Stage 1 (documentation review) done, stage 2 (the on-site audit) follows. Because this is effectively where certification is decided, the tension is higher. The part that worries project owners most is that the auditor interviews staff directly. What if our people cannot answer? Almost every organisation asks it.
The short answer: stage 2 checks whether you operate as you decided. Not whether staff have memorised the standard's vocabulary — whether they know the rules that bear on their own work and follow them. And that check runs across both records and reality.
This article covers the purpose of stage 2, how the days run, what interviews ask, what is checked on the floor, where executives are expected, and what to prepare. For the preceding step, see What Stage 1 (Documentation Review) Actually Examines.
Disclaimer: This article is general information. Audit procedure, duration, and the handling of findings vary by certification body; their published materials and your audit plan are authoritative.
What Stage 2 Is For
Stage 2 confirms that the ISMS is operating effectively. If stage 1 asked whether the design holds together, stage 2 asks whether you are running it as designed.
Three things are checked.
- Do records exist? — for everything the procedures say you do, is there evidence you did it
- Do records match reality? — not only on paper, but on the floor
- Is it working? — is there a functioning cycle of checking, correcting, and improving, rather than motions gone through
The third is what distinguishes stage 2. Complete records are not enough: what happened to the gaps internal audit found, and what management decided at the review, are both traced.
For a small organisation, two to three days is the usual guide, varying with scope, sites, and headcount. Multiple sites may each be visited.
The Focus Is Records Against Reality
This is where most of the time goes. Auditors trace from record to reality and from reality to record.
Take access management:
- The procedure says permissions are granted and removed on joining, transfer, and leaving
- Recent joiners, transfers, and leavers are identified (the record side)
- Their actual permissions in the systems are checked (the reality side)
- Whether leavers' accounts remain, and whether permission reviews are performed, is examined
Deleted in the record but still live, or handled in reality but never recorded — either becomes a finding. The first is an operational problem, the second a record-keeping one, and they call for different responses.
Areas commonly examined:
| Area | On the record side | On the reality side |
|---|---|---|
| Access permissions | Grant/removal requests, periodic review records | Actual account lists, leftover leaver accounts |
| Awareness training | Attendance records, materials, comprehension checks | Whether staff actually know the content |
| Incident response | Reports, response records, preventive actions | Whether staff know where and how to report |
| Supplier management | Supplier list, assessment records, contract clauses | Whether the list matches who you actually use |
| Information assets | Asset register, classification and handling rules | Whether it matches the systems and media in use |
| Logging | Logging configuration, review records | Whether logs are actually captured and retained |
| Physical controls | Entry records, key registers | Actual locking, clear desk condition |
| Change management | Change requests and approvals | Whether they match the actual change history |
Drift between the asset register and reality is especially common: systems added and retired since the register was built, with no update. See Building an Information Asset Register and Supplier Security Management.
How the Days Run
| Segment | Content | Who attends |
|---|---|---|
| Opening meeting | Audit plan, how the days will run, status of stage 1 corrections | Executives, ISMS manager, officers |
| Executive interview | Policy, management involvement, resourcing, decisions at the management review | Executives |
| ISMS operation review | Status of risk treatment, progress against objectives, internal audit and corrections | ISMS manager |
| Department-by-department | Operation as it applies to each department's work; interviews with staff | Departmental staff |
| Floor and physical checks | Working areas, server rooms and storage, entry control, clear desk | Officers, facilities |
| Technical checks | Implementation of access control, logging, backup, vulnerability management | IT and development staff |
| Auditor's writing time | Consolidating findings | — |
| Closing meeting | Findings, any nonconformities, correction deadlines, route to certification | Executives, ISMS manager, officers |
The department-by-department sessions are the core of stage 2. The auditor moves through departments asking how each rule is operated in that context. If your development organisation is in scope, development process and cloud configuration come into it too — see Reading the 34 Technological Controls and Security by Design for Medical Systems.
What Staff Interviews Ask
This is where the anxiety sits. What is actually asked is the rules that bear on that person's work. Nobody is asked to cite clause numbers or control names.
Typical questions:
- Do you know there is an information security policy? Where can you read it?
- What kinds of information do you handle? Where is it stored?
- What are the rules for setting and changing passwords?
- Do you take a work laptop outside the office? What applies when you do?
- If you receive a suspicious email, who do you report it to, and how?
- Have you had security training? When, and on what?
- When someone leaves, who disables their accounts?
Answers in the person's own words are fine. "If something suspicious arrives I forward it to IT and leave it unopened" is a complete answer. Everyone reciting identical phrasing, in fact, reads as unnatural.
What does tend to become a finding:
- Not knowing the policy or procedures exist
- Being unable to say where to report (the incident procedure has not been communicated)
- No recollection of training (records exist, attendance did not)
- Practice differing from the procedure ("the procedure says this, but we actually do that")
That last pattern usually means the procedure does not match reality — and the thing to change is often the procedure, not the behaviour. Write a rule nobody can follow and this gap will surface.
