Skip to main content
An ISO 27001 auditor reviewing evidence
Insight · ISO 27001 careersPublished 12 July 2026 · Updated 13 September 2026

How to become a certified ISO 27001 Lead Auditor in Australia

This guide explains the individual PECB ISO 27001 auditor pathway: learning, examination, credential application and the experience each tier requires. It also distinguishes your personal credential from certification of an organisation and appointment to a certification-body audit assignment.

By Harry SidhuISO 27001 Lead Implementer · Director and Principal Consultant, Aegentra11 min read

In short

Becoming a PECB ISO 27001 Lead Auditor involves learning the audit method, passing the examination and obtaining PECB approval of the required professional and audit experience. The Lead Auditor tier requires five years of professional experience, including two in information security management, and 300 qualifying audit hours. Provisional Auditor has no experience threshold, but an application and PECB approval are still required.

A$829
Self-Study excluding GST — official examination included
Aegentra Academy
300 hrs
Qualifying audit activity for the Lead Auditor tier
PECB requirements
5 years
Professional experience for Lead Auditor, including two in information security management
PECB requirements
4 tiers
Each requires a credential application and PECB approval
PECB requirements

The short version

  • Organisational ISO 27001 certification and personal PECB certification are separate processes. This guide concerns the individual auditor pathway.
  • Learning, examination success, credential application and credential award are separate stages. Provisional Auditor still requires an application and PECB approval.
  • Professional experience and qualifying audit hours are separate requirements: Auditor needs 200 hours, Lead Auditor 300 and Senior Lead Auditor 1,000.
  • Choose Self-Study (A$829 + GST), PECB eLearning (A$849 + GST) or private online training (A$2,799 + GST, by enquiry).

First, clear up the confusion: your company vs you

“ISO 27001 certification” means two completely different things depending on who is asking. Sort this out first — it decides which path you are on.

Path A

Certifying your company

Organisational certification concerns an organisation’s ISMS and a certification body’s decision following its assessment. The outcome is an organisational certificate — covered in our certification guide.

Path B · this guide

Certifying yourself

You earn a personal professional credential — PECB Certified ISO 27001 Lead Auditor — after PECB approves the examination, application and experience requirements for that tier. This is the path this guide covers.

What an ISO 27001 Lead Auditor actually does

An ISO 27001 auditor evaluates an ISMS against defined criteria, including the applicable management-system requirements. The work includes planning, reviewing the Statement of Applicability and supporting evidence, interviewing process owners, selecting samples, evaluating findings and reporting conclusions. Internal, supplier and certification audits have different purposes and commissioning organisations.

Building the ISMS is the other career track — covered in our companion guide, how to become a certified ISO 27001 Lead Implementer. Choose the pathway that fits the work you need to perform.

The step-by-step pathway

  1. 01

    Prepare and complete your learning

    PECB expects a fundamental understanding of ISO/IEC 27001 and comprehensive knowledge of audit principles. Foundation can help with unfamiliar terminology; Foundation and Lead Implementer are not mandatory prior credentials. Study how to plan, conduct, report and follow up an ISMS audit.

  2. 02

    Pass the PECB examination

    The current English PECB examination has 80 multiple-choice questions, including stand-alone and scenario-based questions, across seven competency domains. It lasts three hours, is open book under the permitted-reference rules and has a 70% pass mark. Check the current examination record and assigned candidate handbook in myPECB before booking, particularly for another language.

  3. 03

    Apply with evidence for the eligible tier

    Review the experience table and keep an audit log. Submit the credential application and required evidence, and meet PECB’s examination and Code of Ethics requirements. Provisional Auditor does not require professional experience or audit hours, but the application is still assessed.

  4. 04

    Receive PECB’s credential decision

    PECB evaluates your application and awards the tier supported by the evidence. Passing the examination alone does not award Provisional Auditor or the full Lead Auditor credential. Check the current maintenance requirements, applicable fees and CPD obligations for the tier awarded.

  5. 05

    Meet the requirements for an audit assignment

    A personal credential does not appoint you to conduct certification audits. A certification body separately evaluates your competence, relevant experience, technical knowledge and impartiality for its assignments. Employers and clients also set their own requirements for internal and supplier audit roles.

PECB ISO 27001 Lead Auditor course and exam

Credential tiers & the audit hours each one needs

The same examination supports all four tiers. Your professional experience and qualifying audit activity determine which tier you can apply for. PECB evaluates the application and supporting evidence; additional hours do not automatically upgrade a credential.

Credential tierTotal experienceIn infosec mgmtAudit hours
Provisional AuditorNone0
Auditor2 years1 yr200
Lead Auditorthe target5 years2 yrs300
Senior Lead Auditor10 years7 yrs1,000

Audit activity hours required, by tier

Provisional Auditor
0
Auditor
200
Lead Auditor
300
Senior Lead Auditor
1,000

Requirements are set by PECB — see the official ISO/IEC 27001 Lead Auditor credential page. Every tier also requires signing the PECB Code of Ethics.

The audit hours that actually count

Two things are counted separately. Professional experience is your years working — with a minimum in information security management (one year for Auditor, two for Lead, seven for Senior Lead). Audit activity hours are hands-on hours doing audit work itself.

PECB lists audit planning and programme management, interviews, document review, working papers, onsite audit activity, audit and nonconformity reports, follow-up and leading audit teams as relevant activities. Record the date, audit scope, your role, activities, hours and supporting references. PECB decides whether the evidence meets its requirements; course exercises do not replace qualifying audit activity.

