ISO 42001: Australia's AI Management Standard

The question boards are starting to ask
Most Australian organisations have adopted AI faster than they have governed it. A team stands up a chatbot, finance trials an automated reconciliation, a manager pastes customer data into a public model to save an afternoon. Each decision is small and reasonable on its own. Added together, they leave a business running AI it cannot fully see, cannot fully explain, and cannot demonstrate control over when a regulator, an insurer, or a large customer asks.
The question that follows is uncomfortable and increasingly common. Can you show, on paper, how AI is used across your business, what could go wrong, who is accountable, and what stops it going wrong? For a growing number of organisations the honest answer is no, and that gap is now a commercial problem as much as a compliance one. Procurement teams have started asking suppliers to prove responsible AI use before signing.
There is now a formal answer to that question. ISO/IEC 42001, published in December 2023, is the first international management system standard written specifically for artificial intelligence. Standards Australia has adopted it locally as AS ISO/IEC 42001:2023, which means Australian organisations can build, run, and certify an AI management system against a recognised benchmark rather than inventing governance from scratch. This guide explains what the standard asks for, how it connects to Australia's own AI rules, and how to approach it without stalling the AI work already underway.
What an AI management system actually is
The phrase management system sounds heavier than the idea. A management system is simply a documented, repeatable way of running one part of a business so that it produces consistent, accountable outcomes. Organisations already use this pattern for quality under ISO 9001, for information security under ISO 27001, and for many other functions. ISO/IEC 42001 applies the same discipline to how an organisation develops, provides, or uses AI.
At its heart the standard asks an organisation to do a handful of connected things and to keep doing them. Set a clear AI policy and assign accountability for it. Understand where and why AI is used, and assess the risks each use creates. Assess the impact those AI systems can have on the people and communities affected by them, which is a step unique to AI and absent from older standards. Put controls in place across the AI lifecycle, from data and design through deployment and monitoring. Then audit the whole thing, learn from what the audit finds, and improve it. The pattern is Plan, Do, Check, Improve, applied to AI.
Ad Hoc AI Versus a Governed AI Management System
| Metric | Ad Hoc Adoption | ISO 42001 System | Improvement |
|---|---|---|---|
| Visibility of AI use | Scattered, unknown | Documented inventory | Full view |
| Accountability | Unclear | Named owners | Defined |
| Risk and impact assessment | Rarely done | Required and recorded | Consistent |
| Response when something fails | Improvised | Defined controls | Repeatable |
| Ability to prove it to a buyer | Anecdotal | Auditable evidence | Certifiable |
The value of framing AI governance this way is that it turns a vague aspiration to be responsible into a set of specific, checkable practices. A management system produces evidence. That evidence is what lets you answer the board's question, satisfy a procurement questionnaire, and show a regulator that control exists rather than merely claiming it.
How ISO 42001 connects to Australia's own AI rules
The standard does not exist in isolation here. Australia has been building its own expectations for responsible AI, and ISO/IEC 42001 is the practical machinery for meeting them.
In 2024 the National AI Centre, within the Department of Industry, Science and Resources, published the Voluntary AI Safety Standard, which set out ten guardrails for safe and responsible AI. In October 2025 the department built on that work with its Guidance for AI Adoption, which distils the approach into six essential practices: accountability, impact assessment, risk management, transparency, testing, and human oversight. Both documents describe what good looks like and both align explicitly with AS ISO/IEC 42001. The government guidance tells you what to aim for. The standard gives you a certifiable system to operationalise it and keep it running.
The Australian Government has also signalled that voluntary will not be the end of the story. Its 2024 proposals paper on mandatory guardrails for AI in high-risk settings put forward binding obligations for AI used where the stakes for people are highest. Organisations that already run a management system aligned to ISO/IEC 42001 will be far better placed to absorb mandatory rules when they arrive, because the hard part, the visibility and the controls, is already built.
Existing law sits underneath all of this. The Privacy Act 1988 already governs how personal information is collected, used, and disclosed, and AI systems that touch personal data are subject to it today. An AI management system does not replace privacy obligations. It gives them a home, so that a privacy impact and an AI impact are assessed together rather than in separate silos. For regulated and data-sensitive work, it pays to read the standard alongside our guide to AI and data sovereignty for Australian businesses.
From Voluntary Guardrails to a Certified System
If you already hold ISO 27001, you are partway there
Many organisations that are weighing up ISO/IEC 42001 already run an information security management system under ISO 27001. That is an advantage worth using. The two standards share the same management system backbone: leadership commitment, a defined scope, risk assessment, controls, internal audit, and continual improvement. An organisation that has been through 27001 already knows how to write a policy, run a risk assessment, and survive an audit, and it can extend those muscles to AI rather than building them from nothing.
