Skip to main content

ISO systems, risk reviews and independent audits. Evidence, not decks.

Govern is Aegentra’s governance, risk and compliance practice. We implement ISO/IEC 27001 and ISO/IEC 42001 management systems, assess organisational risk management against ISO 31000, support SOC 2 and SOX readiness, and provide separately scoped ISO 27001, ISO 42001, ISO 9001 and ISO 45001 internal audits where objectivity can be protected. Every engagement begins with a written scope, responsibilities, assumptions and evidence plan.

Govern at a glance

What Govern is
Aegentra’s governance, risk and compliance practice
Standards and assurance services
ISO/IEC 27001, ISO/IEC 42001, ISO/IEC 27701, ISO 31000 risk review, SOC 2, SOX ITGC, and ISO 27001, 42001, 9001 and 45001 internal audits
Service area
Australia — all states and territories; New Zealand and wider Asia Pacific by arrangement
ISO 27001 control selection
Risk-selected controls recorded in the Statement of Applicability; Annex A is not a universal 93-control checklist
ISO 27001 timeline
Confirmed after scope, maturity, evidence, dependencies and certification-body availability are reviewed
Internal audit requirement
At planned intervals, with objectivity and impartiality protected and no self-review
Who certifies
An independent accredited certification body performs the certification audit and decides certification
Delivery model
Remote-first across Australia; onsite by arrangement where the agreed scope requires it

What Govern covers

Govern covers ISO/IEC 27001 information security management, ISO/IEC 42001 AI management systems, ISO/IEC 27701 privacy information management, ISO 31000 risk management reviews, SOC 2 readiness, SOX ITGC readiness and separately scoped ISO 27001, ISO 42001, ISO 9001 and ISO 45001 internal audits. ISO 31000 is guidance rather than a certifiable management-system standard. These are different frameworks and assurance activities, and compatible governance processes may be reused only after the scope, requirements and existing evidence have been assessed.

  • ISO/IEC 27001 information security management and ISO/IEC 42001 AI management-system implementation.
  • ISO/IEC 27701 privacy information management, ISO 31000 risk management review, SOC 2 readiness and SOX ITGC readiness.
  • Separately scoped ISO 27001, ISO 42001, ISO 9001 and ISO 45001 internal audits accepted only where objectivity and impartiality can be protected.

One accountable scope — how Govern is different

Govern combines management-system advice with hands-on implementation, but it does not collapse implementation, internal audit and certification into one role. Aegentra records the service boundary in the engagement scope and checks prior involvement before accepting assurance work. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. An independent accredited certification body remains responsible for the certification audit and certification decision.

  • Discovery confirms the scope, responsibilities, assumptions, exclusions, evidence plan and commercial terms.
  • Implementation starts from the organisation’s context, systems, obligations and risk-treatment decisions.
  • Compatible governance processes are reused only after the relevant scope, requirements and existing evidence have been assessed.

Internal audit at planned intervals

ISO/IEC 27001 Clause 9.2 requires internal audits at planned intervals. The auditor may be a competent internal employee or an external provider, provided the organisation protects objectivity and impartiality and the auditor does not audit their own work. Aegentra accepts internal-audit engagements only after checking the intended scope, prior involvement and conflicts. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required.

  • The audit programme defines frequency, scope, criteria, methods and sampling.
  • Internal audit, implementation and certification remain separate responsibilities.

Risk-selected controls and traceable evidence

Applicable Annex A controls are selected through the organisation’s risk assessment and recorded in the Statement of Applicability. Aegentra implements the management-system requirements and risk-selected controls agreed in scope; it does not treat all 93 Annex A controls as a universal implementation checklist.

  • Aeges can help collect and reproduce supported technical evidence from Microsoft 365 and maintain traceability between requirements, risks, owners, working papers and findings. It does not determine conformity, replace interviews or professional judgement, or provide evidence for every governance, people, physical or supplier control. The engagement scope identifies which evidence Aeges supports and which evidence must be obtained through documents, records, interviews, observation or other systems.

Australia-wide Govern delivery

Teams in Melbourne and Sydney. Delivered across all Australian states and territories, remotely or onsite by arrangement. New Zealand and Asia Pacific by arrangement. Discovery, workshops, evidence review and most fieldwork are normally completed remotely. Onsite attendance is available by arrangement where physical controls, secure evidence handling, stakeholder workshops or the agreed scope require it.

How Aegentra delivers Govern engagements across Australia
Engagement elementDelivery approach
Discovery and planningRemote
Document and evidence reviewRemote through agreed secure channels
InterviewsMicrosoft Teams or another agreed platform
Technical evidence testingRemote where evidence access and security arrangements permit
Physical security reviewOnsite where included in scope
Opening and closing meetingsRemote or onsite
Locations
All Australian states and territories

City services

ISO 27001 implementation, internal audits and certification support

TravelQuoted separately where onsite attendance is required

Govern services

  • ISO 27001 consulting and implementation — a risk-based ISMS with the agreed scope, Statement of Applicability, risk-selected controls, operating evidence and certification-body handover.
  • ISO 42001 (ISO/IEC 42001:2023) — the AI management system standard. Govern the AI you build, embed or deploy, and produce the evidence procurement now asks for.
  • ISO 27701 — ISO/IEC 27701:2025 privacy information management (PIMS), implemented standalone or integrated with an existing ISMS, with controls mapped to the Australian Privacy Principles.
  • SOX / ITGC readiness (Sarbanes-Oxley, ICFR) — IT general controls readiness for US-listed groups, their Australian subsidiaries, and pre-IPO companies.
  • SOC 2 readiness — Type I and Type II preparation, scope assessment and evidence planning. Starting packages suit small businesses with existing controls; independent CPA examination is separate. From A$7,500 + GST Explore SOC 2 services and pricing

Separately scoped audit and testing services

  • ISO 27001 internal audit (Clause 9.2) — separately scoped audits by a different consultant independent of implementation. Clause 9.2 requires auditors to be selected and audits conducted so objectivity and impartiality are protected.
  • ISO 42001 internal audit (Clause 9.2) — risk-based scope and sampling across applicable AIMS requirements.
  • SOX ITGC testing (Section 404) — independent or co-sourced management testing with traceable workpapers structured for external-auditor review.

The implementation route is set out step by step in the ISO 27001 implementation process. For the standard itself, costs in AUD and how Australian organisations get certified, see the ISO 27001 certification guide for Australia. To certify yourself rather than your organisation, Aegentra Academy runs the official PECB courses. Govern is one of four practices — see the solutions overview.

Govern FAQs

What is Aegentra’s Govern practice?

Govern is Aegentra’s governance, risk and compliance practice for management-system implementation, readiness support and separately scoped assurance work. Each engagement has a written scope, responsibilities, assumptions and evidence plan.

Which standards and assurance services does Govern cover?

Govern covers ISO/IEC 27001 information security management, ISO/IEC 42001 AI management systems, ISO/IEC 27701 privacy information management, ISO 31000 risk management reviews, SOC 2 readiness, SOX ITGC readiness and separately scoped ISO 27001, ISO 42001, ISO 9001 and ISO 45001 internal audits. ISO 31000 is guidance rather than a certifiable management-system standard. These are different frameworks and assurance activities, and compatible governance processes may be reused only after the scope, requirements and existing evidence have been assessed.

Where does Aegentra deliver Govern services?

Aegentra has teams based in Melbourne and Sydney, supporting organisations across Australia. Consulting, implementation and audit engagements are delivered remotely or onsite by arrangement, with the scope, delivery roles and fees agreed before work begins. Govern engagements are available across all Australian states and territories, with New Zealand and wider Asia Pacific engagements available by arrangement.

Who can perform an ISO 27001 internal audit?

ISO/IEC 27001 Clause 9.2 requires internal audits at planned intervals. The auditor may be a competent internal employee or an external provider, provided the organisation protects objectivity and impartiality and the auditor does not audit their own work. Aegentra accepts internal-audit engagements only after checking the intended scope, prior involvement and conflicts. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required.

Does Aegentra implement every Annex A control?

Applicable Annex A controls are selected through the organisation’s risk assessment and recorded in the Statement of Applicability. Aegentra implements the management-system requirements and risk-selected controls agreed in scope; it does not treat all 93 Annex A controls as a universal implementation checklist.

What evidence can Aeges support?

Aeges can help collect and reproduce supported technical evidence from Microsoft 365 and maintain traceability between requirements, risks, owners, working papers and findings. It does not determine conformity, replace interviews or professional judgement, or provide evidence for every governance, people, physical or supplier control. The engagement scope identifies which evidence Aeges supports and which evidence must be obtained through documents, records, interviews, observation or other systems.

Can several standards run as one integrated management system?

Compatible processes can be integrated where their scopes and requirements align, but reuse is assessed rather than assumed. Each standard or assurance engagement retains its own criteria, responsibilities and evidence boundaries.

How much does a Govern engagement cost?

Every Govern engagement is scoped after discovery. The written quote identifies the agreed work, assumptions, client responsibilities, exclusions and separate third-party fees. Pricing is in AUD and is confirmed before delivery begins.

Who leads Govern engagements?

Engagements are led by Harry Sidhu, Aegentra’s Director and Principal Consultant. Harry holds the PECB ISO/IEC 27001 Lead Implementer credential. Any additional delivery roles and responsibilities are identified in the agreed scope.

Who will deliver your governance engagement?

Every engagement begins with a written scope that identifies the accountable lead, any supporting roles and the boundary between advice, implementation, internal audit and certification.

  • Accountable delivery — Principal consultant. The named lead, responsibilities and exclusions are recorded in the written scope.
  • Specialist contribution — Assigned only where the agreed scope requires it. The specialist function, relationship and responsibility are disclosed before work begins.
  • Assurance boundary — Implementation, internal audit or readiness support. The scope states which service Aegentra is providing. An independent certification body makes certification decisions.

Qualified delivery matched to your scope

Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.

The people assigned to your engagement—and the experience and qualification evidence relevant to their roles—are confirmed in your proposal before work begins.

Team qualifications and credentials

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Credentials are held across the delivery team and matched to assigned roles. The proposal identifies the consultants, responsibilities and relevant qualification evidence before work begins.

Not every engagement uses every role. The engagement record, rather than a generic team claim, identifies who is responsible for the work. View our delivery-team capability.