Run one AI control set and prove it against every instrument you are asked about.

Take the controls you already run and place each one in ISO/IEC 42001, NIST AI RMF, Australia's Guidance for AI Adoption, New Zealand's Public Service AI Framework and Algorithm Charter, and the privacy principles in both countries. Seven steps and a fifteen-row table get you there. At the end, every control in your register carries a crosswalk row and the evidence each instrument accepts, and you hold a list of the rows with nothing against them.

Go to the table

No government has issued a crosswalk between ISO/IEC 42001 and the Australian or New Zealand guidance, so we built the table on this page ourselves.

Keep your current control list open beside it and work through the steps in order, because each later step cites what the earlier ones produce.

Step 1 of 7

Decide which columns you answer to.

Read the six columns and strike out the ones that do not reach you. The result is a scope line at the top of the register.

  1. 01

    ISO/IEC 42001:2023

    The certifiable AI management system standard, adopted in Australia as AS ISO/IEC 42001:2023. Clauses 4 to 10 set the management system and Annex A holds 38 controls under nine objectives, from AI policy (A.2) to third-party relationships (A.10). It is the only instrument in the table a third party can audit you against, so keep it in scope if anyone plans to audit you. Start with ISO 42001 explained.

  2. 02

    NIST AI RMF 1.0

    United States voluntary guidance with four functions (Govern, Map, Measure, Manage), 19 categories and 72 subcategories. A revision is under way with no draft or date yet, so the table cites the 1.0 identifiers. Keep it in scope when someone you report to cites it. The full explainer is NIST AI RMF for Australia and New Zealand.

  3. 03

    Australia: ten guardrails, six practices

    The Voluntary AI Safety Standard set ten guardrails. The National AI Centre's Guidance for AI Adoption evolves them into six essential practices across a Foundations tier and an Implementation tier, and ships templates for an AI policy, risk screening and an AI register. The guardrails remain in place, so the table cites both as "Guardrail n" and "Practice n". Both are voluntary. Commonwealth entities are bound by the DTA policy and NSW agencies by the AI Assessment Framework.

  4. 04

    New Zealand: PSAIF, Algorithm Charter, GCDO guidance

    The Public Service AI Framework is non-binding, with five OECD-derived principles and six work-programme pillars. The Algorithm Charter is a voluntary commitment by signatory agencies, built on six commitments and a likelihood by impact risk matrix. The GCDO's Responsible AI Guidance for the Public Service covers generative AI. None of these reach a private organisation, whose voluntary equivalent is MBIE's Responsible AI Guidance for Businesses.

  5. 05

    Privacy: APPs and IPPs

    The Australian Privacy Principles and New Zealand's Information Privacy Principles apply whenever personal information enters or leaves an AI system. Every organisation keeps this column.

  6. 06

    Strength and notes

    Our rating of how well a row holds across the columns. Strong means one piece of evidence satisfies every instrument listed. Moderate means at least one column needs a separate artefact. Weak or absent means an instrument does not address the topic, and the cell names which one.

Two organisations reading the same table end up with different scope lines. A New Zealand private company strikes out every PSAIF, Charter and GCDO reference, records MBIE's business guidance as its voluntary reference, and keeps the full privacy column with IPP 3A. A Commonwealth agency keeps every Australian reference and adds the DTA policy, which binds it.

For a private organisation the privacy column is the only one with legal force: APP 1.7 to 1.9 from 10 December 2026 in Australia, and IPP 3A since 1 May 2026 in New Zealand, where the Biometric Processing Privacy Code also covers biometric processing.

Step 2 of 7

Lay the register out on ISO 42001 clauses.

The output is an empty register with sections that follow clauses 4 to 10 and Annex A.

ISO 42001 is the only column with clauses 9 and 10. A register organised by ISO clause already has a place for everything the other columns ask for. A register organised by NIST function leaves internal audit and management review to be bolted on later, because NIST has no construct for either.

Beside each control description, add a column for the crosswalk row, one for the evidence location and one per instrument in your scope line. An ISO auditor, a Commonwealth accountable official and a Charter signatory can then filter the same register to their own view without a second document.

