Cyber Security

ISO 42001 Explained: What It Means for Australian Business

Ashish Srivastava
Ashish Srivastava
Head of Cyber Security & Strategy

Share

Author

Ashish Srivastava
Ashish Srivastava
Head of Cyber Security & Strategy

In this article

    How fast the world has changed! It’s only been 5 years since the first widely available generative AI model, GPT 3, was released from beta. And now, your insurer is asking at renewal whether your company has an AI policy in place to mitigate risk.

    Key tender contracts are asking for documentation around AI governance. And sooner or later, someone at board level is likely to forward the standard number, ISO 42001, asking whether the business needs it.

    We wrote this guide to address those concerns Australian businesses have about AI governance, and where ISO 42001 fits into that picture. Most sources you’ll see coming up in a search will be a certification body selling the audit, a cloud giant announcing its own certificate, or a definition written for a global enterprise (10 times the size of an Australian mid-market firm) and just not relevant locally.

    Does this apply here? Is it mandatory? How does certification work in this country? Does existing ISO 27001 work count for something? How much of an existing ISO 27001 system will carry straight across?

    In this article we address these questions from a local, Australian perspective.

    Key takeaways

    • Voluntary in Australia, with one dated exception: businesses covered by the Privacy Act will be required to include details of automated decision-making in their privacy policy from 10 December 2026.
    • The certificate covers the management system around AI, not the AI itself: the AI management standard applies to organisations only using AI through, for example, an AI assistant or an AI vendor platform. They do not have to build any AI.
    • An existing ISO 27001 system carries a significant % of the documentation across: the shared management-system structure will extend the scope of current work. The remainder of work to be done will be genuine AI-specific work.
    • Align first, certify on a commercial trigger: the presence of an existing management system can reduce the time to certification.

    What ISO 42001 Actually Is

    The AI management standard was published in December 2023 as the world’s first certifiable international standard for AI. It was adopted identically by Standards Australia in February 2024 as AS ISO/IEC 42001:2023.

    Importantly, this is a management system standard: any certificate issued under it relates to the organisational management system (policies, procedures, records) that manages the use of AI, and not to any AI system, model or product itself. This standard applies to organisations that use AI as well as those that build it, meaning a business does not have to build any AI of its own in order to obtain certification.

    Mid-market organisations will typically find that their staff are using tools such as Microsoft Copilot to draft documents and records, that service providers are utilising embedded machine learning within their platforms, and that intake processes are utilising AI to make decisions. Does the organisation have control of all of this? Can someone demonstrate organisational control on paper?

    Is ISO 42001 Mandatory in Australia?

    No. ISO 42001 is voluntary, and Australia has no AI Act to make it otherwise.

    The Australian government undertook public consultation on mandatory guardrails for high-risk AI in 2024. In December 2025 the National AI Plan was released and outlined the direction of travel: existing technology-neutral law rather than a standalone AI statute. In July 2026 the Office of AI was established within the Department of the Prime Minister and Cabinet and work on new Australian AI standards was announced, with legislation flagged for early 2027.

    Although much has been made of the announcement of new Australian AI standards, the real detail of the announcement has largely been lost in the headlines. The new Australian AI standards are for large AI data centres, for AI training and for copyright, and are not a management obligation on businesses that use AI. So far, any headline you might have read is incorrect when it says Australian companies broadly have to adhere to AI standards.

    There is however one firm date, 10 December 2026, when the requirements for transparency around automated decision making will come into force as part of the changes to the Privacy Act. Requirements around transparency of decisions made by automated processing of personal information will need to be outlined in the privacy policy of organisations covered by the Privacy Act. It is a disclosure obligation, and the drafting casts it broadly.

    AI governance is now being included in tender conditions. Whether a business uses AI is now becoming a normal question at renewal. Boards are not interested in enthusiasm for AI adoption, they want control. For many organisations certification is the shortest credible way to meet all of these requirements.

    Timeline of Australian AI rules from the Voluntary AI Safety Standard in 2024 to Privacy Act automated decision-making transparency on 10 December 2026
    Australian regulatory timeline.

    What the Standard Requires

    The AI management standard is based on a management system. This backbone runs through clauses 4 to 10 of the standard, and ISO 27001 runs on the same backbone. In the annex to the standard, approximately 38 AI-specific controls are mapped to nine areas of requirements.

    Here is what needs to happen in real work terms:

    • An approved and reviewed AI policy which is updated rather than left to gather dust on a shelf.
    • Named accountability for use of AI. Individuals are held accountable for the outcomes of their AI use, rather than a general committee.
    • A complete inventory of all the AI systems used within the organisation, including the embedded AI within third-party tools.
    • An impact assessment for any AI systems that could affect customers, staff or organisational decisions, done before deployment.
    • Data governance regarding input to and output from models, including what staff paste into tools.
    • Human oversight for decision making and advice giving, with ability to modify output generated by AI.
    • Supplier governance for the mid-market organisation, as risk typically arrives within the software and services provided by the organisation’s vendors.

    There is no software to buy for any of this, just documentation and review cadence for the decisions that an organisation writes down for its work. And then they have to show that they are following up on it.

