Back to Columns
ISMS & Certification12 min read

What Stage 2 (On-Site Audit) Actually Examines

September 14, 2026

What Stage 2 (On-Site Audit) Actually Examines
Share this article

Stage 1 (documentation review) done, stage 2 (the on-site audit) follows. Because this is effectively where certification is decided, the tension is higher. The part that worries project owners most is that the auditor interviews staff directly. What if our people cannot answer? Almost every organisation asks it.

The short answer: stage 2 checks whether you operate as you decided. Not whether staff have memorised the standard's vocabulary — whether they know the rules that bear on their own work and follow them. And that check runs across both records and reality.

This article covers the purpose of stage 2, how the days run, what interviews ask, what is checked on the floor, where executives are expected, and what to prepare. For the preceding step, see What Stage 1 (Documentation Review) Actually Examines.

Disclaimer: This article is general information. Audit procedure, duration, and the handling of findings vary by certification body; their published materials and your audit plan are authoritative.

What Stage 2 Is For

Stage 2 confirms that the ISMS is operating effectively. If stage 1 asked whether the design holds together, stage 2 asks whether you are running it as designed.

Three things are checked.

  1. Do records exist? — for everything the procedures say you do, is there evidence you did it
  2. Do records match reality? — not only on paper, but on the floor
  3. Is it working? — is there a functioning cycle of checking, correcting, and improving, rather than motions gone through

The third is what distinguishes stage 2. Complete records are not enough: what happened to the gaps internal audit found, and what management decided at the review, are both traced.

For a small organisation, two to three days is the usual guide, varying with scope, sites, and headcount. Multiple sites may each be visited.

The Focus Is Records Against Reality

This is where most of the time goes. Auditors trace from record to reality and from reality to record.

Take access management:

  • The procedure says permissions are granted and removed on joining, transfer, and leaving
  • Recent joiners, transfers, and leavers are identified (the record side)
  • Their actual permissions in the systems are checked (the reality side)
  • Whether leavers' accounts remain, and whether permission reviews are performed, is examined

Deleted in the record but still live, or handled in reality but never recorded — either becomes a finding. The first is an operational problem, the second a record-keeping one, and they call for different responses.

Areas commonly examined:

AreaOn the record sideOn the reality side
Access permissionsGrant/removal requests, periodic review recordsActual account lists, leftover leaver accounts
Awareness trainingAttendance records, materials, comprehension checksWhether staff actually know the content
Incident responseReports, response records, preventive actionsWhether staff know where and how to report
Supplier managementSupplier list, assessment records, contract clausesWhether the list matches who you actually use
Information assetsAsset register, classification and handling rulesWhether it matches the systems and media in use
LoggingLogging configuration, review recordsWhether logs are actually captured and retained
Physical controlsEntry records, key registersActual locking, clear desk condition
Change managementChange requests and approvalsWhether they match the actual change history

Drift between the asset register and reality is especially common: systems added and retired since the register was built, with no update. See Building an Information Asset Register and Supplier Security Management.

How the Days Run

SegmentContentWho attends
Opening meetingAudit plan, how the days will run, status of stage 1 correctionsExecutives, ISMS manager, officers
Executive interviewPolicy, management involvement, resourcing, decisions at the management reviewExecutives
ISMS operation reviewStatus of risk treatment, progress against objectives, internal audit and correctionsISMS manager
Department-by-departmentOperation as it applies to each department's work; interviews with staffDepartmental staff
Floor and physical checksWorking areas, server rooms and storage, entry control, clear deskOfficers, facilities
Technical checksImplementation of access control, logging, backup, vulnerability managementIT and development staff
Auditor's writing timeConsolidating findings
Closing meetingFindings, any nonconformities, correction deadlines, route to certificationExecutives, ISMS manager, officers

The department-by-department sessions are the core of stage 2. The auditor moves through departments asking how each rule is operated in that context. If your development organisation is in scope, development process and cloud configuration come into it too — see Reading the 34 Technological Controls and Security by Design for Medical Systems.

What Staff Interviews Ask

This is where the anxiety sits. What is actually asked is the rules that bear on that person's work. Nobody is asked to cite clause numbers or control names.

Typical questions:

  • Do you know there is an information security policy? Where can you read it?
  • What kinds of information do you handle? Where is it stored?
  • What are the rules for setting and changing passwords?
  • Do you take a work laptop outside the office? What applies when you do?
  • If you receive a suspicious email, who do you report it to, and how?
  • Have you had security training? When, and on what?
  • When someone leaves, who disables their accounts?

Answers in the person's own words are fine. "If something suspicious arrives I forward it to IT and leave it unopened" is a complete answer. Everyone reciting identical phrasing, in fact, reads as unnatural.

What does tend to become a finding:

  • Not knowing the policy or procedures exist
  • Being unable to say where to report (the incident procedure has not been communicated)
  • No recollection of training (records exist, attendance did not)
  • Practice differing from the procedure ("the procedure says this, but we actually do that")

That last pattern usually means the procedure does not match reality — and the thing to change is often the procedure, not the behaviour. Write a rule nobody can follow and this gap will surface.

