ISO/IEC 42001 Certification: A Guide for Australian Firms
ISO/IEC 42001 is the first certifiable international standard for AI management systems. This guide explains what it requires, how it compares to Australia's Voluntary AI Safety Standard and the EU AI Act, and what to have in place before pursuing certification.

ISO/IEC 42001 is the first international standard for an AI management system (AIMS), published in December 2023 by the joint ISO/IEC technical committee responsible for AI standards. It sets out requirements for establishing, implementing, maintaining, and continually improving a management system that governs how an organisation develops, provides, or uses AI systems responsibly. Certification against it is voluntary and issued by an accredited third-party certification body, in the same way ISO 27001 or ISO 9001 certificates are issued.
Australian organisations building or deploying AI are increasingly asking the same question board audit committees have long asked about information security: is there a recognised standard we can be certified against? For AI governance, ISO/IEC 42001 is that standard. This guide explains what it requires, how it relates to Australia's Voluntary AI Safety Standard and the EU AI Act, and what a growing organisation typically needs in place before pursuing certification.
What is ISO/IEC 42001?

Like ISO 27001 (information security) and ISO 9001 (quality), ISO/IEC 42001 follows the common Annex SL high-level structure shared across ISO management system standards. That means the same clauses on leadership, planning, support, operation, performance evaluation, and improvement apply — which is genuinely useful if your organisation already holds an ISO 27001 or ISO 9001 certificate, because the governance scaffolding is familiar and can be extended rather than rebuilt from scratch.
Is ISO/IEC 42001 mandatory in Australia?
No. ISO/IEC 42001 is a voluntary, certifiable standard — no Australian law currently requires it. Certification is pursued by choice, typically to demonstrate responsible AI governance to customers, regulators, insurers, or partners, or because a tender or supply chain requirement asks for it.
Certification is issued by an accredited third-party certification body following an external audit, in the same way ISO 27001 or ISO 9001 certificates are issued. In Australia and New Zealand, certification bodies are typically accredited by JAS-ANZ (the Joint Accreditation System of Australia and New Zealand), which oversees accreditation for management system certification generally.
How does ISO/IEC 42001 differ from Australia's Voluntary AI Safety Standard?
Australia's Voluntary AI Safety Standard, released by the Department of Industry, Science and Resources, is guidance built around ten voluntary guardrails for organisations designing, developing, or deploying AI — not a certifiable management system. It is self-assessed, not independently audited, and there is no accredited certificate an organisation can obtain against it.
The two are complementary rather than competing. The guardrails in the Voluntary AI Safety Standard map reasonably well onto the risk assessment, impact assessment, and human oversight controls in ISO/IEC 42001's Annex A. An organisation working through the Voluntary AI Safety Standard's guardrails is already doing much of the groundwork ISO/IEC 42001 certification would require — it just isn't being independently audited or certified. The Australian government has also flagged proposals for mandatory guardrails in high-risk AI settings, which would sit above the current voluntary standard. That framework is still evolving and is worth monitoring closely if you operate in a higher-risk sector such as healthtech or financial services.
How does ISO/IEC 42001 differ from the EU AI Act?
The EU AI Act is binding law, not a voluntary standard. It entered into force in 2024 and applies a risk-based framework — unacceptable, high, limited, and minimal risk — with obligations phasing in over several years and legal penalties for non-compliance. It applies to organisations placing AI systems on the EU market or whose AI systems affect people in the EU, which can include Australian companies selling into or operating in Europe.
ISO/IEC 42001 is not a substitute for EU AI Act compliance, but a certified AIMS can support it. Conformity assessment for high-risk AI systems under the EU AI Act increasingly looks for the kind of documented risk management, data governance, and human oversight processes that ISO/IEC 42001 requires, so certification can serve as useful supporting evidence — provided the specific legal obligations of the Act are separately mapped and satisfied.
| ISO/IEC 42001 | Australia's Voluntary AI Safety Standard | EU AI Act | |
|---|---|---|---|
| Nature | International management system standard | Government guidance, ten guardrails | Binding regulation |
| Certifiable | Yes, via accredited certification bodies | No, self-assessed | Not certifiable itself; requires conformity assessment for high-risk systems |
| Legal status in Australia | Voluntary | Voluntary | Not applicable unless operating in/into the EU |
| Focus | Governance, risk management, continual improvement | Practical guardrails for responsible AI use | Risk-tiered legal obligations and penalties |
What does a growing organisation need in place before pursuing certification?
Most growing Australian companies do not need to start an ISO/IEC 42001 project from zero — they need to formalise governance that is often already partly in place informally. The core requirements are an AI system inventory, a documented policy and risk framework, defined roles, and evidence of ongoing monitoring.

In practice, that typically means:
- An inventory of AI systems in use or under development, including which are customer-facing, which use third-party models or APIs, and which process personal or sensitive data.
- A documented AI policy and risk framework that sets out how AI risks are identified, assessed, and treated, aligned to the AIMS clauses on planning and risk management.
- Defined roles and accountability for AI governance — who approves new AI use cases, who monitors performance and drift, and who is accountable when something goes wrong.
- Evidence of ongoing monitoring and review, not a one-off assessment. Auditors look for a functioning management system, not a policy document sitting unused in a shared drive.
- Data governance practices that cover data quality, provenance, and lifecycle management for the data used to train, fine-tune, or ground AI systems.
For organisations without a dedicated AI or data governance function, this is often the hardest part — not because the requirements are exotic, but because nobody currently owns the problem end to end. That's a gap we see often when we run ai product strategy engagements: the AI systems exist, the risk awareness exists, but the documented management system connecting them doesn't yet.
A sensible starting point is a gap assessment against the ISO/IEC 42001 clauses and Annex A controls, mapped against whatever you're already doing under the Voluntary AI Safety Standard or existing ISO 27001 controls. That tells you realistically how much work certification requires, rather than guessing from the standard's text alone.
Where this intersects with modernisation and engineering work
Certification readiness isn't purely a policy exercise. Auditors expect to see that risk controls are actually implemented in the systems doing the work — model versioning, logging, human-in-the-loop review points, and rollback mechanisms for AI features in production. That's engineering work as much as governance work, and it's where ai engineering and application modernisation intersect with compliance: a legacy platform with no observability or clear data lineage will struggle to produce the evidence an auditor asks for, regardless of how good the policy documents look.
If you're weighing up whether ISO/IEC 42001 certification is the right next step, or whether a lighter-touch alignment with the Voluntary AI Safety Standard is more proportionate for where you are today, that's a conversation worth having before committing budget to a formal audit. You can browse more insights on AI governance and adoption, or get in touch to talk through what a gap assessment would look like for your organisation.
Chris Kerr
Partner at Horizon Labs, an AI product consultancy and venture studio. A commercially focused product and technology leader with 20+ years building and scaling digital platforms, teams, and businesses across SaaS, travel, eCommerce, logistics and transport, and digital marketing — operating at the intersection of product, engineering, and data. Writes about platform strategy, AI transformation, modern data ecosystems, and the operational discipline that separates AI demos from AI products.


