← All articles

AI Governance

ISO 42001 explained: the new standard for AI management systems

Abstract visualisation of artificial intelligence

Every few years a standard comes along that changes what buyers expect from their suppliers. ISO 27001 did it for information security. A decade ago, hardly anyone outside IT had heard of it; today it shows up in procurement checklists as routinely as insurance certificates. ISO/IEC 42001 is on the same path, and it's moving faster.

If your organisation builds AI products, embeds AI features into software, or uses AI to make decisions that affect people, this article is for you. We'll walk through what the standard actually asks of you, who genuinely needs it, and what certification involves in practice. No hype, no doom, just the practical picture.

What ISO 42001 actually is

ISO/IEC 42001 is the first international standard that lets an organisation certify its AI management system. Notice the wording: it certifies how you manage AI, not the AI itself. Nobody stamps your model as 'safe'. What gets audited is the system of governance around it: the policies, the accountabilities, the risk assessments, the human oversight, and the routines that keep all of it honest as your AI changes.

If you've been through ISO 27001, the shape will feel familiar. There's a management system core (leadership, planning, support, operation, evaluation, improvement) and a set of AI-specific controls sitting underneath it. The difference is the subject matter. Where 27001 asks how you protect information, 42001 asks harder, newer questions.

Who is accountable when your AI gets something wrong? Not in a philosophical sense, but on an org chart, with a name. How do you assess the risks and impacts of an AI system before it ships, and again when you retrain it? What data does the system learn from, where did that data come from, and who checked you were allowed to use it? When the system produces an output that affects a person, a loan decision, a shortlisting, a clinical suggestion, where exactly does a human sit in that loop? And would you actually notice if the system's behaviour drifted over time?

Most AI teams have partial answers to these questions scattered across Slack threads, model cards and the heads of two senior engineers. What the standard does is force those answers into a system that survives staff turnover, product pivots and scale.

Who actually needs it

We'd put organisations into three groups. The first is AI product companies: platforms, copilots, agents, and SaaS products with AI features trained on or applied to customer data. For this group, ISO 42001 is rapidly becoming the cleanest answer to a question they already get in every enterprise deal: 'how do we know your AI is governed responsibly?' Right now most vendors answer with a policy PDF and a hopeful tone. A certificate from an accredited body answers it in one line.

The second group is organisations deploying AI in decisions that matter: recruiters screening candidates, lenders scoring applications, insurers triaging claims, health providers supporting diagnosis, agencies delivering services to the public. These organisations carry the impact risk. Regulators, boards and the public increasingly expect them to show demonstrable oversight, and 'the vendor said it was fine' is not oversight.

The third group is suppliers who simply sell into markets where AI governance questions are starting to appear in due diligence. If your customers are banks, governments or large enterprises, questions about your AI use are coming whether you build models or just use them.

Why the timing matters

The regulatory backdrop is moving in one direction. The EU AI Act is being phased in, and its reach extends well beyond Europe, the same way GDPR's did. Australia has published its own guidance for safe and responsible AI, and procurement rules in several markets are beginning to reference AI governance explicitly. None of these regimes require ISO 42001 by name. But when a regulator, customer or court asks 'show us how you govern AI', a certified management system is the most recognisable, most defensible form that answer can take.

There's also a commercial first-mover effect that we saw play out with ISO 27001. Early certified vendors used it as a differentiator; five years later it was a minimum requirement and nobody got credit for it anymore. ISO 42001 is in the differentiator phase right now. That window won't stay open long.

What certification actually involves

The process mirrors other ISO certifications. A Stage 1 audit reviews your AI management system's design: your AI policy, your risk and impact assessment method, your inventory of AI systems, your defined accountabilities. Stage 2 tests how the system operates in practice. Auditors will want to see real impact assessments for real systems, evidence that humans genuinely review what you say they review, records of how you evaluated a third-party model before building on it, and proof that monitoring actually runs.

A word of reassurance for smaller teams: a management system does not mean a bureaucracy. A twenty-person AI company with a clear policy, a lightweight impact assessment template, a named accountable owner and honest monitoring can absolutely certify. What auditors are looking for is that the governance is real and proportionate, not that it generates paperwork.

Where to start

Start with an inventory: list every AI system you build, embed or rely on, including the third-party ones. For each, write down what data it touches, what decisions it influences, and who owns it. Then pick your highest-impact system and run a first impact assessment on it. Those two artefacts, an inventory and one honest assessment, are the seed of an AI management system, and they'll teach you more about your readiness than any gap checklist.

EVO Certification Group offers independent ISO 42001 certification in Australia and internationally, delivered by auditors who work with model lifecycles, data pipelines and foundation-model products every week. If AI is part of what you build or how you operate, we're happy to talk through what certification would look like for your scope. No obligation, and we'll tell you honestly if you're not ready yet.

Keep reading

Get certified

Talk to a certification body that gets it

Clear scope, fixed pricing and auditors who understand how modern organisations work. Australian based, serving clients worldwide.