ISO 42001 explained for Australian companies

ISO/IEC 42001 is the certifiable management-system standard for AI. What it covers, who is asking for it, and how Australian companies should approach certification.

ISO/IEC 42001 is doing for AI what ISO/IEC 27001 did for information security: turning "trust us, we take it seriously" into something an auditor can certify and a procurement team can require. Published in late 2023, it is the first certifiable management-system standard for artificial intelligence, and in the last year it has started appearing in Australian enterprise vendor questionnaires, right next to the 27001 question it was modelled on.

If you have been through 27001, the shape will be familiar. 42001 is not a checklist of technical controls for your models. It is a management system: a documented, auditable way of governing how your organisation develops, procures, deploys and monitors AI across its lifecycle. It wants to see that you know what AI you run, that you assess the risks and impacts of each system, that someone owns those risks, that controls exist and operate, and that the whole apparatus improves over time. The standard's Annex A provides the control set; the management clauses provide the machinery.

Two things make 42001 particularly relevant for Australian companies right now. First, the commercial pull: enterprise and government buyers are starting to ask for it, and being early is a real differentiator in deals where AI makes procurement nervous. Second, the regulatory hedge: Australia's mandatory AI standards and expected 2027 legislation will almost certainly overlap heavily with what 42001 already requires, which means certification work done now is pre-compliance work you won't have to repeat.

This post explains the standard in plain language: what it requires, how it interacts with 27001 and the NIST AI RMF, what certification costs and takes, and the traps we see companies fall into, starting with scoping the management system far too wide. Ironbark Cyber runs 42001 readiness engagements, and this is the primer we give clients before the first workshop.

What is ISO/IEC 42001, and what is it not?

ISO/IEC 42001 is a standard for an AI management system (AIMS), the organisational apparatus for governing AI responsibly. It is certifiable, which means an accredited certification body can audit you against it and issue a certificate that customers and regulators will recognise. That certificate is the point: it converts your internal good intentions into external, portable proof.

It is worth being clear about what 42001 is not, because the misunderstanding is expensive. It is not a technical security standard for your models, and it will not tell you how to defend against prompt injection or how to test a RAG pipeline. It is not a substitute for testing your AI, which is where offensive testing comes in. And it is not something a consultancy can hand you certified, because certification must come from an accredited certification body, independent of whoever helped you prepare. What a firm like Ironbark Cyber does is readiness: getting you to the point where the audit is a formality rather than a fright.

How does the management system work?

Structurally, 42001 follows the same harmonised structure as ISO/IEC 27001, so the two slot together neatly. The management clauses (roughly 4 through 10) cover context, leadership, planning, support, operation, performance evaluation and improvement, the familiar plan-do-check-act loop. Annex A then provides the AI-specific control set: policies for AI, internal roles and responsibilities, resources for AI systems, the AI system lifecycle, data governance for AI, information provided to interested parties, the responsible use of AI systems, and third-party and supplier relationships.

The parallels with 27001 are not cosmetic. If you already hold 27001, you have an information security policy, a risk process, internal audit, management review and a corrective-action system, and 42001 reuses all of that machinery. In practice, organisations with a mature ISMS can bolt an AIMS onto it far more cheaply than starting cold, because the hard part (the culture and cadence of a management system) already exists. You are adding AI-specific risk and impact assessment, AI lifecycle controls and AI data governance on top of a running engine.

Who is asking for it in Australia, and why now?

Two buyer types are driving the early demand. Enterprise procurement teams, especially in financial services, health and anything touching consumer data, have started adding "are you working toward ISO 42001?" to the security questionnaires their vendors must answer. And government buyers, already comfortable with certifiable standards, see 42001 as a clean way to manage AI supplier risk. In both cases, being able to say "yes, and here is our roadmap" carries deals where "we take AI seriously" falls flat.

The timing is not an accident. Australia's move toward mandatory AI obligations (covered in our piece on the country's AI governance direction) means the frameworks buyers reference today are the ones the regulator is likely to lean on tomorrow. Certifying to 42001 now is a hedge: most of the work counts twice.

Scoping: the decision that determines cost and pain

The single biggest lever on how much a 42001 programme costs is scope, meaning which AI systems and processes the management system covers. Get this wrong by making it "all AI, everywhere" and you have signed up to govern every marketing team's chatbot experiment. Get it right and you cover the systems that carry risk and revenue, and nothing else.

