Professional track
ISO/IEC 27701 Auditor
Develop the skills to plan, conduct and evaluate audits against ISO/IEC 27701 in real organisational contexts
Auditing privacy management beyond legal documentation
By focusing on governance, risk treatment and operational evidence, this track builds the capability to assess whether a Privacy Information Management System is effective, consistent and sustainable.
Overview
What this track is about
A modular training programme for privacy auditors. Learn to audit ISO/IEC 27701 Privacy Information Management Systems by assessing accountability, risk treatment and operational data protection practices.
The ISO/IEC 27701 Auditor Track is designed for professionals who audit Privacy Information Management Systems (PIMS) of organisations acting as controllers and/or processors. Rather than treating privacy audits as a review of policies or legal documentation, the programme focuses on evaluating how privacy requirements are governed, implemented and monitored in practice.
The track covers the full audit life cycle and enables effective PIMS audits in internal auditing, supplier auditing as well as third-party auditing contexts.
Audience
Who it is for
The ISO/IEC 27701 Auditor Track equips professionals to plan, conduct, and report audits of Privacy Information Management Systems (PIMS) against the requirements of ISO/IEC 27701.
Auditors with existing ISO/IEC 27001 experience who want to extend their competence to privacy information management systems
Internal or external auditors involved in audits covering data protection and privacy controls
Information security or data protection professionals seeking to develop formal PIMS auditing capability
Practising ISO/IEC 27701 auditors who want to strengthen their understanding of audit boundaries, scope definition, and evidence evaluation in privacy-related audits
Outcomes
Learning outcomes
4 capability areas. Each is assessed on the case organisation before the credential is issued, not on a multiple-choice paper.
Understand and interpret ISO/IEC 27701 requirements
Interpret ISO/IEC 27701 requirements consistently across different organisational contexts
Understand the structure and practical application of PIMS
Plan and conduct audits in a structured manner
Plan and perform internal, supplier and third-party PIMS audits in accordance with ISO 19011
Apply appropriate audit techniques to obtain objective and verifiable audit evidence
Evaluate conformity and audit findings professionally
Evaluate conformity of a PIMS against ISO/IEC 27701 requirements and defined audit criteria
Formulate clear, well-founded audit findings and nonconformities
Communicate audit results and support improvement
Communicate audit results professionally to auditees and management
Support improvement of privacy governance and controls through clear, actionable audit feedback
Professional positioning
Build a recognised competence profile as an auditor for ISO/IEC 27701 across different organisational contexts
Assess privacy information management systems in a structured, independent and standard-compliant manner, and substantiate audit findings professionally
Act as a competent professional counterpart to organisations, management, certification bodies and other auditors
Credentials
Scalable credential model
Halderstone tracks follow a two-credential model that mirrors their modular structure. Both are awarded without expiry.
Core credential
Diploma in Management System Auditing
Cross-domain management system foundation: the 17 core modules
Applicable across every ISO standard we teach
Reusable across every further specialisation in the same role
Specialisation credential
Halderstone Certified ISO/IEC 27701 Auditor
Fundamentals of data protection management
Ability to audit ISO/IEC 27701-specific requirements
Registered credentials
Once the specialisation credential is held, a Registered credential can be applied for. These confirm verified professional experience alongside the qualification, and keep it current through periodic reassessment.
Registered credentials: Halderstone Certified ISO/IEC 27701 Auditor
The following Registered credentials can be applied for:
Registered Associate Auditor in ISO/IEC 27701 Auditing
Registered Professional Auditor in ISO/IEC 27701 Auditing
Registered Lead Auditor in ISO/IEC 27701 Auditing
Registered Senior Lead Auditor in ISO/IEC 27701 Auditing
Application requires meeting the experience requirements for the respective level.
For employers
How Halderstone credentials translate into capability signals in hiring, role design and professional practice, including what each one does and does not evidence.
Track price
CHF 8,000
All 20 modules, the capstone and the examination
No VAT is charged.
Start with a single module at any time · credited in full if you continue
Bought from us before? Sign in to see the modules you already hold.
Track facts
- Track ID
- HAT-DP-A
- Discipline
- Data Protection
- ISO standard
- ISO/IEC 27701
- Target audience
- Management System Auditor
Modular approach
The core carries into every discipline
The 17 core modules are the same in every auditor track. Completing them here means they are never repeated, never re-assessed and never paid for again, which is what makes a second track short and why most of this one is not about data protection.