Name the sections with descriptive labels. ISO/IEC 42001 is copyrighted and sold by ISO and Standards Australia, so its text stays out of the register.

Step 3 of 7

Tag each control with its row.

Find the ISO clause or Annex A theme a control serves in the left column and write that row number against the control. Then read across to see what each instrument calls the same thing.

Fifteen rows. Scroll sideways on a phone. "Charter" is the Algorithm Charter, "PSAIF" the Public Service AI Framework, "Implementation" the second tier of the Guidance for AI Adoption.

ISO/IEC 42001 NIST AI RMF 1.0 Australia New Zealand Privacy (APP / IPP) Strength
Row 01 Clause 4. Context, interested parties, scope MAP 1 context; GOVERN 5 engagement Guardrail 10 stakeholder engagement; Practice 2 understand impacts PSAIF principle: inclusive, sustainable development; Charter: People APP 1 openness; IPP 1 purpose of collection Strong to NIST and Australia. New Zealand is principle level only.
Row 02 Clause 5 and A.2, A.3. Leadership, AI policy, roles GOVERN 1, GOVERN 2 Guardrail 1 accountability; Practice 1 decide who is accountable (senior owner, AI policy template) GCDO GenAI guidance: senior official; PSAIF pillar Governance APP 1.2 practices and procedures; NZ privacy officer (s 201) Strong across every column. The hub row.
Row 03 Clause 6 and A.5. Risk assessment, risk treatment, impact assessment MAP 4, MAP 5, MANAGE 1, MANAGE 2 Guardrail 2 risk management; Practice 3 measure and manage risks (risk screening template); stakeholder impact assessment in Practice 2 Charter risk matrix and impact assessment; no public equivalent of a DTA-style impact assessment beyond PIA expectations OAIC: PIA for high-risk AI; OPC: PIA before use Strong. ISO A.5 is the subject of ISO/IEC 42005.
Row 04 Clause 6.2. AI objectives GOVERN 1 policies tied to risk tolerance Practice 1 next steps: governance framework PSAIF vision; MBIE business guidance: define the purpose for AI None Moderate. Privacy has no analogue.
Row 05 Clause 7 and A.4. Resources, competence, awareness, documented information GOVERN 2.2 training; GOVERN 4 culture Practice 1 train accountable people; Practice 6 training for overseers; Guardrail 9 records PSAIF pillar Capability; GCDO GenAI skills section APP 1.2; none in the IPPs Moderate. Strong for the NZ public sector, absent for NZ private organisations.
Row 06 Clause 8 and A.6. AI system lifecycle, change control MAP 2, MAP 3, MEASURE 2, MANAGE 4 Guardrail 4 test and monitor; Practice 5 test and monitor (vendor proof of testing, stress tests, independent testing) GCDO GenAI procurement and security; Charter peer review APP 10 and IPP 8 accuracy; APP 11 and IPP 5 security Strong.
Row 07 A.7. Data for AI systems: quality, provenance, preparation MAP 2.3; MEASURE 2 data; GOVERN 6 Guardrail 3 data governance and provenance; Practice 5 extend data governance Charter: Data (limitations, bias). Charter does not fully address Māori data sovereignty APP 3, 5, 6; IPP 1 to 4 and 10; IPP 3A indirect collection; OAIC developer guidance on scraping Strong. The richest privacy hooks sit here.
Row 08 A.8. Information for interested parties: transparency, incident reporting GOVERN 4.3 incident sharing; MANAGE 4.3 Guardrails 6, 7, 8; Practice 4 share essential information (AI register, disclosure, explanations) Charter: Transparency and Human oversight (contact point, appeal channel); PSAIF transparency and explainability APP 1.7 to 1.9 ADM disclosure from 10 Dec 2026; APP 5; IPP 3 and 3A notification Strong. The only row with a hard 2026 legal date.
Row 09 A.9. Use of AI systems: responsible use, intended use MAP 1.1 intended purpose; MANAGE 1.1 go or no-go Practice 3 risk screening for unacceptable uses; Guardrail 5 human oversight GCDO GenAI foundations; PSAIF human-centred values APP 6 purpose limitation; IPP 10 Moderate.
Row 10 A.10. Third-party and customer relationships GOVERN 6, MANAGE 3, MAP 4 Guardrail 8 supply chain; Practice 1 supply-chain accountabilities; Implementation 1.2 and 4.3 model and system cards GCDO GenAI procurement; nothing in the Charter APP 8 and IPP 12 offshore disclosure; OAIC vendor due diligence Strong in Australia, weak in New Zealand.
Row 11 Clause 9. Monitoring, internal audit, management review MEASURE 1, 3, 4; MANAGE 4.1 post-deployment monitoring Guardrail 4 monitor; Practice 5 monitoring matched to risk; Implementation 5.3.3 audit when warranted Charter: regular peer review OAIC: ongoing monitoring; nothing statutory Weak outside ISO. No other instrument requires internal audit or management review.
Row 12 Clause 10. Nonconformity, corrective action, improvement MANAGE 4.2 incident response; GOVERN 4.3 Practice 3 investigate and document incidents; Implementation 3.4 two-way incident reporting GCDO GenAI accountability; NZ private sector absent Notifiable breach schemes: AU Part IIIC, NZ Part 6 Moderate. Breach regimes are the only mandatory incident hooks.
Row 13 Human oversight (A.6 and A.9 controls, cross-cutting) GOVERN 3.2 oversight roles; MAP 3.5; MANAGE 2.2 Guardrail 5 human control; Practice 6 maintain human control (override points, alternative pathways) Charter: Human oversight; PSAIF accountability None. APP 1.7 is disclosure only; the NZ Law Commission is reviewing ADM by government Strong in guidance, absent in law.
Row 14 Contestability and redress GOVERN 5.1 feedback; MANAGE 4.3 Guardrail 7 challenge processes; Practice 2 contestability channels; Ethics Principle: contestability Charter: channel to challenge or appeal None in the APPs; IPP 6 and 7 access and correction only Weak in law in both countries.
Row 15 Māori and First Nations data, Treaty obligations None National AI Plan: Indigenous data sovereignty and Closing the Gap engagement Charter: Partnership (Te Ao Māori); GCDO GenAI section on Māori, Pacific and ethnic communities; OPC: engage Māori on taonga None statutory Absent from ISO and NIST. A distinctive Australian and New Zealand layer.

