ISO 42001 explained. Decide whether to certify, and what to tell your board.

This guide is for the person asked whether an Australian or New Zealand organisation needs ISO/IEC 42001. It runs through the decision in the order you make it. You finish with the document that put the standard on your agenda, a recorded decision to certify, align or wait, and a board brief built from the facts on this page.

Read the clause by clause requirements

Step 01

Confirm what the standard is and that it covers you.

ISO/IEC 42001:2023 is the first certifiable management system standard for artificial intelligence. It sets requirements for establishing, running, maintaining and continually improving an AI management system, shortened to AIMS. The auditable requirements sit in clauses 4 to 10. Annex A lists 38 reference controls, and each one is either applied or excluded with a written reason.

The standard covers any organisation that develops, provides or uses AI, including organisations that manage third-party AI. A bank that only deploys a vendor's model is inside scope. So is a council running a Copilot rollout.

The standard reaches you as ISO/IEC 42001:2023 internationally, AS ISO/IEC 42001:2023 in Australia and NZS ISO/IEC 42001:2025 in New Zealand. The text is identical in each, and the 2025 in the New Zealand designation is the year of adoption.

What you produce

A one-paragraph definition for the board paper, and the right citation for each use: the local designation in a tender response, the international one in a certificate scope.

Worked example

A New Zealand buyer searches for "ISO 42001 2025" and asks whether an Australian supplier's 2023 certificate is out of date. All three designations contain the same requirements, so the certificate stands, and an accredited auditor works from the same clauses whichever cover the standard arrived in.

The standard does not replace any law. It sits on top of obligations you already carry, such as the Privacy Act 1988 in Australia or the Privacy Act 2020 in New Zealand.

Step 02

Name the document that is putting the standard on your agenda.

No law in Australia or New Zealand requires ISO 42001. Australia's National AI Plan relies on existing technology-neutral law and sets no mandatory high-risk guardrails. New Zealand's MBIE Responsible AI Guidance for Businesses is voluntary.

The pressure arrives through a regulator's expectations or a buyer's procurement questions. Find the specific document that applies to your organisation and record it. The lookup table at the end of this page lists nine organisation types and the document that pushes each one.

If nothing on that list applies and no customer has asked for evidence, record that as well. It points toward the wait option in step 3.

What you produce

A register entry naming the driver, its date and what it expects from you.

Worked example

An APRA-regulated insurer records APRA's letter to industry on AI. The letter expects an AI inventory, ownership across the AI lifecycle, a supply chain mapped to fourth parties, tested exit options, drift monitoring and independent assurance capability. It asks for globally recognised control frameworks and names no standard. The board paper says ISO 42001 is the certifiable framework that answers the letter, and stops short of saying APRA endorses it.

In New Zealand, the MBIE guidance names ISO/IEC 42001 as a framework businesses can use.

Step 03

Decide whether to certify, align or wait.

A certificate states that the management system inside a defined scope meets the standard. It says nothing about whether any single AI system is safe, fair or accurate.

Certification fits when the driver from step 2 expects independent evidence, such as a tender that asks for a certificate or a regulator looking for independent assurance capability. Where the driver accepts your own evidence, building the management system to the standard without booking an audit produces the same documents and keeps the audit decision open. An organisation with no driver from step 2 can record its reasoning and revisit it at the next AI policy review.

For exporters to the EU, ISO 42001 is not a harmonised standard under the EU AI Act, so a certificate gives no presumption of conformity. EN 18286:2026 is the Article 17 quality management standard, and its Annex D maps to ISO 42001 Annex A, so controls built for 42001 carry across.

What you produce

A recorded decision to certify, align or wait, with the reason tied to the driver.

Worked example

A software supplier to Commonwealth agencies receives AI-specific questions from buyers working under the DTA policy for responsible use of AI in government. It decides to certify so it can answer those questions with third-party evidence.

Step 04

Scope what you would build.

Clause 4.3 asks you to define which AI systems, business units, sites and processes the management system covers. That definition is printed on the certificate.

