ISO/IEC 42001:2023 is the first international standard for managing artificial intelligence. It does the same job for AI that ISO 27001 does for information security: it defines a management system you build, run and have independently audited, rather than a checklist you tick once.
It is certifiable in Australia. JAS-ANZ, the accreditation body for Australia and New Zealand, has accredited certification bodies for ISO/IEC 42001, so an Australian business can hold a properly accredited certificate rather than a self-assessment.
Worth being straight about this, because the reasons are commercial rather than regulatory.
Australia has no AI-specific legislation. The government consulted on mandatory guardrails for high-risk AI, but that path has not been legislated and a technology-specific AI act remains unlikely. What exists instead is non-binding guidance. In October 2025 the Department of Industry, Science and Resources and the National AI Centre published the Guidance for AI Adoption, which supersedes the earlier Voluntary AI Safety Standard and condenses its ten guardrails into six essential practices. Australia’s eight AI Ethics Principles sit underneath it. All of it is voluntary.
So nobody is forcing you to certify. Anyone telling you ISO 42001 is mandatory in Australia is selling something. The pressure is coming from customers and procurement, not from a regulator.
Three places that pressure is actually coming from:
| Source | What they are asking for |
|---|---|
| Government procurement | The Australian Public Service AI Plan requires suppliers to disclose to their government customers where AI is used to deliver services, and to contract on terms that keep responsibility for that AI use with the supplier. If you sell to government and your product uses AI anywhere, you now have to be able to describe and stand behind it. |
| Enterprise customers | Security questionnaires have started carrying AI sections. If your product has an AI feature, expect questions about training data, human oversight, bias testing and what happens when the model is wrong. |
| Your own ISO 27001 auditor | If you introduced AI into a process inside your certified ISMS scope, that is a change to the management system. It will come up. |
The clause structure, 4 through 10, is the same harmonised structure as ISO 27001, so if you already hold ISO 27001 the shape will be familiar: context, leadership, planning, support, operation, performance evaluation, improvement. The AI-specific substance sits in the annexes and in two requirements that have no ISO 27001 equivalent.
| Part of the standard | What it covers |
|---|---|
| Clauses 4 to 10 | The management system itself. Scope, leadership commitment, objectives, competence, documented information, internal audit, management review, corrective action. Same machinery as ISO 27001. |
| Annex A | The reference controls for AI management, covering AI policy, roles and responsibilities, resources, the AI system lifecycle, data for AI systems, information for interested parties, and use of AI systems. |
| Annex B | Implementation guidance for the Annex A controls. Considerably more detailed than the controls themselves and the part most worth reading first. |
| Annex C | AI-related organisational objectives and risk sources, including fairness, transparency, explainability, reliability, safety, security, privacy, accountability and environmental impact. |
| Annex D | Using the AI management system across different domains and sectors. |
The AI system impact assessment. ISO 42001 asks you to assess the consequences of your AI systems for individuals, groups and society, not just the risk to your own organisation. That is a different exercise from a security risk assessment and usually a new one. It is also the requirement that most often needs input from outside the technology team.
Lifecycle management of the AI system itself. The standard expects you to manage the AI system across its life: objectives and requirements, design, verification and validation, deployment, operation and monitoring, and eventual retirement, with the data used at each stage accounted for. If your answer to “where did the training data come from” is a shrug, that is the gap.
This is the most common question, and the answer is usually both, in that order.
| ISO 27001 | ISO 42001 | |
|---|---|---|
| Protects | Information: confidentiality, integrity, availability. | People and society from the consequences of AI systems, as well as the organisation. |
| Core risk question | What could happen to our information, and who could cause it? | What could our AI system do to someone, including when it works exactly as designed? |
| Distinctive requirement | Statement of Applicability against Annex A. | AI system impact assessment, plus AI lifecycle management. |
| Who asks for it | Almost every Australian enterprise and government customer. | Customers of AI-enabled products, and government buyers under the APS AI Plan. |
| Maturity of demand | Established. Often a hard tender requirement. | Early. Currently a differentiator rather than a gate. |
If you have neither and a customer is asking for something, start with ISO 27001. It is what procurement actually recognises, and ISO 42001 bolts onto it cleanly because they share the same clause structure, the same internal audit machinery and the same management review. Adding ISO 42001 to an existing certified ISMS is a far smaller project than building a management system from scratch.
