How much does the ISO 42001 Lead Implementer exam cost?
Nothing extra. The official PECB examination voucher is included in the course price, so there is no separate exam fee to pay later. The ISO 42001 Lead Implementer course costs $849 + GST as flexible Self-Study or $928 + GST as guided eLearning — course and exam together, not priced separately. Both include two exam attempts — the initial sit plus one free resit within 12 months — and 12 months of myPECB access. A live Online Class or in-person Classroom in Melbourne and Sydney is available on request.
Every ISO 42001 course here is official PECB certification training. ISO 42001 training is priced with the ISO 42001 exam cost included and two attempts, so there is no separate examination fee to budget for.
The optional $89 + GST Aegentra Labs add-on offered on this page is supplementary exam preparation, not a fee for the official PECB examination. The PECB exam voucher and one free resit are already included in the course price.
What is on the ISO 42001 Lead Implementer exam?
PECB publishes the full specification in its candidate handbook, which providers summarise and none link to. The examination is 80 multiple-choice questions across six competency domains, open book, passing at 70%, over three hours. Each question has one correct answer and two distractors, and the scenario questions ask what a competent implementer would do next rather than what a clause says.
Open book has a defined meaning here, and it is worth knowing before you sit. The handbook names exactly what you may use: a hard copy of the ISO/IEC 42001 standard, your training course materials — through the PECB Exams app or printed — and any personal notes you took during the course. Nothing else. Candidates who assume open book means unrestricted internet access are the ones who struggle, and a printed index of your own notes is worth more on the day than a second read of the standard. The domain weightings and sample questions are in the PECB ISO/IEC 42001 Lead Implementer candidate handbook.
What happens if you fail the ISO 42001 Lead Implementer exam?
You sit it again at no cost. Because Aegentra Academy is an official PECB authorised training partner, the course fee covers the first attempt and one retake, valid for 12 months from the date your exam coupon is issued. There is no additional fee and no need to re-purchase the course. After a failed sit you also receive a breakdown of the domains you performed poorly in, which is the most useful preparation material available.
Provisional Implementer or Lead Implementer — which do you get?
Passing the exam and completing the training earns the credential; which tier you are awarded depends on experience you attest to afterwards. PECB Certified ISO/IEC 42001 Implementer requires two years of professional experience with one year in AI management and 200 hours of AIMS project activity. Lead Implementer requires five years with two in AI management plus 300 hours of AI project activities. You can sit the exam before you have those hours and upgrade the credential once you do — the exam result does not expire while you accumulate them.
This credential certifies you to build an AIMS. Getting an organisation certified is the separate project on the other side of it — costs and timelines are in the ISO 42001 certification guide for Australia. If you would rather have it built for you, that is our ISO 42001 AI governance service.
Free ISO 42001 documents you will actually have to produce
As Lead Implementer you are the person who writes these. They are published in full and free — no email required — and all three describe the same worked organisation, so you can follow one company from inventory through to impact assessment.
- Statement of Applicability (CSV) or PDF — all 38 Annex A controls with justifications, implementation status and the AI systems each covers. Note that every control is applicable here — unlike ISO 27001, an organisation that both develops and procures AI has almost nothing it can defensibly scope out, and the last column shows which controls a pure-deployer could argue down.
- AI system inventory (CSV) or PDF — eight worked AI systems with purpose, data, risk tier, human oversight and owner. Includes a shadow-AI row, because tools a team adopted without telling anyone are what scoping actually turns up, and they have to go somewhere.
- AI system impact assessment (CSV) or PDF — the Clause 8.4 assessment worked end to end for a résumé screening assistant — fairness testing, contestability, residual risk and who signed it off. This is the document that separates an AIMS from an ISMS with different words on it.
- Voluntary AI Safety Standard mapped to ISO 42001 (CSV) or PDF — all 10 Australian guardrails against the clauses that satisfy each. Use it to show a board why certification and government policy are the same programme of work, not two.
The parts of ISO 42001 an ISO 27001 background does not prepare you for
Clauses 4 to 10 follow Annex SL, so if you have implemented an ISMS the management-system half will feel familiar. Annex A defines 38 controls, and that is where the work is genuinely new: data quality and provenance across the AI lifecycle, third-party AI provider management, human oversight design, and transparency to the people a system affects.
Clause 8.4 — the AI system impact assessment — is the requirement with no ISO 27001 equivalent, and the one most implementations get wrong. A risk assessment asks what could harm the organisation. An impact assessment asks what the organisation's AI could do to individuals, groups and society. Reusing your risk register template for it produces a document that passes internal review and fails an assessor, because it never leaves the organisation's point of view.
ISO/IEC 42005 gives detailed guidance on conducting an impact assessment and ISO/IEC 23894 covers AI risk management. Neither is certifiable and neither is examinable, but an assessor will assume a Lead Implementer has read both.
Does ISO 42001 make you EU AI Act compliant?
No — and any provider implying otherwise is overselling it. ISO/IEC 42001 is not currently listed as a harmonised standard under the EU AI Act, so certification does not by itself confer presumption of conformity. Harmonised standards for the Act are still being developed through CEN-CENELEC JTC 21. Treat certification as substantial preparation, not as a compliance certificate.
That said, the overlap is the largest of any framework available today, and the work is not wasted. Article 17 of the AI Act requires providers of high-risk AI systems to operate a quality management system — and an AIMS built to ISO 42001 is structurally the same animal.
Where ISO 42001 alone will not get you there: conformity assessment and CE marking, registration in the EU database, the specific technical-documentation format Annex IV prescribes, and the Act's prohibited-practice rules, which are legal obligations rather than management-system ones. An AIMS gives you the governance machinery and most of the evidence; it does not give you the legal filing.
For Australian organisations the practical read is this: if you sell into the EU, build the AIMS now and expect to add AI Act-specific artefacts later. If you do not, ISO 42001 still answers the questions Australian buyers are already asking, and it maps cleanly onto Australia's 10 voluntary guardrails.
Every ISO 42001 course Aegentra Academy sells is official PECB certification training with the ISO 42001 exam bundled in — course and exam, one price, two attempts. There is no separate exam fee and no upsell at the point of sitting.
As a GRC manager, is ISO 42001 Lead Implementer worth it?
It is worth it if you want to own AI governance rather than advise on it. ISO 42001 is currently the only certifiable international management-system standard for artificial intelligence, so it is what Australian organisations reach for when a customer, a regulator or a board asks how AI is controlled. The credential is what says you can answer that question with a system rather than a policy document.
The practical test: if your organisation has AI in production and nobody owns its governance, that gap is yours to fill and this is the qualification that fills it.
As an ISO 27001 Lead Implementer, how much of this is new?
The management system is familiar — same Annex SL clauses, same governance loop. What is genuinely new is Annex A and Clause 8.4. The mistake ISO 27001 practitioners make most often is reusing their risk-register template for the AI system impact assessment. A risk assessment asks what could harm the organisation; an impact assessment asks what the organisation’s AI could do to individuals, groups and society. Same shape, opposite direction, and an assessor will notice.