Training - ISO/IEC 27001 Lead Auditor

ISO/IEC 27001 Lead Auditor Training

Would you like to become a Lead Auditor for the ISO/IEC 27001 Information Security Management System? In this two-day Lead Auditor training course, you will learn how to plan and conduct audits in the role of lead auditor using the criteria of the ISO/IEC 27001 standard. The training is based on the auditing principles outlined in the ISO 19011 standard and provides practical examples of how to conduct audits. The two-day training course costs €1,050 + VAT and qualifies you to serve as an ISO/IEC 27001 Lead Auditor.
Benefits of ISO/IEC 27001 Lead Auditor Training
Confidence in Serving as a Lead Auditor

You will gain the skills to work independently as an ISO/IEC 27001 lead auditor, master the steps of the audit process, and be able to apply the standard’s requirements in practice.

Knowledge of the ISO 19011 Standard

You will understand the basic principles of auditing in accordance with the ISO 19011 standard, as well as best practices in auditing, and you will be able to apply them in your work as an auditor.

A thorough understanding of the ISO/IEC 27001 standard

This training provides a clear overview of the structure of an information security management system and its requirements, as well as how it relates to other management systems, such as ISO 9001.

Practical Tools for Auditing

You’ll learn how to develop audit plans, identify findings, and make recommendations for improvement—you’ll gain practical tools that you can apply directly within your own organization.

How can ISO/IEC 27001 Lead Auditor training benefit your organization?

Those who have completed the training provide the organization with:
  • Strong expertise in planning, leading, and conducting ISO/IEC 27001 audits in accordance with the standard and auditing principles.
  • The ability to apply the requirements of the ISO/IEC 27001 standard in developing an organization’s information security and managing risks.
  • Capabilities to carry out an effective certification process.
Trainers - ISO/IEC 27001 Lead Auditor Training

Jyrki Lahnalahti

Business Manager, Certification, Management Consultant, Lead Auditor, Information Security and IT Services Trainer.

Working with clients is important to me, and it’s what drives me in my roles as a management system consultant, lead auditor, and trainer. I have long been involved in standardization work in the areas of service management and information security.
My previous experience—including as an entrepreneur and in a variety of roles—forms the basis for my training offerings. My training topics include management system standards for information security (ISO/IEC 27001), service management (ISO/IEC 20000-1), business continuity management (ISO 22301), and quality management (ISO 9001). In addition to these, my other areas of expertise and training include corporate security management systems, risk management, and internal auditing. Among the training programs and certifications I have completed, I must mention the Security Management Training Program (TJK 13), which broadened my perspective on the big picture of corporate security and its various subfields.
As a trainer, it’s important to me that, in addition to theoretical or conceptual background, I can also share my own personal experiences with the participants. My style involves close interaction with participants through discussions, challenging assumptions, and sharing real-life, authentic examples. I can’t recall a training session I’ve led from which I didn’t also learn or gain something myself.
I have been working as an auditor for 20 years. Before that, I spent many years in various roles in the ICT sector, including as a programmer, project manager, and consultant. I have been conducting training sessions for over 15 years.
In my free time, I enjoy spending time outdoors, working on my old farmhouse, and tinkering with computers.

Sini Ahlgren

Experience and Expertise

Expert and managerial positions in occupational safety, environmental, and quality management since 2002

Specialized Expertise

Management Systems, particularly ISO 45001
Auditing, particularly ISO 45001 audits and supplier audits
Supplier Management
Risk Management
Measuring Workplace Safety

Audit Experience

Lead Auditor for ISO 14001 and ISO 45001
Industry codes over 20 mm: food, construction, process industry, machine shops
Supplier Audits as Second- and Third-Party Procedures
Security Audits
ISO 45001 Current Status Assessments
Over 500 days of various audits
Completed IRCA training in 2017

Experience with management systems:

ISO 45001 Product Manager, Inspecta Certification, 2017–2025

Examples of training sessions conducted by Sini

ISO 45001 Training Courses Starting in 2018
Internal Audit Certification Training (3 days)
Company-specific internal audit training courses (1/2/3 days) and various client-specific customized packages
Training on the ISO 9001, 14001, and 45001 Management Systems
Common Structures of Management Systems and Specific Features of Standards
(ISO 9001/14001/45001)
Implementing an ISO 45001 System
Supplier Audits and Developing Criteria for Supplier Evaluations
Certification Training Programs for Occupational Safety Managers
Occupational Safety and Health Training for Supervisors
Management Training on Workplace Safety

Contact Information

Email: sini.ahlgren@dekra.com
Phone: +358 50 329 0237

Who is the ISO/IEC 27001 Lead Auditor training course intended for?

