Catalog

ISMS-IA

ISO/IEC 27001:2022 Internal Auditor - AI

Level II certification in auditing an information security management system built to ISO/IEC 27001:2022, using ISO 19011:2026 as the audit methodology and ISO/IEC 27001 as the audit criteria. Covers audit programme management, evidence and sampling, testing Annex A controls against the Statement of Applicability, and findings through to management review - including auditing an ISMS whose scope contains AI systems, and the use of AI tooling within the audit itself.

50Questions
75%To pass
150Minutes
5Domains

Exam Composition

D1The audit function and its boundaries
12.5%

The purposes and parties of management system auditing, the ISO 19011 principles and how they interact under tension, auditor objectivity and competence, and the boundary between what ISO 19011 guides, what ISO/IEC 27001 requires, and what ISO/IEC 17021-1 governs.

D2Audit programme management
20%

Deriving programme objectives from the organization's ISMS objectives, risks and audit history; risk-based frequency and priority; defining scope and criteria for an individual audit; selecting on-site, remote or hybrid auditing methods; team composition; and testing a programme against ISO/IEC 27001 clause 9.2.

D3Conducting the audit: evidence, sampling and testing
25%

Determining the degree of verification information carries and the reliance a finding may place on it; sampling adequacy; evidence obtained by remote auditing methods; selecting collection methods; testing an Annex A control against its Statement of Applicability claim; the boundary of an ISMS audit; and what an AI-assisted evidence process establishes and leaves unverified.

D4Auditing the ISMS against ISO/IEC 27001 as criteria
25%

Auditing clauses 4 through 10 as the yardstick rather than the syllabus - scope, leadership, the whole of clause 6, the Statement of Applicability, support, operation and measurement - together with AI systems inside ISMS scope, control effectiveness under non-determinism, and the boundary between ISMS and AI management system conformity.

D5Findings, reporting, follow-up and management review
17.5%

Determining whether evidence constitutes a nonconformity and whether findings are systemic; classifying against a declared scheme; writing a defensible nonconformity statement; disclosing AI-assisted method in the audit report; judging corrective action adequacy; verification and closure; and what must reach clause 9.3 management review.

The first lesson is free.

No card. See whether Certidemy fits how you learn.

Start free