GLOBAL AI CERTIFICATION COUNCIL
ISO/IEC 27001 Lead Auditor Certification Training in Malaysia
- Earn 32 CPD/PDU hours on completion of the course
- Certification valid for three years, renewable with CPD credits
- Self-paced learning, so you can start immediately and study on your own schedule
- Two packages available, either the full course or membership and exam only
- 32 CPD/PDU hours
- 4-day programme
- HRD Corp claimable

Issued by GAICC
Global AI Certification Council

GAICC Affiliate Partner badge
ProCert is an Affiliate Partner of the Global AI Certification Council (GAICC)


OVERVIEW
What a Lead Auditor does
ISO/IEC 27001:2022 is the standard for an Information Security Management System. Lead Auditor is the credential for the person who tests whether that system works — planning and leading Stage 1 and Stage 2 audits under ISO 19011 and ISO/IEC 17021-1, collecting evidence, grading findings and writing the report a certification body will act on.
The four-day course follows the examination blueprint: four weighted domains from audit principles and programme management, through conducting the ISMS audit and evaluating clauses 4–10 and Annex A, to reporting, follow-up and ethics.
Foundation is how the standard is read. Lead Implementer is how the system is built. This page is the independent audit step. Completing the self-paced course package includes the video course and one examination voucher. A certificate of completion is required before you sit the exam.
WHO IT IS FOR
Who should take this certification
Built for people who will lead an ISMS audit, not only sit in one.
Lead and senior auditors whose remit now includes an ISMS
ISMS implementers and managers preparing for Stage 1 and Stage 2
Certification-body auditors leading second-party and initial third-party audits under ISO/IEC 17021-1
GRC and information security professionals who own the audit programme, findings and corrective-action verification
OUTCOMES
What you will be able to do
By the end of the course you should be able to lead a full ISMS audit lifecycle.
- Plan, lead and report Stage 1 and Stage 2 ISMS audits under ISO 19011 and ISO/IEC 17021-1
- Build audit plans, scopes, criteria and checklists, and run opening and closing meetings
- Collect sufficient and appropriate evidence through interviews, observation and sampling
- Audit the Statement of Applicability and risk treatment against Clause 6 and Annex A
- Classify findings and grade nonconformities as major or minor with evidence-based reasoning
- Produce audit reports, conclusions and certification recommendations, then verify corrective actions
WHY PROCERT
Why enrol through us
Claimable by your employer
HRD Corp registered provider. Where a programme is approved, your employer can claim against their levy.
Malaysian support
A local team handling enrolment, exam booking and any questions along the way.
Team enrolment
Group registration handled end to end, with a single invoice for the whole team.
| PackageSelf-paced course package | Through ProCertUS$698 | Typical listed priceUS$798 |
|---|---|---|
| HRD Corp levy, where the programme is approved | Included | Not included |
| Malaysian enrolment and exam-booking support | Included | Not included |
THE CREDENTIAL
GAICC Certified ISO/IEC 27001 Lead Auditor
The GAICC certification programme is CPD accredited.
INCLUDED
This course includes
- 200+ pages of study material
- 32 CPD/PDU hours on completion
- Certificate of completion Required for exam eligibility
- Four-day self-paced programme
- Scenario-based exam simulator access
- Exam voucher included One exam attempt
Included resources to support your learning
- ISO/IEC 27001:2022 clause and Annex A control map
- Structural Reference and Control Map (GAICC-REF-27001-001)
- Audit workpaper and checklist templates
- Nonconformity and audit report templates
COURSE MODULES
Curriculum
Domains, tasks and illustrative enablers covered in each part of the examination blueprint.
Domain I · Audit principles, ISO 19011 and programme management
4 modules
25% of the examination · 15 items
Apply the principles of auditing
integrity, fair presentation, due professional care, confidentiality, independence, evidence-based and risk-based approaches
Manage an audit programme
objectives, risks and opportunities, resources, auditor competence, monitoring and review
Distinguish audit types and the certification framework
first-, second- and third-party audits; ISO/IEC 17021-1; Stage 1 and Stage 2
Establish auditor competence and impartiality
competence criteria, conflicts of interest, confidentiality of audit information
Domain II · Conducting the ISMS audit
5 modules
40% of the examination · 24 items
Plan and initiate the audit
audit plan, scope and criteria, document review, checklists, opening meeting
Collect and verify audit evidence
interviews, observation, sampling, sufficiency and appropriateness, audit trails
Audit the Statement of Applicability and risk process against Clause 6 and Annex A
Identify and grade findings
conformity, nonconformity (major/minor), opportunities for improvement
Communicate during the audit
auditee liaison, managing access, on-site conduct, closing meeting
Domain III · Evaluating conformity: Clauses 4–10 and Annex A
3 modules
20% of the examination · 12 items
Audit the management-system clauses 4–10
context, leadership, planning and risk, support, operation, performance evaluation, improvement
Audit Annex A control implementation and effectiveness across the four themes against the Statement of Applicability and risk treatment
Evaluate documented information and records (Clause 7.5)
integrity, availability, retention
Domain IV · Reporting, nonconformities, follow-up and ethics
3 modules
15% of the examination · 9 items
Prepare the audit report and conclusions
