ISO systems, risk reviews and independent audits. Evidence, not decks.
Govern is Aegentra’s governance, risk and compliance practice. We implement ISO/IEC 27001 and ISO/IEC 42001 management systems, assess organisational risk management against ISO 31000, support SOC 2 and SOX readiness, and provide separately scoped ISO 27001, ISO 42001, ISO 9001 and ISO 45001 internal audits where objectivity can be protected. Every engagement begins with a written scope, responsibilities, assumptions and evidence plan.
Govern at a glance
- What Govern is
- Aegentra’s governance, risk and compliance practice
- Standards and assurance services
- ISO/IEC 27001, ISO/IEC 42001, ISO/IEC 27701, ISO 31000 risk review, SOC 2, SOX ITGC, and ISO 27001, 42001, 9001 and 45001 internal audits
- Service area
- Australia — all states and territories; New Zealand and wider Asia Pacific by arrangement
- ISO 27001 control selection
- Risk-selected controls recorded in the Statement of Applicability; Annex A is not a universal 93-control checklist
- ISO 27001 timeline
- Confirmed after scope, maturity, evidence, dependencies and certification-body availability are reviewed
- Internal audit requirement
- At planned intervals, with objectivity and impartiality protected and no self-review
- Who certifies
- An independent accredited certification body performs the certification audit and decides certification
- Delivery model
- Remote-first across Australia; onsite by arrangement where the agreed scope requires it
What Govern covers
Govern covers ISO/IEC 27001 information security management, ISO/IEC 42001 AI management systems, ISO/IEC 27701 privacy information management, ISO 31000 risk management reviews, SOC 2 readiness, SOX ITGC readiness and separately scoped ISO 27001, ISO 42001, ISO 9001 and ISO 45001 internal audits. ISO 31000 is guidance rather than a certifiable management-system standard. These are different frameworks and assurance activities, and compatible governance processes may be reused only after the scope, requirements and existing evidence have been assessed.
- ISO/IEC 27001 information security management and ISO/IEC 42001 AI management-system implementation.
- ISO/IEC 27701 privacy information management, ISO 31000 risk management review, SOC 2 readiness and SOX ITGC readiness.
- Separately scoped ISO 27001, ISO 42001, ISO 9001 and ISO 45001 internal audits accepted only where objectivity and impartiality can be protected.
One accountable scope — how Govern is different
Govern combines management-system advice with hands-on implementation, but it does not collapse implementation, internal audit and certification into one role. Aegentra records the service boundary in the engagement scope and checks prior involvement before accepting assurance work. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. An independent accredited certification body remains responsible for the certification audit and certification decision.
- Discovery confirms the scope, responsibilities, assumptions, exclusions, evidence plan and commercial terms.
- Implementation starts from the organisation’s context, systems, obligations and risk-treatment decisions.
- Compatible governance processes are reused only after the relevant scope, requirements and existing evidence have been assessed.
Internal audit at planned intervals
ISO/IEC 27001 Clause 9.2 requires internal audits at planned intervals. The auditor may be a competent internal employee or an external provider, provided the organisation protects objectivity and impartiality and the auditor does not audit their own work. Aegentra accepts internal-audit engagements only after checking the intended scope, prior involvement and conflicts. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required.
- The audit programme defines frequency, scope, criteria, methods and sampling.
- Internal audit, implementation and certification remain separate responsibilities.
Risk-selected controls and traceable evidence
Applicable Annex A controls are selected through the organisation’s risk assessment and recorded in the Statement of Applicability. Aegentra implements the management-system requirements and risk-selected controls agreed in scope; it does not treat all 93 Annex A controls as a universal implementation checklist.
- Aeges can help collect and reproduce supported technical evidence from Microsoft 365 and maintain traceability between requirements, risks, owners, working papers and findings. It does not determine conformity, replace interviews or professional judgement, or provide evidence for every governance, people, physical or supplier control. The engagement scope identifies which evidence Aeges supports and which evidence must be obtained through documents, records, interviews, observation or other systems.
Australia-wide Govern delivery
Teams in Melbourne and Sydney. Delivered across all Australian states and territories, remotely or onsite by arrangement. New Zealand and Asia Pacific by arrangement. Discovery, workshops, evidence review and most fieldwork are normally completed remotely. Onsite attendance is available by arrangement where physical controls, secure evidence handling, stakeholder workshops or the agreed scope require it.
| Engagement element | Delivery approach |
|---|---|
| Discovery and planning | Remote |
| Document and evidence review | Remote through agreed secure channels |
| Interviews | Microsoft Teams or another agreed platform |
| Technical evidence testing | Remote where evidence access and security arrangements permit |
| Physical security review | Onsite where included in scope |
| Opening and closing meetings | Remote or onsite |
| Locations | All Australian states and territoriesCity services ISO 27001 implementation, internal audits and certification support |
| Travel | Quoted separately where onsite attendance is required |
Govern services
- ISO 27001 consulting and implementation — a risk-based ISMS with the agreed scope, Statement of Applicability, risk-selected controls, operating evidence and certification-body handover.
- ISO 42001 (ISO/IEC 42001:2023) — the AI management system standard. Govern the AI you build, embed or deploy, and produce the evidence procurement now asks for.
- ISO 27701 — ISO/IEC 27701:2025 privacy information management (PIMS), implemented standalone or integrated with an existing ISMS, with controls mapped to the Australian Privacy Principles.
- SOX / ITGC readiness (Sarbanes-Oxley, ICFR) — IT general controls readiness for US-listed groups, their Australian subsidiaries, and pre-IPO companies.
- SOC 2 readiness — Type I and Type II preparation, scope assessment and evidence planning. Starting packages suit small businesses with existing controls; independent CPA examination is separate. From A$7,500 + GST Explore SOC 2 services and pricing
Separately scoped audit and testing services
- ISO 27001 internal audit (Clause 9.2) — separately scoped audits by a different consultant independent of implementation. Clause 9.2 requires auditors to be selected and audits conducted so objectivity and impartiality are protected.
- ISO 42001 internal audit (Clause 9.2) — risk-based scope and sampling across applicable AIMS requirements.
- SOX ITGC testing (Section 404) — independent or co-sourced management testing with traceable workpapers structured for external-auditor review.
The implementation route is set out step by step in the ISO 27001 implementation process. For the standard itself, costs in AUD and how Australian organisations get certified, see the ISO 27001 certification guide for Australia. To certify yourself rather than your organisation, Aegentra Academy runs the official PECB courses. Govern is one of four practices — see the solutions overview.
Govern FAQs
What is Aegentra’s Govern practice?
Govern is Aegentra’s governance, risk and compliance practice for management-system implementation, readiness support and separately scoped assurance work. Each engagement has a written scope, responsibilities, assumptions and evidence plan.
Which standards and assurance services does Govern cover?
Govern covers ISO/IEC 27001 information security management, ISO/IEC 42001 AI management systems, ISO/IEC 27701 privacy information management, ISO 31000 risk management reviews, SOC 2 readiness, SOX ITGC readiness and separately scoped ISO 27001, ISO 42001, ISO 9001 and ISO 45001 internal audits. ISO 31000 is guidance rather than a certifiable management-system standard. These are different frameworks and assurance activities, and compatible governance processes may be reused only after the scope, requirements and existing evidence have been assessed.
Where does Aegentra deliver Govern services?
Aegentra has teams based in Melbourne and Sydney, supporting organisations across Australia. Consulting, implementation and audit engagements are delivered remotely or onsite by arrangement, with the scope, delivery roles and fees agreed before work begins. Govern engagements are available across all Australian states and territories, with New Zealand and wider Asia Pacific engagements available by arrangement.
Who can perform an ISO 27001 internal audit?
ISO/IEC 27001 Clause 9.2 requires internal audits at planned intervals. The auditor may be a competent internal employee or an external provider, provided the organisation protects objectivity and impartiality and the auditor does not audit their own work. Aegentra accepts internal-audit engagements only after checking the intended scope, prior involvement and conflicts. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required.
Does Aegentra implement every Annex A control?
Applicable Annex A controls are selected through the organisation’s risk assessment and recorded in the Statement of Applicability. Aegentra implements the management-system requirements and risk-selected controls agreed in scope; it does not treat all 93 Annex A controls as a universal implementation checklist.
What evidence can Aeges support?
Aeges can help collect and reproduce supported technical evidence from Microsoft 365 and maintain traceability between requirements, risks, owners, working papers and findings. It does not determine conformity, replace interviews or professional judgement, or provide evidence for every governance, people, physical or supplier control. The engagement scope identifies which evidence Aeges supports and which evidence must be obtained through documents, records, interviews, observation or other systems.
Can several standards run as one integrated management system?
Compatible processes can be integrated where their scopes and requirements align, but reuse is assessed rather than assumed. Each standard or assurance engagement retains its own criteria, responsibilities and evidence boundaries.
How much does a Govern engagement cost?
Every Govern engagement is scoped after discovery. The written quote identifies the agreed work, assumptions, client responsibilities, exclusions and separate third-party fees. Pricing is in AUD and is confirmed before delivery begins.
Who leads Govern engagements?
Engagements are led by Harry Sidhu, Aegentra’s Director and Principal Consultant. Harry holds the PECB ISO/IEC 27001 Lead Implementer credential. Any additional delivery roles and responsibilities are identified in the agreed scope.
Who will deliver your governance engagement?
Every engagement begins with a written scope that identifies the accountable lead, any supporting roles and the boundary between advice, implementation, internal audit and certification.
- Accountable delivery — Principal consultant. The named lead, responsibilities and exclusions are recorded in the written scope.
- Specialist contribution — Assigned only where the agreed scope requires it. The specialist function, relationship and responsibility are disclosed before work begins.
- Assurance boundary — Implementation, internal audit or readiness support. The scope states which service Aegentra is providing. An independent certification body makes certification decisions.
Qualified delivery matched to your scope
Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.
The people assigned to your engagement—and the experience and qualification evidence relevant to their roles—are confirmed in your proposal before work begins.
Team qualifications and credentials
Qualifications, professional credentials and formal training held across Aegentra’s delivery team.
Management systems and audit
- ISO/IEC 27001 Lead Implementer
- PECB ISO/IEC 27001 Lead Auditor
- ISO/IEC 42001 Lead Auditor
- CISA — Certified Information Systems Auditor
- ISM Auditor
Cybersecurity and cloud
- CISSP — Certified Information Systems Security Professional
- CISM — Certified Information Security Manager
- Certificate of Cloud Security Knowledge (CCSK)
- OSCP+ — OffSec Certified Professional Plus
Service delivery and specialist training
- ITIL Expert
- PRINCE2
- Mastering Generative AI for Cybersecurity Certificate
- Essential Eight Assessment Course certificate — TAFEcyber
Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.
Credentials are held across the delivery team and matched to assigned roles. The proposal identifies the consultants, responsibilities and relevant qualification evidence before work begins.
Not every engagement uses every role. The engagement record, rather than a generic team claim, identifies who is responsible for the work. View our delivery-team capability.