Blog

ISO 42001 for Australian SaaS: Is It Worth It?

ISO/IEC 42001 is the international management system standard for artificial intelligence, published in December 2023 and adopted in Australia as AS ISO/IEC 42001:2023. It is voluntary, no Australian law requires it, and certification takes a two stage audit much like ISO 27001. For most Australian SaaS companies it is worth it only when customers have started asking about AI governance in writing. If they have not, put the money into ISO 27001 or SOC 2 first.

That said, the questions are arriving faster than most people expected. If your product uses a model, even someone else’s model behind an API, you will meet an AI section in a customer security questionnaire this year. Here is what ISO 42001 actually asks for, what certification involves in Australia, and how to decide whether now is the moment.

What is ISO 42001?

ISO/IEC 42001 is a management system standard for artificial intelligence, published on 18 December 2023 as the first edition. It sets out requirements for establishing, running and improving what the standard calls an AI management system, usually shortened to AIMS. It is a requirements standard, so an accredited certification body can audit you against it and issue a certificate.

Structurally it will look familiar to anyone who has been through ISO 27001. There are ten clauses, with clauses 4 to 10 carrying the auditable requirements: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A adds 38 controls across nine categories, covering AI policy, internal organisation, resources for AI systems, impact assessment, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third party and customer relationships. Annex B gives implementation guidance for those controls, Annex C lists AI related objectives and risk sources, and Annex D covers using an AIMS across sectors.

Two things it is not. It is not a test of your model’s accuracy, and it is not a product certification. ISO 42001 certifies how your organisation governs AI, not whether any particular AI system is safe.

Is ISO 42001 mandatory in Australia?

No. ISO 42001 is voluntary in Australia and everywhere else. Standards Australia adopted it identically as AS ISO/IEC 42001:2023 on 16 February 2024, which makes it an Australian Standard, but adopting a standard does not make it law.

The Australian Government’s position has moved and is worth knowing accurately. The Voluntary AI Safety Standard published in September 2024 was superseded in October 2025 by the Guidance for AI Adoption, which sets out six essential practices and explicitly references AS ISO/IEC 42001:2023. The National AI Plan released in December 2025 relies on Australia’s existing technology neutral laws plus a new AI Safety Institute, rather than AI specific legislation. As things stand, no Australian law requires you to certify against ISO 42001.

It is also not a shortcut through the EU AI Act. ISO 42001 has not been cited in the Official Journal as a harmonised standard, so holding it does not give you a presumption of conformity with the Act. It is useful evidence of governance, not a compliance passport.

Who actually needs ISO 42001?

ISO 42001 earns its place when you cannot answer a customer’s AI questions with a paragraph. In practice that means Australian SaaS companies in one of four positions:

Four question decision guide for whether an Australian SaaS company needs ISO 42001 certification
Four questions that settle whether ISO 42001 belongs on your roadmap this year.
  • You build, train or fine tune your own models, so you own the decisions about data, bias and monitoring.
  • You embed or resell another provider’s model, which does not transfer the governance responsibility to them in the eyes of your customer.
  • Your customers are regulated, government or enterprise buyers who have started sending AI specific questionnaires alongside their security ones.
  • You sell into markets where an AI governance credential is becoming a procurement filter, and you would rather be early than explain why you are late.

If none of those describe you, ISO 42001 is a distraction this year. Answer the AI questions in the security questionnaires you already receive honestly, document how you use AI internally, and revisit the decision in twelve months.

How does ISO 42001 compare with ISO 27001?

ISO 42001 and ISO 27001 govern different subject matter through the same machinery. ISO 27001 protects information and runs on 93 Annex A controls. ISO 42001 governs how AI is built and used and runs on 38 Annex A controls. Both use the same clause 4 to 10 management system structure, which is the reason they combine well.

ISO 42001 and ISO 27001 compared showing clauses, control counts and subject matter
The two standards share a management system structure but govern different things.

The practical consequence is that one risk process, one internal audit programme and one management review can serve both standards, and certification bodies routinely audit them together. A company that already holds ISO 27001 is a long way into ISO 42001 before it starts, which is why the usual sequencing advice is ISO 27001 first, ISO 42001 second. If you are choosing between security frameworks, our ISO 27001 and SOC 2 comparison covers that decision, and SOC 2 for AI SaaS companies covers how AI shows up in a SOC 2 examination.

ISO/IEC 27001:2022ISO/IEC 42001:2023
SubjectInformation securityAI management
PublishedOctober 2022December 2023
Annex A controls93 in four themes38 in nine categories
Australian adoptionAS/NZS ISO/IEC 27001:2023AS ISO/IEC 42001:2023
Certification cycleThree years plus annual surveillanceThree years plus annual surveillance
Who asks for itAlmost every enterprise buyerA growing minority, mostly AI heavy deals
ISO 27001 and ISO 42001 side by side for an Australian SaaS company.

