Skip to main content
Guide · Updated

ISO 37301 Certification Australia: A Complete Guide (2026)

A practical guide to ISO 37301 — the international standard for compliance management systems. Built for Australian compliance officers, GRC managers, and the organisations they work for, in a regulatory climate shaped by the Financial Services Royal Commission, ASIC's reportable situations regime, APRA CPS 230, and expanding whistleblower and AML/CTF obligations. Covers the typical timeline, real AUD costs, the two PECB course tiers, the exam, and the credential ladder.
By Harry Sidhu ISO 27001 Lead Implementer · Director and Principal Consultant, Aegentra11 min readLast reviewed

What is ISO 37301?

ISO 37301:2021 is the international standard for a Compliance Management System (CMS) — a documented, auditable system that identifies every obligation an organisation is subject to and demonstrates those obligations are actually being met. Obligations in the standard's vocabulary are broad: legislation and regulation, licence conditions, contractual commitments, industry codes, and voluntary undertakings. The standard is published by ISO.

ISO 37301 replaced ISO 19600 in April 2021, and the change matters: ISO 19600 was guidance, while ISO 37301 is a requirements standard that accredited certification bodies can audit and certify against. It uses Annex SL — the same high-level structure as ISO 27001 and ISO 22301 — so if you already run a certified management system, the governance loop is familiar. What changes is the subject matter: the full obligation set rather than security controls or continuity plans.

Two neighbouring standards are worth distinguishing. ISO 31000 is risk management guidance — not certifiable — that ISO 37301 borrows its risk-assessment thinking from. ISO 37001 is the anti-bribery management system standard: narrower in scope, certifiable, and frequently implemented alongside ISO 37301 with a single governance loop covering both.

Who needs ISO 37301 certification in Australia?

ISO 37301 has two audiences in Australia: organisations that need a defensible compliance framework, and the individuals who build careers running them. The roles that carry the credential:

  • Compliance officers and heads of compliance — the people who own the obligations register and answer to the board when a breach reaches the regulator. Lead Implementer is the practitioner credential for this seat.
  • Risk and GRC managers — remits have widened since the Royal Commission from operational risk to the full regulatory obligation set. ISO 37301 gives that wider remit a recognised structure.
  • Internal auditors and second-line assurance — boards increasingly ask audit committees to review the compliance framework itself, not just financial controls. Lead Auditor is the credential for forming that independent opinion.
  • Consultants and advisers — readiness reviews, enforceable-undertaking remediation programs, and compliance framework builds are a growing Australian advisory market. Holding both PECB tiers is the usual consultant profile.
  • Legal counsel and company secretaries — the natural internal candidates when an organisation formalises a compliance function for the first time and needs someone to translate obligations into controls.

The shorthand: if your organisation reports to ASIC, APRA, AUSTRAC, or an industry ombudsman — or holds licences and contracts with compliance conditions — someone internally should hold this credential.

Industries that need ISO 37301 in Australia

Four sectors generate most Australian ISO 37301 demand: financial services under ASIC and APRA, healthcare and aged care, government suppliers and regulated utilities, and the professions entering AML/CTF regulation in 2026. The pressure shows up differently in each, but the answer is the same management system.

Financial services — the post-Royal-Commission baseline

The Financial Services Royal Commission's final report in 2019 reset expectations for how Australian financial institutions manage compliance, and the regulatory follow-through has been sustained: the reportable situations regime (in force since October 2021) requires AFS and credit licensees to report significant breaches to ASIC within 30 days; RG 271 tightened internal dispute resolution; the Financial Accountability Regime attaches personal accountability to executives; and APRA CPS 220 and CPS 230 require risk management frameworks that expressly cover compliance and operational risk. Every one of those regimes assumes the organisation can detect, escalate, and evidence non-compliance systematically. ISO 37301 is the certifiable structure for exactly that capability.

Healthcare and aged care

Providers operate under dense, overlapping obligation sets — accreditation standards, the strengthened Aged Care Quality Standards, clinical governance, privacy, and funding conditions — each with its own reviewer. A CMS gives the organisation a single obligations register and a single review cycle rather than parallel compliance efforts per regulator, and gives the board evidence that conditions attached to funding are being met rather than assumed.

