The short version
- Passing the exam allows you to apply for the PECB credential that matches your experience. It does not automatically award the Lead Auditor title.
- You should have a fundamental understanding of ISO 42001 and AI concepts. Foundation can help you build that knowledge, but a Foundation certificate is not automatically a compulsory first step. Previous ISO 27001 or other management-system audit experience is useful; it does not remove the need to understand AI-specific risks, impacts and evidence.
- This is not a course in building machine-learning models, and an AIMS audit does not certify that every model output is correct or that a product is free from bias. Technical evaluations may form part of the evidence, but the auditor still needs the competence to understand their relevance and limitations.
- Record actual audit work with dates, scope, your personal role, hours and supporting evidence. PECB decides which experience is accepted.
What an ISO 42001 Lead Auditor actually is
ISO/IEC 42001:2023 is the management-system standard for artificial intelligence — the AI equivalent of what ISO 27001 is for information security. A Lead Auditor is the person who checks whether that system actually works: planning the audit, sampling evidence about models, data and human oversight, testing whether the impact assessments were done and acted on, classifying nonconformities, and writing an opinion someone else will rely on. If you want the detail on the standard itself and how organisations get certified, that is covered in our ISO 42001 certification guide. This page is about the individual credential and the career behind it.
Two clarifications worth making early, because they are where most of the confusion sits. First, the Lead Auditor assesses the system; the Lead Implementer builds it. They are separate credentials and separate career tracks — see the ISO 42001 Lead Implementer course if building is where you are headed. Second, this is an assurance role, not a machine-learning role. You do not need to be able to build a model. You need to be able to ask what evidence exists that it behaves as claimed — and to recognise when the answer is nothing.
The step-by-step pathway
- 01
Build the required grounding
You should have a fundamental understanding of ISO 42001 and AI concepts. Foundation can help you build that knowledge, but a Foundation certificate is not automatically a compulsory first step. Previous ISO 27001 or other management-system audit experience is useful; it does not remove the need to understand AI-specific risks, impacts and evidence.
- 02
Choose the appropriate learning format
Both self-paced options prepare you for the same PECB examination pathway. The difference is how you prefer to learn, not a different credential at the end.
- 03
Complete the applicable examination
The official PECB examination is included in your enrolment. PECB's published course brochure specifies a three-hour exam covering seven competency domains. Check the current PECB exam listing for the applicable language, assessment format, question count and pass mark before booking.
- 04
Record real audit activity
Keep accurate records of the audit dates, scope, your role, activities personally performed and hours, with supporting evidence. Protect client confidentiality and obtain permission before sharing a reference contact.
- 05
Apply for the tier you can evidence
After passing, apply to PECB for the credential supported by your professional and audit experience. Learners without the required experience for a higher tier can consider the Provisional Auditor pathway. PECB assesses the application; Aegentra cannot pre-approve the credential awarded.
- 06
Check maintenance for your tier
Ongoing certification conditions are separate from course completion. Check PECB's current maintenance and continuing professional development requirements for the tier you hold before renewal; do not assume the enrolment price covers every future fee.
Aegentra Academy is an official PECB authorised training partner and delivers the ISO 42001 Lead Auditor course online and self-paced, with instructor-led delivery available on request. Foundation-level grounding is available through the ISO 42001 Foundation course.
Credential tiers & the experience each one needs
“Lead Auditor” is not a single pass/fail credential — it is the third rung of a four-tier ladder. All four tiers sit the same exam. What separates them is the professional experience and the hours of AIMS audit or assessment activity you can evidence. You pass the exam once, then climb as your career grows.
| Credential tier | Total experience | In AI management | AIMS project hours |
|---|---|---|---|
| Provisional Auditor | None | — | 0 |
| Auditor | 2 years | 1 yr | 200 |
| Lead Auditorthe target | 5 years | 2 yrs | 300 |
| Senior Lead Auditor | 10 years | 7 yrs | 1,000 |
AIMS project hours required, by tier
These are PECB scheme requirements, not requirements of the ISO standard itself — confirm the current criteria on the official PECB ISO/IEC 42001 Lead Auditor page. Every tier also requires signing the PECB Code of Ethics.
What counts as AIMS audit hours
Two things are counted separately. Professional experience is your years of work, with a minimum specifically in AI — one year for Auditor, two for Lead Auditor, seven for Senior Lead Auditor. Audit activity hours are hours spent auditing or assessing an AI management system.
The activities below are audit activities, not a promise that every hour qualifies. Building an inventory, implementing controls or attending training does not automatically establish audit experience. Record the work you actually performed and ask PECB about uncertain eligibility.
Planning an audit
Record the objectives, scope, criteria, method and sample you personally helped plan.
Managing an audit programme
Record your actual responsibilities and work on the AIMS audit programme.
Preparing audit working documents
Retain appropriate references for audit plans, questions and working papers you prepared.
Reviewing documents and records
Record the requirements and evidence you examined as part of the audit.
Conducting on-site audit activities
Describe interviews, observations and evidence sampling you personally performed.
Leading an audit team
Record the engagement, team role and responsibilities you actually held.
Preparing audit and nonconformity reports
Record your contribution to reports, evidence evaluation and finding statements.
Performing audit follow-up
Describe your verification of correction and corrective action, with appropriate evidence references.
The Implementer and Auditor routes are complementary, not interchangeable. Holding both does not remove the need for objectivity or make it appropriate to independently audit your own implementation work. Choose based on the role you need to perform, then check the credential requirements for that route. Use the audit experience log (CSV) and its field guidance to record real engagements. The ISO 42001 internal audit checklist provides further evidence prompts. The course page also provides a fictional worked audit example for learning; never record it as professional experience.
Australian context for audit work
Separate guidance, adopted commitments and binding audit criteria. The course does not replace an assessment of the requirements for a particular engagement.
Australian AI adoption guidance
Australia's Guidance for AI Adoption provides practical guidance for responsible AI use and develops the earlier Voluntary AI Safety Standard. For an auditor, the important distinction is between a reference framework, an organisation's adopted commitments and the actual criteria of the audit.
Organisational commitments
Policies, contracts and adopted frameworks may inform agreed audit criteria. Identify what actually applies to the engagement before testing evidence.
Limits of a mapping
A mapping between guidance and ISO 42001 can help organise questions, but it does not prove conformity or legal compliance. Identify the relevant scope and criteria, then examine the evidence. Course completion does not certify an organisation or guarantee that an AI system meets every applicable obligation.
Read the current Australian Guidance for AI Adoption. A course or a framework mapping does not establish legal compliance.
Roles and career pathways in Australia
These are examples of roles in which AIMS audit knowledge may be relevant. They are not a survey of current vacancies or a promise of appointment. A certification body must assess competence and appointment separately.
The credential may support progression into risk, governance, implementation, audit and consulting roles. Actual eligibility, remuneration and engagement requirements depend on experience, sector, location and employer or client requirements.
Auditing an AIMS vs auditing an ISMS
ISO 19011 provides management-system audit guidance. Shared structure does not make AIMS and ISMS requirements identical. The scope, relevant risks, evidence and auditor competence must be considered for each engagement.
| Auditing an ISMS | Auditing an AIMS | |
|---|---|---|
| System audited | Information Security Management System (ISMS) | AI Management System (AIMS) |
| Audit guidance | ISO 19011; certification-body requirements where applicable | ISO 19011; certification-body requirements where applicable |
| Clause structure | Annex SL clauses 4–10 | The same Annex SL clauses 4–10 |
| What you sample | Access reviews, logs, backups, patch records | Model test results, training-data provenance, oversight records |
| Evidence limits | Depend on the organisation, scope and available records | Depend on the organisation, scope and available records |
| The distinguishing clause | Risk assessment and treatment (6.1) | AI system impact assessment (8.4) — no ISO 27001 equivalent |
| Control set | Annex A of ISO/IEC 27001:2022 | 38 Annex A controls of ISO/IEC 42001:2023 |
| Finding basis | Applicable requirements and objective evidence | Applicable requirements and objective evidence |
An integrated engagement still needs appropriate scope, criteria and competence for each management system. For the information-security pathway, read how to become a certified ISO 27001 Lead Auditor. If your organisation needs the audit performed rather than a person trained, that is our ISO 42001 internal audit service.
FAQs
More practitioner guides in the Aegentra Insights library.

