
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Auditing
Audit Working Papers and Review Skills for External Auditors Training Course
External audit files are judged not only by the conclusions reached, but by whether the working papers show a clear, reviewable chain from r…
Insurance Premium and Claims Auditing Training Course
Premium leakage, inaccurate earned-premium calculations, duplicate claim payments, weak reserving evidence, and inconsistent authority contr…
COBIT 2019 Control Assessment for IT Auditors Training Course
IT auditors are increasingly asked to assess whether technology controls support reliable financial reporting, protect regulated data, and p…
Public Sector Internal Auditing Training Course
Public-sector organisations must demonstrate that public money, assets, programmes and services are managed lawfully, economically and trans…