02 Sep
|
AuditPartners
|
Thane
02 Sep
AuditPartners
Thane
READ FIRST — THIS ROLE IS ONLY FOR AUDITORS WHO HAVE BEEN EMPLOYED OR CONTRACTED BY AN ACCREDITED CERTIFICATION BODY.
If your ISO 27001 experience is implementing an ISMS, running internal audits, preparing a client for certification, or acting as the client-side point of contact during a certification audit — that is valuable work, but it is not what this role is.
We will not be able to move forward with your application.
This role is for auditors who have personally conducted Stage 1 and Stage 2 certification audits, surveillance audits, and recertification audits on behalf of an accredited certification body (for example BSI, TÜV SÜD, TÜV Rheinland, DNV, Bureau Veritas, SGS, Intertek, LRQA, DQS, NQA, ISOQAR, IRQS, URS or similar), under an accreditation body such as NABCB, UKAS, ANAB, DAkkS, IAS or JAS-ANZ.
Every applicant must be able to produce their audit log / man-day record from the certification body. We verify this before contracting.
ABOUT AUDITPARTNERS
Audit Partners provides accredited ISO lead auditors on demand to certification bodies. Our bench conducts certification audits on behalf of our certification body clients, under UKAS, ANAB, DAkkS, NABCB and IAS accreditation, across 13 countries and 4,400+ delivered external audit man-days.
This means the work you would do for us is the work you already do — Stage 1, Stage 2, surveillance and recertification audits for a certification body. What changes is that you take the assignments through us, remotely, without carrying a single CB's schedule.
THE ROLE
ISO 27001 Lead Auditor — contract, 100% remote, India-based.
You will lead ISO/IEC 27001:2022 audits end to end: audit planning and Stage 1 documentation review, Stage 2 fieldwork, sampling, evidence gathering, nonconformity write-ups, and final audit reporting to a standard that will withstand accreditation body scrutiny.
Engagements are assigned per audit on a per-audit-day basis. This starts as contract work; auditors who deliver well get consistent, repeat assignments and are first in line for longer-term arrangements as our book grows.
Because you audit on behalf of our certification body clients, you must be able to be empanelled or approved by a CB, and you must be able to meet ISO/IEC 17021-1 impartiality requirements — no consulting relationship with the audit client in the preceding two years.
ISO/IEC 27701 is our highest-priority second standard, and ISO/IEC 42001 is close behind. We are expanding our privacy (PIMS) and AI management system (AIMS) coverage. If you hold ISO/IEC 27701 or ISO/IEC 42001 lead auditor qualifications — especially if you have audited them for a certification body — say so.
Multi-standard auditors get more assignments and a higher day rate.
WHAT YOU WILL DO
- Lead ISO/IEC 27001:2022 Stage 1 and Stage 2 audits, surveillance audits and recertification audits
- Plan audits: scope confirmation, applicability of Annex A controls, audit duration per ISO/IEC 27006, sampling rationale, audit plan and agenda
- Conduct remote and, occasionally, on-site fieldwork; interview control owners; gather and evaluate objective evidence
- Write transparent, defensible nonconformity reports tied to specific clause and control references, and evaluate corrective action and root cause responses
- Produce complete audit reports and recommendations
- Where you are qualified: extend audits to ISO/IEC 27701 (PIMS) and ISO/IEC 42001 (AIMS)
- Uphold impartiality and confidentiality requirements, including declaring any conflict of interest with an audit client
REQUIREMENTS — NON-NEGOTIABLE
1. Employed or contracted by an accredited certification body as an ISO 27001 auditor or lead auditor. You must be able to name the certification body and the dates you worked with them.
2.
A signed audit log / man-day record from that certification body, showing days performed as Auditor and as Lead Auditor. You must be able to provide this on request.
3. Certified ISO/IEC 27001 Lead Auditor (IRCA, Exemplar Global, CQI, or a certification body's internal qualification scheme). Registration number required.
4. Minimum 20 audit days performed as a certification body auditor on ISO/IEC 27001 audits.
5. Working knowledge of ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO/IEC 27006, and ISO 19011 / ISO/IEC 17021-1 audit process requirements.
6. Bachelor's degree or equivalent.
7. Based in India, able to work 100% remotely, with reliable internet and a private space for client interviews.
8. Fluent, professional English — written reports and client-facing interviews.
STRONG PLUSES
- ISO/IEC 27701 lead auditor qualification, and audits performed as a PIMS extension to ISO 27001
- ISO/IEC 42001 lead auditor qualification and any AIMS audit experience, accredited or unaccredited
- Empanelment with more than one certification body, or across more than one accreditation scheme (UKAS, ANAB, DAkkS, NABCB, IAS)
- Approval for a range of IAF/EA technical sectors
- Fluency with compliance platforms clients run on: Drata, Vanta, Thoropass, Secure Frame
- Technical reviewer or certification decision-maker experience
- ISO/IEC 20000-1, ISO 22301, ISO 9001, ISO 27017/27018 qualifications
- Valid passport; Schengen or US visa is a plus for occasional on-site work
- CISA, CISSP, CISM
- SOC 2 or CMMC experience
HOW TO APPLY
Apply through with your resume.
It will speed things up considerably if your application or resume mentions the certification body you worked with, the dates, your auditor grade with them, and roughly how many ISO 27001 audit days you performed as Lead Auditor. We verify certification body employment and audit logs before any contract is issued, so anything you can include up front shortens the process.
Audit Partners is an equal opportunity employer.
📌 ISO 27001 Lead Auditor (Certification Body Experience Required) (Thane)
🏢 AuditPartners
📍 Thane