Somewhere between the board paper that says "we need AI governance" and the engineering backlog that says "ship the copilot", a gap has opened in most Australian organisations. The board wants assurance. The teams want permission. Nobody owns the system in between.
ISO/IEC 42001 exists to close that gap. Published in December 2023, it is the first international standard against which an organisation's AI management system can be certified — the operational spine that turns scattered AI-governance intentions into a system an independent auditor can test.
If you are a director being asked to sign off on AI risk, a risk or compliance lead who has been handed "AI" as a portfolio, or an executive at an APRA-regulated entity reading regulator letters about governance keeping pace with adoption, this page is the operational explainer: what ISO 42001 is, who actually needs it in Australia, what an AI management system involves in practice, and what getting ready looks like.
One framing note before we start. NETEVO's work is operationalising standards like this one — turning their requirements into controls you can run and evidence you can show. Certification itself is performed by accredited certification bodies, not by NETEVO and not by any consultant. That distinction matters, and this article keeps it visible throughout.
What is ISO 42001? #
ISO/IEC 42001:2023 is the international standard for an artificial intelligence management system (AIMS) — and the first standard of its kind that an organisation can be certified against. It specifies, at the level of organisational machinery rather than model internals, what a business must put in place to govern how it develops, procures, deploys and monitors AI: ownership, policy, risk assessment, lifecycle discipline, and evidence.
The shortest useful definition: ISO 42001 does for AI what ISO 27001 did for information security. It converts good intentions into a management system — a defined, documented, continuously improved way of operating — that a third party can audit.
Australia has adopted the standard nationally as AS ISO/IEC 42001:2023, published by Standards Australia. The two designations carry the same substance; the AS number is simply the form Australian boards and procurement teams reference. The Citation Catalogue holds NETEVO's canonical digests of both the international standard and the Australian adoption, and the texts themselves are available from ISO and Standards Australia.
"Certifiable" is doing precise work in that definition. It means an accredited certification body — an independent auditor, not a consultant and not NETEVO — can assess your management system against the standard and issue a certificate attesting to conformity. The certificate says your system for governing AI meets the standard; it does not say your AI is safe, accurate or lawful in every use. Understanding what the claim covers is the first piece of literacy the standard demands.
Two things ISO 42001 is not. It is not a technical checklist for making a model safe — it governs the organisation around the AI, not the weights inside it. And it is not legislation: no Australian law requires anyone to hold it. Its force comes from somewhere else, which is the next question.
Why does ISO 42001 exist? #
Because AI adoption ran ahead of AI governance, and until December 2023 there was no auditable way to demonstrate the difference.
Australia's own regulators have documented the gap. ASIC's review of AI use across financial services licensees — Report 798, aptly titled "Beware the gap" — found governance arrangements at many licensees had not kept pace with AI deployment. APRA's first AI-specific letter to industry reached a similar finding across banks, insurers and superannuation trustees, and called for a step-change in how AI-related risks are managed under existing prudential standards. Neither regulator created a new AI rulebook. Both, in effect, asked the same question: show us the system.
Before ISO 42001, there was no standard answer to that question. Organisations had AI ethics principles, policy PDFs and working groups — artefacts that assert governance without demonstrating it. A management-system standard changes the terms: it defines what a complete governing system contains, and it makes the claim testable, because an auditor can examine whether the system exists, operates and improves.
That is the real problem ISO 42001 solves. It is less a compliance burden than a shared definition of "we govern our AI" that outsiders can verify — boards, customers, regulators, and the certification bodies that formally attest to it.
Who needs ISO 42001 in Australia? #
Nobody is legally required to hold ISO 42001 certification in Australia. It is a voluntary standard, here and everywhere else. The practical question is who benefits from adopting it early — and in the Australian market, three groups stand out.
APRA-regulated entities. Banks, insurers and superannuation trustees already operate under CPS 230 (operational risk) and CPS 234 (information security), and APRA's AI letter makes clear that AI risk sits inside those existing perimeters. An AIMS gives a regulated entity a single, coherent structure for organising AI governance and producing the evidence supervisory conversations increasingly ask for.
Suppliers to government. The National framework for the assurance of AI in government — agreed by the Commonwealth and every state and territory — anchors AI assurance across the public sector. Enterprises tendering into government AI work will increasingly be asked to demonstrate assurance alignment, and a certified management system is the most legible demonstration available.
Listed companies. Boards of ASX-listed entities are being asked AI questions by audit committees, investors and proxy advisers. "We are experimenting responsibly" is an assertion; a management system is an answer. For directors, the standard supplies a defensible structure for the oversight they are already expected to exercise.
There is also a fourth, quieter driver: supply-chain pull-through. ISO 27001 spread through the Australian market less because organisations wanted certificates than because their largest customers started requiring them in vendor questionnaires. The same dynamic is beginning for AI: enterprises that adopt an AIMS push assurance expectations down onto the vendors whose AI is embedded in their stack. If your product carries AI into a bank, an insurer or a government agency, the question is likely to arrive in a due-diligence questionnaire before it ever arrives in a regulation.
And who doesn't need it yet? An organisation whose AI use is limited to low-stakes, off-the-shelf tools probably does not need certification — though it still needs the underlying capabilities (an owner, an inventory, an approval gate) in proportionate form, because ungoverned AI use compounds quietly. Certification is a decision you can defer; governance is not.
A register note for this section and the rest of the article: this page explains the landscape in operational terms; it is not legal advice — consult your own advisers on how these instruments apply to your specific circumstances. NETEVO's role is encoding obligations into controls you can operate and evidence, not interpreting statutes for your facts.
What does an AI management system actually involve? #
Strip away the standards vocabulary and an AIMS is a set of operating capabilities. What follows is NETEVO's operational description — deliberately not the standard's own control list, which is copyrighted and, more importantly, only meaningful once read in full against your context.
Governance ownership. A named owner, with authority, accountable for AI across the organisation — and a line of sight from that owner to top management. AI governance that belongs to everyone belongs to no one.
An AI inventory. A live register of the AI systems in use — built, bought and embedded in vendor products — with each entry tied to its purpose, its data, and its owner. You cannot govern what you have not listed, and most organisations are surprised by their own list.
Risk assessment tied to use. Assessment of what each system could do wrong in its actual deployment — including the impact on the people affected by its outputs, not only the risk to the organisation. A chatbot answering product questions and a model scoring credit applications do not deserve the same scrutiny.
Lifecycle gates. Defined decision points before an AI system goes live, when it materially changes, and when it retires — with criteria, not vibes, deciding what passes.
Monitoring in operation. Deployed AI watched for performance, drift and misuse — because an AI system's behaviour at approval time is the start of the story, not the end.
Incident paths. A defined route for when AI behaves badly: who is told, who decides, what gets remediated, what gets recorded.
Evidence. The connective tissue. Every capability above should generate records as a by-product of operating — so that when an auditor, a regulator or your own board asks "show me", the answer is retrieval, not reconstruction.
The recurring failure mode is owning these capabilities on paper only. A policy that says "all AI systems are risk-assessed" is an intention; a gate that will not release a system to production without a completed assessment is a control. NETEVO's Law-to-Code Methodology sits precisely on that distinction — obligations encoded as executable controls that emit their own evidence — and it is the difference between an AIMS that passes an audit and one that merely anticipates it.
How does ISO 42001 relate to Australia's regulatory posture? #
Australia deliberately chose not to enact a standalone AI act. The Commonwealth strengthened existing laws, empowered sector regulators — APRA, ASIC, the OAIC — and published voluntary instruments: the Voluntary AI Safety Standard with its ten guardrails — whose substance the National AI Centre's Guidance for AI Adoption now carries forward as the current national voluntary frame — the national assurance framework for government, and the broader National AI Plan. (The EU legislated a binding AI Act; Australia's contrast could not be sharper, and for organisations operating across both jurisdictions ISO 42001 is emerging as the certifiable common denominator. That is the extent of the EU's relevance here.)
This distributed posture makes a management system more valuable in Australia, not less. When obligations arrive from many directions rather than one statute, the scarce asset is a single spine to map them onto. An AIMS is that spine.
