Skip to main content
Aegentra
On this page

Official PECB training

ISO 27001 Lead Auditor Course Australia

The PECB ISO 27001 Lead Auditor course teaches you to plan, conduct, report and follow up audits of an ISO/IEC 27001:2022 information security management system. Aegentra Academy, an official PECB training partner in Australia, offers it as Self-Study at A$829, PECB eLearning at A$849, or one-to-one live online training at A$2,799, all excluding GST. The official examination and one free resit are included.

Learn to plan, conduct, report and follow up audits of an ISO/IEC 27001:2022 information security management system. Choose official PECB Self-Study, recorded eLearning or private one-to-one online training with Aegentra Academy.

Study online from Melbourne, Sydney, Brisbane, Perth or elsewhere in Australia, with options for learners across APAC. Private teaching dates and time zones are agreed before booking.

Official PECB course materials · Examination included · Practical audit examples

Standard
ISO/IEC 27001:2022
Official course creator
PECB
Learning formats
Self-Study, eLearning and private online training
Typical self-paced effort
30–40 hours
Read learner feedback

Choose how you want to learn

Self-Study and PECB eLearning are available online through myPECB. Compare the learning format, choose your currency and review the total before payment. Private one-to-one training is arranged separately by enquiry.

This course suits internal auditors, information security and GRC professionals, supplier-assurance practitioners and ISMS managers who need to evaluate an information security management system. It expects an understanding of ISO 27001 and audit principles; review the prerequisites in the curriculum section if you are new to either.

Choose your self-paced learning format

Included with both self-paced options

  • Official PECB course materials and the applicable myPECB access arrangements.
  • The initial official PECB examination attempt and certification application fee.
  • One free examination retake within the applicable PECB cycle.

Allow approximately 30–40 hours for self-paced learning. This is Aegentra’s estimated workload, not video runtime, examination duration or a guaranteed completion time. Confirm the access and examination expiry dates attached to your purchase in myPECB.

For qualifying partner-course purchases, PECB’s current policy also includes the first year of the Annual Maintenance Fee where applicable. Continuing credential requirements depend on the tier and PECB’s current policies.

Prefer individual guidance? Explore private one-to-one training with PECB eLearning, a separate audit-consultant session and one month of Labs practice. See the one-to-one option →

One-to-one ISO 27001 Lead Auditor training

Private online training

Learn privately with Dr Harbir Singh, whose PECB trainer record lists ISO/IEC 27001 Lead Auditor authorisation in English. Work through audit planning, evidence collection, findings and reporting with live explanation and discussion, then connect the methodology to practical work in a separate consultant session.

A$2,799 excluding GST per learner

A$3,078.90 including Australian GST.

  • 24 teaching hours — four days of six-hour sessions, or eight days of three-hour sessions; the learner chooses
  • Official PECB eLearning alongside the live sessions
  • One 60-minute session with an Aegentra audit consultant
  • One month of free Aegentra Labs access for this qualification
  • Official PECB exam voucher and one free resit within 12 months
  • Teaching dates agreed with your trainer and consultant before booking

The free resit is subject to PECB’s applicable 12-month cycle, waiting periods and booking rules. Your written booking confirmation identifies the cycle that applies to the private package.

Connect the course to practical audit work

Bring an audit question or work through a learning example. Discuss how objectives and scope determine the evidence you request, how sampling affects your conclusions, and how to write a finding that connects a requirement to objective evidence.

The private package also includes one month of Aegentra Labs practice for ISO 27001 Lead Auditor, with unlimited attempts at the available practice questions during that period. This included month is separate from the optional A$89 + GST purchase for 12 months. Unlimited practice attempts do not mean unlimited official examination attempts.

The consultant session is educational guidance, not an audit engagement or a certification decision. Avoid including confidential client information in your enquiry.

Your live trainer

Dr Harbir Singh is the instructor named for this live course. His course-specific PECB trainer authorisation and professional credentials can be checked through the linked records. PECB’s recorded eLearning faculty is separate from the instructor assigned to your private class.

Contact us for one-to-one training

Tell us your preferred timing, time zone and learning goal. We confirm the assigned trainer and applicable authorisation, teaching timetable, consultant session, eLearning and Labs access, examination arrangements and booking terms in writing before payment.

Aegentra can provide an Australian tax invoice and discuss multi-seat or private organisational delivery; dates and team terms are confirmed before payment.

The official PECB agenda has four teaching days and a fifth examination entry. Your private timetable may spread the teaching across more days; the examination is arranged separately. Aegentra Academy is online only. Choose self-paced study through myPECB, or one-to-one live online training scheduled around you.

Call 03 9956 9399 or email Academy@aegentra.com.au.

We use these details to respond to your training enquiry. Read our privacy policy.

ISO 27001 learner feedback

“Completed iso 9001 and 27001 course pretty impressive with overall support.”
Div KaurISO 9001 and ISO 27001 course learnerView Aegentra’s Google Business Profile ↗View the Google review profile ↗

Feedback on previous ISO 9001 and ISO 27001 course experience. Name abbreviated with permission. This review is not presented as a review of the Lead Auditor course specifically.

Learn how to plan, conduct and report an ISMS audit

An ISO 27001 audit examines whether the information security management system meets its requirements and operates effectively. Learn to define the audit scope, select evidence, interview process owners, evaluate findings and report conclusions that can be traced to the audit criteria.

  • Interpret ISO/IEC 27001:2022 from an auditor’s perspective.
  • Plan an audit using clear objectives, scope, criteria and appropriate sampling.
  • Collect and evaluate evidence through interviews, observation and document review.
  • Report findings and assess corrective-action follow-up while maintaining objectivity.

Day 1 — ISO 27001 and ISMS audit fundamentals

Review the purpose and structure of an ISMS, ISO/IEC 27001:2022 requirements and the relationship between risk treatment and the Statement of Applicability. Introduce audit terminology, professional responsibilities and the different purposes of internal, supplier and certification audits.

Day 2 — Audit principles, preparation and initiation

Explore audit principles, professional behaviour and audit-programme management. Define objectives, scope and criteria, review documented information and select appropriate methods and resources. Prepare an audit plan, working papers and questions that support a focused evidence-gathering process.

Day 3 — Conducting the audit

Work through the opening meeting, communication, interviews, observation and evidence collection. Evaluate the relevance and sufficiency of a sample, trace evidence to the criteria and develop potential findings. Consider how remote and onsite methods affect the audit approach.

Day 4 — Closing the audit and following up

Evaluate conformity, write clear nonconformities and prepare the audit report. Practise presenting conclusions at a closing meeting, reviewing corrective-action plans and following up on their effectiveness. Consider audit records, team responsibilities, ethics and continuing competence.

Day 5 — PECB certification examination

The official agenda ends with the PECB examination. The current English assessment lasts three hours and covers seven competency domains. For private and self-paced delivery, confirm the examination booking separately from your teaching or study timetable.

Who is this course for, and what should you know first?

This course suits internal auditors, information security and GRC professionals, compliance and risk practitioners, supplier-assurance teams, ISMS managers and consultants who evaluate management systems. PECB expects a fundamental understanding of ISO/IEC 27001 and comprehensive knowledge of audit principles.

ISO 27001 Foundation can help if the terminology is new. Foundation and Lead Implementer are not mandatory prior credentials. Entry knowledge and professional-certification experience requirements are separate considerations.

Official course details

PECB lists more than 450 pages of course materials and an attestation of course completion worth 31 CPD credits for participants who meet its completion conditions. These credits describe course completion; they are not a professional credential or a promise of certification.

Official PECB syllabus

Understand the exam and the credential you can apply for

The current English PECB ISO 27001 Lead Auditor examination lasts three hours and contains 80 multiple-choice questions, including stand-alone and scenario-based questions. It is open book under PECB’s permitted-reference rules, with a 70% pass mark. Check the current examination record and candidate handbook assigned in myPECB before booking.

The seven competency domains cover ISMS concepts, ISO 27001 requirements, audit principles, audit preparation, conducting an audit, closing an audit and managing an audit programme.

The pathway has four steps: complete your learning, pass the examination, submit your credential application with the required evidence, and receive PECB’s decision. Passing does not automatically award the Lead Auditor tier.

PECB credential experience requirements
PECB credential tierProfessional experienceQualifying audit activity
Provisional AuditorNo professional experience requiredNo audit hours required
AuditorTwo years, including one year in information security management200 hours
Lead AuditorFive years, including two years in information security management300 hours
Senior Lead AuditorTen years, including seven years in information security management1,000 hours

All applicants must meet PECB’s applicable examination, application and Code of Ethics requirements. Keep records of your audit role, scope, activities and hours so PECB can evaluate the evidence supporting your application.

Retakes and maintaining your credential

One free retake is included within the applicable PECB cycle. For Self-Study and eLearning, the current 12-month cycle is calculated from purchase; for instructor-led training, it is calculated from course completion. PECB’s waiting periods and booking rules also apply. A failed attempt does not start a new 12-month entitlement.

Professional certification has continuing requirements that depend on the tier. Check PECB’s current maintenance policy for applicable fees and CPD obligations. Course-completion credits and ongoing credential maintenance are different requirements.

