ISO 28000 Supply Chain Security Management Systems Lead Auditor Course

Provided by: Professional Evaluation and Certification Board
ISO 28000 Supply Chain Security Management Systems Lead Auditor Course

Course Overview:

The ISO 28000 Supply Chain Security Management Systems Lead Auditor Course develops the practical knowledge required to plan, conduct, report, and manage audits of a Supply Chain Security Management System.

This ISO 28000 Lead Auditor Training covers ISO 28000 requirements, supply chain risk management, ISO 19011 audit guidelines, audit evidence, sampling, nonconformity reporting, corrective action, and SCSMS audit programme management. Participants examine how security policies, risk assessments, operational controls, emergency arrangements, monitoring, and continual improvement support effective supply chain security.

The course follows the seven lead auditor competency areas identified in the candidate handbook: SCSMS principles, ISO 28000 requirements, audit concepts, audit preparation, audit execution, audit closure, and audit programme management. Through case studies and audit simulations, participants learn how to conduct an ISO 28000 audit, prepare an ISO 28000 audit checklist, evaluate evidence, lead an audit team, and communicate clear audit conclusions.

 

Target Audience:

  • Lead auditors and internal auditors
  • Supply chain security managers
  • Logistics and transport managers
  • Risk and compliance professionals
  • Security and management system consultants
  • Quality and governance managers
  • Technical experts supporting SCSMS audits

 

Targeted Organizational Departments:

  • Internal Audit
  • Supply Chain and Logistics
  • Corporate Security
  • Risk and Compliance
  • Quality and Management Systems
  • Procurement and Supplier Management
  • Operations and Distribution
  • Business Continuity

 

Targeted Industries:

  • Logistics and freight forwarding
  • Shipping, ports, and maritime operations
  • Aviation and air cargo
  • Manufacturing
  • Warehousing and distribution
  • Oil, gas, and energy
  • Retail and e-commerce
  • Food and pharmaceutical supply chains
  • Government and critical infrastructure

 

Course Offerings:

By the end of this course, participants will be able to:

  • Interpret ISO 28000 requirements and SCSMS principles.
  • Apply ISO 19011 audit guidelines.
  • Plan first-party, second-party, and third-party audits.
  • Define audit scope, criteria, objectives, and resources.
  • Conduct Stage 1 and Stage 2 audits.
  • Collect and evaluate objective audit evidence.
  • Apply sampling and risk-based audit techniques.
  • Classify and document nonconformities.
  • Conduct opening and closing meetings.
  • Prepare clear ISO 28000 audit reports.
  • Evaluate corrective action plans.
  • Manage an SCSMS audit programme.

 

Training Methodology:

The ISO 28000 Lead Auditor Course combines instructor-led sessions with practical audit activities. Participants review ISO 28000 requirements, audit principles, supply chain security risks, and evidence-based auditing. Case studies help participants assess security controls, documentation, operational practices, and corrective actions. Group exercises focus on audit planning, checklist development, sampling, interviewing, and evidence evaluation. The course concludes with an integrated supply chain security audit simulation that allows participants to apply the full audit process from planning through reporting and follow-up.

 

Course Toolbox:

The course provides insights and examples of relevant tools rather than licensed tools or official certification-body documents.

  • ISO 28000 requirement guide
  • SCSMS risk register example
  • ISO 28000 audit checklist example
  • Stage 1 review checklist
  • Audit plan example
  • Audit working-paper examples
  • Interview question guide

 

Course Agenda:

Day 1: Understanding ISO 28000 and Supply Chain Security Requirements

  • Topic 1: Purpose, Scope, and Application of ISO 28000
  • Topic 2: Structure of a Supply Chain Security Management System
  • Topic 3: Identifying Supply Chain Stakeholders and Compliance Requirements
  • Topic 4: Assessing Security Threats, Vulnerabilities, and Supply Chain Risks
  • Topic 5: Developing Security Policies, Objectives, Targets, and Programmes
  • Topic 6: Establishing Operational Controls and Continual Improvement Processes
  • Reflection & Review: Connecting ISO 28000 Requirements to Supply Chain Operations

 

