How much does ISO 22301 Lead Auditor training cost in Australia?
$980 + GST self-paced, or $1,060 + GST with guided eLearning. The official PECB examination voucher and two attempts are included, along with 12 months of myPECB access, over 400 pages of course material and 31 CPD credits. The course is equivalent to five days of classroom training, and there is no separate ISO 22301 exam cost.
Compare that against classroom-based ISO 22301 training in Australia, which commonly runs from $2,695 for a three-day Foundation course and past $3,295 for Lead level — before travel and time away from work. Two things are worth checking on any quote. First, which body issues the certificate. Aegentra Academy is an official PECB authorised training partner, and Accreditation is program- and scope-specific; verify the applicable credential before enrolment. Several Australian business continuity courses certify against IRCA, the BCI (CBCI) or GAQM instead — those are different credentials, not cheaper versions of the same one. Second, whether the exam is included. A course fee with the examination billed separately is not the figure you end up paying.
What is on the ISO 22301 Lead Auditor exam?
80 multiple-choice questions across 7 competency domains, open book, 3 hours, 70% to pass. The seven domains follow the audit lifecycle:
- Fundamental principles and concepts of a business continuity management system
- Business continuity management system requirements
- Fundamental audit concepts and principles
- Preparing an ISO 22301 audit
- Conducting an ISO 22301 audit
- Closing an ISO 22301 audit
- Managing an ISO 22301 audit programme
Note that domains 3 to 7 do not appear on the Lead Implementer paper at all — that exam follows the implementation lifecycle instead. Same question count, same format, different ground. The course is taught against ISO 19011 (auditing management systems) and ISO/IEC 17021-1 (requirements for certification bodies).
Internal auditor or lead auditor — which do you need?
Different jobs, and the distinction decides which course to buy.
An internal auditor audits their own organisation’s BCMS against Clause 9.2, checking that what the plans claim is what actually happens — before a certification body arrives. The course covers this audit context; competence, independence, experience and organisational requirements still apply.
A lead auditor plans and leads audits of other organisations — as a consultant, in supplier assurance, or on a certification body assessment team. That is what ISO/IEC 17021-1 competence requirements exist for, and it is the ground domains 4 to 7 cover. There is no separate PECB "internal auditor" credential for ISO 22301; the Lead Auditor course covers both contexts, and the credential awarded depends on attested audit experience.
What does a BCMS auditor actually test?
Business continuity audits fail in predictable places, and knowing them is most of the job.
The business impact analysis. Was it done on activities or on systems? A BIA that lists servers rather than the things the organisation does cannot produce a defensible recovery time objective.
Whether the plan has been exercised. Clause 8.5 requires it. An untested business continuity plan (BCP) is an assumption, and the exercise record is the first thing to request.
Whether RTO and RPO are achievable. Stating a four-hour RTO is easy; evidencing a four-hour recovery is not. Where disaster recovery capability has never been failed over end to end, the objective is aspiration rather than fact.
Supplier dependency. Clause 8.3 covers it, and supply chain disruption is where most modern outages actually originate — a critical single-source provider with no alternative and no contractual right to audit.
Who hires ISO 22301 auditors in Australia?
Demand concentrates in four places, and APRA CPS 230 is behind most of it. The prudential standard requires regulated entities to identify critical operations, set tolerance levels and test them — which creates internal audit work, second-line assurance work, and external review work.
The four: internal audit and operational risk teams in APRA-regulated entities; supplier assurance functions testing whether critical providers can actually recover; consultancies running pre-certification reviews; and certification body assessment teams, where ISO/IEC 17021-1 competence requirements make the credential close to mandatory. The SOCI Act adds the same pressure across critical infrastructure, and operational resilience is increasingly its own job title.
Free audit documents to work through with the course
The artefacts an auditor asks for first, published in full and free.
Building a BCMS rather than auditing one is the Lead Implementer track. For organisational certification, see the ISO 22301 certification guide for Australia.