If you sell an AI product and your buyers are starting to ask AI-specific questions, doing both together is the efficient path. One management system, two certificates.
ISO 42001 is worth the effort if any of these describe you:
It is probably not worth it yet if you simply use third-party AI tools internally, such as a chat assistant or a coding assistant, with no AI in what you sell and no government customers. In that case a short internal AI use policy aligned to the Guidance for AI Adoption does the job, and we will tell you that rather than sell you a certification.
The process mirrors ISO 27001: gap analysis, build the management system, internal audit and management review, then a two-stage audit by an accredited certification body. Stage 1 checks you are ready. Stage 2 tests whether the controls are genuinely operating. The certificate then runs on a three-year cycle with annual surveillance audits.
Two cost notes specific to ISO 42001. The pool of auditors qualified in it is still small, so scheduling can take longer than for ISO 27001 and you should book earlier than feels necessary. And because the standard is new, scoping matters even more than usual: certifying the one AI-enabled product your customers are asking about is far cheaper and faster than certifying everything you do.
CERTIFY includes ISO 42001
Our CERTIFY package covers ISO 27001, SOC 2 and ISO 42001 on one fixed monthly fee: standard $3,750 per month on a 12-month subscription, excluding GST, for organisations up to 50 employees, reduced to $2,750 per month on contracts signed by 31 December 2026. That covers the gap analysis, the management system build, the documentation, the AI system impact assessment, the internal audit, the management review and support through both audit stages. The certification body’s audit fee is quoted separately by the body, and we obtain those quotes for you.
No. Australia has no AI-specific legislation and a technology-specific AI act remains unlikely. The government consulted on mandatory guardrails for high-risk AI but has not legislated them. What exists is voluntary guidance: the Guidance for AI Adoption, published in October 2025 by the Department of Industry, Science and Resources and the National AI Centre, which supersedes the earlier Voluntary AI Safety Standard, sitting on top of Australia’s eight AI Ethics Principles. Pressure to certify is coming from customers and procurement, not from a regulator.
Yes. JAS-ANZ has accredited certification bodies for ISO/IEC 42001:2023, so an accredited certificate is available here rather than only a self-assessment. As with ISO 27001, check the body on the JAS-ANZ register and confirm the accreditation specifically covers ISO/IEC 42001 before you engage them.
ISO 27001 protects information. ISO 42001 manages the consequences of AI systems for people and society as well as for the organisation. The clause structure is the same, so they integrate well, but ISO 42001 adds two things ISO 27001 does not have: an AI system impact assessment that looks outward at effects on individuals and groups, and lifecycle management of the AI system and its data.
Much less than starting from scratch. You reuse the scope, the leadership commitment, the competence and documentation machinery, the internal audit process and the management review. The new work is the AI-specific controls in Annex A, the AI system impact assessment, and documenting the AI lifecycle including where your data comes from.
Usually not. If AI is not in what you sell and you have no government customers, a short internal AI use policy aligned to the Guidance for AI Adoption is normally proportionate. ISO 42001 starts earning its cost when AI is in your product, when you sell to government, or when AI influences decisions about people.
If you supply the Australian government, yes. It requires suppliers to disclose to their government customers where AI is used to deliver services, and to contract on terms that keep responsibility for that AI use with the supplier. You do not need ISO 42001 to meet that, but you do need to be able to describe your AI use accurately and stand behind it, which is most of what the standard makes you document anyway.
Broadly similar to ISO 27001 for an organisation starting from scratch, and considerably faster if you already run a certified ISMS. The practical constraint is often auditor availability rather than your own readiness, because the pool of auditors qualified in ISO 42001 is still small, so book the audit earlier than you would for ISO 27001.