Can you say what AI is running in your business?

Most organisations cannot. Teams deploy assistants and agents faster than anyone catalogues them, and the first real inventory always finds more than leadership expected. We build the register, the risk assessments and the evidence trail that AI governance and ISO/IEC 42001 actually require.

AI governance: a register of every AI system and agent running in the business

Governance is four things, not a principles document

The category produces a great deal of writing about responsible AI and very few organisations that can answer a simple question about what is deployed. These are the four artefacts an auditor, a regulator or a board actually asks to see.

A register

Every AI tool, licence, assistant and agent in use, listed, with a named human accountable for each. You cannot govern, risk-assess or certify what nobody has written down.

A decision trail

How each system was approved, what data it may touch, and what it is not allowed to do. Approvals recorded at the time, not reconstructed the week before an audit.

Monitoring

What the systems actually do once they are live, rather than what the deployment document said they would do. Drift is normal; not noticing it is the failure.

A way to stop it

A kill switch, an owner who can use it, and a rehearsed answer for when an agent gets something materially wrong in front of a customer.

Agent sprawl is shadow IT, moving faster

Shadow IT took a decade to become a board issue. Agent sprawl takes about a year. Individual teams stand up automations that read customer records, send email on the company's behalf and take actions in production systems, and nothing central records that any of it exists.

The organisations that handle this well are not the ones with the strictest policy. They are the ones that made registering an agent easier than not registering it, and put the register somewhere the business can actually see. That is the problem our Agent Management Platform exists to solve, and it is the same artefact ISO/IEC 42001 asks you to produce.

The standards, and which ones can actually be certified

Four names come up in almost every tender. Only one of them is a certification, which matters when a customer asks you to prove something rather than assert it.

Certifiable

ISO/IEC 42001:2023

The first international standard for an AI management system, published December 2023. Risk management, impact assessment, lifecycle governance from design to decommissioning, and supplier oversight. Stage 1 and Stage 2 audit, valid three years, annual surveillance in between.

Guidance

ISO/IEC 23894:2023

AI risk management guidance. Not certifiable on its own, and normally used to inform the risk process that sits inside a 42001 management system.

Voluntary

NIST AI RMF

The US risk management framework. Shares most of its underlying concepts with ISO 42001, and published crosswalks map between them. Widely asked for in tenders, cannot be certified.

Voluntary

Voluntary AI Safety Standard (AU)

Australia's ten guardrails. Mandatory guardrails for high-risk AI were proposed in 2024 and have not been legislated as at mid-2026, though the government announced plans in July 2026 to legislate Australian Standards for AI and stood up an Office of AI.

New Zealand has no AI-specific legislation and has chosen a light touch, risk-based approach that relies on existing law, principally the Privacy Act 2020. That is not an absence of obligation, and any organisation selling into Australia or Europe inherits those regimes regardless of where it is based.

We are not a certification body

Certification is issued by accredited bodies, and the firm that helps you prepare cannot be the firm that audits you. Anyone offering both is offering neither properly.

What we build is the thing the audit inspects: the AI management system, the register, the risk assessments, the approval trail and the evidence that any of it is being followed. Certification typically runs four to nine months, and materially faster if you already hold ISO 27001, because the management-system scaffolding carries across.

We are underway with our own ISO/IEC 42001 certification, so the guidance comes from building the management system rather than from reading the standard. You get the version that has already hit the parts that are harder than they look.

Frequently asked questions

What is AI governance?

AI governance is knowing what AI is running in your business, who approved it, what data it touches, and what happens when it gets something wrong. In practice it comes down to four things: a register of every AI system and agent in use, a decision trail for how each was approved, monitoring of what they actually do, and a named human accountable for each one. Most organisations have none of these, which is why nobody can answer the board when it asks what is deployed.

