Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

ISO 42001 AI Management Consulting, Audits & Mentoring

ISO 42001 consulting, internal audits and mentoring for Australian organisations

You work directly with a qualified ISO Lead Auditor who works across both information security and AI governance. Most organisations reach certification in three to six months, and ISO 42001 is usually built alongside an existing information security system rather than from scratch.

Talk to an ISO 42001 consultant →

Almost every organisation we talk to about ISO 42001 is already using AI. That is not the problem they have come to solve. The problem is that nobody can say which tools are in use, what information has been fed into them, which decisions they now influence, or who signed off on any of it. ISO/IEC 42001 is the international standard for governing that, and it is the first one written specifically for artificial intelligence.

Streamline builds, audits and mentors AI management systems that match how you actually use AI. If you already hold ISO 27001, most of the machinery is already there and this is an extension rather than a second system.

On this page

  • What ISO 42001 certification involves
  • The process, step by step
  • How long does it take?
  • What does it cost?
  • Who needs ISO 42001, and who does not yet
  • Where projects come unstuck
  • Three ways to get there with Streamline

In plain English: ISO 42001 is about knowing where AI touches your business, deciding who is accountable for it, and being able to show that the risks are being managed.

ISO 42001 AI management system governance review
It is the organisation’s AI management system that is certified, not an individual model. ISO/IEC 42001 shares its management system structure with ISO 27001, so the two run as one system rather than two.

What ISO 42001 certification involves

Two things. An AI management system that meets ISO/IEC 42001:2023, covering your AI policy, the scope you have set, your AI inventory, impact assessment and the reference controls you have selected. Then an audit by an accredited certification body, in two stages, the same way every other management system standard is certified.

What surprises people is how little of it is technical. The standard is not asking you to prove a model is accurate. It is asking who decided the model could be used, what could go wrong for the people affected by it, who is watching it, and what happens when it behaves unexpectedly. Those are governance questions, and they are answered with records rather than code.

Defining the scope of your AI management system

Scope is the decision that shapes everything after it, and on AI systems it is harder than on an ISMS. The awkward question is whether you are certifying the AI you build, the AI you buy, or both.

A software company shipping an AI feature has an obvious answer. A professional services firm whose staff use a dozen commercial AI tools has a harder one, because the AI is embedded in products it does not control. Both are legitimate scopes. What does not work is a scope written to sound impressive to a customer that quietly excludes the AI actually making decisions about people.

We argue this out at the start, against the question your customer is really asking, because a scope statement is the first thing an assessor reads and the first thing a client checks on your certificate.

It is already happening in your business

Most organisations cannot say which AI tools their people are using, what company information has been pasted into them, or who approved any of it. That ungoverned use is the problem an AI management system exists to bring under control, and it is usually well underway before anyone starts writing a policy.

Read: Shadow AI in the workplace →

The process, step by step

  1. Gap analysis. Where your current governance sits against the standard, clause by clause. See our gap analysis audits.
  2. Scope, context and AI policy. What the certificate covers, who is accountable, and the position the organisation is taking on how AI may and may not be used.
  3. AI inventory. What you build, what you buy, what is embedded in tools you already pay for, what data feeds each one and what it influences. This step takes longer than anyone expects and it is where the real findings are.
  4. AI risk and impact assessment. Risk to the organisation, and separately, impact on the people the AI affects. The second is the part that is genuinely new.
  5. Controls and operation. Select the reference controls that treat what you found, then run the system long enough to produce records worth auditing.
  6. Internal audit and management review. The independent internal audit under clause 9.2, with findings closed before a certification body sees them.
  7. Certification audit. Stage 1 on your documented system, Stage 2 on whether you do what it says, then annual surveillance and recertification every three years.

How long does it take?

Three to six months for most organisations. The system has to run for a while before there are records to audit, and no amount of consulting compresses that part. Left much longer and the project loses momentum, which derails more certifications than any technical problem.

Two things push ISO 42001 towards the longer end. Building the AI inventory from nothing usually takes longer than planned, because the answer keeps growing as people admit what they are using. And impact assessment is unfamiliar work, so the first few take real time. An organisation with a mature ISMS and a tight scope sits at the shorter end.

What does it cost?

Two separate bills, and it helps to see them apart. Consultant support to design and implement the system, and the certification body’s own fee for the two stage audit, which they set according to your size, scope and the complexity of your AI use.

Our ISO 42001 certification cost guide works through the breakdown properly and is the place to go for figures. In short, a first year commonly lands somewhere around $20,000 to $60,000, which is wider than the older standards because the amount of AI in scope varies so much between organisations. Built alongside an existing ISO 27001 system, expect materially less than doing it standalone, because the management system clauses are already in place.

Government funding for ISO certification

Grants may be available to help with the cost of ISO 42001 certification. Funding is usually offered through broader programs covering cyber security and digital uplift, business capability or industry modernisation, where certification counts as eligible expenditure. Our guide shows how to search the free business.gov.au Grants and Programs Finder for programs your business may be eligible for.

Government Grants & Funding for ISO Certification (AU) →

Who needs ISO 42001, and who does not yet

You are selling AI, or software with AI in it. Your buyers’ security questionnaires have started asking about model provenance, training data and human oversight. Certification answers a page of those questions at once.

AI is making or shaping decisions about people. Credit, hiring, triage, eligibility, pricing, risk scoring. This is where impact assessment earns its keep, and where a governance failure is not a technical embarrassment but a harm to somebody.

Your board has asked a question nobody can answer. Usually some version of what are we using, who approved it, and what is our exposure. An AI inventory answers it in a fortnight, whether or not you go on to certify.

You already hold ISO 27001 and customers are asking about AI. The incremental work is smaller than a standalone build, and the two certificates together are a strong position for a data driven business.

Who does not need it yet. If your AI use is a handful of staff using a commercial chatbot for drafting, and nobody is asking you for assurance, certification is probably premature. What you likely need first is an acceptable use position, a record of what is in use, and some control over what information goes into these tools. That is cyber and information security advisory work, and we would rather tell you that than sell you a certificate you do not need.

ISO 42001 and ISO 27001 together

They share a structure, so context, leadership, competence, document control, internal audit, management review and improvement are written once and serve both. If you hold ISO 27001, that is roughly the half of ISO 42001 you do not have to build again.

What does not carry across is the part that makes AI different. An ISMS asks whether information is protected. An AIMS asks whether an automated decision is defensible, who can overrule it, and what it does to the person on the other end. Our guide to how the two standards fit together works through the overlap clause by clause.

What the system has to govern

AI impact assessment. Separate from risk assessment, and the concept most organisations meet for the first time here. Risk assessment asks what could go wrong for you. Impact assessment asks what could go wrong for the people your AI affects, including people who never chose to interact with it.

Human oversight. Not a line in a policy saying a human reviews the output. An auditor will ask which human, what they are competent to judge, what authority they have to overrule the system, and how often they actually do. If the answer is that nobody has ever overridden it, that is worth knowing before an assessor finds out.

Data. Where training and input data came from, whether you had the right to use it that way, and what happens to what your staff paste into a tool. Much of this sits close to your privacy obligations, which is why it is usually already partly answered if you hold ISO 27001.

Suppliers and third party AI. Most organisations’ AI exposure is bought, not built. The model belongs to a vendor, sits inside a product you licence, and changes without notice when they ship an update. The standard expects you to manage that relationship rather than treat it as somebody else’s system.

Where projects come unstuck

ISO 42001 is young, so there is less accumulated bad practice than on the older standards. The failures we see are fairly consistent all the same.

The AI inventory is a list of the approved tools. It records what the organisation sanctioned, not what people are using. Ask a team what they had open yesterday and the list usually grows. An inventory that does not match reality makes every control built on top of it decorative.

Impact assessment was done as a risk assessment with the words changed. Every entry describes commercial or reputational exposure and none of them describes a person. That is quick for an assessor to test, by picking one AI system and asking who could be disadvantaged by it and how they would find out.

Governance sits with whoever bought the tools. Often IT alone. AI decisions land in operations, HR, credit and clinical settings, and the people accountable for those outcomes were never in the room.

The system was written by AI and never operated. We see this more on 42001 than anywhere else, which has its own irony. Documentation generates no evidence. Stage 2 samples records, and a policy nobody follows produces nothing to sample. Our note on building an ISO system with AI covers where that goes wrong.

There is no project plan. Without dates and milestones, the internal audit and management review get left too late and the certification body cannot fit you in when you are finally ready. We produce a plan at the start and share it with your certification body so Stage 1 and Stage 2 are booked around your real milestones.

The governance gap is the expensive part

IBM’s 2025 research found that breaches involving shadow AI cost US$670,000 more than the average. The damning detail is what sat behind them: 97% of organisations that suffered an AI-related security incident had no AI access controls in place, and 63% had no AI governance policy at all. ISO 42001 is how you close that gap before it bills you.

What poor quality and incidents really cost →

Three ways to get there with Streamline

  • We build it. End to end AI management system development, standalone or integrated with your existing ISMS.
  • You build it, we mentor. ISO mentoring for teams doing the work themselves, with the knowledge staying in your business.
  • You have built it, we check it. An independent internal audit or a certification readiness review before you book the assessment.

Why Streamline

You work directly with a qualified ISO Lead Auditor across both information security and AI governance, which matters here because the two systems are usually built together and the overlap is where the time is saved. We prepare you for certification and the certification body audits the result, so the independence holds.

We work Australia wide, on site and remotely, from Brisbane, Sydney and Melbourne. See our security and AI services, the full range of ISO consulting services, or the other ISO standards we work with.

ISO 42001 guides

  • What is ISO 42001? Australian certification guide
  • ISO 42001 and ISO 27001: how they fit together
  • ISO 42001 certification cost and timeline in Australia
  • Shadow AI in the workplace
  • Building your ISO system with AI? Where it goes wrong

Common questions

Is the model certified, or the organisation?

The organisation’s AI management system. No certificate says a model is safe or unbiased. It says you have the governance, risk management and controls to develop and use AI responsibly, and that an accredited body checked.

We only use other people’s AI. Does this still apply?

Yes. The standard covers organisations that develop, provide or use AI systems. If a vendor’s model shapes decisions you are accountable for, governing that use is your job, and the vendor relationship becomes part of your system.

Do we need ISO 27001 first?

No, ISO 42001 can be certified on its own. In practice most organisations we work with either hold ISO 27001 already or build both together, because the shared clauses mean the second standard costs considerably less than the first.

Who issues the certificate?

An accredited certification body, independent of us. We build and audit the system, they certify it. See ISO certification bodies in Australia.

Where do we start?

With the inventory, almost always. Knowing what AI is actually in use is useful whether or not you certify, and it usually settles the scope argument on its own. A gap analysis against the standard is the natural next step.

Not sure whether you need to certify yet?

We are happy to have a free chat by Teams, Zoom or phone, look at how you are using AI and tell you honestly whether certification is the right answer or whether you need something smaller first. No obligation and no sales pitch.

Arrange a free consultation →

Speak with an ISO 42001 consultant

Tell us how AI is being used in your business and we will map a realistic path. If a customer has sent you a questionnaire about AI governance, send it through and we will tell you what it actually requires.

Talk to an ISO 42001 consultant

Email hello@streamline.business, or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.

Book a free consultation →

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Manager reviewing a budget spreadsheet
    ISO 27001 Certification Cost & Timeline in Australia…

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire