Audit Time Calculation
Audit time calculation is the process a certification body uses to estimate how many days an audit should take. The estimate depends on factors such as the size, complexity, risk profile, and nature of the organization being audited. Because these factors differ from one organization to another, the calculated time varies for each engagement.
Audit time calculation refers to the methodology by which an accredited certification body (or, in the ISO 27001 context, the body conducting the ISMS certification audit) determines the number of auditor-days required for an audit. In most engagements the calculation is driven by variables including organizational size (often measured by effective headcount), the complexity of processes and technology, the assessed risk, and the nature of the organization's activities. The result is not a fixed figure; it is derived per engagement and adjusted based on scope, and specific determination criteria may follow sector-specific procedures (for example, those defined for medical device schemes). Note that this concept as documented in the available evidence relates to management-system and quality-scheme audits rather than to a SOC 2 attestation examination, where the effort estimate is instead set by the CPA firm based on the defined scope and Trust Services Criteria selected.
Why it matters
Audit time calculation directly affects the cost, scheduling, and credibility of a certification engagement. In the ISO 27001 context, the number of auditor-days a certification body allocates determines how thoroughly an ISMS can be examined; too little time may undermine the depth of assurance, while an accurate estimate helps ensure the audit adequately samples the organization's processes, technology, and risk landscape. Because the calculation is driven by variables such as organizational size, complexity, risk, and the nature of activities, two organizations pursuing the same standard can receive materially different audit-day estimates.
For organizations planning a certification, understanding how audit time is derived helps set realistic budget and resourcing expectations and reduces surprises during scoping discussions with a certification body. It also underscores that the estimate is engagement-specific and adjusted based on scope rather than a fixed figure that can be assumed in advance. In certain sector-specific schemes, such as medical device programs, the determination of audit time may follow dedicated procedures, so the applicable methodology depends on the scheme under which the audit is conducted.
It is important to note the boundary of this concept. As documented in the available evidence, audit time calculation relates to management-system and quality-scheme audits (for example, ISO-family certifications and medical device schemes) rather than to a SOC 2 attestation examination. In a SOC 2 engagement, the effort estimate is instead set by the CPA firm based on the defined scope and the Trust Services Criteria selected, so the specific audit-time methodologies described here do not transfer directly to that attestation context.
Who it's relevant to
Inside Audit Time Calculation
Common questions
Answers to the questions practitioners most commonly ask about Audit Time Calculation.