Skip to main content
Operational resilience

ISO 22301 Lead Auditor

ISO 22301 Lead Auditor. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBLead Auditor5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Auditors seeking to perform and lead BCMS audits in accordance with recognised standards
  • Managers and consultants who want to master the BCMS audit process
  • Individuals responsible for maintaining organisational conformity with BCMS requirements
  • Technical experts preparing to support or participate in BCMS audits
  • Expert advisors specialising in business continuity management

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Individuals with no prior exposure to business continuity or management system concepts will likely find the pace of this course challenging
  • Professionals focused exclusively on implementing a BCMS rather than auditing one would be better served by the Lead Implementer course
  • Those seeking only an introductory awareness of ISO 22301 should consider the Foundation course first

What you'll be able to do

  • 1Explain the fundamental concepts and principles of a BCMS based on ISO 22301
  • 2Interpret ISO 22301 requirements from the perspective of a practising auditor
  • 3Evaluate BCMS conformity against ISO 22301 requirements using established audit concepts and principles
  • 4Plan, conduct, and formally close an ISO 22301 compliance audit in accordance with ISO/IEC 17021-1 and ISO 19011
  • 5Lead an audit team through all phases of a BCMS audit, from preparation through to reporting
  • 6Manage an ISO 22301 audit programme across multiple audit cycles
  • 7Apply risk-based thinking to audit planning and the prioritisation of audit activities

Day by day

Day 1Introduction to the BCMS and ISO 22301
  • BCMS Concepts and ISO 22301 Structure

    Participants examine the core concepts, terminology, and structure of ISO 22301 and their relevance to auditing a business continuity management system.

  • Regulatory and Normative Context

    This module explores the broader landscape of standards and guidelines that inform BCMS auditing, including the relationship between ISO 22301 and related frameworks.

By end of day

  • Describe the purpose and structure of ISO 22301 from an auditor's perspective
  • Identify the clauses most relevant to assessing BCMS conformity
Day 2Audit Principles and Preparation for an ISO 22301 Audit
  • Fundamental Audit Concepts and Principles

    Participants study the core principles of auditing as defined by ISO 19011 and their application to BCMS engagements.

  • Initiating and Planning the Audit

    This module covers how to define audit scope and objectives, establish audit criteria, and prepare a structured audit plan aligned with ISO/IEC 17021-1.

  • Audit Documentation and Communication

    Participants learn how to prepare working documents, checklists, and communication plans that support effective audit execution.

By end of day

  • Draft an audit plan that satisfies ISO/IEC 17021-1 requirements
  • Select appropriate audit criteria and define a realistic audit scope
  • Prepare documentation that supports consistent and objective audit evidence collection
Day 3On-Site Audit Activities
  • Conducting the Opening Meeting

    This module explains the purpose, agenda, and expected outcomes of the audit opening meeting and how to facilitate it effectively.

  • Gathering and Verifying Audit Evidence

    Participants practise evidence-collection techniques including interviews, observation, and document review to assess BCMS conformity.

  • Identifying and Documenting Audit Findings

    This module addresses how to classify findings as conformities, nonconformities, or opportunities for improvement and record them accurately.

By end of day

  • Apply structured interview and observation techniques to gather objective audit evidence
  • Classify and document audit findings consistently against ISO 22301 requirements
  • Manage on-site audit activities while maintaining professional auditor conduct
Day 4Closing the Audit
  • Preparing Audit Conclusions

    Participants learn how to analyse findings, form audit conclusions, and assess overall BCMS conformity before closing the audit.

  • Conducting the Closing Meeting

    This module covers how to present audit conclusions, communicate nonconformities, and agree on corrective action timelines with the auditee.

  • Producing the Audit Report

    Participants practise drafting a formal audit report that meets the requirements of ISO/IEC 17021-1 and accurately reflects the audit findings.