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the first international standard for an AI management system, published in December 2023. It gives an organisation an auditable structure for how it develops, provides and uses AI: risk management, impact assessment, lifecycle management from design through to decommissioning, and oversight of third-party suppliers. It is certifiable, which is what separates it from a framework you can simply say you follow.

How long does ISO 42001 certification take?

Typically four to nine months, and materially shorter if you already hold ISO 27001, because the management-system scaffolding and much of the evidence carry across. Certification runs as a Stage 1 and Stage 2 audit, the certificate is valid for three years, and there are annual surveillance audits in between. The work that takes the time is not the audit, it is building the management system the audit inspects.

What is the difference between ISO 42001 and ISO 27001?

ISO 27001 governs information security: protecting data. ISO 42001 governs artificial intelligence: how AI systems are chosen, built, deployed and monitored, including risks that have no security equivalent such as bias, explainability and inappropriate autonomy. They are designed to sit together, and organisations that hold 27001 have already done a large share of the groundwork for 42001.

How does the NIST AI Risk Management Framework relate to ISO 42001?

They overlap heavily and are not alternatives. The NIST AI RMF is a voluntary framework that shares most of its underlying concepts with ISO 42001, and published crosswalks map one to the other. The practical difference is that ISO 42001 can be certified by an accredited body and NIST AI RMF cannot. ISO/IEC 23894 sits alongside both, giving the detailed AI risk-management process that a 42001 management system needs inside it.

Is AI regulated in Australia?

Not yet by dedicated legislation. Australia published a Voluntary AI Safety Standard with ten guardrails, and proposed mandatory guardrails for high-risk AI in 2024 which have not been legislated as at mid-2026. In July 2026 the government announced plans to legislate Australian Standards for AI and established an Office of AI within the Department of the Prime Minister and Cabinet. Existing law still applies in full: privacy, consumer protection, anti-discrimination and sector rules do not pause because a decision was made by a model.

Is AI regulated in New Zealand?

New Zealand has no AI-specific legislation and has deliberately chosen a light-touch, risk-based approach that relies on existing technology-neutral law. The Privacy Act 2020 does most of the work, alongside consumer, intellectual property and human rights law. The absence of a dedicated AI act is not an absence of obligation, and organisations selling into Australia or Europe inherit those regimes regardless of where they are based.

Do we need ISO 42001 certification, or just good governance?

Most organisations need the governance and only some need the certificate. The certificate is worth pursuing when a customer, a tender or a regulator asks for it, or when you sell AI into enterprises that will audit you. If nobody is asking, build the management system anyway and certify later: the value is in the register, the risk assessments and the accountability, and those are what an auditor inspects when the day comes.

Can Sentry AI certify us against ISO 42001?

No, and be careful with anyone who says they can. Certification is issued by accredited certification bodies, and the firm that helps you prepare cannot be the firm that audits you. What we do is build the management system, the AI register and the evidence trail that the audit inspects, and get you to the point where an accredited body is worth engaging. We are underway with our own ISO 42001 certification, so the guidance comes from building the management system rather than reading about it.

What is agent sprawl, and why does it matter for governance?

Agent sprawl is what happens when individual teams start deploying AI agents without a central record. Within a year the organisation is running dozens of automations nobody catalogued, several touching customer data, most with no named owner and no off switch. It is the same pattern as shadow IT, moving considerably faster. Governance is what turns that into a register with owners, permissions and a kill switch, and it is far cheaper to do before the audit than during it.

Where should an organisation start with AI governance?

With an inventory, always. You cannot govern, risk-assess or certify what you have not listed. The first useful piece of work is finding every AI tool, licence, assistant and agent in use across the business, including the ones bought on a credit card, and putting a name against each. Almost every organisation that does this finds more than it expected, and the gap between what leadership thinks is running and what is actually running is the finding that starts the programme.

Start with the inventory

Every governance programme starts the same way: finding out what is actually running. The AI Opportunity Audit does that for free, and the gap between what leadership thinks is deployed and what is deployed is usually the finding that starts the work.