For preparation, communicating across the company and sharing likely questions is what works. Nobody needs to memorise anything: it is enough that everyone can say where the rules touching their work are written and who to ask. See Designing Security Awareness Training.
What Is Checked on the Floor
The working environment itself is examined. Remote auditing may be used in part, but physical controls are generally verified on site.
- Entry control — locking, entry records, visitor handling, restriction of unauthorised areas
- Working areas — clear desk and clear screen, papers left out, screen locking when away
- Server and equipment locations — locking, environment, restriction to authorised people
- Documents and media — locked storage, disposal method, removal records
- Removable media — how USB devices are managed and restricted
- Endpoints — agreement with the asset register, encryption and anti-malware coverage
Where staff work mainly from home, the point becomes the rules for the home working environment and how they are communicated and verified. With less to see physically, you must explain how rules, training, and technical controls carry the weight. See Reading the 14 Physical Controls.
Note that tidying up for the day does not help. Clear desk is judged on the ordinary state, and locking practice and disposal routines reveal the reality regardless.
Where Executives Are Expected
Stage 2 has moments top management cannot delegate. At least two of them.
1. The executive interview
The standard requires leadership and commitment from top management, so the auditor asks executives directly about:
- The content of the security policy and the intent behind it
- How the ISMS is integrated into business processes
- How resources — people and budget — are secured
- What was reported at the management review, and what was decided
- Which information security risks management regards as most serious
"I leave that to the team" leads to a finding here. What is being sought is not technical depth but evidence of genuine management involvement. Where management review has been a formality, this is where it shows. See Conducting a Management Review and Clause 5 Leadership.
2. Opening and closing meetings
The closing meeting presents findings, any nonconformities, and correction deadlines. Since correction involves resourcing decisions, executive presence has a purpose.
This is not only about the audit. In business with hospitals, having management accountable for information security is itself something you are asked to demonstrate — see The Governance Chapter: What Management Is Accountable For.
What to Prepare
Records (one full cycle)
- Evidence of controls implemented per the risk treatment plan
- Measurements of progress against security objectives
- Training records (attendees, dates, content, comprehension checks)
- Internal audit plan, checklist, report, and corrections
- Management review minutes, showing inputs and outputs
- Incident and corrective action records (or, if none occurred, evidence the procedure is communicated)
- Access grant, removal, and review records
- Supplier assessment and review records
- Document revision history and current-version control
Stage 1 follow-up
- Corrections to stage 1 findings complete, with evidence
- Corrections submitted in the body's format, by its deadline
Logistics
- Audit plan received and the departmental timetable shared with each department
- Attendees assigned per slot, with the records and screens they will need
- Route for physical checks confirmed (working areas, storage, server room)
- Executive diaries secured
- Company-wide notice of the dates and the possibility of interviews
- Records organised so they can be produced immediately
That last point matters more than it sounds. Starting to hunt for a record after being asked for it reads as poor control in itself. A short index of likely question to source record keeps the days moving.
For the overall schedule see ISMS Timeline: What Six Months Actually Looks Like; for the patterns that recur, Common Nonconformities and How to Avoid Them.
After Stage 2
Where nonconformities are raised at the closing meeting, you implement corrective action and report it to the body. Once verified, the body's own decision process leads to registration. That takes time, so work it into the calculation if you are counting back from a commercial deadline.
Certification is also not the end. Surveillance audits follow annually and a recertification audit every three years. What stage 2 taught you about records matching reality should feed straight back into how you design day-to-day operation. See Preparing for Surveillance Audits and Preparing for Recertification.
Conclusion
- Stage 2 confirms that you operate as you decided, verified across records and reality
- Two to three days is the guide, built around department-by-department sessions grounded in actual work
- Staff interviews ask about the rules touching that person's job — no memorisation needed, own words are fine
- Where practice diverges from the procedure, the procedure is usually what needs changing
- Floor checks look at clear desk, locking, media handling, and disposal — a one-day tidy-up does not disguise the ordinary state
- The executive interview cannot be delegated; involvement and management review decisions are what is probed
- The heart of preparation is having one cycle of records ready to produce on the spot
Pottech supports record preparation, audit scheduling, and departmental question preparation as part of its ISMS certification support. Attendance at stage 2 is available as an option, with us running the day and the exchanges with the auditor. We can also serve as your internal audit manager and internal auditors.
See ISMS Certification Support for scope and pricing, or contact us. For the wider picture see What Is an ISMS (ISO/IEC 27001)?, and for what hospital customers are held to, The Three-Ministry Guidelines.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: audit procedure, duration, and the categorisation and handling of findings vary by body and are subject to revision. Confirm against the body's publications and your audit plan.