A personal credential is separate from certification of an organisation’s ISMS. A certification body makes its own auditor-competence and assignment decisions; completing this course does not appoint you to conduct certification audits.

ISO 27001 Lead Auditor or Lead Implementer?

ISO 27001 Lead Auditor and Lead Implementer course comparison
Your decisionISO 27001 Lead Auditor courseISO 27001 Lead Implementer course
What you doPlan and lead first-, second- and third-party audits; sample evidence; classify and write nonconformitiesScope and build an ISMS; run the risk assessment; write the Statement of Applicability
Reference standardISO/IEC 27001:2022 plus ISO 19011 auditing guidelinesISO/IEC 27001:2022 and the 93 Annex A controls
Typical rolesInternal auditor, supplier assurance, IT audit consultant, certification-body assessorISMS manager, security manager, GRC lead, compliance consultant
Take it ifYou will check that a management system worksYou will get an organisation audit-ready

See what ISO 27001 audit work looks like

Inspect Aegentra’s free audit resources before choosing a course. Follow the evidence trail from the audit programme and plan to interviews, findings, reporting and corrective-action follow-up. The resources are Aegentra-authored learning aids, separate from official PECB course materials.

These examples do not establish conformity or guarantee acceptance by a certification body. Competent auditors adapt their approach to the scope, criteria and evidence.

A simple audit example

Illustrative learning scenario, not a client outcome

An organisation’s procedure requires access to be removed when a person leaves. An auditor reviews a sample of leaver records and compares the required removal dates with system records. If an account remained active, the auditor checks the applicable requirement, confirms the evidence and considers the context before deciding whether to raise a nonconformity.

A useful finding identifies the requirement, objective evidence and the gap between them. The auditor does not assume that one exception proves every access control is ineffective.

Audit purpose and independence

Internal audits evaluate the organisation’s own ISMS; supplier audits evaluate another party against agreed criteria; certification audits support a certification body’s decision. In each case, the auditor needs suitable competence, scope and objectivity. Training does not remove an independence problem when someone audits work for which they are responsible.

Practise before you buy

Try the free ISO 27001 Lead Auditor practice and exam guide in Aegentra Labs. Use the explanations to examine your reasoning about evidence, sampling and findings, then revisit the relevant learning material. Full Labs access remains an optional purchase for self-paced learners.

Practitioner evidence from Aegentra

Aegentra publishes an ISO 27001 internal-audit engagement record showing how scope, requirements, evidence and professional judgement connect in practice. Read it alongside the learning resources to understand the work behind the methodology.

Aegentra’s implementation and independent audit work are separately scoped. Where Aegentra implements an ISMS, a different competent Aegentra consultant, independent of that work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. The engagement record demonstrates practitioner context; it does not guarantee a learner’s examination result or an organisation’s certification.

Read the internal-audit case study ↗
Aegentra ISO 27001 internal audit case study cover

ISO 27001 Lead Auditor course FAQs

How much does the ISO 27001 Lead Auditor course cost in Australia?

Aegentra Academy’s ISO 27001 Lead Auditor course costs A$829 + GST for Self-Study, A$849 + GST for PECB eLearning or A$2,799 + GST for private one-to-one online training, with the official PECB examination included and different levels of teaching and practice support in each package. For Australian billing addresses, the respective totals are A$911.90, A$933.90 and A$3,078.90 including GST. Review your selected currency and total before payment.

Can I buy the PECB ISO 27001 Lead Auditor exam separately?

Aegentra Academy’s published ISO 27001 Lead Auditor prices cover training packages with the official PECB examination included, and the current page does not publish an exam-only price, so ask whether a standalone examination booking is available and request the applicable cost before comparing offers. A course-and-exam package price is not an exam-only fee or the cost of certifying an organisation.

What is included in the course price?

The published Aegentra Academy ISO 27001 Lead Auditor packages include the applicable official PECB materials, the initial official examination attempt, the certification application fee and one free retake within the applicable PECB cycle, while recorded instruction, live teaching and Labs access depend on your selected package. For qualifying partner-course purchases, PECB also includes the first year of the Annual Maintenance Fee where applicable. Review the package inclusions and current PECB conditions before booking.

What is the difference between Self-Study, eLearning and live training?

For Aegentra Academy’s ISO 27001 Lead Auditor course, Self-Study provides official PECB materials for independent learning, PECB eLearning adds recorded instruction and interactive activities, and private one-to-one online training adds scheduled teaching and discussion with a trainer, with each route supporting the PECB examination and certification pathway. Choose the format that matches how much explanation and discussion you need. Self-Study does not include recorded lessons or scheduled live teaching.

Can I study from Melbourne, Sydney, Brisbane or Perth?

Aegentra Academy’s ISO 27001 Lead Auditor Self-Study, PECB eLearning and private one-to-one training are available online to learners in Melbourne, Sydney, Brisbane and Perth, as well as elsewhere in Australia and across APAC, with private teaching dates and time zones agreed before booking. No public classroom venue or scheduled group cohort is advertised for this course. Organisational delivery can be discussed separately.

Who teaches the one-to-one course?

Aegentra’s live ISO 27001 Lead Auditor page names Dr Harbir Singh as the private online instructor and links to his PECB trainer record for the course, while the assigned instructor and applicable trainer authorisation are confirmed in writing before payment for each booking. PECB’s recorded eLearning faculty is separate from the trainer assigned to your live class. View the instructor profile and current PECB record in the one-to-one section.

How long does ISO 27001 Lead Auditor training take?

PECB’s ISO 27001 Lead Auditor agenda comprises four teaching days and a fifth examination entry, while Aegentra’s private package offers 24 teaching hours over four six-hour or eight three-hour sessions, plus a separate one-hour consultant session, and estimates approximately 30–40 hours of learning for self-paced study. The examination lasts three hours and is arranged separately. The self-paced estimate is learning effort, not video runtime or a completion guarantee.

What is the current PECB ISO 27001 Lead Auditor exam format?

The current English PECB ISO 27001 Lead Auditor examination is a three-hour, open-book assessment with 80 multiple-choice questions across seven competency domains, including stand-alone and scenario-based questions, and a 70% pass mark, with permitted references and examination arrangements governed by the candidate’s assigned PECB instructions. Open book does not mean unrestricted internet research. Check the examination record and candidate handbook in myPECB before booking, particularly for another language.

What happens if I fail the first examination attempt?

Aegentra’s PECB ISO 27001 Lead Auditor course includes one free examination retake within the applicable 12-month PECB cycle, which is calculated from the purchase date for Self-Study or eLearning and from course completion for instructor-led training, subject to PECB’s waiting periods and examination rules. Failing the examination does not start a fresh 12-month entitlement. Confirm the cycle in myPECB; the written private-training confirmation must identify which cycle applies to the blended package.

What are the prerequisites for the course?

PECB expects ISO 27001 Lead Auditor learners to have a fundamental understanding of ISO/IEC 27001 and comprehensive knowledge of audit principles, while ISO 27001 Foundation and Lead Implementer are not mandatory prior credentials, so assess your knowledge before choosing a learning format or booking the examination. If management-system language and the standard are new to you, review ISO 27001 Foundation first. Course entry knowledge is separate from the experience required for a professional credential.

Do I become a certified Lead Auditor when I pass?

Passing the PECB ISO 27001 Lead Auditor examination meets the examination requirement for a credential application, but PECB awards the credential tier supported by your verified professional experience and audit activity, so passing alone does not automatically grant the full Lead Auditor credential or certification-body appointment. Applicants must complete PECB’s application process and meet its applicable ethical requirements. Training completion, examination success and credential award are separate stages.

How much experience do I need for the Lead Auditor credential?

The PECB ISO 27001 Lead Auditor credential requires five years of professional experience, including two years in information security management, and 300 hours of qualifying audit activity, together with the applicable examination and certification requirements, while applicants without the required experience may consider the Provisional Auditor pathway. Keep a dated audit log with your role, scope, activities and hours. PECB evaluates whether the evidence supports the credential tier requested.

Should I choose ISO 27001 Lead Auditor or Lead Implementer?

Choose ISO 27001 Lead Auditor when your work involves evaluating an information security management system through audit planning, evidence collection, findings and reporting, or choose ISO 27001 Lead Implementer when your work involves establishing, operating and improving that system, because the two courses support different professional responsibilities. Each has its own examination and experience pathway. Holding both credentials does not remove the need for objectivity and impartiality when auditing work you helped implement.

Does the course qualify me to conduct certification audits?

A PECB ISO 27001 Lead Auditor course or credential can support an audit career, but a certification body separately decides whether you are competent and suitable to conduct its certification audits, considering the assignment, relevant experience, technical knowledge and impartiality rather than relying on course completion alone. Internal and supplier audits have different purposes and commissioning organisations. See the audit examples and credential pathway on this page before choosing a course for a particular role. Employers, clients and certification bodies decide whether the credential meets their requirements for a particular role.

Is the ISO 27001 Lead Auditor exam hard?

