← Back to Blog
Industry

ISO 27001 Audit Time Calculation: Why the √-Method Trips Up Most CBs

2026-07-18 · 9 min read

Not Just Another Employee-Count Table

If you have calculated audit time for ISO 9001 or ISO 14001, you are familiar with the approach: look up the organization's effective number of personnel in IAF MD 5, find the corresponding audit time band, apply adjustments, and arrive at a total. The table is straightforward. The bands are defined. The logic is linear.

ISO 27001 is different.

The audit time calculation for information security management systems follows a distinct methodology that uses the square root of the effective number of personnel as a starting input, modifies it based on the complexity of the ISMS, and applies category-based adjustments that do not exist in the QMS or EMS frameworks. CBs that treat ISO 27001 audit time the same way they calculate 9001 or 14001 produce incorrect results, and those errors show up during accreditation assessments.

The Square Root Method Explained

For ISO 9001, audit time scales roughly linearly with organization size. A 100-person company requires more audit time than a 50-person company, and the relationship follows defined bands.

For ISO 27001, the relationship between organization size and audit time follows a square root curve. The base audit time is derived from √(effective number of personnel), which means that audit time increases more slowly as organization size grows. A company with 400 employees does not require four times the audit time of a company with 100 employees. It requires roughly twice the base time, because √400 = 20 and √100 = 10.

This mathematical relationship reflects the reality of information security auditing. Much of the ISMS audit focuses on policies, controls, risk assessment processes, and technical infrastructure that do not scale linearly with headcount. A 400-person company may have more users to sample, but it does not necessarily have four times as many information security policies.

ISMS Categories A Through D

ISO 27001 audit time calculation introduces a complexity categorization system that has no parallel in QMS or EMS auditing. Organizations are classified into categories based on the complexity of their information security environment:

  • Category A: Lowest complexity. Typically organizations with simple IT environments, limited external-facing systems, and straightforward information flows.
  • Category B: Moderate complexity. Organizations with multiple sites, moderate IT infrastructure, or some regulated data handling.
  • Category C: Higher complexity. Organizations with complex IT environments, significant external connectivity, multiple regulated data types, or software development activities.
  • Category D: Highest complexity. Organizations operating critical infrastructure, financial services platforms, extensive cloud environments, or systems with high availability requirements.

The category selection directly affects the audit time multiplier. A Category D organization requires significantly more audit time than a Category A organization of the same size. Getting the category wrong in either direction creates problems: too low means insufficient audit coverage, too high means the client pays for audit time they do not need.

Where Manual Calculations Go Wrong

The combination of the square root base, category-based multipliers, and additional adjustment factors creates a calculation that is more complex than most planners realize. Common errors include:

Applying QMS bands to 27001. A planner accustomed to ISO 9001 looks up the employee count in the IAF MD 5 table and uses those audit days for the 27001 quote. The result is usually wrong, sometimes significantly. The methodologies are fundamentally different.

Incorrect category selection. Category assignment requires judgment about the organization's IT complexity. A planner who defaults to Category B for every client will overestimate audit time for simple environments and underestimate it for complex ones. Both outcomes create problems during accreditation review.

Forgetting the Stage 1 to Stage 2 ratio. ISO 27001 has a specific expected split between Stage 1 and Stage 2 audit time. The total audit days need to be allocated correctly between the two stages. Planners who calculate a total and split it arbitrarily may produce a Stage 1 that is too short for adequate documentation review or a Stage 2 that is too compressed for control verification.

Mishandling multi-site adjustments. When the client has multiple locations, the sampling approach for ISO 27001 differs from QMS multi-site sampling. The calculations layer on top of the already-complex base methodology.

Rounding errors. The square root function produces decimal results. Different rounding approaches at different steps of the calculation can produce different final audit times. A planner rounding up at one step and down at another introduces inconsistency.

How Certiva Handles It

Certiva's audit time calculator implements the ISO 27001 methodology as a deterministic algorithm. The planner inputs the effective number of personnel and selects the ISMS category. The system applies the square root base calculation, the category multiplier, and any applicable adjustments. The output is a correctly calculated audit time with the Stage 1 and Stage 2 split applied per the methodology.

The calculator does not guess. It does not approximate. It applies the published methodology exactly, every time. When the accreditation body reviews how audit time was determined, the CB can demonstrate that the calculation followed the prescribed method and that the system enforced it consistently across all ISO 27001 audits.

The same calculator handles audit time for ISO 9001, ISO 14001, ISO 45001, ISO 22000, ISO 13485, and other standards, each applying its own methodology. The planner does not need to remember which method applies to which standard. The system knows.

Why Consistency Matters for Accreditation

Accreditation bodies review audit time calculations as part of their office assessments. They pull sample files and check whether the calculated time matches the methodology. When a CB uses manual calculations, inconsistencies between files are common. Different planners apply different rounding. Different clients get different treatment for similar profiles.

When the calculation is system-driven, every file shows the same methodology applied the same way. This consistency is itself evidence of a functioning management system. The CB can demonstrate that audit time is not a negotiation or an estimate. It is the output of a validated calculation.

Ready to eliminate audit time calculation errors?

Book a demo at getcertiva.com and see how Certiva's deterministic calculator handles ISO 27001 and every other standard your CB certifies.