ISO/IEC 42001, from a team going through it.

What the standard requires, how certification actually works, where organisations fail it, and a readiness checklist you can start on this week. Published in full, because the useful version of this page is the one you can act on without talking to anybody.

ISO/IEC 42001: the AI management system standard, explained for Australian and New Zealand organisations

The short answer

ISO/IEC 42001:2023 is the first international standard for an AI management system, published in December 2023. It is to artificial intelligence what ISO 27001 is to information security: not a technical specification for models, but an auditable structure for how an organisation decides what AI to build or buy, assesses the risk, assigns accountability, monitors what is running, and retires it responsibly. It can be certified by an accredited body, which is what separates it from a framework you can simply claim to follow.

What the standard actually requires

Grouped the way you can act on it rather than clause by clause. Every item below is something an auditor asks to see, and the recurring theme is evidence: almost nothing in ISO 42001 can be satisfied by asserting that you do it.

Scope and policy

A defined boundary for what the management system covers, and a stated AI policy that leadership has actually signed rather than inherited from a template.

An AI inventory

Every AI system in use, listed. This is the clause that catches most organisations out, because the register has to survive questioning and most registers do not.

Risk and impact assessment

AI risk assessed as risk, plus AI system impact assessments covering effects on the people subject to automated decisions. ISO/IEC 23894 supplies the method.

Lifecycle controls

Governance across the whole life of a system: design, development or procurement, deployment, monitoring in production, and responsible decommissioning.

Supplier oversight

Accountability for the third-party AI you buy. Using a vendor does not transfer the obligation, which surprises organisations that assumed the platform carried it.

Competence and evidence

Training records, internal audit, management review, and a trail showing the policies were followed. Almost every clause asks you to show, not to assert.

The inventory clause is where most programmes stall, and it is the same artefact we describe as an agent register. If your organisation has been deploying assistants and automations for a year without a central record, read Agent Sprawl Is the New Shadow IT before you scope anything.

How certification works

Certification runs as a Stage 1 audit, a documentation and readiness review, followed by a Stage 2 audit that assesses whether the management system is genuinely operating rather than merely written. The certificate is valid for three years, with annual surveillance audits in between.

Typical end-to-end timelines run four to nine months, and materially shorter for organisations that already hold ISO 27001, because the management-system scaffolding and much of the evidence carry across. The audits themselves are short. What takes the time is building the system the audits inspect, and accumulating enough operating history that Stage 2 has something real to assess.

Certification is issued only by accredited certification bodies. The firm that helps you prepare cannot be the firm that audits you, so treat any provider offering both with suspicion. We build the management system and the evidence trail; an accredited body certifies it. More on how that engagement runs on our AI governance page.

ISO 42001 against the other names in the tender

Four names come up in nearly every AI procurement question. Only two of them can be certified, and that distinction is usually what the question is really about.

Certifiable

ISO/IEC 42001:2023

The AI management system standard. Accredited bodies audit it and issue a certificate a customer will accept as proof rather than assertion.

Certifiable

ISO/IEC 27001

Information security. Different subject, same management-system architecture, which is why holding it makes 42001 substantially cheaper.

Guidance

ISO/IEC 23894:2023

AI risk management method. Not certifiable alone; normally operated inside a 42001 system to satisfy its risk clauses.

Voluntary

NIST AI RMF

The US framework. Shares most concepts with 42001 and crosswalks to it, frequently named in tenders, cannot be certified.

Readiness checklist

Ten things to do before you call a certification body

Published in full and free to use. Work through these in order and a Stage 1 audit becomes a formality rather than a discovery exercise. The last one is the item that cannot be rushed, which is why it is worth starting today rather than when the tender lands.

01

List every AI system in use

Including the licences bought on a credit card and the agents a team stood up without telling anyone. Expect the list to be longer than leadership believes.

02

Put a named human against each one

Not a team, a person. Someone with the authority to switch it off, not just the job title nearest to it.

03

Write down what each system may touch

Which data, which systems, which actions it is permitted to take, and the actions it is explicitly not permitted to take.

04

Decide your scope before you assess anything

Certifying the whole organisation on the first attempt is the most common way to make the project too big to finish.

05

Run a real risk assessment on the top systems

Bias, explainability, data exposure, inappropriate autonomy, and what happens when the system is confidently wrong in front of a customer.

06

Record approvals at the time, not retrospectively

An approval trail reconstructed the week before Stage 2 reads exactly like an approval trail reconstructed the week before Stage 2.

07

Check what your AI suppliers actually commit to

Read the terms on training, retention and residency. Using a vendor does not move the obligation off your organisation.

08

Give every consequential action a human gate

Anything that spends money, sends externally, or changes a customer record should pass a person before it happens.

09

Make sure something can be stopped

A kill switch that has been tested, and an owner who knows they hold it.

10

Start collecting operating evidence now

Stage 2 assesses whether the system runs, not whether it exists on paper. Evidence needs months of history, which is why this item cannot be left until last.

Items one to three are an inventory, and the free AI Opportunity Audit produces one. Items eight and nine are human-gated approvals and an agent kill switch, which are built into our Agent Management Platform. Item seven is a data residency question, and where the answer rules out the public cloud entirely, private LLM infrastructure is the usual resolution.

Where organisations fail it

Three patterns, and none of them is the technology. An incomplete inventory, so the scope collapses the first time an auditor asks what else is running. No operating evidence, so the policies exist and nothing shows anyone followed them. And nominal accountability, where a name sits against a system but that person has no authority to stop it.

