Next PMP® classroom cohort: 28 Sept - 2 Oct 2026, Kuala Lumpur. Reserve your seat

ProCert

GLOBAL AI CERTIFICATION COUNCIL

ISO/IEC 27001 Lead Auditor Certification Training in Malaysia

  • Earn 32 CPD/PDU hours on completion of the course
  • Certification valid for three years, renewable with CPD credits
  • Self-paced learning, so you can start immediately and study on your own schedule
  • Two packages available, either the full course or membership and exam only
  • 32 CPD/PDU hours
  • 4-day programme
  • HRD Corp claimable
openart gpt image 2 1 1788971265017 be0053c0

Issued by GAICC

Global AI Certification Council

WhatsApp Image 2026 08 29 at 16.01.23 removebg preview

GAICC Affiliate Partner badge

ProCert is an Affiliate Partner of the Global AI Certification Council (GAICC)

HRD Corp claimable
HRD Corp Registered Training Provider

OVERVIEW

What a Lead Auditor does

ISO/IEC 27001:2022 is the standard for an Information Security Management System. Lead Auditor is the credential for the person who tests whether that system works — planning and leading Stage 1 and Stage 2 audits under ISO 19011 and ISO/IEC 17021-1, collecting evidence, grading findings and writing the report a certification body will act on.

The four-day course follows the examination blueprint: four weighted domains from audit principles and programme management, through conducting the ISMS audit and evaluating clauses 4–10 and Annex A, to reporting, follow-up and ethics.

Foundation is how the standard is read. Lead Implementer is how the system is built. This page is the independent audit step. Completing the self-paced course package includes the video course and one examination voucher. A certificate of completion is required before you sit the exam.

WHO IT IS FOR

Who should take this certification

Built for people who will lead an ISMS audit, not only sit in one.

OUTCOMES

What you will be able to do

By the end of the course you should be able to lead a full ISMS audit lifecycle.

  • Plan, lead and report Stage 1 and Stage 2 ISMS audits under ISO 19011 and ISO/IEC 17021-1
  • Build audit plans, scopes, criteria and checklists, and run opening and closing meetings
  • Collect sufficient and appropriate evidence through interviews, observation and sampling
  • Audit the Statement of Applicability and risk treatment against Clause 6 and Annex A
  • Classify findings and grade nonconformities as major or minor with evidence-based reasoning
  • Produce audit reports, conclusions and certification recommendations, then verify corrective actions

WHY PROCERT

Why enrol through us

  1. Claimable by your employer

    HRD Corp registered provider. Where a programme is approved, your employer can claim against their levy.

  2. Malaysian support

    A local team handling enrolment, exam booking and any questions along the way.

  3. Team enrolment

    Group registration handled end to end, with a single invoice for the whole team.

Self-paced course package: Through ProCert US$698 versus typical listed price US$798
PackageSelf-paced course packageThrough ProCertUS$698Typical listed priceUS$798
HRD Corp levy, where the programme is approvedIncludedNot included
Malaysian enrolment and exam-booking supportIncludedNot included

THE CREDENTIAL

GAICC Certified ISO/IEC 27001 Lead Auditor

The GAICC certification programme is CPD accredited.

Sample certificate — upload in the admin

INCLUDED

This course includes

  • 200+ pages of study material
  • 32 CPD/PDU hours on completion
  • Certificate of completion Required for exam eligibility
  • Four-day self-paced programme
  • Scenario-based exam simulator access
  • Exam voucher included One exam attempt

Included resources to support your learning

  • ISO/IEC 27001:2022 clause and Annex A control map
  • Structural Reference and Control Map (GAICC-REF-27001-001)
  • Audit workpaper and checklist templates
  • Nonconformity and audit report templates

COURSE MODULES

Curriculum

Domains, tasks and illustrative enablers covered in each part of the examination blueprint.

  1. Domain I · Audit principles, ISO 19011 and programme management

    4 modules

    25% of the examination · 15 items

    1. Apply the principles of auditing

      integrity, fair presentation, due professional care, confidentiality, independence, evidence-based and risk-based approaches

    2. Manage an audit programme

      objectives, risks and opportunities, resources, auditor competence, monitoring and review

    3. Distinguish audit types and the certification framework

      first-, second- and third-party audits; ISO/IEC 17021-1; Stage 1 and Stage 2

    4. Establish auditor competence and impartiality

      competence criteria, conflicts of interest, confidentiality of audit information

  2. Domain II · Conducting the ISMS audit

    5 modules

    40% of the examination · 24 items

    1. Plan and initiate the audit

      audit plan, scope and criteria, document review, checklists, opening meeting

    2. Collect and verify audit evidence

      interviews, observation, sampling, sufficiency and appropriateness, audit trails

    3. Audit the Statement of Applicability and risk process against Clause 6 and Annex A

    4. Identify and grade findings

      conformity, nonconformity (major/minor), opportunities for improvement

    5. Communicate during the audit

      auditee liaison, managing access, on-site conduct, closing meeting

  3. Domain III · Evaluating conformity: Clauses 4–10 and Annex A

    3 modules

    20% of the examination · 12 items

    1. Audit the management-system clauses 4–10

      context, leadership, planning and risk, support, operation, performance evaluation, improvement

    2. Audit Annex A control implementation and effectiveness across the four themes against the Statement of Applicability and risk treatment

    3. Evaluate documented information and records (Clause 7.5)

      integrity, availability, retention

  4. Domain IV · Reporting, nonconformities, follow-up and ethics

    3 modules

    15% of the examination · 9 items

    1. Prepare the audit report and conclusions

      findings, recommendations, draft and final report, certification recommendation

    2. Manage nonconformities and follow-up

      corrective-action review, verification of effectiveness, audit closure

    3. Apply professional ethics and impartiality

      conflict-of-interest management, confidentiality, cultural sensitivity, professional behaviour

THE EXAM

Four domains, weighted for the real job

The body of knowledge is consolidated into four weighted domains across 60 scored items.