findings, recommendations, draft and final report, certification recommendation
Manage nonconformities and follow-up
corrective-action review, verification of effectiveness, audit closure
Apply professional ethics and impartiality
conflict-of-interest management, confidentiality, cultural sensitivity, professional behaviour
THE EXAM
Four domains, weighted for the real job
The body of knowledge is consolidated into four weighted domains across 60 scored items.
I · Audit Principles, ISO 19011 and Audit Programme Management
25% · 15 items
II · Conducting the ISMS Audit
40% · 24 items
III · Evaluating Conformity: Clauses 4–10 and Annex A Controls
20% · 12 items
IV · Reporting, Nonconformities, Follow-up and Ethics
15% · 9 items
Exam structure at a glance
- 60 scored items — 45 single-answer MCQ plus 15 multi-answer
- Single-answer A–D; multi-answer A–E, select all that apply, no partial credit
- 90 minutes, closed book, online AI-proctored or test centre
- 70% pass mark
- Valid three years, renewable with CPD credits
- Standard — ISO/IEC 27001:2022, with audit practice in ISO 19011:2018 and ISO/IEC 17021-1:2015
- Credential — GAICC Certified ISO/IEC 27001 Lead Auditor
- Issuer — Global AI Certification Council (GAICC)
HOW IT FITS
How it fits with standards you may already run
| Standard | What it governs | Relationship to this audit |
|---|---|---|
| ISO 19011:2018 | What it governsGuidelines for auditing management systems | Relationship to this auditThe audit principles, programme management and evidence method this credential examines. |
| ISO/IEC 17021-1:2015 | What it governsRequirements for bodies providing audit and certification | Relationship to this auditThe certification framework for first-, second- and third-party audits, including Stage 1 and Stage 2. |
| ISO/IEC 42001 | What it governsArtificial intelligence management | Relationship to this auditThe same management-system shape. GAICC’s 27001 Lead Auditor scheme is aligned with its ISO/IEC 42001 Lead Auditor scheme. |
| ISO 9001 | What it governsQuality management | Relationship to this auditShares the same high-level structure. Audit technique transfers; the criteria being audited do not. |
INSTRUCTOR
Dr Faiz Rasool
Director at the Global AI Certification Council (GAICC) and PM Training School
A globally certified instructor in ISO/IEC, PMI®, TOGAF®, SAFe®, and Scrum.org disciplines. With over three years’ hands-on experience in ISO/IEC 42001 AI governance, he delivers training and consulting across New Zealand, Australia, Malaysia, the Philippines, and the UAE, combining high-end credentials with practical, real-world expertise and global reach.
LinkedIn — Dr Faiz Rasool (opens in a new tab)ENROL
Enrol on ISO/IEC 27001 Lead Auditor
Choose a package and enter your name and email. If you choose the membership and exam package, you must confirm you have completed the required training.
Most popular
Self-paced course package
US$698
- Video lessons included
- Learning resources
- Exam simulator access
- One exam voucher
- Certificate of completion
Membership and exam package
US$248
- Video lessons included (not included)
- Learning resources
- Exam simulator access
- Examination voucher
Membership included
FAQ
FAQ
What is the GAICC ISO/IEC 27001 Lead Auditor certification?
It is GAICC’s auditor-level credential for ISO/IEC 27001:2022. A Lead Auditor plans, leads and reports ISMS audits under ISO 19011 and ISO/IEC 17021-1 — Stage 1 and Stage 2, evidence, findings, the report and follow-up.
Who is this training for in Malaysia?
Lead and senior auditors whose work now includes an ISMS, implementers and managers preparing for Stage 1 and Stage 2, certification-body auditors, and GRC or information-security professionals who own the audit programme.
How is the exam set?
Sixty scored items: 45 single-answer multiple-choice questions (A–D) and 15 multi-answer items (A–E, select all that apply, no partial credit), sat in 90 minutes, closed book. Delivery is online AI-proctored or at a test centre. The published pass mark is 70%.
Which standards does this certification cover?
ISO/IEC 27001:2022, with audit practice grounded in ISO 19011:2018 and ISO/IEC 17021-1:2015.
How long is the certification valid, and how do I renew it?
The credential is valid for three years and may be renewed with CPD credits.
How many CPD hours will I earn?
You receive 32 CPD/PDU hours on completion of the Lead Auditor course.
How many exam attempts are included?
The self-paced course package includes one exam voucher.
What happens if I do not pass the exam?
The self-paced course package includes one exam voucher. A further sitting requires the applicable exam fee.
What is the difference between the two packages?
The self-paced course package includes the full video course and everything needed to prepare from scratch. The membership and exam package is for candidates who have already completed their ISO/IEC 27001 Lead Auditor training and only need the examination, membership and supporting resources.
Can I buy the exam package if I have not done the training?
No. A certificate of completion is required for exam eligibility. If you have not completed the training, choose the self-paced course package.
How is this different from ISO/IEC 27001 Lead Implementer?
Lead Implementer is the four-day credential for the person who builds and operates the ISMS. Lead Auditor is the four-day credential for the person who independently plans, conducts and reports Stage 1 and Stage 2 audits of that system.
Is the GAICC certification programme CPD accredited?
The GAICC certification programme is CPD accredited.
Can I enrol a team?
Yes. Group rates apply for five or more. Contact us for a corporate quote and consolidated invoicing.
Certifying more than one person?
We handle group enrolment, consolidated billing and HRD Corp documentation.
