The short answer
ISO/IEC 42001:2023 is the international standard for an AI management system. It sets out how an organisation governs the artificial intelligence it builds, buys or uses: who is accountable, what could go wrong for the people affected, which controls are in place, and how any of it is evidenced. It is voluntary, it is certifiable by an accredited certification body, and Standards Australia has adopted it locally as AS ISO/IEC 42001:2023.
What gets certified is your management system, not an individual AI model or product.
ISO/IEC 42001:2023 is the world’s first international standard for managing artificial intelligence, and it has arrived at the moment Australian organisations are being asked, often for the first time, to show how they govern AI. This guide covers what the standard is, what it requires, how certification works, how long it takes, who it applies to, and what a certificate does and does not tell a customer.
In the AI-focused audits I have been doing lately, the gap I see most often is not the technology. It is governance. Teams can tell me in detail how their model works, yet nobody can point to who signed off on its use, what the known risks are, or how a bad output would be caught. ISO 42001 exists to close precisely that gap.

What is ISO 42001?
ISO/IEC 42001:2023 specifies the requirements for an artificial intelligence management system, usually shortened to AIMS. It is a structured way to govern the risks and the opportunities of AI: bias, transparency, data provenance, human oversight, accountability and unintended consequences. Published in 2023, it applies to any organisation that develops, provides or uses AI, in any sector and at any size.
It follows the same management system structure as ISO 27001 and ISO 9001: context, leadership, planning, support, operation, performance evaluation and improvement. If you have been through an ISO certification before, the shape of it will be familiar. What is new is the subject matter, and one requirement in particular that has no equivalent in the older standards.
What surprises most people is how little of the standard is technical. It does not ask you to prove a model is accurate. It asks who decided the model could be used, what could go wrong for the people affected by it, who is watching it, and what happens when it behaves unexpectedly. Those are governance questions, and they are answered with records rather than code.
ISO 42001 in Australia
Yes, ISO 42001 certification is available in Australia. Standards Australia adopted the standard as AS ISO/IEC 42001:2023, an identical adoption of the international text, so an Australian organisation certifying to ISO/IEC 42001 and one certifying to AS ISO/IEC 42001 are meeting the same requirements. Certification is issued by an accredited certification body, not by Standards Australia and not by a consultant.
Two things are worth being precise about, because they are commonly blurred. An Australian adoption of an international standard is not legislation. AS ISO/IEC 42001:2023 does not create a legal duty, and holding the certificate is not a defence to one. And accreditation is granted scheme by scheme. JAS-ANZ operates an Artificial Intelligence Management System scheme, but only a small number of certification bodies currently hold accreditation under it, and several that certify ISO 27001 in Australia do not. A body you already use for information security may not be able to certify your AI management system. Confirm the accredited scope before you build a project plan around a certification date: our guide to ISO certification bodies in Australia lists the current JAS-ANZ schemes for each body, with the date each was checked.
What ISO 42001 requires
- An AI governance framework. Clear roles, accountability and oversight for AI, set by leadership rather than inherited from whoever bought the tools.
- Scope and an AI inventory. What you build, what you buy, and what is embedded in software you already pay for. This step routinely takes longer than planned, because the list keeps growing as people say what they are using.
- AI risk management, aligned with ISO/IEC 23894 and ISO 31000.
- AI impact assessment. Separate from risk assessment, and the requirement most organisations meet for the first time here. Risk assessment asks what could go wrong for you. Impact assessment asks what could go wrong for the people your AI affects, including people who never chose to interact with it, and for society more broadly.
- Transparency and documentation of how your AI systems work and what they are used for.
- Data quality and data governance, covering where training and input data came from and whether you had the right to use it that way.
- Controls for bias, safety, human oversight and responsible use, selected from Annex A.
- Lifecycle management, governing an AI system from design through deployment, monitoring and eventual retirement.
- Monitoring, internal audit and management review, then continual improvement on the back of what they find.
Annex A, the reference controls
The main clauses tell you what the management system must do. Annex A is the reference set of controls you draw on to treat what your risk and impact assessments found, covering areas such as AI policy, internal organisation, resources for AI systems, impact assessment, the AI system lifecycle, data for AI systems, information for interested parties, use of AI systems, and third party and customer relationships. You select the controls that fit the risks you have identified and you justify the selection, in the same way an ISO 27001 Statement of Applicability works. Annex A is not a checklist to implement wholesale.
What certification does, and what it does not
This is worth stating plainly, because a good deal of what is written about ISO 42001 overstates it.
- It certifies the organisation’s management system, not an AI model or product. No certificate says a model is safe, accurate or unbiased. There is no such certificate.
- It is voluntary. ISO 42001 is not required by Australian law. It becomes a requirement only when a customer, a tender or a contract makes it one, which is increasingly where the pressure comes from.
- It supports assurance and governance. It does not by itself establish legal compliance. Certification does not discharge your obligations under the Privacy Act, work health and safety law, consumer law or anti-discrimination law, and an accredited body does not assess those.
- What it does say is that you have defined how AI is governed in your organisation, that you have assessed the risks and the impacts, that you have selected and operated controls, and that an independent accredited body sampled the evidence and found the system conforming.
That is a genuinely useful thing to be able to demonstrate. It is simply not the same as proving your AI is responsible, and a buyer who reads the certificate carefully will know the difference.
How ISO 42001 certification works
The path mirrors every other ISO management system standard. You build the AI management system, run it long enough to generate real records, complete an internal audit and a management review, then pass a two stage external audit with an accredited certification body.

- Gap analysis. Where your current governance sits against the standard, clause by clause, and how big the job is. See gap analysis audits.
- Scope, context and AI policy. What the certificate will cover, who is accountable, and the position the organisation takes on how AI may and may not be used.
- AI inventory, risk assessment and impact assessment. What is in use, what could go wrong for the business, and separately what could go wrong for the people affected.
- Controls and operation. Select the Annex A controls that treat what you found, then run the system long enough to produce records worth auditing.
- Internal audit and management review. An independent internal audit under clause 9.2, with findings closed before a certification body sees them. You cannot credibly audit a system you wrote yourself, which is why this step is usually outsourced even by capable in-house teams.
- Stage 1. The certification body reviews your documented system and your readiness, and tells you what will not survive Stage 2.
- Stage 2. The full assessment of whether you do what your system says, tested against records and interviews.
- Surveillance and recertification. Annual surveillance audits keep the certificate live, with a fuller recertification audit every three years.
How long it takes
Three to six months for most organisations, from starting the AI management system to passing Stage 2. An organisation with a mature ISO 27001 system and a tight scope sits at the short end. Starting from nothing with several high risk AI systems to govern runs longer, as do larger, multi site and multinational organisations.
You cannot compress it below the point where you have generated real records. An internal audit and a management review must have happened, on a system that was running, before Stage 2. Left much longer than six months and projects tend to lose momentum, which derails more certifications than any technical problem.
Cost varies more than on the older standards, because the amount of AI in scope differs so much between organisations, and holding ISO 27001 already moves the number materially. Our ISO 42001 certification cost guide works through the breakdown, the worked examples by starting point and the ongoing annual costs.
Who needs ISO 42001, and why now
AI governance has moved from a nice to have to a board level and procurement question. Enterprise and government buyers want assurance about how AI is governed, and their security questionnaires have started asking about model provenance, training data and human oversight. Certification answers a page of those questions at once, and it does so with an independent assessment behind it rather than a self declaration.
It is most relevant if you sell AI or software with AI in it, if AI is making or shaping decisions about people such as credit, hiring, triage, eligibility or pricing, if your board has asked what you are using and nobody can answer, or if you already hold ISO 27001 and customers have started asking about AI.
Regulation is a factor but a slower one. The EU AI Act is the most developed regime and affects Australian organisations that place AI systems on the European market. Australia has no equivalent AI act, and the standard is not a substitute for whatever eventually arrives. What certification does is put the governance, the inventory and the assessments in place, which is work you would have to do under any regime.
The practical tell I look for is whether AI decisions leave a trail. When I ask to see how a model was assessed before it went live, or how someone would trace a problematic output back to its cause, a mature organisation can walk me through it; a less mature one goes quiet. ISO 42001 turns that scramble into a documented, repeatable process, which is what an enterprise buyer’s due diligence questionnaire is really testing for.
Who does not need it yet. If your AI use is a handful of staff using a commercial chatbot for drafting, and nobody is asking you for assurance, certification is probably premature. What you likely need first is an acceptable use position, a record of what is in use, and some control over what information goes into these tools.
How ISO 42001 fits with ISO 27001
If you already hold ISO 27001, you are part of the way there. The two standards share the same management system structure, so context, leadership, competence, document control, internal audit, management review and improvement are written once and serve both. That is roughly the half of ISO 42001 you do not have to build again, and it is why a combined system is usually cheaper than two separate programs.
What does not carry across is the part that makes AI different. An information security system asks whether information is protected. An AI management system asks whether an automated decision is defensible, who can overrule it, and what it does to the person on the other end. Our guide to how ISO 42001 and ISO 27001 fit together works through the overlap and what each one adds.
Implementing an AI management system
Start with the inventory, almost always. Knowing what AI is in use is useful whether or not you go on to certify, and it usually settles the scope argument on its own. Scope is the decision that shapes everything after it, and the awkward question is whether you are certifying the AI you build, the AI you buy, or both. Both are legitimate. What does not work is a scope written to sound impressive to a customer that quietly excludes the AI making decisions about people.
A word of warning on drafting the system with AI, which is more common on this standard than any other. Documentation generates no evidence. Stage 2 samples records, and a policy nobody follows produces nothing to sample. Our note on building an ISO system with AI covers where that goes wrong and how to put it right.
How Streamline helps
Streamline helps Australian organisations implement, audit or mentor an ISO 42001 AI management system, standalone or integrated with ISO 27001. You work directly with a qualified ISO Lead Auditor across both information security and AI governance. We prepare you for certification and an accredited certification body audits the result, so the independence holds. See our ISO 42001 consulting, audits and mentoring page for how the three routes work, or the wider security and AI services.
Common questions
Can an AI system be certified to ISO 42001?
No. It is the organisation’s AI management system that is certified, not an individual AI model or product. The certificate says you have defined how AI is governed, assessed the risks and impacts, selected and operated controls, and that an accredited body checked. It does not say a model is safe or unbiased.
Is ISO 42001 mandatory in Australia?
No. ISO 42001 is voluntary and Australia has no law requiring it. Standards Australia has adopted it as AS ISO/IEC 42001:2023, which is an identical adoption of the international standard rather than legislation. In practice it becomes a requirement when a customer, tender or contract makes it one.
Who needs ISO 42001?
Organisations that build, sell or rely on AI, and increasingly those whose customers or regulators expect demonstrable AI governance. It is most relevant where AI shapes decisions about people, or where enterprise and government buyers are asking about AI governance in their due diligence.
We only use other people’s AI. Does ISO 42001 apply?
Yes. The standard covers organisations that develop, provide or use AI systems. If a vendor’s model shapes decisions you are accountable for, governing that use is your job, and the vendor relationship becomes part of your management system.
Do we need ISO 27001 first?
No, ISO 42001 can be certified on its own. It does help. The two integrate cleanly and share most of the management system clauses, so many organisations build both together and cover information security and AI governance in one program.
How long does ISO 42001 certification take?
Three to six months for most organisations, from starting the system to passing Stage 2. An existing ISO 27001 system and a tight scope put you at the short end. A larger organisation, or one with several high risk AI systems and no management system to build on, runs longer.
Speak with an experienced ISO auditor
Getting ahead of AI governance, or answering a customer questionnaire you cannot yet evidence? Tell us how AI is being used in your business and we will map a realistic path. Get in touch for a no obligation chat with an experienced ISO auditor.
Talk to an ISO 42001 consultant
Email hello@streamline.business, or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.
Book a free consultation →Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











