Skip to main content
PECB · 27701Lead Auditor

PECB ISO/IEC 27701 Lead Auditor Course & Exam Australia

Learn to plan, lead and report audits of an ISO/IEC 27701 privacy information management system (PIMS) through flexible Self-Study from $849 + GST, with the official PECB Lead Auditor exam voucher and one free resit included — instructor-led training in Melbourne & Sydney available on request across Australia.

Available Australia-wide, in New Zealand and across Asia Pacific — and, because self-study and eLearning are delivered online through the myPECB platform, from anywhere in the world. Live online classes run in Australian time zones; in-person classroom delivery in Melbourne and Sydney is available on request. Base prices are published in AUD, and every course page supports available local currencies including NZD. An Australian billing address adds 10% GST; a non-Australian billing address has no Australian GST.

The PECB ISO 27701 Lead Auditor training course costs $849 + GST through Aegentra Academy, an official PECB authorised training partner in Australia. That price includes the official PECB examination voucher, the full course materials, 12 months of myPECB access, and one free exam resit within 12 months. The eLearning format is $928 + GST.

Official course provider
PECB
Standard family recorded
ISO 27701
Self-Study · eLearning
12 months access
Initial attempt and one free retake
2 exam attempts included
/ Purchase order

ISO 27701 Lead Auditor course price and enrolment options

Live online class

Online classes are arranged through the Aegentra Academy team for individual learners and groups.

Contact us for online class

Learn · Practise · Implement

More than the course: learn, practise and implement

Aegentra combines official PECB training with free exam-preparation resources, practical ISO 27701 implementation tools and optional full exam practice through Aegentra Labs.

Learn

Included with course

Official PECB training + exam

  • Official PECB ISO 27701 Lead Auditor training
  • Official PECB examination voucher
  • Initial exam attempt plus one free resit
  • 12 months myPECB access
  • Official course materials
  • PECB credential application pathway

This is what the $849 + GST Self-Study price covers, or $928 + GST with PECB eLearning.

Choose your course

Implement

Free · No email required

Free ISO 27701 practitioner resources

Go beyond passing the exam. Practical resources built around the work itself — the documents you will actually have to produce.

Explore free ISO 27701 resources

How much does ISO 27701 Lead Auditor training cost in Australia?

$849 + GST self-paced, or $928 + GST with guided eLearning. The official PECB examination voucher is included along with two attempts — PECB’s course documentation states the training fee includes a first exam attempt and one free retake within 12 months — so there is no separate ISO 27701 exam cost to budget for. All ISO 27701 training through Aegentra Academy is official PECB certification training. Also included: 12 months of myPECB access, over 400 pages of course material, and 31 CPD credits. The course is equivalent to five days of classroom training.

CourseWhat it qualifies you to doExamSelf-StudyeLearning
FoundationUnderstand a PIMS — the controller/processor split, the clause structure and the Annex A tables40 questions, 1 hour, closed book$399 + GST$449 + GST
Lead ImplementerBuild the PIMS — scope it, run the privacy risk assessment, write the Statement of Applicability, take it to certification80 questions, 3 hours, open book$849 + GST$928 + GST
Lead AuditorAudit the PIMS — plan and lead privacy audits against ISO 19011 and ISO/IEC 17021-180 questions, 3 hours, open book$849 + GST$928 + GST

What is on the ISO 27701 Lead Auditor exam?

80 multiple-choice questions across 7 competency domains, open book, 3 hours, 70% to pass. The seven domains follow the audit lifecycle: fundamental principles and concepts of a PIMS; PIMS requirements; fundamental audit concepts and principles; preparing an ISO/IEC 27701 audit; conducting the audit; closing the audit; and managing an audit programme.

Note that the domain split differs from the Lead Implementer exam, which follows the implementation lifecycle instead. Same question count, same duration, different ground. The course itself is taught against ISO 19011 (auditing management systems), ISO/IEC 17021-1 (requirements for certification bodies) and ISO/IEC 27706 — the last of which almost no provider mentions.