  1. I · Audit Principles, ISO 19011 and Audit Programme Management

  2. II · Conducting the ISMS Audit

  3. III · Evaluating Conformity: Clauses 4–10 and Annex A Controls

  4. IV · Reporting, Nonconformities, Follow-up and Ethics

Exam structure at a glance

  • 60 scored items — 45 single-answer MCQ plus 15 multi-answer
  • Single-answer A–D; multi-answer A–E, select all that apply, no partial credit
  • 90 minutes, closed book, online AI-proctored or test centre
  • 70% pass mark
  • Valid three years, renewable with CPD credits
  • Standard — ISO/IEC 27001:2022, with audit practice in ISO 19011:2018 and ISO/IEC 17021-1:2015
  • Credential — GAICC Certified ISO/IEC 27001 Lead Auditor
  • Issuer — Global AI Certification Council (GAICC)

HOW IT FITS

How it fits with standards you may already run

ISO 19011:2018What it governsGuidelines for auditing management systemsRelationship to this auditThe audit principles, programme management and evidence method this credential examines.
ISO/IEC 17021-1:2015What it governsRequirements for bodies providing audit and certificationRelationship to this auditThe certification framework for first-, second- and third-party audits, including Stage 1 and Stage 2.
ISO/IEC 42001What it governsArtificial intelligence managementRelationship to this auditThe same management-system shape. GAICC’s 27001 Lead Auditor scheme is aligned with its ISO/IEC 42001 Lead Auditor scheme.
ISO 9001What it governsQuality managementRelationship to this auditShares the same high-level structure. Audit technique transfers; the criteria being audited do not.

INSTRUCTOR

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

A globally certified instructor in ISO/IEC, PMI®, TOGAF®, SAFe®, and Scrum.org disciplines. With over three years’ hands-on experience in ISO/IEC 42001 AI governance, he delivers training and consulting across New Zealand, Australia, Malaysia, the Philippines, and the UAE, combining high-end credentials with practical, real-world expertise and global reach.

LinkedIn — Dr Faiz Rasool (opens in a new tab)

ENROL

Enrol on ISO/IEC 27001 Lead Auditor

Choose a package and enter your name and email. If you choose the membership and exam package, you must confirm you have completed the required training.

  • Self-paced course package

    US$698

    • Video lessons included
    • Learning resources
    • Exam simulator access
    • One exam voucher
    • Certificate of completion
  • Membership and exam package

    US$248

    • Video lessons included (not included)
    • Learning resources
    • Exam simulator access
    • Examination voucher

    Membership included

FAQ

FAQ

What is the GAICC ISO/IEC 27001 Lead Auditor certification?

It is GAICC’s auditor-level credential for ISO/IEC 27001:2022. A Lead Auditor plans, leads and reports ISMS audits under ISO 19011 and ISO/IEC 17021-1 — Stage 1 and Stage 2, evidence, findings, the report and follow-up.

Who is this training for in Malaysia?

Lead and senior auditors whose work now includes an ISMS, implementers and managers preparing for Stage 1 and Stage 2, certification-body auditors, and GRC or information-security professionals who own the audit programme.

How is the exam set?

Sixty scored items: 45 single-answer multiple-choice questions (A–D) and 15 multi-answer items (A–E, select all that apply, no partial credit), sat in 90 minutes, closed book. Delivery is online AI-proctored or at a test centre. The published pass mark is 70%.

Which standards does this certification cover?

ISO/IEC 27001:2022, with audit practice grounded in ISO 19011:2018 and ISO/IEC 17021-1:2015.

How long is the certification valid, and how do I renew it?

The credential is valid for three years and may be renewed with CPD credits.

How many CPD hours will I earn?

You receive 32 CPD/PDU hours on completion of the Lead Auditor course.

How many exam attempts are included?

The self-paced course package includes one exam voucher.

What happens if I do not pass the exam?

The self-paced course package includes one exam voucher. A further sitting requires the applicable exam fee.

What is the difference between the two packages?

The self-paced course package includes the full video course and everything needed to prepare from scratch. The membership and exam package is for candidates who have already completed their ISO/IEC 27001 Lead Auditor training and only need the examination, membership and supporting resources.

Can I buy the exam package if I have not done the training?

No. A certificate of completion is required for exam eligibility. If you have not completed the training, choose the self-paced course package.

How is this different from ISO/IEC 27001 Lead Implementer?

Lead Implementer is the four-day credential for the person who builds and operates the ISMS. Lead Auditor is the four-day credential for the person who independently plans, conducts and reports Stage 1 and Stage 2 audits of that system.

Is the GAICC certification programme CPD accredited?

The GAICC certification programme is CPD accredited.

Can I enrol a team?

Yes. Group rates apply for five or more. Contact us for a corporate quote and consolidated invoicing.

Certifying more than one person?

We handle group enrolment, consolidated billing and HRD Corp documentation.

Request a corporate quote