ISO 37301 Lead Implementer — course at a glance
- Course
- PECB Certified ISO 37301 Lead Implementer
- Standard
- ISO 37301:2021 — compliance management systems
- Duration
- 5-day equivalent, 35–45 hours self-paced
- Exam
- 3 hours, open book, 80 multiple-choice questions, 100 points, 70% to pass
- Materials
- 500+ pages
- CPD
- 31 credits
- Price
- $849 + GST
How is the ISO 37301 Lead Implementer exam structured?
Three hours, open book, 80 multiple-choice questions worth 100 points, 70% to pass — stand-alone and scenario-based, not essay.
Planning is a quarter of the exam. Figures are from PECB Candidate Handbook version 1.5.
What is a compliance management system?
A compliance management system (CMS) is the structured way an organisation identifies its compliance obligations, assigns them owners, controls them, and demonstrates it is meeting them. ISO 37301:2021 is the standard that says what one must contain.
It rests on six principles: integrity, good governance, proportionality, transparency, accountability and sustainability. Like the other management system standards it follows the high-level structure, with the requirements in Clauses 4 to 10 — so an organisation already certified to ISO 9001 or ISO 27001 is integrating, not starting over.
How does ISO 37301 differ from ISO 19600?
ISO 19600:2014 was guidance. You could align with it, but no certification body could certify you against it, because guidance documents contain no requirements to audit.
ISO 37301 is a Type A management system standard — it contains requirements, so an organisation can undergo third-party conformity assessment and hold a certificate. That is the whole point of the change, and it is why compliance functions that had quietly aligned to ISO 19600 for years suddenly had something to certify. Organisations with an ISO 19600-based programme start well ahead: the structure carries over, and the work is converting guidance-shaped practice into auditable requirements with evidence behind them.
How do you implement a CMS with PECB’s IMS2 methodology?
- Context and interested parties. Regulators, customers, communities and the obligations each creates.
- Compliance obligations register. Every requirement and commitment, its source, its owner, and the control that satisfies it. This is the artefact the whole system hangs from.
- Compliance risk assessment. Likelihood and consequence of non-compliance, evaluated against defined criteria so control effort follows exposure.
- Governance and the compliance function. Governing body accountability, a compliance policy, and a compliance function with real independence and access.
- Controls and competence. Operational controls, training, awareness, and documented information.
- Performance evaluation. Monitoring, compliance reporting, internal audit and management review.
- Improvement. Non-compliance handling, corrective action, and continual improvement.
Compliance obligations vs voluntary commitments
ISO 37301 splits everything an organisation must or chooses to follow into two categories, and getting the split right is most of the work.
- Compliance requirements — what you must comply with: legislation, regulations, permits, licences, court rulings, and binding contractual terms.
- Compliance commitments — what you choose to comply with: internal policies, codes of conduct, industry standards, agreements with communities or NGOs, and public undertakings.
Both go in the compliance obligations register, and both are auditable once adopted. The common failure is treating a voluntary commitment as decoration — once it is published and the CMS claims it, an auditor will test whether it is met. Our free ISO 37301 compliance obligations register shows the shape auditors expect.
Why Australian organisations certify a CMS
ISO 37301 is voluntary. What drives adoption here is that a documented, tested and independently audited CMS is the most direct way to show a regulator, board or counterparty that compliance is managed rather than assumed. In several regimes the existence of a functioning compliance programme is relevant to how an organisation is treated after something goes wrong — whether it is sufficient in any given case is a legal question, and one for lawyers rather than a training provider.
Practically, the demand comes from financial services under AUSTRAC and ASIC oversight, from organisations tendering into government where compliance capability is scored, from regulated infrastructure and health, and from groups consolidating several separate compliance programmes into one auditable system.
Lead Implementer or Lead Auditor?
Same price, same exam format. Lead Implementer builds and runs the CMS — the credential for a compliance manager or consultant who owns the system. Lead Auditor assesses one under ISO 19011 and ISO/IEC 17021-1. The two log different experience toward the PECB ladder, which is why consultants often hold both.
PECB also offers an ISO 37301 Foundation and an ISO 37301 Transition course for people moving from ISO 19600. Aegentra’s catalogue currently starts at Lead Implementer — ask if you need one of the others.
What is included for $849 + GST
Aegentra Academy is an official PECB authorised training partner. Courses are bought online and studied at your own pace from anywhere in Australia — Melbourne, Sydney, Brisbane, Perth, Adelaide, Canberra or regional — with the exam sat under remote proctoring. For group enrolments, email Academy@aegentra.com.au to request a written quote confirming the current price, payment terms and inclusions before purchase.