Good scoping starts from your AI inventory and your risk register: which AI systems are customer-facing, handle sensitive data, make or influence consequential decisions, or are contractually promised to a big customer. That is usually a much smaller set than "everything with a model in it". A tight, defensible scope is the difference between a readiness programme measured in a few months and one that never finishes.

Impact assessments: the heart of the standard

If 27001's centre of gravity is the risk assessment, 42001's is the AI system impact assessment. For each in-scope system, you are expected to assess both the risk to your organisation and the potential impact on the people and groups the system affects: fairness, safety, transparency, and the consequences of the system being wrong or misused. This is the requirement that most often surprises 27001-hardened teams, because it asks a different question than "could this be breached?"

Done well, the impact assessment is where AI governance stops being paperwork and starts being useful. It forces a structured conversation about what your AI does to the world, who owns the downside, and what controls sit between the model and a bad outcome. It also aligns closely with the AI Impact Assessments the Australian Government now expects for public-sector AI use, so the effort transfers.

How does it map to the NIST AI RMF and the AU AI Technical Standard?

These frameworks complement each other rather than competing, and the smart move is to do the work once and map it to all three.

FrameworkTypeBest used for
ISO/IEC 42001Certifiable management systemProvable governance buyers and regulators recognise
NIST AI RMFVoluntary risk frameworkStructuring how you identify, measure and manage AI risk
AU AI Technical StandardGovernment technical baselineSelling to, or operating within, the Commonwealth

In practice, the NIST AI RMF gives you a vocabulary for risk that maps cleanly onto 42001's risk and impact clauses, and the AU AI Technical Standard adds the technical expectations you need if government is in your market. We cover the first pairing in detail in ISO 42001 vs NIST AI RMF.

What does the certification path look like?

The route to a certificate has a predictable shape. A gap assessment establishes where you stand against every clause and Annex A control, typically a couple of weeks of work. A remediation phase closes the gaps: writing the policies, standing up the risk and impact processes, and implementing the controls, usually over a few months depending on how much already exists. Then an accredited certification body runs a Stage 1 (documentation) and Stage 2 (implementation) audit, after which the certificate issues, with surveillance audits following annually.

Ironbark Cyber's role is the readiness half: gap assessment, roadmap, and the technical testing that evidences controls, with fixed-fee gap assessments starting around AU$15,000 and full programmes scoped to the organisation. The certification body's fees are separate and depend on your size and scope. The honest headline is to budget in months rather than weeks, and let scope discipline do the cost control.

What goes wrong?

The failure modes are consistent. Scoping too wide, as above, is the classic. Treating 42001 as a documentation exercise divorced from what the AI does is the next one, because a beautiful policy set that no engineer has read protects no one. Skipping the impact assessment or reducing it to a tick-box misses the point of the standard. And leaving the technical evidence until last means discovering, days before the audit, that a control you claimed does not hold. The fix for all four is the same: ground the management system in a real inventory and real testing from the start.

ISO/IEC 42001 is not hard so much as unfamiliar, and the organisations that struggle are usually the ones treating it as a certificate to be bought rather than a system to be built. Ironbark Cyber runs 42001 readiness the way we run everything else: offensive-first, senior-only, and honest about what your controls do. If it is turning up in your customers' questionnaires, the cheapest time to start was last quarter, and the second cheapest is now.

FAQ

Frequently asked questions

Is ISO 42001 mandatory in Australia?

Not yet, but it is increasingly requested by enterprise and government buyers, and it overlaps heavily with the mandatory AI standards and 2027 legislation Australia is moving toward. So certifying now is largely pre-compliance work.

Can a consultancy certify us to ISO 42001?

No. Certification must come from an accredited, independent certification body. A consultancy like Ironbark Cyber does readiness. The gap assessment, remediation roadmap and technical evidence. So the certification audit is a formality.

How long does ISO 42001 certification take?

A gap assessment is typically a couple of weeks; closing the gaps to audit-ready is usually a few months depending on how much already exists; then the certification body runs Stage 1 and Stage 2 audits. Budget in months, not weeks.

We already have ISO 27001. Does that help?

Considerably. ISO 42001 shares 27001's management-system structure, so your existing risk process, internal audit and management review are reusable. You are mainly adding AI-specific risk and impact assessment, AI lifecycle controls and AI data governance.

What does ISO 42001 readiness cost?

Ironbark Cyber's fixed-fee gap assessments start around AU$15,000, with full readiness programmes scoped to your organisation. The accredited certification body's audit fees are separate.

Put this into practice

A senior Ironbark Cyber consultant will scope your engagement on a free 30-minute call and give you a fixed quote within one business day.