ISO 27001, ISO 42001 and independent audits. Evidence, not decks.
Govern is Aegentra's governance, risk and compliance practice. We implement ISO 27001 and ISO 42001 management systems, support SOC 2 and SOX readiness, and run separately scoped independent internal audits for systems built in-house or by another provider. Every engagement starts with a written scope, responsibilities and evidence plan.
Govern is Aegentra's governance, risk and compliance practice. We implement ISO 27001 and ISO 42001 management systems, support SOC 2 and SOX readiness, and run separately scoped independent internal audits for systems built in-house or by another provider. Every engagement starts with a written scope, responsibilities and evidence plan.
Delivered remotely across Australia, New Zealand and the wider Asia Pacific — every state and territory, including regional and remote. On-site attendance is available nationally by arrangement.
Govern at a glance
- What Govern is
- Aegentra's governance, risk and compliance (GRC) practice
- Standards covered
- ISO/IEC 27001, ISO/IEC 42001, SOC 2 (Trust Services Criteria), SOX ITGC (ICFR), plus independent internal audit (ISO 27001 Clause 9.2)
- Service area
- Australia (all states and territories), New Zealand and the wider Asia Pacific — remote delivery, on-site nationally on request
- ISO 27001 controls
- 93 Annex A controls (ISO/IEC 27001:2022)
- ISO 27001 timeline
- Confirmed after scope, maturity, evidence and certification-body availability are reviewed
- ISO 42001 standard
- ISO/IEC 42001:2023 — AI management system (AIMS)
- SOX key sections
- Section 302 (certification) and Section 404 (ICFR assessment and attestation)
- Internal audit clause
- ISO 27001 Clause 9.2 — mandatory, must be independent
- Internal audit duration
- Confirmed in the audit plan after scope and sampling needs are reviewed
- Where it is built
- Inside your own Microsoft 365 tenant
- How it is evidenced
- Live, on-demand evidence from the Aeges risk engine
- Who certifies
- A JAS-ANZ-accredited certification body (ISO); the external auditor attests (SOX)
- Who delivers
- Australian-led; Principal Consultant holds PECB ISO 27001 LI and AGSVA NV1
- Pricing
- Fixed scope and fixed price, agreed after a Week 0 discovery
- Location
- Remote across Australia, New Zealand and Asia Pacific; onsite by arrangement
Govern: Aegentra's governance, risk and compliance practice
Govern is the practice within Aegentra that builds and evaluates the management systems customers, regulators and boards ask organisations to evidence. Implementation starts from the real scope, systems, obligations and risk treatment decisions rather than a generic policy pack. ISO 27001 and ISO 42001 can share compatible governance processes where that is appropriate, while independent internal audits are conflict-checked and kept separate from the work being evaluated. Delivery is remote across Australia, New Zealand and the wider Asia Pacific, with onsite attendance available by arrangement.
- Four implementation services: ISO 27001, ISO 42001 (AI management), SOC 2, and SOX ITGC internal controls.
- Plus independent internal audit — the ISO 27001 Clause 9.2 audit you are required to run, performed by someone who did not build the system.
- Built inside your own Microsoft 365 tenant, from your real configuration — never a generic template.
- Evidence mapped to applicable requirements, risks and control owners.
- Led by Harry Sidhu, a PECB ISO 27001 Lead Implementer with ten years of consulting experience.
- Fixed scope, responsibilities and pricing agreed after discovery.
One senior team, one tenant — how Govern is different
Most organisations are offered two models. A traditional consultancy advises, drafts policies and hands over a gap report; a compliance platform collects evidence but leaves the design and technical work to the client. Govern combines advice with implementation. The engagement starts from the organisation's scope, risks and systems, then assigns requirements to accountable owners and operating evidence. Compatible processes may be integrated across standards, but reuse is assessed rather than assumed.
- Model 1 — consultancy: advises and hands over a binder; your team still implements.
- Model 2 — platform: automates evidence; you still write policy and do the technical work.
- Govern — the third option: one senior team advises and implements, inside your tenant.
- One integrated management system across standards — add a spoke, reuse the governance.
How a Govern engagement runs
Every Govern engagement starts with a Week 0 discovery. A senior engineer maps your tenant, your contractual and regulatory obligations, and your risk appetite, then returns a fixed scope, a fixed price and a named lead — no hourly billing and no scope creep. From there the Aeges risk engine runs read-only against your environment to produce a control-by-control gap map, senior engineers implement each control directly in your tenant, and a pre-audit internal review closes residual findings before any external body sees the environment. The engineers who scope your programme are the ones who build it, and the same method runs whether you are certifying ISO 27001, standing up an ISO 42001 AIMS, or preparing for a SOX ICFR attestation.
- Week 0: discovery, fixed scope, fixed price, and a named lead.
- Gap map: Aeges runs read-only to show what is in place, partial or missing.
- Implementation: senior engineers configure each control directly inside your tenant.
- Handover: a clean evidence pack to the certification body or external auditor.
Where the evidence lives — the Aeges risk engine
The difference between a management system that operates and one that drifts is whether evidence stays current. Aeges is Aegentra's risk engine for collecting supported evidence from Microsoft 365. It can help reproduce technical control evidence and identify changes, while policies, interviews, management decisions and non-Microsoft systems still require their own records and audit sampling.
- Live, on-demand evidence pulled from your real Microsoft 365 configuration.
- One evidence spine shared across ISO 27001, ISO 42001 and SOX controls.
- Surfaces control drift before surveillance audits or year-end attestations.
- Optional retainer for quarterly re-runs and continuous monitoring.
What Govern implements
- ISO 27001 implementation (ISO/IEC 27001:2022) — the flagship ISMS the whole market recognises. 93 Annex A controls built in your tenant, audit-ready in about 12 weeks, then handed to a JAS-ANZ-accredited certification body.
- ISO 42001 (ISO/IEC 42001:2023) — the AI management system standard. Govern the AI you build, embed or deploy, and produce the evidence procurement now asks for.
- ISO 27701 — the privacy information management extension to ISO 27001, mapped to the Australian Privacy Principles.
- SOX / ITGC readiness (Sarbanes-Oxley, ICFR) — IT general controls readiness for US-listed groups, their Australian subsidiaries, and pre-IPO companies.
- SOC 2 readiness (AICPA Trust Services Criteria) — Type I and Type II audit preparation for Australian SaaS and MSPs selling into US buyers, with CPA-auditor liaison included.
What Govern audits
- ISO 27001 internal audit (Clause 9.2) — independent audits of an ISMS someone else built. Clause 9.2 requires auditors independent of the work being audited, which is exactly what a certification body checks.
- ISO 42001 internal audit (Clause 9.2) — Clauses 4–10 and all 38 Annex A controls sampled.
- SOX ITGC testing (Section 404) — independent or co-sourced management testing with traceable workpapers structured for external-auditor review.
The implementation route is set out step by step in the ISO 27001 implementation process. For the standard itself, costs in AUD and how Australian organisations get certified, see the ISO 27001 certification guide for Australia. To certify yourself rather than your organisation, Aegentra Academy runs the official PECB courses. Govern is one of four practices — see the solutions overview.
Govern FAQs
What is Aegentra's Govern practice?
Govern is Aegentra's governance, risk and compliance practice. It implements ISO 27001 and ISO 42001 management systems, supports SOC 2 and SOX readiness, and provides separately scoped independent internal audits. Aegentra prepares the system; an accredited certification body certifies an ISO management system.
Which Govern service is the most common starting point?
ISO 27001 is a common starting point because many Australian buyers and tenders recognise it. Its dedicated page covers scope, the 93-control Annex A reference set, risk treatment, implementation and audit readiness. ISO 42001, SOC 2 and SOX ITGC remain separate scopes; existing governance may be reused only after it is assessed.
Where does Aegentra deliver Govern services — is it Melbourne and Sydney only?
No. Govern engagements are delivered remotely across all of Australia — every state and territory, including regional and remote areas — as well as New Zealand and the wider Asia Pacific. Onsite attendance is available by arrangement. Aegentra is a remote business and does not publish a staffed office address.
Which governance standards does Govern cover?
Four: ISO/IEC 27001 (information security management), ISO/IEC 42001:2023 (AI management systems), SOX (US Sarbanes-Oxley internal controls over financial reporting), and the ISO 27001 Clause 9.2 internal audit delivered independently. All four are built inside your Microsoft 365 tenant and evidenced live, so they run as one integrated management system rather than four separate projects.
What is ISO 42001 and how does it relate to ISO 27001?
ISO/IEC 42001:2023 specifies requirements for an artificial intelligence management system. It has a management-system structure compatible with ISO 27001, so an operating ISMS may provide reusable processes such as document control, internal audit and corrective action. The amount of reuse depends on scope and maturity and is assessed during discovery.
Does Aegentra help with SOX compliance in Australia, and who needs it?
Yes. SOX applies to Australian companies listed on the NYSE or Nasdaq, Australian subsidiaries of US SEC-registrant parents, and businesses preparing for a US IPO. SOX is not a certificate — Section 302 requires executive certification of the financials and Section 404 requires an assessment of internal control over financial reporting (ICFR) against a framework such as COSO. Aegentra designs and operates the IT general controls in your Microsoft 365 tenant, maps them to your COSO matrix, and produces the live evidence your external auditor tests.
What is the ISO 27001 internal audit service?
It delivers the internal audit ISO 27001 Clause 9.2 requires, using objective and impartial auditors. The engagement covers the audit plan, evidence sampling across Clauses 4–10 and applicable Annex A controls, a findings register and corrective-action close-out. Schedule and price are confirmed after scope and sampling needs are reviewed. We audit; an accredited certification body certifies.
Can several standards run as one integrated management system?
Yes — that is the core of the Govern approach. ISO 27001 and ISO 42001 share the Annex SL structure, so the governance loop (context, leadership, risk treatment, internal audit, management review) is unified even though the Annex A control sets differ. SOX IT general controls and the ISO Annex A controls draw on the same live evidence from Aeges. Adding a spoke to an existing ISMS reuses the governance you already have instead of starting a fresh project.
Where is the evidence stored, and what is Aeges?
Aeges is Aegentra's risk engine for collecting supported evidence from Microsoft 365 and identifying changes in technical control state. It does not replace non-technical evidence, interviews, management decisions or independent audit sampling.
How much does a Govern engagement cost?
Every Govern engagement is scoped after discovery. The written quote identifies the agreed work, assumptions, client responsibilities, exclusions and separate third-party fees. Pricing is in AUD and is confirmed before delivery begins.
Who actually does the work?
Engagements are led by Harry Sidhu, Aegentra's Director and Principal Consultant. He holds the PECB ISO 27001 Lead Implementer credential, has ten years of consulting and cybersecurity experience, and holds an AGSVA NV1 security clearance. Any additional delivery roles are identified in the agreed scope.