For preparation, communicating across the company and sharing likely questions is what works. Nobody needs to memorise anything: it is enough that everyone can say where the rules touching their work are written and who to ask. See Designing Security Awareness Training.

What Is Checked on the Floor

The working environment itself is examined. Remote auditing may be used in part, but physical controls are generally verified on site.

  • Entry control — locking, entry records, visitor handling, restriction of unauthorised areas
  • Working areas — clear desk and clear screen, papers left out, screen locking when away
  • Server and equipment locations — locking, environment, restriction to authorised people
  • Documents and media — locked storage, disposal method, removal records
  • Removable media — how USB devices are managed and restricted
  • Endpoints — agreement with the asset register, encryption and anti-malware coverage

Where staff work mainly from home, the point becomes the rules for the home working environment and how they are communicated and verified. With less to see physically, you must explain how rules, training, and technical controls carry the weight. See Reading the 14 Physical Controls.

Note that tidying up for the day does not help. Clear desk is judged on the ordinary state, and locking practice and disposal routines reveal the reality regardless.

Where Executives Are Expected

Stage 2 has moments top management cannot delegate. At least two of them.

1. The executive interview

The standard requires leadership and commitment from top management, so the auditor asks executives directly about:

  • The content of the security policy and the intent behind it
  • How the ISMS is integrated into business processes
  • How resources — people and budget — are secured
  • What was reported at the management review, and what was decided
  • Which information security risks management regards as most serious

"I leave that to the team" leads to a finding here. What is being sought is not technical depth but evidence of genuine management involvement. Where management review has been a formality, this is where it shows. See Conducting a Management Review and Clause 5 Leadership.

2. Opening and closing meetings

The closing meeting presents findings, any nonconformities, and correction deadlines. Since correction involves resourcing decisions, executive presence has a purpose.

This is not only about the audit. In business with hospitals, having management accountable for information security is itself something you are asked to demonstrate — see The Governance Chapter: What Management Is Accountable For.

What to Prepare

Records (one full cycle)

  • Evidence of controls implemented per the risk treatment plan
  • Measurements of progress against security objectives
  • Training records (attendees, dates, content, comprehension checks)
  • Internal audit plan, checklist, report, and corrections
  • Management review minutes, showing inputs and outputs
  • Incident and corrective action records (or, if none occurred, evidence the procedure is communicated)
  • Access grant, removal, and review records
  • Supplier assessment and review records
  • Document revision history and current-version control

Stage 1 follow-up

  • Corrections to stage 1 findings complete, with evidence
  • Corrections submitted in the body's format, by its deadline

Logistics

  • Audit plan received and the departmental timetable shared with each department
  • Attendees assigned per slot, with the records and screens they will need
  • Route for physical checks confirmed (working areas, storage, server room)
  • Executive diaries secured
  • Company-wide notice of the dates and the possibility of interviews
  • Records organised so they can be produced immediately

That last point matters more than it sounds. Starting to hunt for a record after being asked for it reads as poor control in itself. A short index of likely question to source record keeps the days moving.

For the overall schedule see ISMS Timeline: What Six Months Actually Looks Like; for the patterns that recur, Common Nonconformities and How to Avoid Them.

After Stage 2

Where nonconformities are raised at the closing meeting, you implement corrective action and report it to the body. Once verified, the body's own decision process leads to registration. That takes time, so work it into the calculation if you are counting back from a commercial deadline.

Certification is also not the end. Surveillance audits follow annually and a recertification audit every three years. What stage 2 taught you about records matching reality should feed straight back into how you design day-to-day operation. See Preparing for Surveillance Audits and Preparing for Recertification.

Conclusion

  1. Stage 2 confirms that you operate as you decided, verified across records and reality
  2. Two to three days is the guide, built around department-by-department sessions grounded in actual work
  3. Staff interviews ask about the rules touching that person's job — no memorisation needed, own words are fine
  4. Where practice diverges from the procedure, the procedure is usually what needs changing
  5. Floor checks look at clear desk, locking, media handling, and disposal — a one-day tidy-up does not disguise the ordinary state
  6. The executive interview cannot be delegated; involvement and management review decisions are what is probed
  7. The heart of preparation is having one cycle of records ready to produce on the spot

Pottech supports record preparation, audit scheduling, and departmental question preparation as part of its ISMS certification support. Attendance at stage 2 is available as an option, with us running the day and the exchanges with the auditor. We can also serve as your internal audit manager and internal auditors.

See ISMS Certification Support for scope and pricing, or contact us. For the wider picture see What Is an ISMS (ISO/IEC 27001)?, and for what hospital customers are held to, The Three-Ministry Guidelines.

References and Sources

Note: audit procedure, duration, and the categorisation and handling of findings vary by body and are subject to revision. Confirm against the body's publications and your audit plan.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.