Government suppliers and regulated utilities

Where contracts carry compliance conditions and audit rights — Commonwealth panels, defence supply chains, energy and water licensees — demonstrating a systematic approach to obligations is increasingly a procurement expectation rather than an internal nicety. Suppliers already holding ISO 9001 or ISO 27001 certificates find ISO 37301 slots into the same integrated management system, sharing the internal audit and management review cycle.

Professions entering AML/CTF regulation — Tranche 2

From 1 July 2026, Australia's AML/CTF regime extends to tranche-two entities — lawyers, accountants, real estate professionals, and trust and company service providers — under AUSTRAC supervision. Thousands of firms that have never run a formal compliance program must now stand up customer due diligence, transaction monitoring, reporting, and a documented AML/CTF program. ISO 37301 is the management-system skeleton that absorbs a new obligation set like this without inventing a framework from scratch, which is why 2026 is driving a visible uptick in Australian CMS interest.

Mapping ISO 37301 to Australian regulatory expectations

ISO 37301 is not Australian law, but it is the management-system structure most often used to satisfy the compliance-framework expectations Australian regulators now hold. The table summarises the regimes Aegentra is most often asked about.

Regulation or frameworkWhat it requiresHow ISO 37301 helps
ASIC reportable situations regimeAFS and credit licensees must identify significant breaches and report them to ASIC within 30 days of deciding a situation is reportable.The CMS obligations register, monitoring controls, and escalation paths make breach detection systematic rather than incidental — the difference between reporting on time and explaining a late report.
APRA CPS 220 and CPS 230A risk management framework covering compliance risk (CPS 220), plus operational risk and service-provider management obligations (CPS 230, in force July 2025).A documented CMS is the standing evidence that compliance risk is identified, owned, controlled, and reviewed — the exact questions APRA supervisors ask in prudential reviews.
Whistleblower protections (Corporations Act Part 9.4AAA)Public and large proprietary companies must maintain a whistleblower policy, protect disclosers, and prevent victimisation.ISO 37301 requires a raising-concerns process with protection from retaliation as a core CMS element — the operational machinery behind the policy the law requires.
AML/CTF Act (AUSTRAC) — including Tranche 2Regulated entities must run an AML/CTF program: customer due diligence, monitoring, and reporting. Tranche-two professions come under the regime from 1 July 2026.The CMS provides the governance loop — obligations, controls, training, monitoring, review — that an AML/CTF program needs to operate inside, particularly for firms regulated for the first time.
Privacy Act 1988 and the NDB schemeAPP compliance plus assessment and notification of eligible data breaches to the OAIC and affected individuals.Privacy obligations sit in the same register as every other obligation, with owners, controls, and escalation. The CMS non-compliance handling process drives the NDB assessment clock.
Modern Slavery Act 2018Entities with revenue over $100M must publish annual modern slavery statements covering supply-chain risk and due diligence.Supplier due diligence, obligation tracking, and evidence collection are standing CMS processes — the statement becomes an output of the system rather than an annual scramble.
Australian Consumer Law (ACCC)Prohibitions on misleading conduct, unfair contract terms (with substantial penalties since 2023), and product safety obligations.Court-enforceable undertakings routinely require a compliance program; an ISO 37301-aligned CMS is the recognised template, and holding one before an issue arises is strong mitigation evidence.

The pattern across all seven items is the same: ISO 37301 is rarely a literal requirement, but it is almost always the most efficient documentary answer to a regulator, a board audit committee, or a procurement team that asks "show me your compliance framework."

How long does ISO 37301 certification take?

For an Australian SMB that already runs an Annex SL management system — ISO 27001 or ISO 9001, say — the realistic plan is 12–16 weeks of readiness followed by a Stage 1 / Stage 2 audit. Most of that time goes into the compliance obligations register: identifying every obligation source, assigning owners, mapping controls, and setting review frequencies. The governance skeleton — internal audit, management review, corrective action — extends from the existing system.

A greenfield build with no existing management system is typically four to six months. The extra time is not the documentation; it is embedding the monitoring and escalation behaviours so that Stage 2 evidence shows a system operating, not a binder written the month before.

As with every ISO scheme, audit bookings need 6–10 weeks lead time with Australian certification bodies. Book Stage 2 at the start of readiness, not the end.

Individual training is a sub-$1,000 decision; certifying the organisation is a five-figure program. Budget for both sides separately.

How much does ISO 37301 certification cost in Australia?

Individual PECB training (Aegentra Academy)

Prices exclude GST (added at checkout). Both include the official PECB exam voucher, one free resit within 12 months, 12 months of myPECB access, and 31 CPD credits. There is no Foundation tier for ISO 37301 — the range starts at Lead level.

Organisational certification

Ranges are typical for an Australian SMB of 10–50 staff. Organisations extending an existing Annex SL system land at the lower end; greenfield builds at the upper end.

ComponentTypical AUDFrequency
Readiness and implementation support$25,000–$55,000Once
Stage 1 + Stage 2 certification audit$8,000–$18,000Once (every 3 years)
Annual surveillance auditStarting at $2,500Year 1 + Year 2
Three-year re-certification$8,000–$15,000Year 3
Before any policy is written, you build the compliance obligations register — every obligation source, an owner, a control, and evidence it operates.

The certification process, step-by-step

  1. 01
    Compliance obligations register

    Identify every obligation source — legislation, licences, contracts, codes, voluntary commitments. Record the requirement, the owner, the control that satisfies it, the evidence, and the review frequency. This register is the spine of the whole system.

  2. 02
    Context and scope

    Define what the CMS covers — entities, business lines, jurisdictions. Analyse interested parties: regulators, licensors, customers, and the board. Declare the scope you will be audited against.

  3. 03
    Compliance risk assessment

    Assess each obligation for likelihood and consequence of non-compliance. This prioritises where controls and monitoring effort concentrate — the standard expects risk-based proportionality, not uniform coverage.

  4. 04
    CMS design

    Write the compliance policy, define the compliance function and its independence, set roles and authorities, and establish the raising-concerns (speak-up) process with protection from retaliation.

  5. 05
    Control implementation

    Operationalise the controls — training and awareness, third-party due diligence, monitoring and indicators, and the non-compliance handling process from detection through escalation to regulatory reporting where required.

  6. 06
    Internal audit

    An independent reviewer audits the CMS against every applicable ISO 37301 clause. If you run other Annex SL systems, this typically joins the existing internal audit program.

  7. 07
    Management review

    Leadership reviews CMS performance — obligations changes, non-compliance events, indicator trends, audit results — and records decisions. Auditors read this record closely; it evidences governing-body engagement.

  8. 08
    Stage 1 audit

    Documentation review by an accredited certification body: the register, the policy, the risk assessment, and readiness for Stage 2. Typically 1–2 days, often remote.

  9. 09
    Stage 2 audit and certificate

    Effectiveness audit — evidence sampled against operating controls, staff interviewed, escalations traced end-to-end. On a clear result, a three-year certificate issues with annual surveillance in years one and two.

Two tiers, one decision: Lead Implementer builds the compliance management system; Lead Auditor independently assesses one.

Choosing a PECB ISO 37301 course

The ISO 37301 range runs at two tiers — there is no Foundation course. The decision is a role decision: implementers build and run the CMS; auditors form an independent opinion on one. Both are five-day-equivalent programs delivered as self-paced study, both end in the same style of three-hour PECB exam, and both are $849 + GST.

CourseBuilt forPrice (AUD + GST)Format and effort
ISO 37301 Lead ImplementerCompliance officers, GRC managers, and consultants building and running a CMS — the internal owner of the obligations register.$849 + GSTSelf-study, 35–45 hours, 500+ pages of material, 31 CPD credits.
ISO 37301 Lead AuditorInternal auditors, second-line assurance, and certification-body careers — auditing a CMS under ISO 19011 and ISO/IEC 17021-1.$849 + GSTSelf-study, 35–45 hours, 450+ pages of material, 31 CPD credits.

Practitioners who intend to consult independently often take both: holding Lead Implementer and Lead Auditor in a scheme qualifies you for the corresponding PECB Master credential, subject to four additional Foundation exams. Most people start with Lead Implementer, because understanding how a CMS is built makes it easier to judge whether one is working.

Aegentra Academy is an official PECB authorised training partner in Australia (verifiable on the PECB partner directory). Every enrolment includes the official PECB exam voucher and a free resit within 12 months. In-person and instructor-led delivery is available in Melbourne and Sydney on request.

The exam and credential tiers

Both ISO 37301 exams follow the standard PECB Lead-level format: three hours, open-book, mixing multiple-choice and scenario-based questions across seven competency domains, with a 70% pass mark. The exam is remotely proctored, so you can sit it from anywhere in Australia. Certification and examination fees are included in the course price, with one free retake within 12 months of the initial exam date.

The credential you receive depends on attested professional experience, not on which exam you sat. On the implementer ladder: Provisional Implementer requires no experience; Implementer requires two years (one in compliance management) plus 200 hours of activities; Lead Implementer requires five years (two in compliance management) plus 300 hours; Senior Lead Implementer requires ten years (seven in compliance management) plus 1,000 hours. The auditor ladder mirrors this exactly, with audit hours in place of project hours. All tiers require signing the PECB Code of Ethics, and credentials are maintained through CPD.

A practical note on transferability: the Lead Auditor method is not ISO 37301-specific. It is the general management-system audit discipline of ISO 19011 plus the certification process of ISO/IEC 17021-1 — the same method used to audit ISO 27001 and ISO 42001 systems. Auditors accumulate schemes rather than restart each time, which is why the credential compounds well for a GRC career.

FAQs

No. ISO 37301 is voluntary. But ASIC and APRA both expect regulated entities to operate a systematic compliance framework — ASIC through the reportable situations regime and RG 271, APRA through CPS 220 and CPS 230. ISO 37301 is the most rigorous certifiable structure for that framework, and the certificate is the cleanest documentary evidence when a regulator, board, or procurement team asks how compliance is actually managed.

Yes. ISO 37301:2021 is a requirements standard, which means accredited certification bodies can audit and certify against it. This is the key change from its predecessor ISO 19600, which was guidance only. The certificate follows the standard ISO pattern: a Stage 1 and Stage 2 audit, a three-year certificate, and annual surveillance audits.

Yes. ISO 37301:2021 replaced ISO 19600:2014 in April 2021. The substantive change is certifiability: ISO 19600 was a guidance document, while ISO 37301 contains auditable requirements. Organisations that aligned to ISO 19600 can generally transition without restructuring, because the underlying compliance management principles carried over.

ISO 37301 is the general compliance management standard — it covers the full obligation set an organisation faces, whether legal, regulatory, contractual, or voluntary. ISO 37001 is a targeted anti-bribery management system standard. They share the Annex SL structure and are frequently implemented together with a single governance loop. If bribery and corruption is the dominant risk, start with ISO 37001; if the problem is the breadth of your obligations, start with ISO 37301.

Not in the Aegentra Academy line-up. PECB training for ISO 37301 through Aegentra runs at two tiers: Lead Implementer for the person building and running the compliance management system, and Lead Auditor for the person independently assessing one. Both are $849 + GST, delivered as self-paced study with the official exam voucher and one free resit included.

Both ISO 37301 exams are three hours, open-book, and remotely proctored, mixing multiple-choice and scenario-based questions across seven competency domains with a 70% pass mark. The exam voucher is included in the course price, and a free retake within 12 months of the initial exam date is included if you do not pass the first time.

None to sit the exam. After passing, you can apply for the Provisional Implementer credential. Implementer requires two years of experience with one in compliance management plus 200 hours of activities. Lead Implementer requires five years with two in compliance management plus 300 hours. Senior Lead Implementer requires ten years with seven in compliance management plus 1,000 hours. PECB must approve the application; the Lead Auditor ladder mirrors this with audit hours instead of project hours.

No. The course certifies you as a practitioner. Certifying the organisation requires actually building the CMS — the compliance obligations register, controls, monitoring, and internal audit — then passing a Stage 1 and Stage 2 audit by an accredited certification body. The course teaches exactly that work, including preparation for the certification audit.

Next step

Build a compliance function that holds up in front of the regulator.

Two paths. Both run by senior practitioners, not consultants reading from a deck.