Clause and Annex A names are descriptive labels. ISO/IEC 42001 is copyrighted and sold by ISO and Standards Australia; nothing from the standard's text is reproduced here.

Step 4 of 7

Map one control across every column.

A worked example on row 03. The output is a register entry that names the evidence each instrument accepts.

Take a common control: before an AI system goes live, its accountable owner signs a risk assessment. Walk it across the row one cell at a time and note what each instrument needs that the document does not yet hold.

  1. 01

    ISO/IEC 42001

    Clause 6 and A.5 cover risk assessment, risk treatment and impact assessment. The document needs a treatment plan and an impact section beside the assessment itself. ISO's A.5 impact assessment is the subject of ISO/IEC 42005.

  2. 02

    NIST AI RMF

    MAP 4 looks at risks and benefits for every component, third-party parts included. MAP 5 looks at impacts on individuals, groups, communities, organisations and society. MANAGE 1 and 2 cover the prioritised response. List the vendor model as a component and record a response against each risk, and the same document answers all four.

  3. 03

    Australia

    Guardrail 2 and Practice 3. Run the Guidance's risk screening template before the full assessment, since Practice 3 uses it to flag unacceptable uses early. Practice 2's stakeholder impact assessment is the impact section you already wrote for ISO.

  4. 04

    New Zealand

    A Charter signatory adds one field for the Charter rating. Its matrix crosses likelihood (probable, occasional, improbable) with impact (low, moderate, high). A low rating means the Charter "could" apply, moderate means "should" and high means "must".

  5. 05

    Privacy

    The OAIC expects a PIA for high-risk AI. The Office of the Privacy Commissioner expects one before any AI use involving personal information. Attach the PIA to the assessment and record its date in the register.