The underlying cause is usually the same one that kills AI programmes generally, which we wrote about in Why 95 Percent of AI Pilots Die: the work is treated as a document to produce rather than a system to operate. For an example of building under real privacy constraints from the start, our medical conversational assistant case study is the closest analogue, and our own trust centre documents how we run this internally.

Frequently asked questions

What is ISO/IEC 42001 in simple terms?

ISO/IEC 42001:2023 is the first international standard for an AI management system, published in December 2023. It is the AI equivalent of what ISO 27001 is for information security: not a technical specification for models, but an auditable structure for how an organisation decides what AI to build or buy, assesses the risk, assigns accountability, monitors what is running, and retires it responsibly. It is certifiable by an accredited body, which is what separates it from a framework you can simply claim to follow.

What does ISO 42001 actually require?

In practice: a defined scope, a stated AI policy, leadership accountability, an inventory of the AI systems in use, risk assessments and AI system impact assessments, controls over the full lifecycle from design through deployment to decommissioning, oversight of third-party AI suppliers, competence and training records, internal audit, and management review. The recurring theme is evidence. Almost every clause asks you to show that something happened, not to assert that it does.

How much does ISO 42001 certification cost?

There are two separate costs and they are often confused. The certification body's audit fee depends on your headcount, the number of sites and the scope you certify, and is quoted per organisation. The larger cost is usually internal: building the management system, running the risk assessments, and producing the evidence before anyone audits it. Organisations that already hold ISO 27001 spend materially less on the second, because the management-system scaffolding is already in place.

How long does ISO 42001 certification take?

Typically four to nine months, and shorter if you already hold ISO 27001. Certification runs as a Stage 1 audit (a documentation and readiness review) followed by a Stage 2 audit (an assessment of whether the system is genuinely operating). The certificate is valid for three years with annual surveillance audits in between. The audits themselves are short. What takes the time is building the management system the audits inspect, and accumulating enough operating evidence that Stage 2 has something to look at.

What is the difference between ISO 42001 and ISO 27001?

ISO 27001 governs information security: keeping data confidential, available and intact. ISO 42001 governs artificial intelligence: how AI systems are selected, developed, deployed and monitored, including risks that have no security equivalent such as bias, explainability, inappropriate autonomy and the societal impact of automated decisions. They share the same management-system structure by design, so they layer neatly. If you hold 27001, a large share of the 42001 groundwork is already done.

Is ISO 42001 the same as the NIST AI Risk Management Framework?

No, though they overlap heavily and published crosswalks map between them. The NIST AI RMF is a voluntary framework that describes good practice and cannot be certified. ISO 42001 is a certifiable management-system standard, so an accredited body can audit you and issue a certificate a customer will accept as proof. ISO/IEC 23894 sits alongside both and provides the detailed AI risk-management process that a 42001 system needs operating inside it. Most mature programmes use all three: 42001 for the structure, 23894 for the risk method, NIST AI RMF for the vocabulary tenders ask for.

Do we actually need ISO 42001, or is good governance enough?

Most organisations need the governance; only some need the certificate. Pursue certification when a customer, a tender or a regulator asks for it, or when you sell AI into enterprises that will audit their suppliers. If nobody is asking yet, build the management system anyway and certify later. The value sits in the register, the risk assessments and the named accountability, and those are what the auditor inspects on the day you decide you do need it.

Can Sentry AI certify us against ISO 42001?

No. Certification is issued only by accredited certification bodies, and the firm that helps you prepare cannot be the firm that audits you. Anyone offering both is offering neither properly. What we build is the thing the audit inspects: the AI management system, the inventory, the risk assessments, the approval trail and the evidence that it is all being followed. Then you engage an accredited body with a real chance of passing Stage 2.

Where do organisations most often fail ISO 42001?

Three places, in our experience and in the pattern of the standard itself. First, an incomplete AI inventory: the register misses the tools bought on a credit card and the agents a team stood up quietly, and the scope collapses under questioning. Second, no operating evidence: the policies exist but nothing shows they were followed, so Stage 2 has nothing to assess. Third, accountability that is nominal, where a name sits against a system but that person has no authority to stop it.

Does ISO 42001 apply if we only use AI, and do not build it?

Yes. The standard covers organisations that develop, provide or use AI systems, and the majority of certifications will be organisations that mostly buy. If your business runs Copilot, Claude, ChatGPT or Gemini across its teams, and has agents acting in production systems, you are in scope for the parts that matter: inventory, risk assessment, supplier oversight and accountability.

Is ISO 42001 required by law in Australia or New Zealand?

No. Neither country mandates it. Australia published a Voluntary AI Safety Standard with ten guardrails and proposed mandatory guardrails for high-risk AI in 2024 which have not been legislated as at mid-2026, though in July 2026 the government announced plans to legislate Australian Standards for AI and established an Office of AI. New Zealand has no AI-specific legislation and relies on existing technology-neutral law, principally the Privacy Act 2020. Certification is currently a commercial advantage rather than a legal obligation, which is precisely why early certificates are worth something.

What is the first thing we should do?

Build the inventory. You cannot scope, risk-assess or certify what has not been listed, and every programme that skips this step reworks it later. Find every AI tool, licence, assistant and agent in use across the business, including the ones nobody told IT about, and put a named owner against each. The gap between what leadership believes is running and what is actually running is usually the finding that gets the programme funded.

Start with the inventory

Items one to three of the checklist are the whole foundation, and the free AI Opportunity Audit produces them. We are underway with our own ISO/IEC 42001 certification, so what you get is the version that has already hit the parts that are harder than they look.