The PECB ISO 27001 Lead Auditor exam tests applied audit knowledge, not just the ability to look up information. The current English examination is open-book, lasts three hours and contains 80 multiple-choice questions across seven competency domains, with a 70% pass mark. It includes stand-alone and scenario-based questions, so preparation should focus on understanding the requirements and applying audit principles to evidence and audit situations.

How long is the PECB Lead Auditor credential valid, and how do I renew it?

PECB Auditor, Lead Auditor and Senior Lead Auditor certifications have a three-year certification cycle. Maintaining them requires the applicable annual maintenance fees, continuing professional development and adherence to the PECB Code of Ethics. The three-year CPD requirements are 60 hours for Auditor, 90 for Lead Auditor and 180 for Senior Lead Auditor. Provisional credentials do not require CPD or maintenance fees.

Can I conduct internal audits with this credential?

The course covers planning and conducting first-party internal audits, and the knowledge applies directly. Whether you can perform a specific audit depends on competence, objectivity, independence and your organisation's own engagement requirements. Holding the credential is evidence of knowledge; it is not, by itself, sufficient evidence of independence for every assignment.

How do I become an ISO 27001 Lead Auditor in Australia?

To become a PECB ISO 27001 Lead Auditor in Australia, pass the relevant examination and apply to PECB for the credential tier supported by your experience. Official PECB training prepares you for the examination but is not a mandatory certification prerequisite. The Lead Auditor tier requires five years of professional experience, including two years in information security management, plus 300 hours of audit activity and agreement to the PECB Code of Ethics. Candidates without the required experience can apply for Provisional Auditor; passing the examination does not automatically award any credential.

Is PECB accredited, and is the credential recognised in Australia?

PECB holds IAS and UKAS accreditation under ISO/IEC 17024, and ISO/IEC 27001 Lead Auditor appears in both published personnel-certification scopes. PECB also holds separate ANAB accreditation for specified certificate programmes under ANSI/ASTM E2659-24; that is not the same as personnel-certification accreditation. The PECB credential is not an Australian government licence or VET qualification. Employers and clients determine whether it meets their role or contract requirements.

When can I book the PECB exam? Are there set exam dates?

You book an available PECB remote examination session through myPECB once your account is eligible. Available dates, languages, times and seats are shown when you book; a particular slot is not guaranteed. PECB's current included examination cycle must be completed within 12 months of purchase for Self-Study and eLearning, or within 12 months of course completion for instructor-led training. Course-material access and the examination deadline are separate conditions; your written private-training confirmation identifies the cycle applicable to the blended package.

Is the first-year certification fee included?

Yes. For qualifying partner-course purchases, PECB's current rules include the first examination attempt, one free retake, the certification application fee and the first year of the annual maintenance fee where maintenance applies. Provisional credentials do not require maintenance fees. Subsequent annual maintenance fees remain payable under PECB's current policy; they are not limited to the end of the three-year renewal cycle.

How do I access the course and receive my certificate?

Your official course materials and certification records are accessed through myPECB. After enrolment, Aegentra arranges the course assignment to your existing account, or you receive an invitation to create an account if needed. You schedule the examination through myPECB and sit the remote examination in the PECB Exams application. After you pass and PECB approves your credential application, your digital certificate is available to download from your account.

Is Aegentra Labs included, and is it official PECB content?

Aegentra Labs is independently authored supplementary ISO 27001 Lead Auditor practice, with one month included in Aegentra’s private one-to-one package and an optional 12-month Full Exam Prep add-on priced at A$89 + GST for Academy learners, separate from the official PECB materials and examination. The optional add-on is one payment with no automatic renewal. You choose whether to add it during enrolment. Labs practice attempts are not official examination attempts, and the questions are not official PECB examination content.

Related learning

Each qualification has its own scope, examination and credential requirements. Related courses and existing CISA, CISM or CISSP knowledge do not automatically waive PECB requirements.

Choose your next step

Choose Self-Study for independent learning, PECB eLearning for recorded instruction, or private one-to-one online training for live explanation and discussion. Review the course inclusions and credential requirements, then enrol online or contact Aegentra Academy to arrange private teaching.

Sources and factual review

PECB defines the official course, examination and certification requirements. Aegentra Academy publishes its own prices, delivery options and learner-support arrangements. Check the current PECB examination record and the booking terms that apply to your enrolment.

Editorial owner: Harry Sidhu — Director and Principal Consultant, Aegentra. PECB Certified ISO 27001 Lead Implementer, certificate 9303577-2026-05. Verify Harry Sidhu’s PECB certificate. View Harry Sidhu’s LinkedIn profile.

Last updated: .