  6. 06

    The register entry

    Row 03. Evidence: the signed assessment with its treatment plan and impact section, the screening result, the attached PIA and, for a signatory, the Charter rating. One document with one added field and one attachment now answers five columns, which is why the table rates the row strong.

Step 5 of 7

Build the evidence file for each row.

Repeat step 4 for the other rows. Strong rows close with one artefact. Moderate rows need a second one, named here.

  1. 01

    Row 01. A scope statement.

    List the AI systems in play, the people affected and the external parties with an interest. That one list covers clause 4, MAP 1 and GOVERN 5, Guardrail 10 and Practice 2, and the Charter's People commitment asks for the same list of impacted communities. Date it and cite it from every other artefact.

  2. 02

    Row 02. An AI policy with a roles table.

    Every column converges on this row. Practice 1 asks for a senior leader as overall AI governance owner and a named accountable person per system. The GCDO recommends a senior official for generative AI, NIST GOVERN 2 asks for accountability structures, and ISO A.2 and A.3 ask for a policy and an internal organisation. One policy with a named owner and a roles table discharges all of it. The Guidance for AI Adoption ships an AI policy template, and ours is on the AI policy template page.

  3. 03

    Rows 06 and 07. A test, monitoring and data file.

    Pre-deployment test results, post-deployment monitoring and a data provenance record satisfy Guardrails 3 and 4, Practice 5, MAP 2 and MEASURE 2, and ISO A.6 and A.7. Practice 5 says to ask vendors for proof of testing, so file the vendor's evidence alongside your own.

  4. 04

    Row 08. An AI register with a disclosure column.

    Practice 4 asks for an organisation-wide AI register. Add a column stating what each system discloses and to whom. That column feeds the Australian privacy policy, the Charter's plain-English documentation and the ISO A.8 artefact from one source. Step 6 fills it in.

  5. 05

    Row 10. A vendor due diligence file.

    The Implementation tier asks deployers to clarify accountability across model developers, system developers and deployers, and to pass model and system cards downstream. NIST GOVERN 6 and MANAGE 3 cover the same ground, and APP 8 and IPP 12 govern offshore disclosure. The Algorithm Charter says nothing about suppliers, so a New Zealand agency relying on it alone needs this file to close the row. Our third-party AI risk work builds it.

  6. 06

    Row 05. Training records as the second artefact.

    Training records for accountable people and overseers cover Practice 1, Practice 6, GOVERN 2.2 and clause 7. Commonwealth entities have a mandatory staff training requirement under the DTA policy. The New Zealand private sector has nothing equivalent, so there the certification auditor is the only party who will ask to see the records.

  7. 07

    Row 12. An incident procedure that routes into the breach scheme.

    Practice 3 asks you to investigate and document incidents, and the Implementation tier adds two-way incident reporting. NIST places incident response in MANAGE 4.2. The only mandatory incident hooks in either country are the notifiable data breach schemes (Part IIIC in Australia, Part 6 in New Zealand), so write the AI incident procedure to hand a qualifying breach into the existing scheme.

  8. 08

    Rows 04 and 09. Objectives and intended use.

    Privacy has no analogue for AI objectives, so record them in the AI policy against clause 6.2 and GOVERN 1. For intended use, NIST MANAGE 1.1 calls for a go or no-go decision and Practice 3 screens for unacceptable uses. Record that decision per system, with the purpose it was approved for, because APP 6 and IPP 10 limit use to the purpose of collection.

Step 6 of 7

Mark the systems that trigger a privacy date.

The output is the disclosure column from step 5, filled in for every system on the AI register.

Row 08 carries Australia's date. From 10 December 2026 a privacy policy must state the kinds of personal information used by, and the kinds of decisions made or substantially assisted by, a computer program where the decision could significantly affect a person's rights or interests.

Apply the OAIC's broad reading of "computer program" as you go down the register. Rule-based tools, machine learning, spreadsheets and chatbots all count, and human review does not take a tool out of scope if its output is a key factor in the decision. Each system you mark supplies a line of the privacy-policy text.