By end of day

  • Facilitate a closing meeting that clearly communicates audit outcomes to stakeholders
  • Produce a structured audit report that supports certification decision-making
  • Follow up on corrective actions in a manner consistent with audit programme requirements
Day 5Managing an ISO 22301 Audit Programme and Exam Preparation
  • Establishing and Managing an Audit Programme

    This module addresses how to design, resource, and continuously improve an audit programme that covers multiple BCMS audit cycles.

  • Domain Review: Audit Competency Domains 1 to 7

    Participants consolidate knowledge across all seven exam competency domains, from BCMS fundamentals through audit programme management.

By end of day

  • Design a multi-cycle audit programme appropriate to an organisation's BCMS scope and risk profile
  • Assess personal readiness across all seven competency domains before sitting the PECB Lead Auditor exam
  • Integrate audit programme outputs into organisational continual improvement processes

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of a business continuity management system
  • Domain 2: Business continuity management system requirements
  • Domain 3: Fundamental audit concepts and principles
  • Domain 4: Preparing an ISO 22301 audit
  • Domain 5: Conducting an ISO 22301 audit
  • Domain 6: Closing an ISO 22301 audit
  • Domain 7: Managing an ISO 22301 audit program
  1. Planning an audit
  2. Preparing audit working papers or test plans
  3. Managing an audit program
  4. Reviewing documented information
  5. Conducting opening and closing meetings
  6. Conducting audit interviews
  7. Collecting and analyzing audit evidence
  8. Documenting nonconformities
  9. Preparing audit reports
  10. Following up on nonconformities
  11. Leading an audit team

Certification Rules and Policies

  • Certification and examination fees are included in the price of the training course.
  • Participants will be provided with training course materials containing over 400 pages of information, practical examples, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • Candidates who have completed the training course but failed the exam are eligible to retake the exam once for free within a 12 month period from the initial date of the exam.

Educational approach

  • Elaborates theoretical knowledge, industry-level best practices in BCMS audits, ISO 22301 requirements, and globally recognized auditing standards
  • Provides lecture sessions are illustrated with practical exercises based on a case study which includes role-playing and discussions
  • Encourages discussions between the trainer and the participants
  • Contains multiple-choice quizzes, some of which are scenario-based, designed to help prepare for the certification exam

Buyers always ask

What standards govern the audit methodology taught in this course?+

The course aligns the audit process with ISO/IEC 17021-1, which sets requirements for certification body audits, and ISO 19011, which provides guidelines for auditing management systems.

Participants learn to apply both standards throughout the audit lifecycle, from planning through to programme management.

How many competency domains does the PECB ISO 22301 Lead Auditor exam cover?+

The exam spans seven domains: BCMS fundamental principles and concepts, BCMS requirements, fundamental audit concepts and principles, preparing an ISO 22301 audit, conducting an ISO 22301 audit, closing an ISO 22301 audit, and managing an ISO 22301 audit programme.

Candidates should consult the PECB List of Exams and Examination Rules and Policies for precise information on exam format and available languages.

Is passing the exam alone sufficient to receive the PECB Lead Auditor credential?+

Passing the PECB exam is a necessary step but not the only requirement. After passing, candidates must apply for the credential and demonstrate that they satisfy all requirements outlined in PECB's Certification Rules and Policies.

Different credential levels may have differing requirements, so candidates should review the applicable credential table on the PECB website before applying.

What level of prior knowledge is expected before attending this five-day programme?+

Participants are expected to arrive with a foundational understanding of business continuity concepts and a working knowledge of BCMS audit principles.

Individuals who lack this background may wish to complete the ISO 22301 Foundation course beforehand to ensure they can engage fully with the audit-focused content from day one.

What is the difference between attending the course and being a certified Lead Auditor?+

Attending the course and completing the training provides participants with structured learning across all audit phases and earns an attestation of completion. It does not automatically confer the Lead Auditor credential.

The credential is issued by PECB only after a candidate has passed the exam and submitted a successful certification application meeting all relevant PECB requirements.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.