Start with an AI system inventory. No clause names it, but you cannot write a scope without one, and APRA now expects regulated entities to hold one.

If you only use vendor AI, a supplier's own ISO 42001 certificate feeds your supplier controls under Annex A.10. It covers none of your policy, impact assessments or management review.

What you produce

An AI system inventory and a draft scope statement.

Worked example

A payroll software provider writes its scope around the product families its customers buy and names the AI features inside each one. A buyer reading the certificate can then tell whether the AI it uses sits inside the scope.

The build list for each clause is on the ISO 42001 requirements page.

Step 05

Set the timeline.

Accredited certification runs in two stages. Stage 1 reviews your documents: scope, policy, risk and impact assessment methods, the Statement of Applicability, and evidence of internal audit and management review. Stage 2 tests whether the system runs as documented, through interviews, observation and sampling of records. The certificate is issued once nonconformities are closed. It lasts three years, with surveillance audits in years one and two and a full recertification at the end of year three.

Most organisations building their first management system need 9 to 12 months from gap assessment to stage 2. An organisation already certified to ISO 27001 or a similar standard can work to 4 to 6 months, and a large or multi-entity group needs 12 to 18 months.

Plan backwards from stage 1. The stage 1 auditor looks for a completed internal audit and a management review, so both have to run once on the live system before you book it. Allow at least 3 months of operating records for that, and 4 to 8 weeks between stage 1 and stage 2.

What you produce

A timeline for the board with a target month for stage 1.

Worked example

An insurer with a tender deadline sets its stage 1 month first. It then schedules the internal audit and the first management review ahead of that month, and the board paper shows all three dates.

Step 06

Shortlist a certification body a regulator will accept.

ISO does not certify anyone. Independent certification bodies do, and their certificates carry weight because an accreditation body has assessed them. ISO/IEC 17021-1 sets the general rules for those bodies. ISO/IEC 42006:2025 adds the AI-specific requirements.

Choose a body that JAS-ANZ has accredited for ISO 42001, and check its accreditation scope on the JAS-ANZ register before you sign.

A certification body cannot design the management system it then audits. Implementation support and certification are two separate engagements, which is why PolyGovern does not issue certificates.

What you produce

A shortlist of accredited bodies, each with its accreditation scope checked.

Worked example

A procurement lead looks up each shortlisted body on the JAS-ANZ register and confirms ISO/IEC 42001 appears in its accreditation scope. A body that cannot show it comes off the list.

Step 07

Write the board brief.

The board needs a short paper it can approve or reject. Build it from the outputs of steps 1 to 6, in this order.

  1. 01
    A one-paragraph definition of the standard, using the local designation.
  2. 02
    The driver from step 2, with its date and what it expects.
  3. 03
    Your recommendation to certify, align or wait, and the reason for it.
  4. 04
    Draft scope, naming the AI systems inside it.
  5. 05
    Timeline, with the target month for stage 1.
  6. 06
    Shortlisted certification bodies and their accreditation.
  7. 07
    One line on what a certificate proves: the management system meets the standard within its scope, and no individual AI system is certified safe or fair.

ISO/IEC 38507:2022 is guidance written for governing bodies on overseeing AI use. Directors who want the board-level reading can start there.

What you produce

A board paper with a decision for the directors to approve.

Worked example

An APRA-regulated entity's paper names APRA's letter to industry on AI as the driver. It recommends certification because the letter looks for independent assurance capability. The scope covers the AI systems that support critical operations, and the paper sets a target month for stage 1.

Reference

Who is asking, by organisation type.

Find your row for step 2. Each one names the document creating the pressure and what it expects. An organisation can sit in more than one row.