Row 07 carries New Zealand's date. Since 1 May 2026, IPP 3A has required notification when personal information is collected from a source other than the individual. Mark every system fed with scraped or vendor-sourced personal information collected on or after that date.

Mark generated outputs too. The OAIC treats AI-generated information about an identifiable person as personal information, and its generation as collection under APP 3.

Step 7 of 7

Record a decision on every gap.

Some gaps no crosswalk can close. Put each one to the board as a decision, so the gap list it signs off shows a choice made on purpose.

Internal audit, management review and the Statement of Applicability exist only in ISO 42001 (row 11). The Guidance for AI Adoption mentions audit only "when warranted" in its Implementation tier, and the Charter asks for regular peer review. If certification is the goal, add the audit plan and the first management review to the register now.
NIST does not certify. Decide whether the board needs a certificate, since ISO/IEC 42001 is the only instrument in the table a third party can audit you against.
New Zealand has no automated decision-making transparency duty. IPP 3A is a collection notice. The Law Commission's review of ADM by government is at scoping stage.
Australia's APP 1.7 to 1.9 is a disclosure duty with no right to an explanation, to human review or to contest a decision. Contestability (row 14) sits in Guardrail 7, Practice 2 and the Charter, and nowhere in law. Decide whether you offer a challenge channel anyway.
Human oversight (row 13) is strong in guidance and absent in law. Practice 6 asks for override points and alternative pathways if the AI fails; APP 1.7 asks only for disclosure.
Māori and First Nations data obligations (row 15) are absent from ISO and NIST. In New Zealand the Charter's Partnership commitment, the GCDO guidance and the Privacy Commissioner's expectation to engage Māori on taonga carry them, although the Charter covers government algorithms only and does not fully address Māori data sovereignty. In Australia the National AI Plan names Indigenous data sovereignty. See Māori data governance.

Give rows 13 to 15 an owner and evidence like any other control. A certification audit will not ask about them, and a regulator or a Treaty partner will.

To score the finished register, the maturity model explains the levels and the risk calculator classifies a single system against the same instruments. Both use this crosswalk underneath.

Questions the table raises.

Is there an official crosswalk between ISO 42001 and the Australian or New Zealand frameworks?

No government has issued a mapping between ISO 42001 and the Guidance for AI Adoption, the Public Service AI Framework or the Algorithm Charter. The table on this page is PolyGovern's own mapping.

Which of these instruments is actually mandatory?

For private organisations, only privacy law. In Australia, APP 1.7 to 1.9 require privacy policies to describe qualifying automated decision-making from 10 December 2026. In New Zealand, IPP 3A has required indirect-collection notification since 1 May 2026, and the Biometric Processing Privacy Code applies to biometric processing. ISO 42001, NIST AI RMF, the Guidance for AI Adoption, the Public Service AI Framework and the Algorithm Charter are all voluntary. Commonwealth agencies are bound by the DTA policy and NSW agencies by the AI Assessment Framework.

Did Australia's Voluntary AI Safety Standard get replaced?

The ten guardrails remain in place. The National AI Centre's Guidance for AI Adoption evolves the standard into six essential practices across two tiers, and this crosswalk cites both.

Are Australia's mandatory guardrails for high-risk AI law?

No. The proposals for mandatory guardrails have not become legislation. The National AI Plan relies on existing technology-neutral laws, keeps sector regulators responsible and establishes an AI Safety Institute without enforcement powers.

Where does the crosswalk have no mapping at all?

ISO 42001's internal audit, management review and Statement of Applicability have no equivalent in NIST AI RMF or in the Australian and New Zealand guidance. Māori and First Nations data obligations appear in the Algorithm Charter, GCDO guidance and the National AI Plan but have no ISO or NIST counterpart. Neither Australian nor New Zealand law gives individuals a right to contest an automated decision.

Does the Algorithm Charter apply to private companies?

No. It is a voluntary commitment signed by government agencies, and it does not fully address Māori data sovereignty.

Map your existing controls to the fifteen rows.

A working session with a senior consultant. Bring your control register or your AI policy. You leave with each control tagged to a crosswalk row and a list of the rows with nothing against them.

Get in Touch