Internal auditor or Lead Auditor — which do you need?

They are different jobs, and the distinction decides which course to buy.

An internal auditor audits their own organisation’s PIMS against Clause 9.2 — checking that what the Statement of Applicability claims is actually operating, before a certification body arrives. The PECB Lead Auditor credential fully qualifies you for this, and internal audit is where most credential holders start.

A lead auditor plans and leads audits of other organisations — as a consultant, in supplier assurance, or on a certification body assessment team. That is what ISO/IEC 17021-1 competence requirements exist for, and it is the ground domains 4 to 7 cover. There is no separate PECB "internal auditor" credential for ISO 27701; the Lead Auditor course covers both contexts, and the credential you are awarded depends on attested audit experience rather than on which role you intend to fill.

How do you audit a standalone PIMS versus a combined audit?

Since the October 2025 revision this is a live question rather than a theoretical one. ISO/IEC 27701:2025 is a stand-alone standard — PECB states the 2025 edition introduces a stand-alone PIMS, no longer requiring ISO/IEC 27001-based security management — so an auditor now meets both shapes in the field.

A standalone PIMS audit covers clauses 4 to 10 and Annex A in their own right. The scope statement stands alone, and Table A.3 shared security controls are audited as part of the PIMS rather than inherited from an ISMS.

A combined ISO 27001 + ISO 27701 audit shares the management-system clauses and audits the privacy controls as an extension of the existing ISMS scope. It is more efficient, and it is what most certified organisations still do — but the auditor has to be explicit about which certificate each finding attaches to. Getting that wrong is a common quality-review failure.

Either way you are auditing against 78 Annex A controls in three tables — A.1 for PII controllers (31), A.2 for PII processors (18), A.3 shared security (29) — with Annex B as the implementation guidance you read to understand what good looks like. An auditee that is both controller and processor is in scope for all three.

Who hires ISO 27701 auditors in Australia?

Privacy assurance is a smaller market than information security, and that cuts both ways — fewer roles, far fewer qualified people. The demand sits in four places: internal audit and second-line privacy teams in organisations holding or seeking certification; supplier assurance functions assessing processors, which the Privacy Act 1988 makes an obligation rather than a courtesy under APP 11 and APP 8; consultancies running readiness and pre-certification reviews; and certification body assessment teams, where ISO/IEC 17021-1 competence requirements make the credential close to mandatory.

Australian organisations handling health information, financial services data, or EU personal data are where the work concentrates.

Free audit documents to work through with the course

The artefacts an auditor asks for first — published in full, free, no email required.

Building a PIMS rather than auditing one is the Lead Implementer track. For what organisational certification involves, see the ISO 27701 certification guide for Australia.

/ What you get

What's included in the ISO 27701 Lead Auditor course fee

The official PECB course and exam package starts at $849 + GST — with no separate exam fee after enrolment. Optional Aegentra Labs exam preparation is clearly priced separately.

Course materials
  • PECB ISO/IEC 27701 Lead Auditor slide deck (digital)
  • 12 months access via myPECB
  • Privacy-audit scenario library and worked-finding examples
  • ISO 19011 audit-principles reference set
Exam package
  • Official PECB Lead Auditor exam voucher
  • Three-hour open-book exam, remotely proctored
  • Two exam attempts (initial + one free resit)
  • PECB Auditor / Lead Auditor credential on pass
Practitioner extras
  • Combined ISO 27001 + ISO 27701 audit checklist
  • Sample privacy nonconformity statements
  • Australian Privacy Act and CDR reference materials
  • Pathway support toward Senior Lead Auditor (CPDs)
/ Exam requirements & credential

ISO 27701 Lead Auditor exam format, duration and pass mark

The exam voucher is included in your enrolment, and so is one free resit if you don't pass first time. Both the exam and the credential are issued directly by PECB.

