In short
Lead Implementer if you need to build the information security management system: scope, risk assessment, statement of applicability, treatment plan. Lead Auditor if you need to verify it, internally or at suppliers. A company seeking certification needs the former; a company auditing its supply chain needs the latter.
Lead Implementer
ISO/IEC 27001 Lead Implementer
Set up and run an information security management system.
Best for: CISOs, compliance project leads, teams aiming for certification.
Lead Auditor
ISO/IEC 27001 Lead Auditor
Plan and run an audit of an information security management system.
Best for: Internal auditors, quality managers, procurement teams assessing suppliers.
The comparison, criterion by criterion
| Criterion | Lead Implementer | Lead Auditor |
|---|---|---|
| Verb of the role | Build | Verify |
| Typical deliverable | Statement of applicability, risk treatment plan | Audit report and findings |
| Project stage | Before certification | During and after, as surveillance |
| Core skill | Risk analysis and control trade-offs | Audit technique, sampling, evidence |
| Use beyond certification | Structures security even without seeking the certificate | Useful to assess suppliers and subcontractors |
How to decide
Lead Implementer
Choose Lead Implementer if nobody in-house could currently define the management system's scope.
Lead Auditor
Choose Lead Auditor if your challenge is to control, internally or at your providers.
Matching training courses
Lead Implementer
Security standards & governance · 4 days · Remote
Security standards & governance · 1 day · Remote
ERP, CRM & business tools · 1 day · Remote
Lead Auditor
Security standards & governance · 2 days · Remote
Backend & APIs · 3 days · Remote
Blockchain & Web3 · 4 days · Remote
Frequently asked questions
- Do you need the certification to lead an ISO 27001 programme?
- No, the standard certifies the organisation, not the individual. In practice, a trained lead shortens the programme considerably and avoids scoping mistakes, which are the most expensive to fix.
- Can the same person implement then audit?
- Not on the same scope: auditing your own work strips the finding of value. In a group, the usual practice is to have one entity audited by another.
Still undecided?
Describe your context in two lines and we come back with a reasoned recommendation and a quote within 48 hours.