Can you get ISO 42001 certified in Australia?

Yes, but the pool of accredited certification bodies is still small. JAS-ANZ, the accreditation body for Australia and New Zealand, granted its first ISO/IEC 42001 accreditation in July 2025, and the number of accredited bodies has grown slowly since. That matters for two reasons: availability, because audit slots are limited, and credibility, because an unaccredited certificate carries far less weight with a serious buyer.

Before you sign anything, ask the certification body which accreditation body has accredited them for ISO/IEC 42001 specifically, and check that accreditation on the accreditation body’s own register. A firm accredited for ISO 27001 is not automatically accredited for ISO 42001. You can buy the Australian adoption, AS ISO/IEC 42001:2023, from Standards Australia.

How long does ISO 42001 certification take?

Certification against ISO 42001 follows the same two stage audit as ISO 27001. Stage 1 reviews your documented AI management system and commonly takes one to two auditor days. Stage 2 tests whether the system operates and commonly takes three or more, rising with the size and complexity of your AI footprint. The two stages are normally separated by several weeks. A certificate then runs for three years, with a surveillance audit each year in between at roughly a third of the initial audit duration.

The audit is the short part. Building the AIMS is the long part, and for a small SaaS company the realistic constraint is not auditor availability but how long it takes to write an AI policy your engineers will follow, run genuine impact assessments on the AI features you have shipped, and produce a few months of records showing the process was used rather than written.

What does ISO 42001 cost?

There is no published, independent cost data for ISO 42001 certification. Every figure circulating online comes from a consultancy or platform selling ISO 42001 services, and the ranges disagree wildly, so treat them accordingly and get quotes.

What you can plan around is the shape of the spend: the standard itself, the internal or external effort to build the AIMS, the certification body’s fees for Stage 1 and Stage 2, and annual surveillance audits for the life of the certificate. If you already hold ISO 27001, the incremental cost is smaller than the standalone cost, because the management system, internal audit and management review already exist.

Should an Australian SaaS company do ISO 42001 now?

Do it now if AI is central to what you sell, your buyers are enterprise or government, and you already hold ISO 27001 so the incremental work is manageable. In that position ISO 42001 is a genuine differentiator while the field is thin, and the governance work is worth doing regardless of the certificate.

Wait if AI is a feature rather than the product, if no customer has asked in writing, or if you are still chasing your first security certification. Getting ISO 27001 certified or producing a SOC 2 report answers far more customer questions per dollar today, and it makes ISO 42001 cheaper when you do get to it.

Common questions

Is ISO 42001 worth it?

ISO 42001 is worth it when customers are asking about AI governance and you want a credible, independent answer rather than a written assurance. It is not worth it if AI is a minor feature, nobody has asked, or you have no security certification yet. The governance work has value on its own; the certificate has value only when someone is asking to see it.

Is ISO 42001 mandatory?

No. ISO 42001 is a voluntary standard and no Australian law requires it. Australia adopted it as AS ISO/IEC 42001:2023, and the government’s Guidance for AI Adoption references it, but references are not requirements. It is also not a harmonised standard under the EU AI Act, so it does not by itself demonstrate conformity with that regulation.

How many controls are in ISO 42001?

ISO/IEC 42001 Annex A contains 38 controls across nine categories, covering AI policy, internal organisation, resources for AI systems, assessing AI system impacts, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third party and customer relationships. As with ISO 27001, you assess each control’s applicability rather than implementing all of them blindly.

What is the difference between ISO 42001 and ISO 27001?

ISO 27001 is about protecting information and has 93 Annex A controls. ISO 42001 is about governing artificial intelligence and has 38 Annex A controls, including impact assessments on the people affected by an AI system. They share the same clause 4 to 10 management system structure, so the risk process, internal audit and management review can be run once and serve both.

How long does ISO 42001 certification take?

The audit itself is short: Stage 1 typically one to two auditor days, Stage 2 typically three or more, with several weeks between them. The certificate runs three years with annual surveillance audits. The longer part is building the AI management system and running it long enough to produce evidence, which for a small SaaS company usually means several months of preparation before Stage 1.

When was ISO 42001 published?

ISO/IEC 42001 was published on 18 December 2023 as the first edition, making it the first international management system standard for artificial intelligence. Standards Australia adopted it identically as AS ISO/IEC 42001:2023 on 16 February 2024, and JAS-ANZ granted its first Australian accreditation for the scheme in July 2025.

Where to go next

The useful first move is not booking an audit, it is writing down where AI already sits in your product and your internal operations, then testing that against the ISO 42001 clauses to see how far off you are. That work is worth doing even if you decide to wait, because it is exactly what a customer questionnaire will ask for next quarter. Our cyber security advisory team helps Australian SaaS companies sequence this properly against ISO 27001 and SOC 2. Get in touch and we will tell you whether ISO 42001 is your next step or a distraction.