Day 2: Applying Audit Principles and Preparing the Audit

  • Topic 1: Applying ISO 19011 Principles to ISO 28000 Audits
  • Topic 2: Understanding Internal, Supplier, and Certification Audits
  • Topic 3: Maintaining Auditor Ethics, Independence, and Confidentiality
  • Topic 4: Defining Audit Objectives, Scope, Criteria, and Methods
  • Topic 5: Assessing Audit Feasibility and Assigning Audit Team Responsibilities
  • Topic 6: Preparing Audit Plans, Checklists, Working Papers, and Test Plans
  • Reflection & Review: Building a Practical Risk-Based ISO 28000 Audit Plan

 

Day 3: Conducting Stage 1 and Stage 2 ISO 28000 Audits

  • Topic 1: Conducting the Opening Meeting and Confirming Audit Arrangements
  • Topic 2: Reviewing SCSMS Documentation during the Stage 1 Audit
  • Topic 3: Verifying Control Implementation during the Stage 2 Audit
  • Topic 4: Collecting Evidence through Interviews, Observation, and Document Review
  • Topic 5: Applying Audit Sampling and Evaluating Evidence Reliability
  • Topic 6: Managing Audit Teams, Guides, Observers, and Difficult Situations
  • Reflection & Review: Determining Whether Audit Evidence Is Sufficient and Appropriate

 

Day 4: Developing Findings, Reports, and Follow-Up Actions

  • Topic 1: Comparing Audit Evidence against ISO 28000 Audit Criteria
  • Topic 2: Distinguishing Conformity, Observations, and Nonconformities
  • Topic 3: Writing Clear and Evidence-Based Audit Findings
  • Topic 4: Developing Audit Conclusions and Appropriate Recommendations
  • Topic 5: Conducting the Closing Meeting and Preparing the Audit Report
  • Topic 6: Evaluating Corrective Actions and Conducting Follow-Up Audits
  • Reflection & Review: Testing Audit Findings for Accuracy and Traceability

 

Day 5: Managing the SCSMS Audit Programme and Lead Auditor Practice

  • Topic 1: Establishing and Maintaining an SCSMS Audit Programme
  • Topic 2: Managing Audit Programme Risks, Resources, Records, and Confidentiality
  • Topic 3: Evaluating Auditor Competence and Audit Team Performance
  • Topic 4: Planning Combined and Integrated Management System Audits
  • Topic 5: Conducting a Complete ISO 28000 Audit Simulation
  • Topic 6: Solving Scenario-Based Lead Auditor Challenges
  • Reflection & Review: Consolidating the Complete ISO 28000 Audit Process

 

FAQ:

What specific qualifications or prerequisites are needed for participants before enrolling in the course?

Formal prerequisites are not mandatory. However, prior knowledge of ISO management systems, supply chain operations, security, risk management, or internal auditing is recommended.

How long is each day's session, and is there a total number of hours required for the entire course?

Each day's session is generally structured to last around 4–5 hours, with breaks and interactive activities included. The total course duration spans five days, approximately 20–25 hours of instruction.

What is the difference between an ISO 28000 internal auditor and a lead auditor?

An internal auditor usually conducts audits within one organization. A lead auditor plans and manages the full audit, leads the audit team, evaluates complex evidence, approves findings, conducts closing meetings, and oversees reporting and follow-up.

 

How This Course is Different from Other ISO 28000 Lead Auditor Courses:

This ISO 28000 Lead Auditor Training Course focuses on the complete audit lifecycle rather than general awareness. Participants move from interpreting ISO 28000 requirements to planning, conducting, closing, and managing SCSMS audits. The course is aligned with the seven competency areas identified in the candidate handbook. It also gives strong attention to practical audit work, including Stage 1 reviews, Stage 2 audits, audit checklists, sampling, evidence evaluation, nonconformity writing, corrective action, and audit programme management. 

Realistic scenarios strengthen professional judgement and prepare participants to manage supply chain compliance auditing across logistics, transportation, manufacturing, warehousing, and other security-sensitive operations.

credits: 5 credit per day

Course Mode: full-time

Provider: Agile Leaders Training Center

No Events Currently Scheduled

This course is available on demand. Contact us to arrange training dates that suit your schedule.

Contact Us
footer.svg