How to Pass Your ISO 27001 Audit
Watch the on-demand training on what ANAB-accredited auditors actually check, and how to reach Stage 2 without surprises.
You’ll learn how to:
- Scope the certification audit so the boundary stays manageable
- Confirm your Annex A controls are implemented and evidenced before the auditor arrives
- Structure documentation the way auditors expect to read it
- Use your internal audit and management review as a dress rehearsal
- Know what evidence Stage 1 and Stage 2 each require
Led by Nelly Spieler, CISA, CIPT, Partner at Frank, Rimerman + Co., and Nexeris CEO Zach Tracy, CISA, CISSP.
ISO 27001 Webinar - PREVIEW
Don’t guess your way into a Stage 2 audit.
For most companies, ISO 27001 certification is a customer or contract requirement, and a stalled audit means a delayed deal. This session pairs the two perspectives that matter: an ANAB-accredited auditor explaining what a certification body looks for, and a consultant who has prepared dozens of organizations to meet it. You get the actual review criteria and the prep work that closes gaps before the auditor sees them, not a theory lecture on the standard.
What You Will Learn in 30 Minutes
This session moves past the text of the standard and into what decides a certification audit:
- Precision Scoping. Define the technology, people, and locations in scope so the audit boundary stays manageable and you are not defending systems that never needed to be there.
- Gap Remediation. Assess your Annex A controls and confirm each one is implemented and evidenced before the auditor arrives, not during the audit.
- Auditor-Friendly Documentation. Structure policies and records the way assessors expect to read them: clear unique identifiers (POL-01), version history, and the mandatory elements they ask for first.
- The Dress Rehearsal. Use your internal audit and management review to surface and close the last gaps before the certification body ever sees them.
- The Audit Experience. Understand how Stage 1 differs from Stage 2, and prepare the specific evidence each stage calls for.
Meet The Experts
Learn from both sides of the certification table, the accredited auditor and the prep consultant:
- Nelly Spieler, CISA, CIPT. Partner at Frank, Rimerman + Co., with 20+ years in IT audit and compliance. Nelly leads the firm’s ANAB-accredited certification body and conducts ISO 27000-family assessments for companies worldwide.
- Zach Tracy, CISA, CISSP: CEO and Founder of Nexeris, with over 10 years of experience leading 100+ audits and building security programs for 50+ organizations. Holds CISSP, CISA, ISO 27001 and ISO 9001 Lead Implementer certifications.
Nexeris helped our company to rapidly meet cybersecurity and compliance requirements during the due diligence process of a potential customer. The speed of delivery and quality of the work was exceptional. I highly recommend Nexeris for cybersecurity and compliance support.
- Jorge Newbery, OwnEasy Solutions LLC
Why Choose Nexeris?
- Project Plan and Management
- Start in 24 Hours
- 90% Done For You Solutions
- $5k Refundable Audit Victory Guarantee
- C3PAO and Technology Partner Discounts
Before your audit, pressure-test your risk treatment with our free ISO 27001 Risk Assessment Template. Then contact Nexeris for a consultation on getting your ISMS audit-ready.
Frequently Asked Questions
Is this a live webinar?
No. This is an on-demand recording from a previously held live Nexeris webinar. You can watch it at any time after signing up.
Who is this training for?
Security, compliance, IT, and risk leaders pursuing or maintaining ISO 27001 certification, especially teams facing customer, contract, or international market requirements to certify.
How long is the recording?
The recording is approximately 30 minutes long and is structured to be practical and easy to follow.
Is this a sales presentation?
No. The session is educational and focused on audit preparation. There is no requirement to speak with sales to access the recording or checklist.
Will this make us ISO 27001 certified?
No. This training helps you understand the standard, find common gaps, and prepare for assessment. Certification requires an audit by an independent, accredited certification body.