ISO 28000:2022 Security Management Systems - Lead Auditor Course
- Description
- Curriculum

Course Overview
Welcome to QGlobal Academy!
Our ISO 28000 Lead Auditor Course is a comprehensive, professional training program designed to equip participants with the knowledge and practical skills required to audit a Supply Chain Security Management System (SCSMS) in accordance with ISO 28000 standard. ISO 28000 Lead Implementer Course provides an in-depth understanding of the standard’s requirements, risk-based thinking, and security controls necessary to safeguard supply chain operations against threats such as terrorism, theft, piracy, and disruptions.
Participants will gain detailed insights into audit principles based on ISO 19011 guidelines for management system auditing. The course combines theoretical knowledge with practical audit exercises, case studies, and real-world scenarios to ensure participants are capable of planning, conducting, reporting, and following up on first-party, second-party, and third-party audits.
By the end of this ISO 28000 Lead Auditor Training, learners will be able to confidently lead audit teams, assess compliance, identify risks and vulnerabilities in supply chains, and add value to organizations by enhancing security performance and resilience.
Who Should Attend
This ISO 28000 lead auditor training is ideally suited for professionals involved in supply chain operations, security management, and auditing activities. It is particularly beneficial for individuals seeking to develop or advance their careers as certified lead auditors.
The course is recommended for:
- Supply Chain Managers and Logistics Professionals responsible for secure operations
- Security Managers and Risk Management Professionals
- Internal Auditors and Existing Lead Auditors transitioning to ISO 28000
- Quality, HSE, and Compliance Professionals
- ISO 28000 Consultants and Trainers in management systems
- Professionals working in ports, shipping, oil & gas, manufacturing, warehousing, and transportation sectors
- Individuals seeking internationally recognized auditor certification in supply chain security
Prior knowledge of management systems or auditing principles is helpful but not mandatory, as the course covers foundational to advanced concepts.
Benefits of ISO 28000 Lead Auditor Course
Completing the ISO 28000 Lead Auditor Course provides significant professional and organizational advantages. Participants will gain the competence to conduct effective audits and contribute to strengthening supply chain security frameworks.
Key benefits include:
- Comprehensive understanding of ISO 28000 requirements and implementation
- Ability to plan, conduct, and lead SCSMS audits in accordance with international standards
- Enhanced skills in identifying supply chain risks, threats, and vulnerabilities
- Improved career prospects with globally recognized lead auditor qualification
- Practical exposure through case studies, audit simulations, and real-life scenarios
- Strengthened capability to ensure regulatory compliance and stakeholder confidence
- Contribution to organizational resilience, risk reduction, and operational continuity
This ISO 28000 lead auditor course ultimately empowers professionals to become trusted auditors and advisors in securing global supply chains.
Learning & Evaluation method
Our courses are designed as self-paced learning programs, allowing you to study anytime, anywhere at your own convenience. You can progress through the modules based on your schedule, making it ideal for working professionals and flexible learners.
For those who prefer guided learning, we also offer an option to upgrade to a live instructor-led course for an additional fee. This includes real-time sessions, expert interaction, doubt clarification, and practical insights to enhance your learning experience.
Certification
Upon successful completion of the course, participants will be awarded a course certificate issued by QGlobal.
Furthermore, your credentials will be listed in our online directory, where they can be verified by anyone using your unique certificate number. This ensures transparency and authenticity of your qualification. Our training programs are widely recognized and valued by organizations across various industries and geographical regions.
Sample Certificate

-
1ISO 28000 Introduction
-
2ISO 28000 Context of the organization
ISO 28000:2022 – Clause 4: Context of the Organization
This lesson introduces how organizations establish the foundation of a supply chain security management system by understanding their operating environment. It covers identifying internal and external issues, recognizing stakeholder expectations, defining the scope, and establishing the overall structure of the system to support effective security management.
Clauses Covered under Clause 4
Clause 4.1 – Understanding the organization and its context
Clause 4.2 – Understanding the needs and expectations of interested parties
Clause 4.2.1 – General
Clause 4.2.2 – Legal, regulatory and other requirements
Clause 4.2.3 – Principles
Clause 4.3 – Determining the scope of the security management system
Clause 4.4 – Security management system -
3ISO 28000 Leadership
ISO 28000:2022 – Clause 5: Leadership
This lesson explains the critical role of leadership in establishing and maintaining an effective supply chain security management system. It focuses on top management’s responsibility to demonstrate commitment, establish a security policy, and assign clear roles, responsibilities, and authorities to ensure the system is effectively implemented and aligned with organizational objectives.
