WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Demand for AI governance in New Zealand is not coming from a regulator. It is coming from the person who sends you a security questionnaire.

Somewhere in the last year, that questionnaire grew an AI section. How do you govern AI use across your business? What controls apply to the models in your product? Who is accountable when the output is wrong, and how would you know? Those questions are now standard in enterprise vendor reviews and government procurement, and they are difficult to answer convincingly with a policy document and good intentions.

ISO/IEC 42001:2023 is the first certifiable AI management system standard. Nathan ISO Consulting builds AI management systems for New Zealand organisations that develop AI, embed it in products, or use it heavily enough that governance has become a commercial question.

Where New Zealand AI Rules Actually Stand

New Zealand has no AI Act and no announced plan for one. The Government released its first national AI Strategy, Investing with Confidence, in July 2025, alongside Responsible AI Guidance for Businesses. Both confirm a light-touch, principles-based approach that relies on existing technology-neutral law rather than new AI-specific legislation. For the public sector, the Algorithm Charter for Aotearoa New Zealand sets voluntary transparency and accountability commitments, supported by Government Chief Data Steward guidance.

This does not mean AI is unregulated in New Zealand. It means your obligations arrive through laws that were already on the books.

  • Privacy Act 2020. Personal information used to train, prompt or evaluate a model is still personal information. IPP3A, in force since May 2026, requires notification where personal information is collected indirectly, which reaches scraped and third party training data.
  • Biometric Processing Privacy Code 2025. Facial recognition and voiceprint systems now carry a proportionality requirement and a specific rulebook, with the transitional grace period for existing systems having ended in August 2026.
  • Fair Trading Act 1986. Misleading representations about what an AI product does are misleading representations. The prohibition does not care that a model produced the claim.
  • Human Rights Act 1993. A model producing discriminatory outcomes in employment, credit or service provision creates exposure under law that predates the model by three decades.
  • Health and Safety at Work Act 2015. Where AI informs operational decisions affecting worker safety, the primary duty applies as it always has.
  • The EU AI Act, for exporters. New Zealand organisations placing AI systems on the European market face conformity assessment obligations there regardless of the position at home.

The honest consequence is that ISO 42001 in New Zealand is a commercial and risk decision rather than a compliance obligation. That is a better reason to do it, and considerably more defensible than implying a regulator is about to arrive.

Looking for an ISO 42001 Consultant in New Zealand?

What ISO 42001 Certifies, and What It Does Not

It CertifiesIt Does Not Certify
That you have a management system governing AI across its lifecycleThat any particular model is accurate, safe or unbiased
That leadership is accountable and roles are definedThat your AI outputs are correct
That AI-specific risks are identified, assessed and treatedThe technical performance of an algorithm
That impact on individuals and society is assessed before deploymentCompliance with any specific AI law
That systems are monitored after they go liveThe conduct of third-party AI vendors you use

It is a governance certification, not a product certification. That is exactly what makes it answerable in a procurement questionnaire, because the buyer is asking how you run the thing rather than how the model scores on a benchmark.

Three Positions, Three Different Projects

If You Are a…Your FocusTypical New Zealand Example
DeveloperTraining data governance, model documentation, evaluation and testing, bias assessment, release controlsA company training or fine-tuning its own models
ProviderLifecycle controls over what you supply, transparency to customers, incident handling, downstream guidanceSaaS platforms with AI features in the product
Deployer or userVendor due diligence, human oversight, use policies, outcome monitoring, control of unapproved toolsAny organisation using third party AI across its operations

The Privacy Intersection Is Where New Zealand Differs

Most international AI governance material treats privacy as one control area among many. In New Zealand it is the sharpest edge, because two specific obligations landed in 2026 and both bite directly on common AI practice.

IPP3A means that if your AI system is fed personal information obtained from data brokers, enrichment services or scraped public sources, notification obligations now attach. Many organisations have no inventory of where their training or inference data came from, which makes that obligation unanswerable rather than merely inconvenient.

The Biometric Processing Privacy Code means that any facial recognition or voice identification capability, whether you built it or bought it, needs a documented proportionality assessment. Necessary, effective and proportionate, assessed before deployment. A vendor telling you their product is compliant does not discharge your obligation as the organisation collecting the data.

We build the AI inventory and the personal information inventory together for exactly this reason. Doing them separately produces two partial pictures.

Using facial recognition or third party AI tools?

Shadow AI Is the Exposure Nobody Has Scoped

Ask a room of employees whether they use AI at work and you will hear one answer. Look at what is actually happening and you will find another. Staff paste client information into consumer chatbots, run drafts through translation tools, and use AI features embedded in software the organisation never assessed for that purpose.

Banning it does not work. Every organisation that has tried has discovered the usage moved somewhere it could not see. An AI management system gives you a defensible position instead: an inventory of approved tools, a route for staff to request new ones, use policies reflecting what people actually need to do, and monitoring that tells you when the picture changes.

How Nathan ISO Consulting Assists

ServiceWhat We Deliver
AI inventoryEvery AI system you develop, supply or use, including embedded features and the tools nobody registered
Role mappingWhere you sit as developer, provider or deployer for each system, since that determines which controls apply
Gap assessmentAgainst ISO/IEC 42001:2023 and its 38 Annex A controls, plus alignment to current New Zealand guidance
AI governance frameworkAI policy, accountability structure, decision rights, and a governance forum that will actually meet
AI impact assessmentMethodology, templates and thresholds, plus completed assessments for your highest-risk systems
Privacy integrationIPP3A data provenance work and biometric proportionality assessments built alongside the AI inventory rather than after it
AI risk managementCriteria covering bias, transparency, data quality, security, drift and misuse, integrated with your existing risk framework
Human oversight designWhere a human must be in the loop, what they can genuinely override, and how that is evidenced
Shadow AI controlApproved tool register, request pathway, acceptable use policy, and monitoring that reflects real workplace behaviour
Third party AI assuranceVendor due diligence process and contractual terms that make it enforceable
Internal audit and certificationFull internal audit, management review, certification body selection, and attendance at Stage 1 and Stage 2

Why Organisations Choose Nathan

  • We tell you the truth about New Zealand AI regulation. There is no AI Act and none announced. The procurement case is strong enough without inventing a regulatory one.
  • We build the AI inventory and the privacy inventory together. IPP3A and the Biometric Code make data provenance an AI governance problem here, not a separate privacy workstream.
  • We start with an inventory, not a policy. An AI policy written before anyone has listed what AI the organisation uses is a document about an imagined company.
  • We integrate rather than duplicate. If you hold ISO 27001, most of the governance, risk and audit machinery already exists. We extend it.
  • We treat shadow AI as in scope. The tools staff use without permission are the ones creating exposure, and most AIMS projects quietly ignore them.
  • We handle the EU AI Act question honestly. If you sell into Europe, ISO 42001 helps but does not discharge conformity assessment obligations there. We will show you where the gap sits.

Where We Work

Auckland accounts for most of our New Zealand AI governance work, across SaaS and platform businesses, fintech, health technology and professional services deploying AI internally. Wellington work is weighted toward government agencies working within the Algorithm Charter and toward suppliers facing AI assurance questions in public sector procurement.

Christchurch work spans technology, aerospace and agritech. We also work with organisations in Hamilton, Tauranga, Dunedin, Palmerston North and Nelson. AI governance runs almost entirely remotely, so location rarely affects the project or the timeline.

Preparing for an upcoming audit?

Start With the Inventory

The first question we will ask is what AI your organisation actually uses, including the things nobody has written down. If you can answer that, everything after it moves quickly.

Ready to start your ISO 42001 certification journey?

FAQ'S

No. New Zealand has no AI Act and none has been announced. The Government's AI Strategy, released in July 2025, confirms a light-touch, principles-based approach relying on existing technology-neutral legislation such as the Privacy Act, Fair Trading Act and Human Rights Act.

A voluntary commitment signed by government agencies to use algorithms transparently and accountably, covering explanation of decisions, data quality, human oversight and the ability to challenge outcomes. It applies to signatory public sector agencies rather than to private businesses.

No. Certification is voluntary. Demand is driven by enterprise procurement, government tenders and vendor security reviews rather than regulation. Organisations pursue it because customers ask how AI is governed and a certificate answers in one line.

No. It certifies that your organisation has a management system governing AI responsibly across the lifecycle. It assesses governance, accountability, risk and oversight, not the technical accuracy or fairness of any individual model.

Personal information used to train, prompt or evaluate a model remains personal information under the Act. IPP3A, effective from May 2026, adds notification obligations where that information was collected indirectly, which reaches scraped and third party sourced training data.

The Biometric Processing Privacy Code 2025, which requires a documented assessment that collection is necessary, effective and proportionate, plus disclosure of purpose, alternatives, recipients and retention. The grace period for systems already in use ended in August 2026.

Yes, and this is the most common situation. As a deployer your focus shifts to vendor due diligence, human oversight, use policies, outcome monitoring and controlling unapproved tools. The project is usually smaller than for a developer.

They overlap around risk management, data governance, transparency and human oversight, but ISO 42001 is not a harmonised standard under the Act. If you place AI systems on the European market, certification helps but does not discharge conformity assessment obligations.

Yes, and you should if you hold ISO 27001. Both follow the same high-level structure and share governance, risk methodology, internal audit and management review. Adding an AIMS to an existing ISMS is a much smaller project than building either alone.

Annex A contains 38 controls across nine categories, covering AI policy, internal organisation, resources, impact assessment, lifecycle management, data for AI systems, information for interested parties, use of AI systems, and third party relationships.

Typically 14 to 22 weeks. The AI inventory and impact assessments take the most elapsed time, particularly where AI use has spread informally and nobody has a complete picture of what is actually in use across the organisation.

All regions. Our AI governance clients concentrate in Auckland, Wellington and Christchurch, with work also in Hamilton, Tauranga, Dunedin and Palmerston North. Delivery is largely remote, so location rarely affects the project.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance