Framework

ISO/IEC 42001:2023

The world's first certifiable AI management system standard, adopted in Australia as AS ISO/IEC 42001:2023. The baseline for governance maturity and a bridge to EU AI Act compliance.

What it is

ISO/IEC 42001:2023 is the world's first certifiable AI management system standard. Published by the International Organization for Standardization in December 2023, it was adopted by Standards Australia as AS ISO/IEC 42001:2023 (an identical adoption with no local deviations) in February 2024. The standard provides a structured approach for organisations to establish, implement, maintain and continually improve an AI management system.

How it's structured

ISO 42001 follows the ISO harmonised high-level structure used by ISO 27001 (information security), ISO 27701 (privacy), and ISO 9001 (quality management). This means an organisation that already has one of those standards in place has a head start on 42001. The management system structure is the same, only the domain-specific controls change. The standard covers:

  • Context of the organisation: understanding internal and external issues that affect AI management
  • Leadership: top management accountability, AI policy, roles and responsibilities
  • Planning: AI risks and opportunities, objectives, change management
  • Support: resources, competence, awareness, documentation
  • Operation: operational planning and control, including the Annex A mandatory controls
  • Performance evaluation: monitoring, measurement, internal audit, management review
  • Improvement: nonconformity, corrective action, continual improvement

Annex A

The substantive AI-specific content sits in Annex A, which contains mandatory controls. Among them:

  • Policies related to AI, including AI use and AI resources
  • Roles and responsibilities for the AI management system
  • Impact assessment of AI systems on individuals and groups
  • Data quality management for AI training and operation
  • System lifecycle management: design, development, verification, deployment, operation, decommissioning
  • Human oversight of AI systems
  • Transparency and explainability
  • Third-party and customer responsibilities

Certification

ISO 42001 is certifiable, meaning an accredited certification body can audit an organisation's AI management system against the standard and issue a certificate. KPMG Australia was the first organisation in the world to achieve 42001 certification, from BSI, in October 2024. Several certification bodies are active in Australia including DNV, Intertek SAI Global, and Certifi International. Certification carries no legal mandate in Australia, but it's increasingly referenced in government procurement, the Voluntary AI Safety Standard, and industry guidance as a credible signal of governance maturity.

Why it matters for Australian organisations

There are two reasons. First, as a baseline for governance maturity. ISO 42001 is the most complete structured description of what "AI governance" means as an operational function, and organisations building programs from scratch benefit from starting with the structure even if they don't pursue certification. Second, as a bridge to international compliance. Australian organisations with European operations face the EU AI Act, which places obligations on high-risk AI systems from August 2026. ISO 42001 certification doesn't satisfy EU AI Act compliance automatically, but it provides independently audited evidence of governance processes that are directly relevant to EU requirements and is treated by EU regulators as a credible input.

Common misreadings

"ISO 42001 is just documentation." All ISO management system standards require documentation, but the standard is fundamentally about operational practice, not paperwork. Auditors test whether the documented processes are actually being followed.

"We have ISO 27001, so we're basically done." The management system structure overlaps, which saves work, but the AI-specific controls in Annex A do not overlap, so you still need to do the AI-specific implementation work.

"It's too heavy for us." ISO management system standards scale with the size and complexity of the organisation. A small organisation can implement 42001 at a proportionate level. The standard doesn't prescribe the depth of each control. It prescribes that the control exists and is effective.

How Aicura supports work against it

Aicura uses ISO/IEC 42001 as a guidance source when reviewing AI Risk Assessment Policies. When you upload your organisation's risk assessment policy for review, the rules Aicura scans it against are extracted from the standard alongside Australian guidance sources. The product doesn't certify you to the standard (that's the job of an accredited certification body) but it does use the standard's vocabulary and structure as part of the baseline for that policy type.


A note on this page

This is Aicura's reading of the framework, written to help you understand what the product is wired into. It is not legal advice and it is not the framework itself. Read the primary source. Where Aicura's interpretation differs from yours or from your advisors', go with theirs.

For a more complete picture of what Aicura does and doesn't do for any framework, see the boundaries page.

Get started with Aicura.

Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.