The Voluntary AI Safety Standard. The ten guardrails — spanning accountability, risk management, testing, human oversight, transparency and supply-chain expectations — describe what good AI governance looks like in Commonwealth vocabulary, and their substance now lives on in the National AI Centre's Guidance for AI Adoption, which evolves them into six essential practices. An organisation implementing those practices is already building AIMS capabilities; ISO 42001 adds the management-system discipline around them and the option of certification. They are complementary instruments, not rivals.
APRA and ASIC. Neither regulator mandates ISO 42001. Both, however, expect AI risk to be governed inside existing frameworks, and both have publicly found current practice wanting. An AIMS organises the response in a shape supervisors recognise — accountable owner, risk process, monitoring, evidence — rather than as an ad-hoc AI programme.
ISO 27001. ISO 42001 is built on the same harmonised management-system architecture as ISO 27001, ISO 9001 and their siblings. An organisation already running an ISO 27001 information security management system extends it to cover AI; it does not build a parallel stack. This is not theoretical for NETEVO: Gregory McKenzie led RISKflo Associates Pty Ltd to ISO/IEC 27001:2022 certification in 2025, and the management-system mechanics — scoping, risk treatment, evidence discipline, audit readiness — transfer directly.
Privacy and the OAIC. Where an AI system touches personal information — and most consequential ones do — the Privacy Act's obligations attach regardless of any standard, and the OAIC has published its expectations for both using and training AI on personal information. An AIMS does not replace privacy compliance; it gives the privacy function a governed inventory to work from, which is usually the piece it is missing.
NIST AI RMF. The main international comparator, with its four functions of Govern, Map, Measure and Manage, maps cleanly onto the same management-system structure — one engineered control set can serve both. The full comparison across NIST, ISO 42001, APRA and the Voluntary AI Safety Standard has its own page, the NIST AI RMF digest covers the framework itself, and the AI Governance in ANZ whitepaper carries the deep regulatory evidence base this article deliberately summarises rather than repeats.
What does getting ready for ISO 42001 look like operationally? #
Readiness is a sequence, not an event, and it does not begin with buying the standard. It begins with three honest questions: where is AI actually in use here, who answers for it, and what could we show an auditor today?
NETEVO frames the work as three phases — Baseline, Gap, Operate — detailed in the diagnostic grid below. The first pass establishes what exists: the inventory, the ownership map, the current state of approvals and evidence. The second reads that baseline against the capabilities an AIMS requires and produces a prioritised gap register. The third builds and runs the controls — gates, monitoring, incident paths — until the system is generating its own evidence in ordinary operation. Only then does certification become a scheduling decision rather than an aspiration.
It is worth being concrete about what "evidence" means at the end of that sequence, because it is where readiness efforts most often disappoint. An auditor does not want a well-written policy; they want to see that the system ran. That looks like: the inventory entry for a model, the completed risk assessment attached to it, the approval record from the gate it passed through, the monitoring output from last month, and the incident record — including the boring ones — with its closure trail. When those records are produced by the controls themselves as they execute, audit preparation shrinks to retrieval rather than reconstruction. When they must be assembled by hand in the weeks before an audit, the system exists on paper and everyone in the room knows it.
Two distinctions keep this honest. First, readiness and certification are different things done by different parties. NETEVO designs and operationalises the management system; an accredited certification body independently audits it and issues the certificate. Any provider offering to do both for you is describing a conflict of interest, not a service. Second, the timeline is a function of your baseline, which is why this article promises phases and not weeks.
If you want to locate your own starting point before speaking to anyone, the ISO 42001 readiness checklist (PDF) is NETEVO's self-assessment: the readiness questions we ask, phrased for a board or risk lead to run internally. It is deliberately our own instrument, not a reproduction of the standard. From there, the AI Governance & Readiness solution page sets out how the operationalising work is scoped and delivered.
Where to start: Baseline → Gap → Operate
The phased read NETEVO uses to take an organisation from scattered AI activity to an operating, evidence-producing management system.