Format
Open-book, multiple-choice — stand-alone and scenario-based questions
Duration
3 hours
Questions
80 multiple-choice questions across 7 competency domains — fundamental principles and concepts of a PIMS, PIMS requirements, fundamental audit concepts and principles, preparing an ISO/IEC 27701 audit, conducting the audit, closing the audit, and managing an audit programme
Pass mark
70%
Language
English (other PECB languages available on request)
Credential experience requirements

PECB credential ladder: Provisional Auditor (no experience) → Auditor (2 years, 1 in privacy management, 200 audit hours) → Lead Auditor (5 years, 2 in privacy management, 300 audit hours) → Senior Lead Auditor (10 years, 7 in privacy management, 1,000 audit hours). Above these sits PECB Certified ISO/IEC 27701 Master, which requires 20 years of professional experience with 10 in a leadership role, 5,000 hours of combined audit and project activity, and passing both the ISO/IEC 27701 and Lead Auditor exams. All tiers require signing the PECB Code of Ethics and are maintained through continuing professional development (CPD) credits.

/ Before you enrol

Clear answers about price, tax, exams, and certification.

These answers use this course's current catalogue record and PECB's published exam, certification, and maintenance policies.

What is included in the ISO 27701 Lead Auditor course fee?

The published price is A$849 for Self-Study or A$928 for eLearning, before tax. It includes the official PECB course materials, 12 months of access, the first exam attempt, one free retake, and the certification application fee. PECB’s partner-course policy also includes the first year of the Annual Maintenance Fee where maintenance applies; Foundation and Provisional credentials are maintenance-exempt. There is no separate first-exam or certification-application charge after enrolment.

What will PECB charge to maintain the ISO 27701 Lead Auditor credential?

PECB’s current maintenance policy lists no maintenance fee for Foundation, Provisional, or Transition credentials. For all other PECB certifications, the published fee is $390 per three-year certification cycle, together with the applicable CPD requirements and continued adherence to the PECB Code of Ethics. PECB sets this fee and may change it, so check the linked policy before renewal.

Can I pay in NZD or another currency, and when is Australian GST added?

Yes. Every Academy course supports AUD and multiple local currencies, including NZD, USD, SGD, GBP, EUR, INR, AED, MYR, PHP, IDR, and VND when a live quote is available. Currency and tax are separate: an Australian billing address adds 10% GST, while a non-Australian billing address has no Australian GST. For example, an Australian working in New Zealand may pay in NZD and use an Australian billing address, but 10% GST will still be added because the billing address is Australian.

What is the difference between Self-Study and eLearning for ISO 27701 Lead Auditor?

Self-Study costs A$849 before tax and uses the official PECB slide-based materials. eLearning costs A$928 before tax — A$79 more — and adds recorded trainer-led lessons and interactive learning activities. Both routes lead to the same PECB exam and credential, and both include the same exam package. Choose eLearning if explanations and video guidance help you learn; choose Self-Study if you are comfortable working through standards-based material independently and want the lowest price.

Can I sit the ISO 27701 Lead Auditor exam remotely from New Zealand or another time zone?

Yes. PECB publishes remote online exam sessions that candidates can take from home or another suitable location through the PECB Exams application. The published course record lists these exam facts: duration — 3 hours; format — Open-book, multiple-choice — stand-alone and scenario-based questions; assessment — 80 multiple-choice questions across 7 competency domains — fundamental principles and concepts of a PIMS, PIMS requirements, fundamental audit concepts and principles, preparing an ISO/IEC 27701 audit, conducting the audit, closing the audit, and managing an audit programme; pass mark — 70%; language — English (other PECB languages available on request). New Zealand candidates should choose a published session that suits their local time, meet PECB’s identity and technical requirements, and complete the system check before exam day. PECB’s general exam policy does not publish a New Zealand restriction.

Which credential tier will I receive after the ISO 27701 Lead Auditor exam, and who assesses it?

PECB credential ladder: Provisional Auditor (no experience) → Auditor (2 years, 1 in privacy management, 200 audit hours) → Lead Auditor (5 years, 2 in privacy management, 300 audit hours) → Senior Lead Auditor (10 years, 7 in privacy management, 1,000 audit hours). Above these sits PECB Certified ISO/IEC 27701 Master, which requires 20 years of professional experience with 10 in a leadership role, 5,000 hours of combined audit and project activity, and passing both the ISO/IEC 27701 and Lead Auditor exams. All tiers require signing the PECB Code of Ethics and are maintained through continuing professional development (CPD) credits. Passing the exam does not by itself guarantee the highest experience-based credential tier. PECB requires an online certification application and reference contact details, and its Certification Department decides whether the education, professional experience, and audit or assessment activity requirements are met.

What evidence does PECB accept for the experience or project hours for ISO 27701 Lead Auditor?

PECB’s public certification-process page does not publish a closed list of documents that automatically proves project hours. It requires the online application and contact details for references who may be contacted to validate your experience. Keep a dated activity log showing the organisation or client, your role, the audit or assessment activity, dates, responsibilities, and hours; retain employer or client confirmations, statements of work, timesheets, or similar records in case PECB asks for support. The PECB Certification Department assesses the application and makes the final decision.

Can I become both a Lead Implementer and a Lead Auditor?

Yes. You can hold both the ISO 27701 Lead Implementer and ISO 27701 Lead Auditor credentials. They are separate, complementary certifications: Lead Implementer demonstrates that you can build and operate the management system, while Lead Auditor demonstrates that you can audit and verify it. To earn both, complete each course, pass each exam, and apply for each credential. PECB assesses implementation-project experience for the Implementer tier and audit experience for the Auditor tier separately. If you pass an exam before meeting its full experience requirements, you can receive the applicable Provisional credential and upgrade later when those requirements are met; you do not need to retake that exam. Neither credential automatically grants the other.

/ Training prerequisites

What you should know before starting ISO 27701 Lead Auditor

  • Working knowledge of management system auditing (ISO 19011).
  • ISO 27701 Foundation, or equivalent lead-auditor experience on another ISO management system, recommended.
/ Who this course is for

Who should take the ISO 27701 Lead Auditor course

  • Audit professionals adding privacy scope
  • DPOs expanding into audit capability
  • Consultants offering PIMS audit services
/ What you'll learn

By the end of this course you'll be able to:

  • Plan and lead an ISO/IEC 27701 audit programme — internal, supplier, or third-party.
  • Audit privacy-specific controls in both controller and processor contexts.
  • Run combined ISMS / PIMS audits efficiently.
  • Classify privacy nonconformities and write defensible findings.
  • Handle audit disputes around lawful basis, consent, and cross-border transfers.
/ Curriculum

What does the ISO 27701 Lead Auditor course cover?

6 modules, fully on-demand. Click any module to see the topics inside.

01Foundations of privacy auditing
  • ISO 19011 principles applied to PIMS
  • Auditor competence for privacy
  • Auditing a standalone PIMS or a combined ISMS / PIMS
  • Ethics and impartiality
02Planning the PIMS audit
  • PII inventory verification
  • Controller vs. processor scope
  • Stage 1 documentation review
  • Risk-based audit planning for privacy
03Conducting the audit
  • Auditing lawful basis and consent
  • Auditing data subject rights handling
  • Auditing cross-border transfers
  • Evidence sampling for personal data
04Closing and reporting
  • Classifying privacy nonconformities
  • Writing the audit report
  • Closing meeting and presentation
  • Corrective action verification
05Special audit situations
  • Auditing third-party processors
  • Combined ISMS / PIMS audits
  • Remote audits and sampling
  • Dispute resolution on consent and lawful basis
06Certification body practice and exam prep
  • Working under a certification body
  • Surveillance and recertification audits
  • Ethics and impartiality
  • Exam strategy and case studies
/ Career signal

What is the ISO 27701 Lead Auditor credential worth?