    Table of the nine ISO 42001 Annex A areas with what each asks of an organisation in plain English
    The nine Annex A areas in plain English.

    ISO 42001 vs ISO 27001

    It is worth separating two standards, ISO 27001 and the recently published AI management standard. The first is about information through the medium of an information security management system. The second is about AI systems managed by an AI management system. Information security deals with protecting information, i.e. the confidentiality, integrity and availability of information. AI management deals with the responsible development, deployment and use of AI systems.

    Both are not alternatives but rather stacked layers. While an information security system tells you whether a document is confidential, the AI management system questions whether it was even appropriate to use a language model on that document in the first place, who would have decided to use it and what happens if the model makes mistakes.

    Information security has 93 controls spread over 4 themes in the 2022 edition of the ISO 27001 standard. The AI management standard has around 38 controls that are distributed over 9 areas.

    ISO 27001 certification is well established in Australia compared to the new AI management standard. For IT, finance, health and government supply chains a security questionnaire is typically followed by certification against the information security standard. For the AI management standard, certification typically follows from governance questions that a business cannot yet answer on paper. Such questions typically occur for technology providers as well as firms under tender pressure.

    Organisations can however certify against the AI management standard without holding ISO 27001 certification. In Australia, almost nobody does though. Those that are pursuing certification against the AI management standard are overwhelmingly organisations that already run an information security system. The key question that this raises is addressed in the next section.

    Side-by-side comparison of ISO 27001 and ISO 42001: what each governs, controls, adoption, triggers and owners
    ISO 27001 vs ISO 42001 side by side.

    If You Hold ISO 27001, You Are 40–60% There

    For organisations already holding an ISO 27001 certification, a large proportion of the existing management system will transfer into the AI standard.

    Practitioners and certification bodies estimate that 40% to 60% of the existing documentation can be reused within the new scope. Therefore, while the core of the management system will need extending rather than rebuilding, all of the key structural elements (document control, internal audit, management review, corrective action, risk methodology) transfer into the new scope of the AI standard.

    For businesses that already have high-transfer work running in the information security system: asset inventories, supplier controls, incident management and monitoring. The new work of conducting AI impact assessments, creating model lifecycle documentation, and dealing with bias and explainability will be very difficult to describe as paperwork. The scope of work will extend rather than form the basis of a new programme.

    ISO 27001 processes that carry across to an ISO 42001 AI management system, and the genuinely new AI-specific work
    The 27001 to 42001 bridge.

    Getting Certified in Australia

    For the purpose of Australian AI certification, certification bodies need to be accredited.

    To date, only a small number of certification bodies have been accredited to issue certificates under the new AI standard, through national accreditation bodies recognised by the International Accreditation Forum (IAF). Most of the well established certification bodies are still getting up to speed with the new requirements, and with few Australian auditors available, most ISO 42001 certificates in Australia are currently issued by overseas certification bodies. KPMG Australia, one of the few local examples, was certified by BSI Group Netherlands under the Dutch accreditation body, Raad voor Accreditatie (RvA).

    The five stages of the certification process are well established. The necessary gap analysis is followed by the documentation of the necessary processes and their implementation. The stage 1 audit verifies the documented system, the stage 2 audit tests the system under operation and, in the end, the certification is awarded with subsequent annual surveillance audits.

    “TechBrain implemented ISO 27001 internally, and that hands-on experience proved irreplaceable when we came to ISO 42001. We used our experience in IT, security and AI to run the gap analysis first, then expanded the existing ISMS processes we had built to include AI requirements. That gave us one integrated management system, rather than two running in parallel.”

    “Adapting the risk management procedure for AI is typically the biggest hurdle in these transitions, but our experience meant we were able to do it with relative ease. Information risk and AI risk are similar in approach, but they’re different in nature and have to be handled as such.”

    Ashish (Ash) Srivastava, Head of AI, TechBrain

    Indicative timescales for the certification for a mid-market business would be around 6-12 months, with significantly shorter timescales for organisations with an ISO 27001 foundation.

    Currently the major constraint on the certification process is the capacity of the certification bodies, i.e. the auditor availability, which is the scarcest resource within the certification process. Booking windows of the certification bodies drive the timescales available within the certification process as much as the organisation’s readiness for certification.

    What certification actually costs

    Initial certification (the sum of stage 1 and stage 2 audits) will cost a mid-market Australian business with one site of operation typically $15,000 to $40,000, with subsequent annual surveillance audits costing between 30% and 40% of the initial fee ($5,000 to $15,000 per year after that).

    Note that these figures are estimates, based on practitioners’ hours rather than actual quotes from certification bodies, and they are not TechBrain pricing. The largest international certification bodies charge at the top end of this estimate, while smaller accredited bodies charge at the lower end.

    Subsequent recertification audits (occurring every 3 years) will cost according to the scope of audit: headcount, sites, complexity of the AI footprint under audit. Recertification audits can be priced lower when combined with an annual ISO 27001 surveillance audit. The estimates provided above do not include the cost of readiness (establishing and embedding the management system in the first place), which varies based on the starting point, but decreases dramatically where there is an existing ISO 27001 management system in place.

