ISO/IEC 27701 Lead Auditor – eLearning

Develop the knowledge and skills needed to plan, conduct and manage audits of a Privacy Information Management System (PIMS) based on ISO/IEC 27701:2025. The course focuses on recognised audit principles, procedures and techniques and prepares you to assess whether an organisation’s privacy management system meets the requirements of the standard.

Order e-learning course here

 

The course provides a comprehensive understanding of how to audit a PIMS, including both internal and external audits. You will learn how to apply ISO 19011, ISO/IEC 17021-1 and ISO/IEC 27706 when planning, conducting and following up on audits.

You will also develop skills in evidence-based and risk-based auditing, information collection and analysis, communication during audits, reporting nonconformities and evaluating corrective action plans. Particular attention is given to auditing the requirements of ISO/IEC 27701:2025 and the privacy controls applicable to PII controllers and processors.

The training is delivered through the myPECB platform and combines video-based learning with course materials, exercises and quizzes.

What will you get out of the course?

After completing the course, you will be able to:

  • Explain the fundamental concepts and principles of a Privacy Information Management System
  • Interpret ISO/IEC 27701 requirements from an auditor’s perspective
  • Evaluate whether a PIMS conforms to ISO/IEC 27701 requirements
  • Apply fundamental audit concepts and principles
  • Plan, conduct and close an ISO/IEC 27701 compliance audit
  • Apply ISO 19011 and ISO/IEC 17021-1 requirements during audits
  • Audit privacy controls for PII controllers and processors
  • Manage an ISO/IEC 27701 audit programme

Who is this course for?

The course is suitable for:

  • Auditors who want to perform and lead PIMS certification audits
  • Managers and consultants who want to develop expertise in PIMS auditing
  • Professionals responsible for maintaining conformity with PIMS requirements
  • Technical experts preparing for PIMS audits
  • Advisors working with the protection of personally identifiable information

Prerequisites

There are no formal prerequisites for this course.

Course content

The course covers:

  • Training course objectives and structure
  • Introduction to ISO/IEC 27701 and PIMS
  • Certification process
  • Fundamental concepts and principles related to information privacy
  • Overview of ISO/IEC 27701 requirements
  • Fundamental audit concepts and principles
  • Trends and technology in auditing
  • Evidence-based auditing
  • Risk-based auditing
  • Initiation of the audit process
  • Stage 1 audit
  • Preparation for stage 2 audit
  • Stage 2 audit
  • Communication during the audit
  • Information collection and analysis methods
  • Creating audit test plans
  • Auditing ISO/IEC 27701 clauses 4 to 10
  • Auditing ISO/IEC 27701 Annex A controls
  • Drafting audit findings and nonconformity reports
  • Audit documentation and quality review
  • Closing the audit
  • Evaluation of action plans
  • Activities beyond the initial audit
  • Managing an internal audit programme

Training course structure

Exam and certification

Exam

After completing the course, you can take the PECB ISO/IEC 27701 Lead Auditor exam.

The exam covers seven competency domains, including PIMS principles and requirements, audit concepts, preparation and conduct of ISO/IEC 27701 audits, closing an audit and management of an audit programme.

Certification

After successfully passing the exam, you can apply for the credential shown on the table below. You will receive the certificate once you comply with all the requirements related to the selected credential. Certification fees are included on the exam price.

For more information about the PECB certification process, please refer to the Certification Rules and Policies.

Certification LI 27001.png