Baseline
First pass
- Inventory of AI systems in use — built, bought, and embedded in vendor products
- Ownership map: who answers for each system, and to whom
- Current state of approvals, monitoring, and incident handling
- Evidence audit: what could be shown to an auditor today, unprepared
Gap
Second pass
- Baseline read against the operating capabilities an AIMS requires
- Risk-tiering of the inventory so scrutiny lands where impact lives
- Overlap analysis with existing management systems (ISO 27001, CPS 230/234 programmes)
- Prioritisation by exposure and by the evidence each fix generates
Operate
Ongoing
- Lifecycle gates enforced in the deployment path, not in a policy PDF
- Monitoring and incident routes wired into normal operations
- Evidence generated as a by-product of the controls executing
- Management review cadence so the system improves rather than decays
The phases are sequential; their duration is a function of your baseline. The readiness checklist linked above is the self-assessment version of this whole readiness sequence — a first pass across all three phases.
Where to read next
The comparison, the evidence base, the canonical digests, and the two ways to act on what you have just read.
ISO 42001 Readiness Checklist
NETEVO's self-assessment: the readiness questions a board or risk lead can run internally before any programme begins.
Download the checklistAI Governance Frameworks Compared
NIST AI RMF, ISO 42001, APRA's prudential standards and the Voluntary AI Safety Standard — four lenses, one discipline, and how to choose.
Read the comparisonAI Governance, Explained
The front door: what AI governance means in Australia's no-single-AI-act landscape, and where each instrument fits.
Read the explainerAI Governance in ANZ 2026
The deep evidence base — the full regulatory landscape, readiness data, and the research behind this article.
Read the evidence baseAI Governance & Readiness
How NETEVO operationalises the management system: readiness assessment, policy-as-code, audit-trail architecture, board reporting.
View solutionISO/IEC 42001:2023 — Citation Catalogue digest
NETEVO's canonical digest of the standard itself: designations, structure, and why it anchors the AU governance stack.
View the digestQuestions
Frequently asked questions
Definition, comparison, and readiness questions. Service-mechanics questions — scope, engagement models, deliverables — are answered on AI Governance & Readiness.
Is ISO 42001 mandatory in Australia?
No. ISO/IEC 42001 is a voluntary standard in Australia and everywhere else — no Australian law requires certification. Australian regulators do expect AI risk to be governed under existing obligations, and sectors such as APRA-regulated finance and government supply are where certification is becoming commercially significant. Mandatory and valuable are different questions.
How is ISO 42001 different from ISO 27001?
ISO 27001 specifies a management system for information security; ISO 42001 specifies one for artificial intelligence — including concerns security standards do not reach, such as the impact of AI decisions on the people subject to them and oversight across an AI system's lifecycle. The two share the same harmonised management-system architecture, so an organisation running ISO 27001 extends its existing system to AI rather than building a second one.
Do we need ISO 42001 if we already follow the Voluntary AI Safety Standard?
They do different jobs. The Voluntary AI Safety Standard's ten guardrails describe what good AI governance looks like; ISO 42001 wraps those practices in a management system that can be independently audited and certified. Implementing the guardrails builds much of the substance an AIMS needs — ISO 42001 adds the discipline, the continual-improvement loop, and the certifiable claim.
How long does ISO 42001 readiness take?
It depends on your baseline, which is why NETEVO describes phases rather than promising a timeline. The work runs Baseline (inventory, ownership, evidence audit), then Gap (prioritised against AIMS capabilities), then Operate (controls running and producing evidence). An organisation with a mature ISO 27001 system starts much further along than one starting cold.
Can you give us the ISO 42001 controls?
No — the standard is a copyrighted work, purchased from Standards Australia or ISO, and reproducing its control list would be both unlawful and unhelpful. A management system is not a list to transcribe; it is a set of capabilities operated in your context. What NETEVO provides is the operationalisation: your obligations encoded as executable controls, with the standard itself as the licensed reference.
Who signs off AI governance under ISO 42001?
Accountability sits at the top. The standard expects the organisation's leadership — top management, with the governing body engaged — to own the AI management system's direction, resourcing and outcomes. Day-to-day operation can be delegated to a risk or technology function; accountability for the system cannot.