  • For individuals who serve or intend to serve as ISO/IEC 27001 lead auditors
  • For internal auditors who wish to deepen their expertise in auditing information security management systems
  • For professionals working in information security, risk management, or compliance
  • For individuals responsible for auditing or developing the ISO/IEC 27001 system

ISO/IEC 27001 Lead Auditor Training Course Content

The ISO/IEC 27001 Lead Auditor training provides you with practical tools and methods for auditing information security management systems. In this training, you will learn how to plan and conduct audits in accordance with the ISO/IEC 27001 standard in the role of Lead Auditor, analyze findings, and identify areas for improvement that support the continuous improvement of information security and risk management.
Mock Audit and Audit Plan
  • During the training, you will develop an audit plan that you can use directly in your company’s audit work.
  • You will conduct a mock audit that provides hands-on experience with auditing in accordance with the ISO/IEC 27001 standard.
  • You'll receive feedback on your practice audit to support your development.
  • You will learn about different ways to conduct audits as part of an information security management system.
Tools and Documentation
  • You will have access to audit questions and forms that support the planning and conduct of audits.
  • You will learn to apply audit methods in accordance with ISO standards and to assess the significance of corrective actions.
Practical Exercises and Feedback
  • The training includes practical exercises designed to help you develop your skills in the role of Lead Auditor.
  • You'll receive expert feedback that supports your development as an auditor.
Dates - ISO/IEC 27001 Lead Auditor Training
DateLocationRegistration closesPrice
September 23–24, 2026Original Sokos Hotel Tripla, PasilaSeptember 9, 2026€1,050 (+25.5% VAT)
November 18–19, 2026Solo Sokos Hotel Torni, TampereNovember 4, 2026€1,050 (+25.5% VAT)

Program - ISO 27001 Lead Auditor Training

The training is spread over two separate training days. The training days begin at 9:00 a.m. and end at 4:00 p.m. Lunch and coffee are included for each day of the training.

Day 1

Audit Objectives and Principles
The Audit Process and the Importance of the Audit Program
Audit Planning
Preparing an Audit Plan
Conducting the Audit
Audit Reporting
Audit Follow-up
The instructor is Sini Ahlgren.

Day 2

Key definitions, concepts, and principles of information security management.
The content of the ISO/IEC 27001 Information Security Management Standard.
How does information security management relate to other ISO management systems, such as ISO 9001?
You will learn how to apply the ISO/IEC 27001 standard to your own operations through the instructor’s practical examples.
The instructor is Jyrki Lahnalahti.
Why Choose DEKRA?
DEKRA is a leading international expert organization with extensive experience in ISO standards training and audits. Our trainers have in-depth knowledge of management system standards such as ISO 9001, ISO 14001, ISO 45001, and ISO 50001, and provide up-to-date information on best practices for internal audits.
We offer flexible training options: open enrollment courses, online courses, and customized training tailored to your company's needs.

Register for the training

All of Our Training Programs

Lead Auditor for Internal Audits

Requirements for internal audits of the ISO 9001, ISO 14001, and ISO 45001 management systems, as well as the ISO 50001 energy management system.
Learn more about the Lead Auditor Training for Internal Auditing

ISO 9001 Quality Management Systems Standard

Training on the content and practical application of the ISO 9001:2015 Quality Management Systems standard.
Learn more about ISO 9001 training

ISO 14001 Environmental Management Systems Standard

Training on the content and practical application of the ISO 14001:2015 Environmental Management Systems standard.
Learn more about ISO 14001 training

ISO 45001 Occupational Health and Safety Management Systems Standard

Training Course 45001:2023: The Content and Practical Application of Occupational Health and Safety Management Systems.
Learn more about ISO 45001 training

ISO 50001 Energy Management Systems Standard

Training on the content and practical application of the ISO 50001 Energy Management Systems standard.
Learn more about ISO 50001 training

Corporate Social Responsibility Management

The training provides an introduction to corporate responsibility management in business, as well as its key principles, frameworks, and legislation.
Learn more about the program

ISO/IEC 27001 Information Security Standard

In the ISO/IEC 27001 Information Security Standard training course, you will learn the requirements of the management system and how to interpret them through examples.
Learn more about ISO/IEC 27001 training

Internal Information Security Audit

The training delves into the internal audit process, particularly from the perspective of information security.
Learn more about the program

ISO 22301:2019 Business Continuity Management System

In our ISO 22301:2019 training, we clearly and comprehensively cover the standard’s requirements for a business continuity management system
Learn more about ISO 22301 training

ISO/IEC 20000 Standard

In this training course, you will learn the key requirements of the ISO/IEC 20000-1:2018 standard.
Learn more about ISO 20000 training

Internal Audit Day

The Internal Audit Workshop provides a concise and practical overview of the entire internal audit process as well as the requirements of ISO management systems.
Learn more about Power Day

Webinar on Criteria for Internal Auditing

This webinar, which complements the training day, prepares participants to conduct internal audits for ISO 9001, 14001, 45001, and 50001 based on the audit criteria.
Check out the webinar

ISO 50001 Lead Auditor

This training course provides a comprehensive and practical overview of auditing an energy management system in accordance with the ISO 50001 standard, as well as the responsibilities of a lead auditor.
Learn more about the ISO 50001 Lead Auditor training course
Share page :