The credential that says you can verify the privacy system

PECB ISO 27701 Lead Auditor is the certification a hiring manager looks for when the work is to plan, conduct, and report on a combined ISO 27001 + ISO 27701 audit — internal, supplier, or third-party. It is the difference between an auditor who understands information-security generally and a specialist who can verify a privacy programme against the 78 Annex A controls and defend findings to a privacy regulator.

Where it shows up in Australian job descriptions

Privacy Auditor, Internal Audit Manager (privacy scope), Information Security and Privacy Auditor, Third-Party Privacy Risk Manager, Supplier Privacy Assurance Manager — every one of these roles in the Australian market either requires Lead Auditor or treats it as a strong substitute for years of equivalent experience. JAS-ANZ accredited certification bodies need it on assessment teams that conduct combined ISO 27001 + ISO 27701 audits. Tier-1 consultancies and privacy boutiques use it for senior privacy-assurance hires.

How it complements an implementation background

Many practitioners progress from ISO 27701 Lead Implementer to ISO 27701 Lead Auditor — the implementation lens makes you a sharper auditor because you can see when a privacy control is evidenced only on paper. The two credentials together are the gold standard for privacy-assurance leadership in Australia.

The credential that lets you sign privacy findings

Only individuals appropriately credentialled and registered with a certification body programme can lead a third-party combined ISO 27001 + ISO 27701 audit under JAS-ANZ accreditation rules. Lead Auditor is the PECB credential that satisfies the personnel-competency requirement for the privacy extension to ISO/IEC 17021-1.

/ Where this lands in Australia

ISO 27701 auditor roles in Australia — who hires it

Certification bodies running combined audits

JAS-ANZ accredited certification bodies in Australia running combined management-system audits staff their privacy-scope assessment teams with PECB Lead Auditor (or equivalent IRCA) credentialled assessors. Day rates for credentialled privacy lead auditors in Australia typically range from $1,800 to $3,000 AUD.

Internal audit, second and third lines of defence

APRA-regulated entities maintain second and third lines of defence that conduct independent reviews of the privacy programme alongside the information-security programme under CPS 234 and the associated prudential guides. Lead Auditor is the dominant credential for staff conducting those privacy reviews.

Supplier and third-party privacy risk management

Large Australian enterprises and government agencies operate supplier-privacy programmes that include privacy-scope audits of critical suppliers. Lead Auditor is the credential the supplier-assurance team holds when conducting those audits — particularly for suppliers handling sensitive personal information or inheriting compliance obligations under the Privacy Act, CDR, or sector-specific health-privacy regimes.

CDR-accredited data recipient assurance

CDR data recipients must operate audit-ready privacy management programmes. Lead Auditor is the credential most commonly held by the internal-audit staff and the supplier-assurance teams reviewing those programmes against the CDR privacy safeguards.

/ Study plan

How hard is the ISO 27701 Lead Auditor exam?

The exam is open-book, but the questions reward fluency, not lookup. Plan your study around these checkpoints.

  1. 01Memorise the seven ISO 19011 audit principles. They underpin every scenario-question answer.
  2. 02Build a one-page diagram comparing the audit lifecycle for a stand-alone ISO 27701 audit and a combined ISO 27001 + ISO 27701 audit. The combined-audit nuances are heavily tested.
  3. 03Practise classifying privacy nonconformities — major vs minor vs OFI. The exam tests the decision rules cold; learn to write a defensible finding statement quickly.
  4. 04Walk worked stage-1 and stage-2 audits with privacy scope. The exam will ask you to make decisions across the combined audit cycle, not just within a single audit.
  5. 05Write three sample privacy nonconformity statements (Requirement / Evidence / Statement of nonconformity / Classification). Scenario questions test your ability to write a defensible finding, not just to spot one.
  6. 06Schedule the exam 14-21 days after finishing the slides. This is dense, scenario-heavy material; rushing the exam window is the biggest cause of first-attempt failure.

Free learning resources

Put the course concepts into practice.