Roles and career pathways in Australia

A personal credential does not appoint you to conduct certification audits. A certification body separately evaluates your competence, relevant experience, technical knowledge and impartiality for its assignments. Employers and clients also set their own requirements for internal and supplier audit roles.

Roles this credential supportsEligibility varies by role
Internal ISMS AuditorExperience dependent
GRC / Compliance AuditorExperience dependent
Certification-body ISO 27001 AuditorExperience dependent
Compliance / Risk ManagerExperience dependent
Audit & Assurance LeadExperience dependent

The credential may support progression into risk, governance, implementation, audit and consulting roles. Actual eligibility, remuneration and engagement requirements depend on experience, sector, location and employer or client requirements.

Where ISO 27001 audit work is used

Match the audit method, scope and competence to the purpose of the assignment:

  • Internal audits evaluate the organisation’s own ISMS against its audit criteria, with objectivity and impartiality protected.
  • Supplier audits evaluate another party against agreed requirements; the scope and reporting recipient depend on the commissioning organisation.
  • Certification audits support a certification body’s decision. An individual course certificate or credential does not certify an organisation.
  • Implementation and audit responsibilities need clear boundaries. Holding both credentials does not remove an independence problem when auditing work for which you are responsible.

For a separately scoped engagement, see Aegentra’s independent ISO 27001 internal-audit service. Assignment suitability and independence are assessed separately from training.

Course costs, study time and examination arrangements

Aegentra Academy offers Self-Study for A$829 + GST, PECB eLearning for A$849 + GST and private one-to-one online training for A$2,799 + GST per learner. Each includes the official PECB examination pathway. Australian billing addresses attract 10% GST; review supported currencies and the total payable on the course page before payment. Private training is arranged by enquiry, with the timetable, trainer, access, examination arrangements and terms confirmed in writing before payment.

One free retake is included within the applicable PECB cycle. For Self-Study and eLearning, the current 12-month cycle starts at purchase; for instructor-led training, it starts at course completion. Waiting periods and booking rules apply. Failing does not restart the cycle. The written private-training confirmation must identify which cycle applies to the blended package.

PECB ISO 27001 Lead Auditor course and exam · ISO 27001 learning pathway · Lead Auditor exam guide

FAQs

What is the difference between certifying my company and certifying myself?

Organisational certification concerns an organisation’s ISMS and a certification body’s decision following its assessment. Personal certification concerns the PECB credential tier approved for an individual after examination and application. An individual credential does not certify an organisation or appoint its holder to a certification-body audit team.

Do I need experience to start?

Course entry knowledge and credential experience are separate. PECB expects understanding of ISO/IEC 27001 and audit principles. Provisional Auditor has no professional-experience or audit-hour threshold, but passing alone does not award it: you must apply and receive PECB approval. The Lead Auditor tier requires five years of professional experience, including two in information security management, and 300 qualifying audit hours.

What counts as audit activity hours?

PECB lists audit planning and programme management, interviews, document review, working papers, onsite audit activity, audit and nonconformity reports, follow-up and leading audit teams as relevant activities. Record the date, audit scope, your role, activities, hours and supporting references. PECB decides whether the evidence meets its requirements; course exercises do not replace qualifying audit activity.

Lead Implementer or Lead Auditor — which should I take?

Choose Lead Implementer for establishing, operating and improving an ISMS, or Lead Auditor for evaluating it through audit planning, evidence collection, findings and reporting. Each has its own examination and experience pathway. Holding both credentials does not remove the need for objectivity when auditing work you helped implement.

How much does it cost and how long does it take?

Aegentra Academy offers Self-Study for A$829 + GST, PECB eLearning for A$849 + GST and private one-to-one online training for A$2,799 + GST per learner. Each includes the official PECB examination pathway. Australian billing addresses attract 10% GST; review supported currencies and the total payable on the course page before payment. Private training is arranged by enquiry, with the timetable, trainer, access, examination arrangements and terms confirmed in writing before payment. Aegentra estimates 30–40 hours of self-paced learning effort; this is not video runtime or a completion guarantee. Private teaching comprises 24 hours across four six-hour or eight three-hour sessions, plus a separate one-hour consultant session. The three-hour examination is arranged separately. No public group cohort or classroom venue is currently advertised.

Can a Lead Auditor certify a company to ISO 27001?

A personal credential does not appoint you to conduct certification audits. A certification body separately evaluates your competence, relevant experience, technical knowledge and impartiality for its assignments. Employers and clients also set their own requirements for internal and supplier audit roles.

Sources and factual checks

PECB course, examination and credential sources checked 13 September 2026. Check your assigned myPECB examination record and current booking terms before enrolling.

Official PECB course and credential requirements · Current candidate handbook · PECB examination and retake rules

Start here

Choose the learning format that fits your work

Aegentra Academy offers Self-Study for A$829 + GST, PECB eLearning for A$849 + GST and private one-to-one online training for A$2,799 + GST per learner. Each includes the official PECB examination pathway. Australian billing addresses attract 10% GST; review supported currencies and the total payable on the course page before payment. Private training is arranged by enquiry, with the timetable, trainer, access, examination arrangements and terms confirmed in writing before payment.

Reader preference

Follow Aegentra on Google

Choose Aegentra as a preferred source to see more of our latest insights in Google Search.

Your choice personalises your Google experience. It is not a general ranking or endorsement signal.