ISO/IEC 42001: AI management systems
The international standard for running an AI management system, adopted in Australia as AS ISO/IEC 42001:2023. Voluntary. Relevant when a large customer or tender asks for certification; not needed to use AI tools.
- Status
- Voluntary · International · Standards Australia
- Applies to
- Businesses asked for certification by a customer or tender; not businesses that only use AI tools
- Primary source
- Official document →
- Last reviewed
- 28 September 2026
What it is
ISO/IEC 42001 is the international standard for running an AI management system: a documented way of deciding what AI an organisation uses, who is accountable for it, what could go wrong and how it is checked. Standards Australia adopted it as AS ISO/IEC 42001:2023. It is voluntary. No Australian law requires it, and most businesses that use AI tools do not need certification. It matters when a customer asks for it.
What it requires
The standard follows the same structure as ISO 27001 and ISO 9001. An organisation has to understand its context and the AI it uses, assign leadership and roles, assess AI risks and impacts, put controls in place, keep records, measure whether the system works and improve it. Annex A lists the controls to choose from: an AI policy, defined responsibilities, an inventory of AI systems, impact assessments, data handling rules, human oversight, monitoring and incident handling. Certification means an accredited third party has audited that system and found it operating as written. It certifies the organisation’s management of AI, not any particular product or model.
Does this reach your business?
Only if someone asks for it. The people who ask are large customers and government buyers who want a certificate rather than having to check your governance themselves, the same way they ask for ISO 27001 or SOC 2 today. If you sell an AI-enabled product or service into those buyers, expect the question. If your team uses Copilot, ChatGPT or similar for everyday work, the standard does not reach you and a certificate would be money spent answering a question nobody has asked.
What we recommend
Our advice is not to certify pre-emptively. Build the record now, because the substance of ISO 42001 is a record any well-run business should have anyway: what AI is in use, who owns each system, what it may be given, what could go wrong, and how often you look again. Keep that record in the standard’s shape and most of the readiness work is done. When a tender asks, answer with the record and a dated roadmap to certification. Certify when a contract depends on it, and get quotes from two accredited certification bodies before you start.
Questions people ask
No. It is a voluntary international standard, adopted here as AS ISO/IEC 42001:2023. No Australian law or regulator requires certification. The obligations that do apply come from existing law such as the Privacy Act and consumer law, and from voluntary government guidance. A customer's contract can require it; the law does not.
Almost certainly not. The standard certifies how an organisation manages the AI it develops, provides or relies on at scale. If your team uses ChatGPT, Copilot or similar for everyday work, what you need is a clear record of what is used, who owns it and what it may be given. That is the substance of ISO 42001 without the audit.
An accredited certification body audits your AI management system in two stages: first your documents, then whether the system operates as written. A certificate lasts three years with a surveillance audit each year. In Australia, look for a body accredited by JAS-ANZ or an equivalent overseas accreditor. As at September 2026 only four certification bodies worldwide hold JAS-ANZ accreditation for this standard, and the companion standard that governs the auditors themselves, ISO/IEC 42006, only arrived in July 2025. The market is young, so get more than one quote.
There are two costs: getting ready, and the audit. Readiness is the larger one for most small businesses, because someone has to write down and run the management system, with or without a consultant. Certification body fees depend on your size and the scope you certify, and they recur with each surveillance audit. Plan in months rather than weeks, and get quotes from two bodies before committing.
Same structure, different subject. ISO 27001 governs information security. ISO 42001 governs how you manage AI: its purposes, risks, data, human oversight and improvement over time. If you already hold ISO 27001, much of the management-system scaffolding carries over, which is why most businesses add 42001 to an existing system rather than start from scratch.
No. It shows the organisation has a system for managing AI responsibly and follows it. It does not test any particular model or product. Buyers read it as evidence of governance, not a guarantee of outcomes, and that is the honest way to present it.