Use Aegentra’s existing templates, checklists, registers and mappings alongside your course. No account or email is required.

Browse free ISO 27701 resources
/ Related reading

Related ISO 27701 resources

Free companion reading for anyone studying or implementing ISO/IEC 27701:2025, the privacy information management standard:

  • ISO 27701 certification guide for Australia — what changed in the October 2025 revision that made ISO 27701 a standalone standard, real costs in AUD, the controller/processor distinction, and how it maps to the Australian Privacy Principles and GDPR.
  • ISO 27001 certification guide — the information security standard ISO 27701 was originally an extension to, and which most Australian buyers still ask for first.
  • ISO 27001 and privacy readiness — what implementing a management system involves when someone builds it with you.

Compare the family

See where this course fits

The ISO 27701 family page compares current levels, prices, delivery, audiences and exam facts before you choose a pathway.

Compare ISO 27701 pathways

Source and review status

How these course facts are governed

Price, delivery and course content are generated from Aegentra’s authoritative catalogue record. The official PECB course page and exam policy are linked directly below. Source-link checks and substantive human review are tracked separately so one is never presented as the other.

Official PECB sources

Editorial accountability

Harry Sidhu owns publication of this record. A separate course-specific substantive reviewer has not yet been recorded.

Substantive review status

Official source links are checked separately. A course-specific substantive review date will be published when completed.

/ Accreditation

Is the ISO 27701 Lead Auditor certification recognised in Australia?

Yes. PECB certifications are internationally accredited and are accepted on Australian resumes, tender responses and procurement panels. Australia has no separate national licence for ISO 27701 Lead Auditor — the recognition comes from the accreditation behind the credential, which is international.

PECB’s professional certifications are accredited under ISO/IEC 17024 — the international standard for bodies certifying persons — by IAS, UKAS, KAB and COFRAC. Its Foundation certificate programs are separately accredited by ANAB (ANSI National Accreditation Board) under ANSI/ASTM E2659.

Aegentra Academy is an official PECB authorised training partner in Australia, which is what allows this course to include the official PECB examination voucher rather than billing it separately. You can confirm that directly with PECB through the official PECB partner directory.

This official PECB course is sold and supported by Aegentra Academy. PECB supplies the course material, examination and professional credential scheme. Aegentra's wider practice also runs privacy and GRC engagements and Microsoft 365 hardening for Australian organisations. Named eLearning trainers are credited separately on this page when the course record supplies them.

Courses run online and self-paced through the myPECB platform, so professionals across Melbourne, Sydney, Brisbane, Perth, Adelaide, Canberra and New Zealand enrol online. Instructor-led cohorts and in-person delivery in Melbourne and Sydney are available on request. Multi-seat team pricing is available for five or more seats — email Academy@aegentra.com.au for an enterprise quote. Tax invoices with GST and ABN are issued automatically at checkout.

/ Frequently asked

ISO 27701 Lead Auditor — frequently asked.

What does an ISO 27701 Lead Auditor audit?

A Privacy Information Management System — the controls governing how an organisation collects, uses, stores, discloses and disposes of personally identifiable information, in both the controller and processor roles. Since the ISO/IEC 27701:2025 revision made the standard standalone, a PIMS can be audited on its own rather than only as an extension to an ISO 27001 ISMS audit. In practice many Australian audits still cover both together, because the two share the same management-system structure.

How much does the ISO 27701 Lead Auditor course cost in Australia?

The PECB ISO 27701 Lead Auditor course costs $849 + GST through Aegentra Academy, including the official PECB examination voucher, course materials, 12 months of myPECB access, and one free resit within 12 months. There is no separate examination fee. The exam is open-book and remotely proctored, so it can be sat from anywhere in Australia.

What does the PECB ISO 27701 Lead Auditor course cover?

Six modules covering the foundations of auditing under ISO 19011, audit planning and resource allocation for stand-alone and combined PIMS audits, the on-site audit programme, privacy-specific nonconformity classification and finding-writing, the stage 1 / stage 2 / surveillance / recertification cycle for combined audits, and certification-body practice for the privacy extension. Total effort is 30-40 hours.

Do I need lead-auditor experience on another standard first?

Helpful, but not required. Since the ISO/IEC 27701:2025 revision a PIMS can be audited standalone, though many Australian audits still run combined with the information-security audit. Most successful Lead Auditor alumni arrive with lead-auditor experience on another management system. Starting here cold is possible, but the learning curve is much steeper.

How is the Lead Auditor exam structured?

80 multiple-choice questions across seven competency domains, open book, three hours, with a 70% pass mark. The domains are: fundamental principles and concepts of a PIMS; PIMS requirements; fundamental audit concepts and principles; preparing an ISO/IEC 27701 audit; conducting the audit; closing the audit; and managing an audit programme. Scenario-based items are still multiple-choice — there is no essay paper. The course is taught against ISO 19011, ISO/IEC 17021-1 and ISO/IEC 27706. The credential awarded depends on attested audit experience: Provisional Auditor (none), Auditor (2 years, 1 in privacy management, 200 audit hours), Lead Auditor (5 years, 2 in privacy management, 300 audit hours), Senior Lead Auditor (10 years, 7 in privacy management, 1,000 audit hours).

What makes the Aegentra Lead Auditor course different?

Every authorised PECB Lead Auditor course leads to the same credential — the certificate is identical wherever you buy it. The differences are price, format, and who supports you. Aegentra delivers Lead Auditor at $849 + GST self-study, with the exam voucher and one free resit included. The Australian-context privacy-audit references are informed by current assurance practice.

Can I become a certification-body lead auditor for ISO 27701 with this credential?

Yes — Lead Auditor is the personnel-competency credential certification bodies look for to staff combined ISO 27001 + ISO 27701 assessment teams. Certification bodies will run their own onboarding programme on top.

Does Lead Auditor cover first-, second-, and third-party audits?

Yes. The course explicitly covers all three audit types — first-party (internal privacy audits), second-party (supplier and contractor audits), and third-party (certification-body audits leading to issuance of a combined ISO 27001 + ISO 27701 certificate).

Will Lead Auditor help me audit GDPR or other privacy regimes?

The audit principles, methodology, and finding discipline transfer to other privacy regimes. The course is specifically about ISO 27701, but Annex D and Annex E cross-walks to GDPR mean a Lead Auditor is well placed to support GDPR-aligned privacy audits as well.

How long does the Lead Auditor course take?

Typical effort is 30-40 hours of self-paced study spread over four to six weeks. You have 12 months of myPECB access so the pace is yours.

What CPD credits do I earn?

PECB awards 31 CPD credits on completion of the ISO 27701 Lead Auditor course. These count toward CPD requirements at IAPP, ISACA, (ISC)², IIA, AISA, and other professional bodies on submission.

Can I deliver internal audits using this credential alone?

Yes. Lead Auditor qualifies you to plan and conduct internal privacy audits inside your own organisation, regardless of attested external experience. The internal audit programme is one of the most common starting points for Lead-Auditor-credentialled practitioners.

Can my employer pay or reimburse?

Yes. Either complete checkout yourself and forward the Stripe tax invoice for reimbursement, or write to Academy@aegentra.com.au and we will issue an invoice direct to your organisation with payment terms. Groups of five or more receive a discount.

When can I start the course?

Immediately after payment. The Academy team confirms your seat with PECB and you receive login details by email — usually within one business day.

How long do I have access to the course?

You have 12 months of access from enrolment. That window covers the course material, the official PECB exam, and one free resit if you need it.

What if I fail the exam?

One PECB-issued resit is included in your enrolment at no extra cost. Aegentra does not publish a pass-rate claim without an audited cohort dataset.

Questions about invoicing, GST, group bookings, refunds or instructor-led delivery? Read the Academy FAQ.

$849AUD · EXCL. TAX