    Each business will be scoped for the readiness work, and no range referenced above is a suitable substitute for actual quotes, since certification bodies charge commercially on a basis of auditor days. Thus, it is wise to ask for quotes from more than one certification body.

    The aligned then certified approach is best for mid-market businesses. Aligning first in order to derive the most value from the governance and then certifying when a client, tender or insurer requires you to do so in order to convert the work into a credential is generally the best approach. While there are calendar reasons to certify in due course, a commercial trigger is generally the right moment.

    “As the ISO standard itself is not mandatory, we see organisations adopt ISO 42001 and stay aligned to it rather than pursue certification. Typically, it takes proactive leadership or an external trigger, such as competitive pressure or an upstream requirement, to move the business from aligned to certified.”

    Ashish (Ash) Srivastava, Head of AI, TechBrain

    Mapping ISO 42001 to Australia’s Voluntary AI Safety Standard

    Australia’s Voluntary AI Safety Standard is the free way in. This has been published by the Department of Industry, Science and Resources in September 2024.

    The 10 guardrails cover topics of accountability, risk management, data governance, testing, human oversight and transparency, and map against the certifiable AI management standard. Working through the guardrails is largely equivalent to working through what an auditor would in the end assess.

    How TechBrain Helps

    TechBrain is ISO 27001 certified and pursuing ISO 42001 certification. This isn’t a description of a bridge from afar, we are actually walking across it. Our AI governance work is being delivered from Australia by our in-house team, under the same management disciplines that we help our clients to set up and run themselves.

    Understanding the standard is one thing. Implementing it is another.

    This guidance is general in nature, does not constitute legal advice, and is current as at publication.

    Sources

    1. AS ISO/IEC 42001:2023 adoption, Standards Australia, February 2024.
    2. ISO/IEC 42001:2023, artificial intelligence management system standard, International Organization for Standardization, December 2023.
    3. Voluntary AI Safety Standard, Department of Industry, Science and Resources, September 2024.
    4. National AI Plan, Australian Government, December 2025.
    5. Office of AI and Australian Standards for AI announcements, Department of the Prime Minister and Cabinet, July 2026.
    6. Privacy and Other Legislation Amendment Act 2024, automated decision-making transparency provisions commencing 10 December 2026, Office of the Australian Information Commissioner.
    7. IAF accreditation framework and the IAF CertSearch register of accredited certifications, International Accreditation Forum.
    8. KPMG Australia ISO/IEC 42001 certification by BSI, KPMG Australia and BSI media releases, October 2024.
    9. Certification cost and audit-day estimates, aggregated from published certification-body and practitioner figures, 2025-2026.

    FAQ

    What is ISO 42001?

    The AI management standard, ISO/IEC 42001:2023, is the world’s first certifiable international standard for an artificial intelligence management system. It was released in December 2023 and adopted identically by Standards Australia in February 2024 as AS ISO/IEC 42001:2023. The new international standard outlines how an organisation can manage the development and use of AI.

    Is ISO 42001 mandatory in Australia?

    The AI management standard is not mandatory in Australia and certification against the standard is on a voluntary basis only. AI is regulated through existing technology-neutral laws in Australia, and the standard does not replace any of them. Businesses will need to comply with the obligation under the Privacy Act to provide transparency about automated decision-making from 10 December 2026.

    What is the difference between ISO 42001 and ISO 27001?

    ISO 27001 deals with information security through the medium of an information security management system (ISMS). The AI management standard deals with AI systems through the medium of an AI management system (AIMS). The AI management standard can be layered on top of ISO 27001 at relatively low cost. They are both based on the same management structure.

    How do you get ISO 42001 certified in Australia?

    Certification in Australia is completed by an accredited certification body, conducting a gap analysis and then implementing the necessary items. Following this would be a stage 1 documentation audit and a stage 2 operational audit. Certification would then be issued with the organisation subject to annual audits. An existing ISO 27001 implementation can greatly reduce the amount of work required to complete certification.

    What is an AIMS?

    An AI management system (AIMS) outlines policies and accountabilities as well as risk assessments, AI inventories and reviews of current AI within an organisation. Although it can be very valuable when no certification is achieved, in the end it is this framework that gets certified.

    Does ISO 42001 certification mean we comply with the EU AI Act?

    No. Both governance frameworks mainly cover the same scope of governance. However, European law is governed by a number of special requirements and definitions of risks. Certification of the governance of an organisation proves its maturity, but does not replace the legislation imposed requirements.

    Ashish Srivastava

    Head of Cyber Security & Strategy

    I’ve been working in the cyber security space for over 10 years, turning Essential Eight and ISO 27001 into practical steps that cut risk, shorten audits and lift security maturity.

    Ashish Srivastava

    Ashish Srivastava

    Head of Cyber Security & Strategy

    I’ve been working in the cyber security space for over 10 years, turning Essential Eight and ISO 27001 into practical steps that cut risk, shorten audits and lift security maturity.

    Related Posts

    View all