WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

New Zealand has no AI Act, but it does have something most countries lack: a binding code of practice governing how organisations process biometric information. The Biometric Processing Privacy Code came into force in November 2025, and the transition window for processing already underway closed in August 2026.

That matters because biometric processing is where a great deal of commercial AI actually lives. Facial recognition in retail, voice authentication in contact centres, identity verification in onboarding, attendance systems on sites. Auckland businesses running any of these are already inside a regulated space while the broader AI conversation remains guidance.

Nathan ISO Consulting implements AI management systems under ISO/IEC 42001:2023 for Auckland organisations across software and platforms, financial services, health, retail and government supply.

Where New Zealand AI regulation actually stands

There is no AI statute. The Government published an AI strategy in July 2025 signalling a light-touch approach relying on existing law, supported by responsible AI guidance for businesses. Government agencies that signed the Algorithm Charter carry commitments about transparency and human oversight in algorithmic decision-making, and those can reach suppliers through contract. The genuinely binding instrument for many commercial applications is the Biometric Processing Privacy Code, issued under the Privacy Act, which sets rules for collecting and using biometric information. Anyone telling you New Zealand AI legislation is imminent is describing something that has not been proposed.

Why ISO 42001 matters for Auckland organisations

The biometric code creates a hard edge that general AI guidance does not. Where your product or operation processes biometric information, there are rules about proportionality, transparency and alternatives, and the transition period has expired. An organisation that cannot describe how it assessed necessity and proportionality for a facial recognition deployment is exposed now, not at some future point.

Buyer assurance is the commercial driver, and for Auckland it arrives from three directions at once. Domestic enterprise customers, Australian buyers applying their own expectations, and offshore buyers in markets where AI governance questions are further advanced. Answering each separately costs more than the contracts justify.

The third driver is agency supply. Government agencies operating under Algorithm Charter commitments and Privacy Act obligations ask suppliers how algorithmic decisions affecting people are governed. A certified management system gives a supplier an assessed position to answer from rather than drafting a response per tender.

Legal and regulatory compliance in New Zealand

ObligationHow it reaches AIAuckland relevance
Biometric Processing Privacy Code 2025Binding rules on collecting and using biometric information, in force since November 2025 with the transition period now closedRetail facial recognition, voice authentication, identity verification, site attendance systems
Privacy Act 2020 and the IPPsPersonal information used to train, prompt or evaluate a model remains personal informationFinancial services, health, consumer platforms and marketing technology
IPP 3ANotification obligations where personal information is collected indirectly, in force since May 2026Models trained or enriched using data obtained from third parties
Algorithm Charter for Aotearoa New ZealandCommitments by signatory agencies on transparency and human oversight in algorithmic decisionsSuppliers delivering algorithmic services to signatory agencies
Health and Safety at Work Act 2015The primary duty applies where AI informs decisions affecting worker safetyScheduling, fatigue management and operational decision support
Human Rights Act 1993Discriminatory outcomes create exposure regardless of whether a model produced themRecruitment, lending, insurance and service allocation
Fair Trading Act 1986Overstated AI capability claims are misleading representationsAny Auckland business marketing AI features in a product
EU AI ActApplies to organisations placing AI systems on the European marketAuckland software exporters selling into Europe

Auckland business districts and regions

Auckland locationBusiness activityAI governance driver
Auckland CBD and BritomartFinancial services, insurance, corporate head officesAutomated decisioning in lending, claims and onboarding
Newmarket and ParnellTechnology, professional services, retail head officesProduct-embedded models and customer assurance questions
Grafton and health precinctsHospitals, medical research, health technologyClinical decision support and health information governance
Takapuna and Smales FarmCorporate operations, technology, insuranceGroup AI policy alignment and supplier assessments
Albany and the North ShoreSoftware, product engineering, light manufacturingOffshore buyer assurance and export market requirements
Retail networks across AucklandSupermarkets, retail chains, hospitality groupsFacial recognition and biometric processing under the Code
Manukau and WiriLogistics, distribution, workforce-intensive operationsRostering, routing and biometric attendance systems
Government and agency precinctsDepartments, agencies and contracted providersAlgorithm Charter commitments and privacy obligations
Airport precinctAviation services, border-adjacent operations, freightIdentity verification and biometric processing at scale

Biometrics is where most Auckland exposure actually sits

Ask an Auckland leadership team whether the organisation uses AI and the answer usually covers a chatbot and some analytics. Ask whether it processes biometric information and the picture changes, because facial recognition, voice matching and fingerprint access were rarely procured as artificial intelligence.

The Code applies regardless of what the purchase order called it. It sets expectations around whether biometric processing is necessary and proportionate for the purpose, whether less intrusive alternatives were considered, how people are told, and what choices they have. Those are exactly the questions an AI impact assessment answers, which is why the two fit together rather than competing.

We start Auckland engagements by establishing where biometric processing occurs, because that is the part with a live regulatory deadline behind it. General AI governance follows; the biometric question does not wait.

Working with us in Auckland

Design and build

Cataloguing comes before any policy, covering what you build, what you supply and what you merely operate, including biometric processing and analytics embedded in platforms nobody classified as AI. Each system is positioned as developer, provider or deployer, which settles the applicable controls. Then governance structure, impact assessment methodology aligned to both the standard and the biometric code's proportionality expectations, risk criteria covering bias, drift and misuse, human oversight design, and vendor assurance requirements.

Reaching the certificate

AI management assessment is new everywhere and the New Zealand assessor pool is small, so availability rather than readiness is frequently the constraint. We identify bodies with genuine assessment experience, start scheduling early, and complete readiness through internal audit and a recorded review. Both stages attended.

Life after the audit

Cataloguing is repeated on a defined cycle, impact assessments revisited when models are retrained or vendors update platforms, and regulatory developments tracked. Given how recently the biometric code took effect and how quickly guidance is issuing, this is a genuinely active maintenance obligation rather than an annual formality.

What gets delivered

  • System catalogue. Everything you build, buy or run, including biometric processing and embedded analytics that were never procured as artificial intelligence.
  • Biometric processing assessment. Necessity, proportionality, alternatives considered, transparency and choice, documented against the Code's expectations.
  • Position determination. Developer, provider or deployer settled per system, since the binding controls follow from that placement.
  • Impact assessments. Methodology, thresholds and worked assessments for your highest-consequence systems, written to survive close reading.
  • Governance arrangements. Policy, decision rights, accountability and an oversight forum with a real remit rather than a standing agenda item.
  • Vendor assurance requirements. Due diligence for suppliers embedding models in your products or platforms, with enforceable contract terms.

Where Auckland ISO 42001 projects go wrong

  • Biometric processing left outside scope because it was bought as access control or attendance rather than as AI.
  • No record of how necessity and proportionality were assessed, which is the first thing the Code expects you to be able to show.
  • Policy drafted before the catalogue exists, producing governance for systems the organisation does not run.
  • Impact assessments completed as forms with every consequence rated low, which buyers recognise immediately.
  • Australian or European frameworks assumed to apply, when the binding New Zealand instrument is the biometric code.
  • Vendor-supplied models treated as the vendor's accountability, when the outcome remains yours.

Who certifies you, and where we fit

We implement. An accredited body certifies.

Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority established jointly by the New Zealand and Australian governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.

Choosing the accredited body, agreeing what it costs and fixing when it happens are tasks we absorb, weighed against your scope, your sector and the audit style that suits how you work. We sit through Stage 1 and Stage 2 with your team, and clearing whatever is raised falls to us rather than landing on your desk afterwards. One check worth making yourself: confirm on the JAS-ANZ register that the body holds accreditation for your scope. Unaccredited certificates are cheap and fast, and procurement teams decline them often enough to justify the minute it takes.

FAQ'S

No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.

A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.

Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.

No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.

No AI statute exists. The Government published a strategy in July 2025 signalling reliance on existing law, supported by guidance. The binding instrument for many commercial applications is the Biometric Processing Privacy Code, issued under the Privacy Act.

A code of practice issued under the Privacy Act setting rules for collecting and using biometric information. It came into force in November 2025, and the transition period for processing already underway closed in August 2026.

Almost certainly. The Code applies to biometric processing regardless of what the system was called at purchase. Expect to show how necessity and proportionality were assessed, what alternatives were considered, and how people are informed.

A set of commitments signed by New Zealand government agencies covering transparency and human oversight in algorithmic decision-making. It binds signatory agencies rather than private organisations, though it can reach suppliers through contract terms.

No. It certifies that the organisation governs AI responsibly across the lifecycle, covering accountability, risk, impact and oversight. Model performance is a separate technical question, which is why the certificate answers procurement rather than engineering.

It is a genuine consideration in New Zealand data and AI governance, concerning Māori rights and interests in data about Māori people and resources. Where your systems touch that, we recommend engaging appropriate expertise rather than treating it as a documentation exercise.

Yes, and it is the common situation here. As a deployer your focus shifts to vendor due diligence, human oversight, use policies and monitoring outcomes. The project is usually smaller than for an organisation training its own models.

Where one exists that is the efficient route. The clause structures align and governance, audit and review are already running, so the additional build is considerably smaller than starting from nothing.

Fourteen to twenty-two weeks typically. The catalogue and impact assessments consume most elapsed time, particularly where biometric processing has to be identified across sites nobody previously treated as AI deployments.

They overlap on risk management, data governance, transparency and oversight, but the standard carries no formal status under the European legislation. Auckland businesses placing AI systems on that market still face separate conformity obligations.

Start with biometrics

The first question we ask is whether anything in your operation processes biometric information, because that is the part with a regulatory deadline already behind it rather than ahead of it.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance