Demand for AI governance in New Zealand is not coming from a regulator. It is coming from the person who sends you a security questionnaire.
Somewhere in the last year, that questionnaire grew an AI section. How do you govern AI use across your business? What controls apply to the models in your product? Who is accountable when the output is wrong, and how would you know? Those questions are now standard in enterprise vendor reviews and government procurement, and they are difficult to answer convincingly with a policy document and good intentions.
ISO/IEC 42001:2023 is the first certifiable AI management system standard. Nathan ISO Consulting builds AI management systems for New Zealand organisations that develop AI, embed it in products, or use it heavily enough that governance has become a commercial question.
Where New Zealand AI Rules Actually Stand
New Zealand has no AI Act and no announced plan for one. The Government released its first national AI Strategy, Investing with Confidence, in July 2025, alongside Responsible AI Guidance for Businesses. Both confirm a light-touch, principles-based approach that relies on existing technology-neutral law rather than new AI-specific legislation. For the public sector, the Algorithm Charter for Aotearoa New Zealand sets voluntary transparency and accountability commitments, supported by Government Chief Data Steward guidance.
This does not mean AI is unregulated in New Zealand. It means your obligations arrive through laws that were already on the books.
The honest consequence is that ISO 42001 in New Zealand is a commercial and risk decision rather than a compliance obligation. That is a better reason to do it, and considerably more defensible than implying a regulator is about to arrive.
Looking for an ISO 42001 Consultant in New Zealand?
What ISO 42001 Certifies, and What It Does Not
| It Certifies | It Does Not Certify |
|---|---|
| That you have a management system governing AI across its lifecycle | That any particular model is accurate, safe or unbiased |
| That leadership is accountable and roles are defined | That your AI outputs are correct |
| That AI-specific risks are identified, assessed and treated | The technical performance of an algorithm |
| That impact on individuals and society is assessed before deployment | Compliance with any specific AI law |
| That systems are monitored after they go live | The conduct of third-party AI vendors you use |
It is a governance certification, not a product certification. That is exactly what makes it answerable in a procurement questionnaire, because the buyer is asking how you run the thing rather than how the model scores on a benchmark.
Three Positions, Three Different Projects
| If You Are a… | Your Focus | Typical New Zealand Example |
|---|---|---|
| Developer | Training data governance, model documentation, evaluation and testing, bias assessment, release controls | A company training or fine-tuning its own models |
| Provider | Lifecycle controls over what you supply, transparency to customers, incident handling, downstream guidance | SaaS platforms with AI features in the product |
| Deployer or user | Vendor due diligence, human oversight, use policies, outcome monitoring, control of unapproved tools | Any organisation using third party AI across its operations |
The Privacy Intersection Is Where New Zealand Differs
Most international AI governance material treats privacy as one control area among many. In New Zealand it is the sharpest edge, because two specific obligations landed in 2026 and both bite directly on common AI practice.
IPP3A means that if your AI system is fed personal information obtained from data brokers, enrichment services or scraped public sources, notification obligations now attach. Many organisations have no inventory of where their training or inference data came from, which makes that obligation unanswerable rather than merely inconvenient.
The Biometric Processing Privacy Code means that any facial recognition or voice identification capability, whether you built it or bought it, needs a documented proportionality assessment. Necessary, effective and proportionate, assessed before deployment. A vendor telling you their product is compliant does not discharge your obligation as the organisation collecting the data.
We build the AI inventory and the personal information inventory together for exactly this reason. Doing them separately produces two partial pictures.
Using facial recognition or third party AI tools?
Shadow AI Is the Exposure Nobody Has Scoped
Ask a room of employees whether they use AI at work and you will hear one answer. Look at what is actually happening and you will find another. Staff paste client information into consumer chatbots, run drafts through translation tools, and use AI features embedded in software the organisation never assessed for that purpose.
Banning it does not work. Every organisation that has tried has discovered the usage moved somewhere it could not see. An AI management system gives you a defensible position instead: an inventory of approved tools, a route for staff to request new ones, use policies reflecting what people actually need to do, and monitoring that tells you when the picture changes.
How Nathan ISO Consulting Assists
| Service | What We Deliver |
|---|---|
| AI inventory | Every AI system you develop, supply or use, including embedded features and the tools nobody registered |
| Role mapping | Where you sit as developer, provider or deployer for each system, since that determines which controls apply |
| Gap assessment | Against ISO/IEC 42001:2023 and its 38 Annex A controls, plus alignment to current New Zealand guidance |
| AI governance framework | AI policy, accountability structure, decision rights, and a governance forum that will actually meet |
| AI impact assessment | Methodology, templates and thresholds, plus completed assessments for your highest-risk systems |
| Privacy integration | IPP3A data provenance work and biometric proportionality assessments built alongside the AI inventory rather than after it |
| AI risk management | Criteria covering bias, transparency, data quality, security, drift and misuse, integrated with your existing risk framework |
| Human oversight design | Where a human must be in the loop, what they can genuinely override, and how that is evidenced |
| Shadow AI control | Approved tool register, request pathway, acceptable use policy, and monitoring that reflects real workplace behaviour |
| Third party AI assurance | Vendor due diligence process and contractual terms that make it enforceable |
| Internal audit and certification | Full internal audit, management review, certification body selection, and attendance at Stage 1 and Stage 2 |
Why Organisations Choose Nathan
Where We Work
Auckland accounts for most of our New Zealand AI governance work, across SaaS and platform businesses, fintech, health technology and professional services deploying AI internally. Wellington work is weighted toward government agencies working within the Algorithm Charter and toward suppliers facing AI assurance questions in public sector procurement.
Christchurch work spans technology, aerospace and agritech. We also work with organisations in Hamilton, Tauranga, Dunedin, Palmerston North and Nelson. AI governance runs almost entirely remotely, so location rarely affects the project or the timeline.
Preparing for an upcoming audit?
Start With the Inventory
The first question we will ask is what AI your organisation actually uses, including the things nobody has written down. If you can answer that, everything after it moves quickly.
Ready to start your ISO 42001 certification journey?
FAQ'S
No. New Zealand has no AI Act and none has been announced. The Government's AI Strategy, released in July 2025, confirms a light-touch, principles-based approach relying on existing technology-neutral legislation such as the Privacy Act, Fair Trading Act and Human Rights Act.
A voluntary commitment signed by government agencies to use algorithms transparently and accountably, covering explanation of decisions, data quality, human oversight and the ability to challenge outcomes. It applies to signatory public sector agencies rather than to private businesses.
No. Certification is voluntary. Demand is driven by enterprise procurement, government tenders and vendor security reviews rather than regulation. Organisations pursue it because customers ask how AI is governed and a certificate answers in one line.
No. It certifies that your organisation has a management system governing AI responsibly across the lifecycle. It assesses governance, accountability, risk and oversight, not the technical accuracy or fairness of any individual model.
Personal information used to train, prompt or evaluate a model remains personal information under the Act. IPP3A, effective from May 2026, adds notification obligations where that information was collected indirectly, which reaches scraped and third party sourced training data.
The Biometric Processing Privacy Code 2025, which requires a documented assessment that collection is necessary, effective and proportionate, plus disclosure of purpose, alternatives, recipients and retention. The grace period for systems already in use ended in August 2026.
Yes, and this is the most common situation. As a deployer your focus shifts to vendor due diligence, human oversight, use policies, outcome monitoring and controlling unapproved tools. The project is usually smaller than for a developer.
They overlap around risk management, data governance, transparency and human oversight, but ISO 42001 is not a harmonised standard under the Act. If you place AI systems on the European market, certification helps but does not discharge conformity assessment obligations.
Yes, and you should if you hold ISO 27001. Both follow the same high-level structure and share governance, risk methodology, internal audit and management review. Adding an AIMS to an existing ISMS is a much smaller project than building either alone.
Annex A contains 38 controls across nine categories, covering AI policy, internal organisation, resources, impact assessment, lifecycle management, data for AI systems, information for interested parties, use of AI systems, and third party relationships.
Typically 14 to 22 weeks. The AI inventory and impact assessments take the most elapsed time, particularly where AI use has spread informally and nobody has a complete picture of what is actually in use across the organisation.
All regions. Our AI governance clients concentrate in Auckland, Wellington and Christchurch, with work also in Hamilton, Tauranga, Dunedin and Palmerston North. Delivery is largely remote, so location rarely affects the project.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving