ISO 42001 consulting, internal audits and mentoring for Australian organisations
You work directly with a qualified ISO Lead Auditor who works across both information security and AI governance. Most organisations reach certification in three to six months, and ISO 42001 is usually built alongside an existing information security system rather than from scratch.
Talk to an ISO 42001 consultant →Almost every organisation we talk to about ISO 42001 is already using AI. That is not the problem they have come to solve. The problem is that nobody can say which tools are in use, what information has been fed into them, which decisions they now influence, or who signed off on any of it. ISO/IEC 42001 is the international standard for governing that, and it is the first one written specifically for artificial intelligence.
Streamline builds, audits and mentors AI management systems that match how you actually use AI. If you already hold ISO 27001, most of the machinery is already there and this is an extension rather than a second system.
In plain English: ISO 42001 is about knowing where AI touches your business, deciding who is accountable for it, and being able to show that the risks are being managed.

What ISO 42001 certification involves
Two things. An AI management system that meets ISO/IEC 42001:2023, covering your AI policy, the scope you have set, your AI inventory, impact assessment and the reference controls you have selected. Then an audit by an accredited certification body, in two stages, the same way every other management system standard is certified.
What surprises people is how little of it is technical. The standard is not asking you to prove a model is accurate. It is asking who decided the model could be used, what could go wrong for the people affected by it, who is watching it, and what happens when it behaves unexpectedly. Those are governance questions, and they are answered with records rather than code.
Defining the scope of your AI management system
Scope is the decision that shapes everything after it, and on AI systems it is harder than on an ISMS. The awkward question is whether you are certifying the AI you build, the AI you buy, or both.
A software company shipping an AI feature has an obvious answer. A professional services firm whose staff use a dozen commercial AI tools has a harder one, because the AI is embedded in products it does not control. Both are legitimate scopes. What does not work is a scope written to sound impressive to a customer that quietly excludes the AI actually making decisions about people.
We argue this out at the start, against the question your customer is really asking, because a scope statement is the first thing an assessor reads and the first thing a client checks on your certificate.
It is already happening in your business
Most organisations cannot say which AI tools their people are using, what company information has been pasted into them, or who approved any of it. That ungoverned use is the problem an AI management system exists to bring under control, and it is usually well underway before anyone starts writing a policy.
Read: Shadow AI in the workplace →The process, step by step
- Gap analysis. Where your current governance sits against the standard, clause by clause. See our gap analysis audits.
- Scope, context and AI policy. What the certificate covers, who is accountable, and the position the organisation is taking on how AI may and may not be used.
- AI inventory. What you build, what you buy, what is embedded in tools you already pay for, what data feeds each one and what it influences. This step takes longer than anyone expects and it is where the real findings are.
- AI risk and impact assessment. Risk to the organisation, and separately, impact on the people the AI affects. The second is the part that is genuinely new.
- Controls and operation. Select the reference controls that treat what you found, then run the system long enough to produce records worth auditing.
- Internal audit and management review. The independent internal audit under clause 9.2, with findings closed before a certification body sees them.
- Certification audit. Stage 1 on your documented system, Stage 2 on whether you do what it says, then annual surveillance and recertification every three years.
How long does it take?
Three to six months for most organisations. The system has to run for a while before there are records to audit, and no amount of consulting compresses that part. Left much longer and the project loses momentum, which derails more certifications than any technical problem.
Two things push ISO 42001 towards the longer end. Building the AI inventory from nothing usually takes longer than planned, because the answer keeps growing as people admit what they are using. And impact assessment is unfamiliar work, so the first few take real time. An organisation with a mature ISMS and a tight scope sits at the shorter end.
What does it cost?
Two separate bills, and it helps to see them apart. Consultant support to design and implement the system, and the certification body’s own fee for the two stage audit, which they set according to your size, scope and the complexity of your AI use.
Our ISO 42001 certification cost guide works through the breakdown properly and is the place to go for figures. In short, a first year commonly lands somewhere around $20,000 to $60,000, which is wider than the older standards because the amount of AI in scope varies so much between organisations. Built alongside an existing ISO 27001 system, expect materially less than doing it standalone, because the management system clauses are already in place.
Government funding for ISO certification
Grants may be available to help with the cost of ISO 42001 certification. Funding is usually offered through broader programs covering cyber security and digital uplift, business capability or industry modernisation, where certification counts as eligible expenditure. Our guide shows how to search the free business.gov.au Grants and Programs Finder for programs your business may be eligible for.
Government Grants & Funding for ISO Certification (AU) →Who needs ISO 42001, and who does not yet
You are selling AI, or software with AI in it. Your buyers’ security questionnaires have started asking about model provenance, training data and human oversight. Certification answers a page of those questions at once.
AI is making or shaping decisions about people. Credit, hiring, triage, eligibility, pricing, risk scoring. This is where impact assessment earns its keep, and where a governance failure is not a technical embarrassment but a harm to somebody.
Your board has asked a question nobody can answer. Usually some version of what are we using, who approved it, and what is our exposure. An AI inventory answers it in a fortnight, whether or not you go on to certify.
You already hold ISO 27001 and customers are asking about AI. The incremental work is smaller than a standalone build, and the two certificates together are a strong position for a data driven business.
Who does not need it yet. If your AI use is a handful of staff using a commercial chatbot for drafting, and nobody is asking you for assurance, certification is probably premature. What you likely need first is an acceptable use position, a record of what is in use, and some control over what information goes into these tools. That is cyber and information security advisory work, and we would rather tell you that than sell you a certificate you do not need.
ISO 42001 and ISO 27001 together
They share a structure, so context, leadership, competence, document control, internal audit, management review and improvement are written once and serve both. If you hold ISO 27001, that is roughly the half of ISO 42001 you do not have to build again.
What does not carry across is the part that makes AI different. An ISMS asks whether information is protected. An AIMS asks whether an automated decision is defensible, who can overrule it, and what it does to the person on the other end. Our guide to how the two standards fit together works through the overlap clause by clause.
What the system has to govern
AI impact assessment. Separate from risk assessment, and the concept most organisations meet for the first time here. Risk assessment asks what could go wrong for you. Impact assessment asks what could go wrong for the people your AI affects, including people who never chose to interact with it.
Human oversight. Not a line in a policy saying a human reviews the output. An auditor will ask which human, what they are competent to judge, what authority they have to overrule the system, and how often they actually do. If the answer is that nobody has ever overridden it, that is worth knowing before an assessor finds out.
Data. Where training and input data came from, whether you had the right to use it that way, and what happens to what your staff paste into a tool. Much of this sits close to your privacy obligations, which is why it is usually already partly answered if you hold ISO 27001.
Suppliers and third party AI. Most organisations’ AI exposure is bought, not built. The model belongs to a vendor, sits inside a product you licence, and changes without notice when they ship an update. The standard expects you to manage that relationship rather than treat it as somebody else’s system.
Where projects come unstuck
ISO 42001 is young, so there is less accumulated bad practice than on the older standards. The failures we see are fairly consistent all the same.
The AI inventory is a list of the approved tools. It records what the organisation sanctioned, not what people are using. Ask a team what they had open yesterday and the list usually grows. An inventory that does not match reality makes every control built on top of it decorative.
Impact assessment was done as a risk assessment with the words changed. Every entry describes commercial or reputational exposure and none of them describes a person. That is quick for an assessor to test, by picking one AI system and asking who could be disadvantaged by it and how they would find out.
Governance sits with whoever bought the tools. Often IT alone. AI decisions land in operations, HR, credit and clinical settings, and the people accountable for those outcomes were never in the room.
The system was written by AI and never operated. We see this more on 42001 than anywhere else, which has its own irony. Documentation generates no evidence. Stage 2 samples records, and a policy nobody follows produces nothing to sample. Our note on building an ISO system with AI covers where that goes wrong.
There is no project plan. Without dates and milestones, the internal audit and management review get left too late and the certification body cannot fit you in when you are finally ready. We produce a plan at the start and share it with your certification body so Stage 1 and Stage 2 are booked around your real milestones.
The governance gap is the expensive part
IBM’s 2025 research found that breaches involving shadow AI cost US$670,000 more than the average. The damning detail is what sat behind them: 97% of organisations that suffered an AI-related security incident had no AI access controls in place, and 63% had no AI governance policy at all. ISO 42001 is how you close that gap before it bills you.
What poor quality and incidents really cost →Three ways to get there with Streamline
- We build it. End to end AI management system development, standalone or integrated with your existing ISMS.
- You build it, we mentor. ISO mentoring for teams doing the work themselves, with the knowledge staying in your business.
- You have built it, we check it. An independent internal audit or a certification readiness review before you book the assessment.
Why Streamline
You work directly with a qualified ISO Lead Auditor across both information security and AI governance, which matters here because the two systems are usually built together and the overlap is where the time is saved. We prepare you for certification and the certification body audits the result, so the independence holds.
We work Australia wide, on site and remotely, from Brisbane, Sydney and Melbourne. See our security and AI services, the full range of ISO consulting services, or the other ISO standards we work with.
Common questions
Is the model certified, or the organisation?
The organisation’s AI management system. No certificate says a model is safe or unbiased. It says you have the governance, risk management and controls to develop and use AI responsibly, and that an accredited body checked.
We only use other people’s AI. Does this still apply?
Yes. The standard covers organisations that develop, provide or use AI systems. If a vendor’s model shapes decisions you are accountable for, governing that use is your job, and the vendor relationship becomes part of your system.
Do we need ISO 27001 first?
No, ISO 42001 can be certified on its own. In practice most organisations we work with either hold ISO 27001 already or build both together, because the shared clauses mean the second standard costs considerably less than the first.
Who issues the certificate?
An accredited certification body, independent of us. We build and audit the system, they certify it. See ISO certification bodies in Australia.
Where do we start?
With the inventory, almost always. Knowing what AI is actually in use is useful whether or not you certify, and it usually settles the scope argument on its own. A gap analysis against the standard is the natural next step.
Not sure whether you need to certify yet?
We are happy to have a free chat by Teams, Zoom or phone, look at how you are using AI and tell you honestly whether certification is the right answer or whether you need something smaller first. No obligation and no sales pitch.
Arrange a free consultation →Speak with an ISO 42001 consultant
Tell us how AI is being used in your business and we will map a realistic path. If a customer has sent you a questionnaire about AI governance, send it through and we will tell you what it actually requires.
Talk to an ISO 42001 consultant
Email hello@streamline.business, or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.
Book a free consultation →