Clauses Covered under Clause 5
Clause 5.1 – Leadership and commitment
Clause 5.2 – Security policy
Clause 5.3 – Roles, responsibilities and authorities -
4ISO 28000 Planning
ISO 28000:2022 – Clause 6: Planning
This lesson focuses on how organizations plan their supply chain security management system using a risk-based approach. It covers identifying and addressing security risks and opportunities, establishing measurable security objectives, and planning changes to ensure the system remains effective and aligned with evolving threats and business needs.
Clauses Covered under Clause 6
Clause 6.1 – Actions to address risks and opportunities
Clause 6.1.1 – General
Clause 6.1.2 – Determining security-related risks and identifying opportunities
Clause 6.1.3 – Addressing security-related risks and exploiting opportunities
Clause 6.2 – Security objectives and planning to achieve them
Clause 6.2.1 – Establishing security objectives
Clause 6.2.2 – Planning to achieve security objectives
Clause 6.3 – Planning of changes -
5ISO 28000 Support
ISO 28000:2022 – Clause 7: Support
This lesson explains the support elements required to effectively implement and maintain the supply chain security management system. It covers resources, competence, awareness, communication, and control of documented information to ensure that personnel, infrastructure, and information systems support security objectives and operational effectiveness.
Clauses Covered under Clause 7
Clause 7.1 – Resources
Clause 7.2 – Competence
Clause 7.3 – Awareness
Clause 7.4 – Communication
Clause 7.5 – Documented information
Clause 7.5.1 – General
Clause 7.5.2 – Creating and updating
Clause 7.5.3 – Control of documented information -
6ISO 28000 Operation
ISO 28000:2022 – Clause 8: Operation
This lesson focuses on the operational implementation of the supply chain security management system. It explains how organizations identify critical processes, establish operational controls, conduct risk assessments at the operational level, implement security measures, and develop security plans to effectively manage and respond to security threats and disruptions.
Clauses Covered under Clause 8
Clause 8.1 – Operational planning and control
Clause 8.2 – Identification of processes and activities
Clause 8.3 – Security risk assessment and treatment
Clause 8.4 – Controls
Clause 8.5 – Security strategies, procedures, processes and treatments
Clause 8.5.1 – Identification and selection of strategies and treatments
Clause 8.6 – Security plans
Clause 8.6.1 – General
Clause 8.6.2 – Requirements for security plans
Clause 8.6.3 – Testing and updating of security plans
Clause 8.6.4 – Content of security plans -
7ISO 28000 Performance evaluation
ISO 28000:2022 – Clause 9: Performance Evaluation
This lesson explains how organizations evaluate the performance and effectiveness of the supply chain security management system. It covers monitoring and measurement, internal audits, and management review to ensure that security controls are functioning as intended and that continual improvement is achieved.
Clauses Covered under Clause 9
Clause 9.1 – Monitoring, measurement, analysis and evaluation
Clause 9.2 – Internal audit
Clause 9.3 – Management review -
8ISO 28000 Improvement
ISO 28000:2022 – Clause 10: Improvement
This lesson focuses on how organizations improve the effectiveness of their supply chain security management system. It explains the processes for handling nonconformities, taking corrective actions, and driving continual improvement to enhance security performance and resilience against evolving threats.
Clauses Covered under Clause 10
Clause 10.1 – Nonconformity and corrective action
Clause 10.2 – Continual improvement
-
9LI 01 Building the team
-
10LI 02 Conducting gap analysis
-
11LI 03 Preparing milestones and timelines
-
12LI 04 Creating awareness
-
13LI 05 Conducting trainings
-
14LI 06 Identifying documentation requirements
-
15LI 07 Creating management system manual
-
16LI 08 Creating policies and procedures
-
17LI 09 Creating forms and templates
-
18LI 10 Planning certification audits
-
19LI 11 Implementation methodology
-
20LI 12 Role of leadership in implementing the management system
-
21LI 13 Employee motivation and involvement
-
22LI 14 Obstacles in implementing the management system
-
23ISO 19011 Introduction
This lesson introduces ISO 19011, the international guideline for auditing management systems. It explains the purpose, scope and importance of audits.
-
24ISO 19011 Terms & definitions
This lesson introduces the key terminology used in ISO 19011 for auditing management systems. It explains essential concepts such as audit, audit criteria, audit evidence, findings, and audit results, along with roles like auditor, auditee, and audit team. The lesson also covers terms related to audit planning and execution, including audit programme, scope, and plan, as well as newer concepts like remote auditing methods. Understanding these definitions ensures clear communication, consistent interpretation, and effective implementation of auditing practices.
-
25ISO 19011 Principles of auditing
This lesson explains the fundamental principles of auditing defined in ISO 19011:2026, which ensure audits are credible, objective, and reliable. It covers key principles such as integrity, fair presentation, due professional care, confidentiality, independence, and evidence-based approach, along with the risk-based approach to auditing. Learners understand how these principles guide auditor behavior, decision-making, and audit outcomes, forming the foundation for conducting effective and trustworthy management system audits.
-
26ISO 19011 Managing audit programme
This lesson introduces how to establish, implement, monitor, and improve an audit programme in accordance with ISO 19011.
It explains the need to align the programme with organizational objectives, risks, and priorities, and covers key aspects such as defining scope, assigning responsibilities, allocating resources, and scheduling audits. The lesson also highlights the importance of monitoring performance, evaluating effectiveness, and driving continual improvement, ensuring the audit programme remains efficient, risk-based, and value-adding.
-
27ISO 19011 Conducting audit
This lesson explains the process of planning and carrying out an audit in line with ISO 19011 standard. It covers key stages such as initiating the audit, preparing audit plans, conducting audit activities, collecting and verifying evidence, and communicating findings. The lesson also emphasizes effective interaction with the auditee, use of appropriate audit methods (including remote auditing), and maintaining objectivity throughout the audit. Learners gain an understanding of how to ensure audits are systematic, evidence-based, and result-oriented.
-
28ISO 19011 Auditor competence
This lesson explains the competence requirements for auditors as defined in ISO 19011. It covers the necessary knowledge, skills, and personal attributes required to perform effective audits, including understanding of management system standards, audit principles, and industry-specific processes. The lesson also addresses evaluation of auditor competence, ongoing development, and maintaining proficiency, ensuring auditors can conduct audits that are credible, consistent, and value-adding.
-
29Introduction to ISO 19011 Guidelines for auditing management systems
- Scope
- Normative references
- Terms and definitions
-
30ISO 19011 Principles of auditing
-
31ISO 19011 Managing an audit program
- Establishing audit programme objectives
- Determining and evaluating audit programme risks and opportunities
- Establishing the audit programme
- Roles and responsibilities of the individual(s) managing the audit programme
- Competence of individual(s) managing audit programme
- Establishing extent of audit programme
- Determining audit programme resources
- Implementing audit programme
- Defining the objectives, scope and criteria for an individual audit
- Selecting and determining audit methods
- Selecting audit team members
- Assigning responsibility for an individual audit to the audit team leader
- Managing audit programme results
- Managing and maintaining audit programme records
- Monitoring audit programme
- Reviewing and improving audit programme
-
32ISO 19011 Conducting an audit
- Initiating audit
- Establishing contact with auditee
- Determining feasibility of audit
- Preparing audit activities
- Performing review of documented information
- Audit planning
- Assigning work to audit team
- Preparing documented information for audit
- Conducting audit activities
- Assigning roles and responsibilities of guides and observers
- Conducting opening meeting
- Communicating during audit
- Audit information availability and access
- Reviewing documented information while conducting audit
- Collecting and verifying information
- Generating audit findings
- Determining audit conclusions
- Conducting closing meeting
- Preparing and distributing audit report
- Preparing audit report
- Distributing audit report
- Completing audit
- Conducting audit follow-up
-
33ISO 19011 Competence and evaluation of auditors
- Determining auditor competence
- Personal behavior
- Knowledge and skills
- Achieving auditor competence
- Achieving audit team leader competence
- Establishing auditor evaluation criteria
- Selecting appropriate auditor evaluation method
- Conducting auditor evaluation
- Maintaining and improving auditor competence
-
34ISO 19011 Auditor training practice questions
-
35ISO 28000 Awareness training - Final examExamination and Assessment Guidelines The examination is designed to evaluate the participant’s understanding of the course content, key concepts, and practical application of the relevant standard.Eligibility and Access Participants are eligible to take the examination any time after successfully completing the course. The exam can be accessed at the learner’s convenience through the learning platform.Passing Criteria Participants must achieve a minimum score of 50% to successfully pass the examination. The scoring is based on correct responses to multiple-choice questions and/or scenario-based assessments, depending on the course structure.Examination Duration The total duration of the examination is 60 minutes. Candidates are required to complete all questions within the allotted time. The timer will begin once the examination is launched and cannot be paused.Retake Policy Participants who do not achieve the minimum passing score are allowed to retake. There is no waiting period for retake.