Core modules
Auditor capabilities across disciplines
17 modules · shared by every auditor track
Awarded as the Diploma in Management System Auditing: the credential you keep whichever discipline you specialise in.
Specialisation · 2–4 modulesHighlighted: this track
A second auditor track is 2–4 modules, not 20
Its specialisation modules, a capstone and an exam, whenever you want them, with no time limit on the core you completed here.
Curriculum
How the modules fit together
Every module is self-contained. There is no fixed order and no schedule: take them in whatever sequence your work makes useful, at whatever pace you can sustain. The grouping below is how we would sequence them if you have no reason to do otherwise.
Core
Shared with every auditor track. Complete them once and they count towards any further qualification in the same role.
ISO/IEC 27701 Auditing
These modules carry the same audit work into ISO/IEC 27701. The method does not change; the material does. What counts as evidence, which controls are worth sampling and where a system of this kind usually fails are specific to the standard. The aim is an audit of the system as it operates, not of the system as it is documented.
The capstone engagement
Practical application of the acquired auditing competencies
Demonstrates ability to audit a PIMS according to ISO/IEC 27701 in a real-world scenario
Based on case proposed by the candidate or provided by Halderstone
The final examination
Confirms solid and actionable understanding of data protection management principles and ability to audit a PIMS based on ISO/IEC 27701
Covers all core and specialization modules of the track
Method
How you learn it
Two things separate knowing a standard from being able to audit a management system against it: what is trained, and what it is trained on.
Practical reflexes, not topics covered
Every module is built around practical reflexes rather than around a list of topics. A practical reflex is what a practitioner asks and does without being prompted, under pressure: whether an owner can actually act, whether an exposure is being accepted or merely tolerated, whether the criteria in use can carry the decisions they are asked to carry, and then the move that follows from the answer. Topics can be listed after a course; reflexes show up in the next review, the next escalation and the next signature. Each one is developed in the written module, practised on the case organisation’s own material, and assessed in graded exercises that must be passed before the certificate is issued.
Three examples from this track’s modules:
Real ownership and escalation
Test whether a named owner actually holds the authority and the resources to act, keep risk, control and treatment ownership apart, and recognise when an exposure needs escalating as a decision request rather than another status update.
Residual exposure and explicit acceptance
See where exposure is being carried rather than treated, accept that an organisation may run exposure deliberately to pursue its objectives, and insist that such acceptance is named, dated, reasoned and signed instead of arriving by inertia.
Risk criteria and acceptance authority
Design impact, likelihood and acceptance criteria proportionate to the organisation's size and decision needs, with named acceptance authority, escalation thresholds and a review cadence, and recognise the defects that make a framework unusable: scales that cannot be compared across units, criteria without decision consequence, and rules copied from elsewhere that nobody applies consistently.
Trained on one organisation
Exercises run on Northstar Integrated Services AG, a Zurich company that provides digital operations platforms and managed operational services to organisations in healthcare, the public sector, industry and energy.
One organisation, carried across modules
Northstar has a management system with the wear of a real one. Authority is not always where the org chart puts it. The founder stepped off the board years ago and teams still seek his signal on the calls that matter. The decision log he kept personally faded out during a growth phase and nothing replaced it. You work that organisation rather than a tidy example, and the exercises are marked on what you did with it.
It has a timeline
Governance changes as the company grows, suppliers move through their lifecycle, and modules travel into earlier windows as well as later ones
Nothing resets between modules
The state you leave the organisation in is the state the next module finds it in
Why it matters
Judgement cannot be trained on tidy examples, and it cannot be trained on a fresh one each week. Because the modules work the same organisation, they compound into one continuous engagement rather than a series of disconnected courses.
Related track
The same discipline, the other role
The same discipline is taught from the manager’s side as well. That track rests on a different core and carries its own specialisation modules, capstone and examination, so the two qualifications are earned separately.
Track price
CHF 8,000
20 modules, the capstone and the examination
Getting it signed off
Most people pay for this from a training budget. This page is written to be forwarded to whoever approves it: what the qualification covers, what it costs and what it changes in the role are all on it. If your approver needs something the page does not answer, ask us.
Not sure this is the one?
Start with a single module and have it credited in full later. If the work is running and improving your own management system rather than assessing other people’s, the manager track is the one. Tell us the situation and we will say which, honestly.