If you are The document creating the pressure What it expects
An APRA-regulated entity APRA letter to industry on AI An AI inventory, lifecycle ownership, supply chain mapped to fourth parties, tested exit options, drift monitoring, independent assurance capability and "globally recognised control frameworks". APRA names no standard. ISO 42001 is the certifiable one.
An AFS or credit licensee ASIC REP 798 ASIC reviewed 23 licensees, found governance lagging adoption and flagged a credit model it called a black box. It expects risk frameworks updated for bias, transparency and data quality. Clauses 6 and 8 hold the documented answer.
Any Australian deployer of AI Voluntary AI Safety Standard Ten guardrails, from accountability through to stakeholder engagement. It is written to be consistent with AS ISO/IEC 42001:2023 and NIST AI RMF 1.0.
A supplier to Commonwealth or NSW agencies DTA policy for responsible use of AI in government; NSW AI Assessment Framework Agencies name accountable officials and publish transparency statements. The DTA also provides an AI Impact Assessment Tool and procurement guidance. NSW agencies apply the AIAF to procurement. Vendors face AI-specific questions in both.
A New Zealand business MBIE Responsible AI Guidance for Businesses Names ISO/IEC 42001 and ISO/IEC 23894 as frameworks businesses can use. Includes an AI Procurement Checklist covering supplier capability, legal compliance and data governance terms.
A supplier to NZ public agencies Public Service AI Framework; GCDO procurement guidance Non-binding and silent on ISO 42001. Asks agencies for accountability through reporting, auditing and independent review, and for AI risk assessment inside procurement plans. Vendors get asked for evidence at that point.
A NZ organisation using personal information in AI Privacy Commissioner expectations on AI All 13 Information Privacy Principles apply to AI tools. The Commissioner expects a privacy impact assessment before deployment and senior leaders involved in generative AI decisions.
A NZ financial adviser or regulated entity FMA review of AI in financial advice; RBNZ financial stability expectations The FMA is probing governance, oversight, suitability and record keeping. The RBNZ expects AI exposures assessed inside existing risk management and treats reliance on a few third-party AI providers as a systemic vulnerability.
An exporter to the EU EU AI Act, Article 17; EN 18286:2026 ISO 42001 gives no presumption of conformity. EN 18286 is the Article 17 standard, and its Annex D maps to ISO 42001 Annex A.

Questions buyers ask.

Is ISO 42001 mandatory in Australia or New Zealand?

No law in either country requires it. Australia's National AI Plan relies on existing technology-neutral law and sets no AI-specific mandatory guardrails. New Zealand's MBIE Responsible AI Guidance for Businesses is voluntary. The pressure comes from regulator expectations, chiefly APRA and ASIC in Australia, and from procurement questions on both sides of the Tasman.

Is there a 2025 version of ISO 42001?

No. NZS ISO/IEC 42001:2025 is New Zealand's identical adoption of ISO/IEC 42001:2023. The year in the designation is the adoption year. The requirements are the same as the 2023 international standard and the same as AS ISO/IEC 42001:2023 in Australia.

Does ISO certify organisations?

No. ISO publishes the standard. Independent certification bodies audit and certify organisations, and accreditation bodies assess those certification bodies. In Australia and New Zealand the accreditor is JAS-ANZ.

Does ISO 42001 certification satisfy the EU AI Act?

No. ISO/IEC 42001 is not a harmonised standard under the EU AI Act and gives no presumption of conformity. EN 18286:2026 is the Article 17 quality management standard. Its Annex D maps to ISO 42001 Annex A, so controls built for 42001 carry across.

Which Australian organisations are certified?

Ask the organisation for its certificate and read the scope printed on it. Then check the JAS-ANZ register to confirm the issuing body is accredited for ISO 42001.

Find out how far your AI governance is from a stage 1 audit.

PolyGovern builds the management system and prepares the evidence. An accredited body audits it. A readiness review maps what you already have against clauses 4 to 10 and the 38 Annex A controls, and names the gaps a stage 1 auditor would raise.

Next read

What to build before stage 1.

The documents and records clauses 4 to 10 call for, in build order, with the full clause map at the end.

Read the requirements

Thirty-minute call

ISO 42001 readiness review.

A senior consultant walks through your AI inventory, policy and risk process against the standard.

Get in Touch