The overlap is real but not total. Information security asks whether data is protected. AI management asks a broader set of questions: whether an AI system is fair, whether a person affected by it can understand and challenge a decision, whether the model behaves as intended once it meets the messiness of real use, and whether a human stays meaningfully in control. The AI impact assessment, which considers the effect of a system on individuals and groups rather than only on the business, is the piece that has no direct equivalent in the security world. That is the part most organisations underestimate.
The practical move for a business with existing certifications is an integrated management system, where AI governance is added as another layer over shared foundations rather than run as a separate regime. It reduces duplication, keeps one audit calendar, and means the AI controls sit next to the security and privacy controls they depend on. For the data-handling questions where these regimes meet, the data sovereignty guide is a useful companion.
Who should take this seriously now
Not every organisation needs a certified AI management system this year. The standard is deliberately scalable, and a two-person team using one AI tool does not need the same apparatus as a bank. The useful question is not size. It is exposure. The organisations that should move first are the ones where AI already touches something that carries real consequences.
Does Your Organisation Need an AI Management System?
A professional services firm feeding client documents into AI, a healthcare provider using AI in triage or administration, a lender applying models to decisions about people, a government supplier bound by procurement rules, all of these sit in the zone where governance is no longer optional. So do the many businesses that have quietly become AI suppliers by embedding it in a product they sell. If your customers depend on your AI behaving, they will eventually ask you to prove it does.
There is a commercial upside worth naming. In a market where every vendor claims to use AI responsibly, being able to point to an independently certified management system is a genuine differentiator in a tender. Governance done properly is not only a shield. It is something you can sell.
Building one without stalling the work
The common fear is that a management system means a freeze, a year of documentation, and a committee that says no to everything. Done well, it is the opposite. The point of ISO/IEC 42001 is to let an organisation use AI more confidently, because it finally understands what it is running. The path there is staged, and the early steps deliver value long before any certificate arrives.
A Practical Path to an AI Management System
The first step alone, building an honest inventory of where AI is actually used across the business, is often the most revealing thing an organisation does all year. It surfaces shadow AI that leadership did not know about, data flowing to places it should not, and duplicated tools that can be consolidated. That inventory pays for itself in reduced risk and clearer spending before a single control is written.
From there the work is a matter of prioritising by exposure and building controls where they matter most. Certification, when you choose to pursue it, comes through an independent audit by a body accredited for the purpose, and in Australia that means working with a JAS-ANZ accredited or internationally recognised certifier. Certification is the milestone, not the reason. The reason is that you can run AI at speed because you can see it, explain it, and control it.
What a Governed AI System Returns
What separates a system that passes from one that only looks tidy
There is a failure mode worth naming, because it is common and expensive. An organisation writes a thick AI policy, builds a register of good intentions, prints it, and believes the governance is done. An auditor arrives and asks a different question: show me this working. Show me the impact assessment for the model that scores loan applications. Show me the last time a human overrode an automated decision and what happened next. Show me who was accountable when the chatbot gave a wrong answer to a customer last month. Paper without evidence does not pass, and it does not protect anyone.
The systems that hold up share a few traits. Their AI inventory is current, because someone owns keeping it current, not because it was compiled once. Their higher-risk uses carry real impact assessments that name the people who could be harmed and the controls that reduce the harm. Their human oversight is specified rather than assumed, so it is clear who can intervene, when, and how. And they generate evidence as a byproduct of operating, logs, reviews, sign-offs, so that proving control is a matter of retrieval rather than reconstruction.
The other frequent misstep is scope. An organisation either tries to govern every trivial use of AI at once and collapses under the weight, or draws the scope so narrowly that the risky uses fall outside it. The standard rewards judgement here. Start the scope where the exposure is, prove the system works there, and widen it deliberately. A tight, genuinely operating management system over your three riskiest AI uses is worth more than a sprawling one that no one maintains.
Where consulting earns its place
Plenty of the work above an organisation can do itself, and the inventory and policy steps are a good place to start in-house. The parts that benefit from outside help are the impact assessments, the control design for higher-risk uses, and the honest gap analysis against the standard before an auditor sees it. This is where experience across enterprise systems and regulated environments matters, because the difference between a management system that passes and one that merely looks tidy is in the detail of the controls.
This is the kind of work Solve8 does in its consulting lane, and it connects to the broader governance material worth reading first: our AI governance framework for Australian organisations covers the foundations, and our piece on AI agent governance, data access and human override goes deeper on the controls that keep autonomous systems accountable. For the data-residency questions that sit underneath any certifiable system, the data sovereignty guide is the companion read.
If AI has spread across your organisation faster than your ability to govern it, the sensible next step is to map your current AI use against ISO/IEC 42001 and see where the real gaps are before anyone else finds them. That mapping is a scoped, finite piece of work, and it is where our AI strategy engagements usually begin. When you are ready to scope one, start a conversation with Solve8 and we will work out what a management system needs to look like for your particular exposure. You can also see how the two lanes of our work fit together across Solve8's products and services.