WEBSITE PREVIEW /Draft prices. Bookings are not open.
AegentraNew Zealand

ISO 27001 Lead Auditor Course New Zealand

Learn to plan and conduct ISO/IEC 27001:2022 information security management system audits, evaluate evidence and communicate findings. Study online with official PECB Self-Study materials or recorded eLearning, with practical Aegentra consultancy training available.

Draft starting price NZ$1,050.00per learner · Self-Study · before applicable tax

Compare formats & prices

PECB Partner ID 232290 · Verify our listing

Passing the exam does not automatically award the full Lead Auditor credential. PECB assesses your experience and certification application separately.

On this page

Your learning format

Choose how you build your audit skills.

Self-Study uses reading and exercises. Recorded eLearning adds PECB video-led content. The two-hour consultancy option is a separate practical session, not a full live PECB course.

Self-Study

Official slide-based materials for independent study. Read the audit concepts, revisit examples and work through the exercises at your own pace.

NZ$1,050.00Draft · per learner · before applicable tax

Optional exam preparation

10-day money-back guarantee if you’re not satisfied with Aegentra Labs. Applies to the Labs add-on, not the PECB course.

PECB eLearning

Recorded learning for people who prefer video explanation alongside the official course materials. This is not scheduled live classroom teaching.

NZ$1,070.00Draft · per learner · before applicable tax

Optional exam preparation

10-day money-back guarantee if you’re not satisfied with Aegentra Labs. Applies to the Labs add-on, not the PECB course.

Consultancy training

PECB course + two hours with a consultantLearn how to implement ISO 27001 in a real organisation with an Aegentra consultant who has hands-on implementation and auditing experience. Work through practical scope, risk, controls and audit-evidence questions. Confirm the session focus, consultant and timing before booking; do not share confidential client data.

Request a quoteSeparate package; not included in the prices alongside

Discuss this option

PECB’s qualifying partner-package policy includes the first exam attempt, one free retake, the certification application fee and the first year of the Annual Maintenance Fee (AMF) within its required cycle. The learner must still apply and submit the required evidence. Confirm these inclusions for the final NZ booking. Read the current exam rules.

Training is online only. Aegentra Academy does not offer physical classroom or onsite training.

At a glance

Know what you are choosing.

Standard
ISO/IEC 27001:2022
Course provider
PECB
Delivery
Online; English Self-Study or recorded eLearning
Syllabus
Four training days; PECB lists the exam on Day 5
English exam
3 hours · 80 multiple-choice questions
Exam rules
Open book · 70% pass mark
Official materials
More than 450 pages, according to PECB
Course CPD
PECB lists 31 CPD credits for attendees
PECB partner-policy window
12 months from purchase for Self-Study/eLearning; NZ entitlement to be confirmed
Material access
Confirm the specific access terms before booking

Checked against the PECB course outline, current English exam listing and candidate handbook. The 12-month cycle is not a material-access promise. Exam arrangements can differ by language.

Who this course suits best

For people who need to assess, not assume.

  • Internal auditors: plan an ISMS audit, select evidence and write clear findings.
  • ISMS, compliance and GRC professionals: understand what an audit conclusion needs to be supported by.
  • Supplier-assurance teams: connect agreed requirements to the services and systems you assess.
  • Audit consultants: develop a structured approach to preparation, fieldwork, reporting and follow-up.
  • Technical security specialists: connect technical evidence to management-system requirements.

Check your starting point.

PECB expects a fundamental understanding of ISO/IEC 27001 and comprehensive knowledge of audit principles. If the standard is new to you, explore ISO 27001 Foundation first.

Course entry knowledge and certification eligibility are different. You can develop audit skills before meeting the full Lead Auditor experience threshold. The course does not guarantee a job, appointment or certification outcome.

What you will learn

From audit criteria to a defensible conclusion.

These four study modules summarise PECB’s training-day sequence. Self-paced learners set their own timetable. The syllabus draws on ISO 19011 audit guidance and ISO/IEC 17021-1 certification-body requirements; that does not make every internal audit a certification audit.

Read the management system

Understand the ISMS and interpret its requirements from an auditor’s perspective. Connect the organisation’s scope, risks and responsibilities to the audit criteria.

Prepare the audit

Set objectives and a workable audit plan. Consider impartiality, evidence sources, sampling, the team and communication before fieldwork begins.

Evaluate the evidence

Use interviews, observation and document review to test what is actually happening. Distinguish a statement from evidence and a sample from the whole population.

Report and follow up

Communicate findings clearly, support conclusions and review corrective-action evidence. Understand closure and the wider audit programme.

Seven exam competency areas

  • ISMS principles and concepts
  • ISMS requirements
  • Audit principles
  • Audit preparation
  • Conducting an audit
  • Closing an audit
  • Managing an audit programme

Short summaries, not a substitute for the official syllabus and candidate handbook.

Exam and professional certification

An exam result. Then an evidence-based application.

The English examination

Three hours, 80 multiple-choice questions, open book and a 70% pass mark. Questions include standalone items and applied scenarios. Open book permits specified references, not unrestricted internet access. Check your assigned exam’s reference and technical rules.

For Self-Study and eLearning, PECB’s qualifying partner-policy cycle runs for 12 months from purchase; confirm your specific entitlement before booking. The first retake requires a 15-day wait after failure, and a failed attempt does not restart the cycle.

Apply for the tier you can evidence

Passing the exam is not the same as being certified. Submit the application, comply with PECB’s Code of Ethics and provide the professional experience and audit activity required for the relevant tier.

PECB reviews your evidence. A lower-experience learner should consider the Provisional Auditor pathway rather than assume immediate eligibility for the full Lead Auditor credential.

PECB ISO/IEC 27001 auditor credential tiers
Credential tierProfessional experienceAudit activity
Provisional AuditorNo professional experience requirementNone
Auditor2 years overall, including 1 in information security management200 hours
Lead Auditor5 years overall, including 2 in information security management300 hours
Senior Lead Auditor10 years overall, including 7 in information security management1,000 hours

The exam requirement and ethical obligations also apply. Check the PECB credential table and certification policy before applying.

What can count towards audit hours?

Engagement type: PECB lists pre-audits, gap analyses, internal audits, second-party audits, third-party audits and opinion audits as valid types of audit experience. That identifies the kind of engagement; it does not mean every hour spent on the project automatically qualifies.

Activities performed: the handbook includes audit planning, audit-programme management, report and nonconformity preparation, working-document preparation, review and management of audit documentation, on-site audit work, follow-up and team leadership. Keep a log of the engagement, your responsibilities, dates and eligible hours, supported by evidence. General cybersecurity employment is not automatically audit experience. PECB decides whether your records satisfy its certification rules and candidate-handbook requirements.

After certification: the full Lead Auditor tier has a three-year maintenance cycle, currently requiring 90 CPD hours, applicable maintenance fees and ethical compliance. Other tiers have different requirements. The 31 course CPD credits listed for attendees are not the complete maintenance requirement. Check the current maintenance policy.

A credential is not a certification-body appointment.

A certification body separately assesses competence, experience, impartiality and suitability for its audit assignments. Your personal qualification does not certify an organisation, remove a conflict of interest or authorise you to issue its ISO certificate.

Choosing a credential

Compare the outcome, not just the course name.

Start with what your employer, customer or intended certification body requires. A training completion certificate, passing an examination and registration or certification as an auditor are distinct achievements.

Questions to ask when comparing auditor pathways
PathwayDistinction to checkBefore choosing
PECBThe Lead Auditor course and exam lead to a separate personnel-certification application.Check the tier, experience evidence and maintenance requirements with PECB.
CQI / IRCACompleting relevant certified training is separate from meeting IRCA auditor-certification requirements.Check the intended grade and current requirements in the IRCA ISMS scheme.
Exemplar GlobalAuditor personnel certification has its own application and qualification requirements.Check the current ISMS auditor pathway and the outcome of your chosen training.
Course completion certificateRecords a training outcome; do not assume it is an auditor personnel certification.Ask who issues it, what was assessed and whether a further application is required.

This is a decision aid, not a ranking of providers or a claim that their credentials, exams or grades are interchangeable.

Using audit skills in New Zealand

Understand the obligation behind the evidence.

Decide which requirements actually apply to the organisation and the audit scope. ISO 27001 training does not establish legal compliance, government accreditation or automatic acceptance by a buyer.

Privacy Act 2020, Principle 5

IPP 5 concerns safeguards reasonable in the circumstances for personal information. Relevant audit evidence may include access records, supplier safeguards and incident procedures. An ISMS audit is not, by itself, a legal opinion on Privacy Act compliance.

Privacy Commissioner: IPP 5

NZISM

The New Zealand Information Security Manual supports government information assurance and systems security. For agency or supplier work, verify the applicable obligations, contractual boundary and required assurance. Do not apply every government requirement to every NZ business by default.

NCSC: NZISM

Protective Security Requirements

PSR includes governance, personnel, physical and information security. Confirm whether it applies to the organisation or contract and what evidence is required. A personal course credential is not evidence that these broader requirements have been met.

PSR: information security

No NZQA approval or NZQCF level-equivalence is claimed. Check NZQA’s assessment scope and ask the employer or client which credentials it accepts.

Try the audit thinking

A requirement. Evidence. A finding.

Follow a fictional NZ software provider’s leaver-access audit. This is original Aegentra teaching material, not a client case study, PECB examination question or complete audit programme.

Start with a requirement you can test.

Fictional example: a software provider’s approved leaver procedure requires access to its customer-support system to end on the person’s final working day. The auditor first confirms the current procedure, the service boundary and who owns access removal.

Audit objective
Evaluate whether the agreed leaver process operates as intended.
Criterion
The organisation’s approved access-removal procedure.
Plan
Agree a sample period, obtain the leaver population and select records with a reasoned sampling approach.

This is an organisation-specific requirement. The example does not claim that ISO 27001 sets a universal same-day removal deadline.

Compare records, not assurances.

The fictional sample contains five leavers. For one, the departure record shows a final working day of 2 October, while the relevant account remained enabled on 6 October. The auditor verifies the records with the responsible people and checks whether an authorised exception or other relevant context exists.

Evidence requested
Departure records, account status/history, removal requests and approved exceptions.
What is known
One sampled account remained enabled beyond the stated removal requirement.
What is not established
Whether that account was used, whether data was accessed, or how often this happens outside the sample.

An enabled account is evidence about access removal, not proof that a breach occurred. Record the sample limits and investigate contradictory evidence.

Connect the finding to the evidence.

Illustrative finding, after verification: the leaver procedure’s removal requirement was not met for one of the five sampled records. Identify the procedure version and evidence references. Do not assign a major/minor grade from this short scenario alone.

Finding record
Applicable requirement, verified evidence, sample boundaries and a clear statement of the gap.
Organisation’s action
Address the immediate issue, investigate the cause and decide appropriate corrective action.
Follow-up
Evaluate implementation and effectiveness using suitable evidence; do not close the issue only because a ticket says “done”.

This original Aegentra learning example is not a client case study, official PECB exam question, complete audit report or certification decision.

Nothing is saved or sent. The example does not calculate a score, assign an audit grade or make a certification decision.

Choose for the work you want to do

Assess the system or build it?

Lead Auditor

Plan audits, evaluate evidence, communicate findings and follow up corrective actions. Choose this pathway when assessment and assurance are central to your role.

Compare Lead Auditor formats

Lead Implementer

Define the scope, establish the ISMS, coordinate risk treatment and organise monitoring and improvement. Choose it when putting the system into operation is your main responsibility.

Explore the Lead Implementer course

Practical audit resources

Explore Aegentra’s internal-audit checklist and planning pack and Australian internal-audit engagement case study. These resources open on the separate Australian website; the engagement is not a NZ learner testimonial. Adapt templates to the audit criteria and scope rather than treating a completed checklist as assurance.

Separate exam-practice platform

Aegentra Labs

Practise interpreting scenarios, test your reasoning and learn from explanations. Labs questions are independently authored, not official PECB exam questions or exam dumps.

Build a more deliberate practice routine.

  • Practice questions and answer explanations
  • Timed exam practice
  • Feedback by topic

Optional access is NZ$120.00 for 12 months, before applicable tax. 10-day money-back guarantee if you’re not satisfied with Aegentra Labs. Applies to the Labs add-on, not the PECB course. Practice does not guarantee an examination result or professional credential.

Explore Aegentra Labs

Before you decide

Your questions, answered.

How much does the ISO 27001 Lead Auditor course cost in NZ?

Self-Study is NZ$1,050.00 per learner and recorded PECB eLearning is NZ$1,070.00, before applicable tax. The two-hour consultancy package is by quote and is not included in these prices. NZ bookings are not yet open.

Can I add Aegentra Labs exam practice?

Yes. Optional Labs access is NZ$120.00 for 12 months. Course plus Labs is NZ$1,170.00 with Self-Study or NZ$1,190.00 with recorded eLearning, before applicable tax. 10-day money-back guarantee if you’re not satisfied with Aegentra Labs. Applies to the Labs add-on, not the PECB course. Practice questions are independently authored, not official PECB exam content or a pass guarantee.

Which ISO 27001 Lead Auditor certification is best?

Choose for your intended role and the requirements of the employer, client or certification body. Compare the actual issuer, assessment, experience rules and maintenance obligations. A training completion certificate and an auditor personnel certification are not the same outcome; no single route is best for every learner.

How do I become a PECB certified ISO 27001 Lead Auditor?

Develop the required knowledge, pass the applicable exam and submit a certification application with supporting professional experience and audit activity. PECB evaluates the application and awards the tier whose requirements are met. Passing the exam alone does not award the full Lead Auditor credential.

Who is eligible, and do I need audit experience before studying?

PECB expects a fundamental understanding of ISO/IEC 27001 and comprehensive knowledge of audit principles before the course. This entry knowledge is separate from certification experience requirements. The Provisional Auditor tier has no experience requirement, while the full Lead Auditor tier requires five years of professional experience, including two in information security management, and 300 audit hours.

How long does the course take?

PECB structures the syllabus around four training days and an examination on Day 5. Self-Study and recorded eLearning do not impose that timetable: study effort depends on your starting knowledge and pace. No fixed self-paced completion time or material-access period is promised here.

What is the English Lead Auditor examination format?

The current English PECB examination has 80 multiple-choice questions, a three-hour duration and a 70% pass mark. It is open book under PECB’s permitted-reference rules and includes applied scenarios. Open book does not mean unrestricted internet access; check the instructions for your assigned examination.

What happens if I fail the exam?

PECB’s qualifying partner-course policy includes one free retake within the applicable cycle. For Self-Study and eLearning the cycle is 12 months from purchase, not a new period starting after a failed attempt. Waiting periods also apply, including 15 days before the first retake. Confirm the dates and entitlement in myPECB.

Is the exam difficult, and how should I prepare?

Difficulty depends on your audit knowledge and preparation. Practise interpreting requirements, evaluating evidence, deciding what a sample supports and writing defensible findings. Use the official syllabus and permitted references. Original practice questions can support learning but do not predict or guarantee your result.

Can I audit for a certification body after this course?

Not automatically. The certification body separately assesses auditor competence, relevant experience, impartiality and suitability for an assignment. A personal credential is not an appointment to conduct certification audits and does not certify an organisation.

Is this suitable for internal auditors?

Yes. Audit planning, evidence evaluation, reporting and follow-up are relevant to internal auditors. An organisation must still select competent, objective and impartial auditors for its audit programme. Holding a credential does not remove a conflict of interest or make someone independent of their own implementation work.

Should I choose Lead Auditor or Lead Implementer?

Choose Lead Auditor when your main responsibility is evaluating a management system through audit evidence and conclusions. Choose Lead Implementer when you need to establish, operate and improve the system. They cover different responsibilities and have separate examination and credential pathways.

Can I study online from New Zealand?

Self-Study and recorded PECB eLearning are online, self-paced options in English. The separate two-hour consultancy package is arranged by enquiry; confirm dates, New Zealand time-zone arrangements and inclusions in writing. Aegentra Academy does not offer physical classroom or onsite training.

Is the PECB credential recognised in New Zealand?

PECB operates an international personnel-certification pathway. Acceptance for a particular role is decided by the employer, client or certification body. This page makes no NZQA approval or NZQCF level-equivalence claim. Check those requirements before choosing a course for employment, immigration or formal qualification recognition.

Is there a free ISO 27001 Lead Auditor course or certificate?

The original worked example on this page is free to read. It does not include the paid PECB course, official examination or a professional credential. Check the dedicated Aegentra Labs website for its current practice options; a practice score is not a PECB examination result.

Can my employer fund the course, and is GST charged?

Discuss employer-funded learning or an enterprise group through the enquiry route. Confirm the billing entity, learner details, NZD package price, applicable tax and invoice requirements before booking. NZ tax treatment and booking arrangements remain unconfirmed; this page does not promise a GST exemption.

Sources and next steps.

Last updated . Public source facts checked for this draft; final NZ commercial terms and human publication review remain pending.

Need an organisational audit rather than a personal course? Explore Aegentra’s audit services. For learning or enterprise training requirements, discuss your needs with Aegentra.