WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

The demand for ISO 42001 in Australia is not coming from regulators. It is coming from procurement.

Somewhere in your last few enterprise deals, a security questionnaire grew an AI section. How do you govern AI use? What controls apply to the models in your product? Who is accountable when the output is wrong? These questions are now standard in vendor reviews and government tenders, and they are difficult to answer convincingly with a policy document and good intentions.

ISO/IEC 42001:2023 is the world's first certifiable AI management system standard, adopted in Australia as AS ISO/IEC 42001:2023. Nathan ISO Consulting builds AI management systems for Australian organisations that develop AI, embed it in products, or simply use it heavily enough that governance has become a commercial question.

What ISO 42001 certifies, and what it does not

This distinction is worth being clear about early, because it is the source of most confusion in the market.

ISO 42001 certifiesISO 42001 does not certify
That you have a management system for governing AI across its lifecycleThat any particular model is accurate, safe or unbiased
That leadership is accountable and roles are definedThat your AI outputs are correct
That AI-specific risks are identified, assessed and treatedThe technical performance of an algorithm
That impact on individuals and society is assessed before deploymentCompliance with any specific AI law
That AI systems are monitored after they go liveThe conduct of third-party AI vendors you use

It is a governance certification, not a product certification. That is precisely what makes it answerable in a procurement questionnaire, because the buyer is asking how you run the thing, not whether your model scores well on a benchmark.

Where Australian AI rules actually stand

A lot of AI governance content written for the Australian market is out of date, and it is out of date in a specific and misleading direction. It tells readers to prepare for mandatory AI guardrails. Those were proposed and never legislated.

The current position, stated plainlyThere is no Australian AI Act. The mandatory guardrails proposed in September 2024 for AI in high-risk settings were not enacted. In October 2025 the Department of Industry, Science and Resources published Guidance for AI Adoption, setting out six essential practices and evolving the earlier Voluntary AI Safety Standard and its ten guardrails. Australia governs AI through existing technology-neutral law and sector regulators, supported by voluntary guidance and the Australian AI Safety Institute.

That does not mean AI is unregulated in Australia. It means your obligations arrive through laws that were already there.

Privacy Act 1988 and the Australian Privacy Principles. Personal information used to train, prompt or evaluate AI is still personal information. Automated decision-making transparency obligations come out of their grace period on 10 December 2026.

Australian Consumer Law. Misleading representations about what an AI product does are misleading representations, and the same prohibitions apply.

Anti-discrimination legislation. A model that produces discriminatory outcomes in employment, credit or service provision creates exposure under existing federal and state law.

Work health and safety duties. Where AI is used in operational decisions affecting worker safety, the primary duty applies as it always has.

Sector-specific regulation. APRA, ASIC, the TGA and others apply existing frameworks to AI-driven activity within their remit rather than waiting for new AI-specific law.

The EU AI Act, for exporters. Australian organisations placing AI systems on the European market face conformity assessment obligations there, with substantial penalties, regardless of the position at home.

The practical consequence is that ISO 42001 in Australia is a commercial and risk decision rather than a compliance obligation. That is a better reason to do it, and a considerably more honest one than implying a regulator is about to knock.

Three roles, three different projects

The standard applies across the AI supply chain, and where you sit in it changes the work substantially. Most organisations occupy more than one of these positions and have never mapped which is which.

If you are a...Your AIMS focusTypical Australian example
AI developerTraining data governance, model documentation, evaluation and testing, bias assessment, release controlsA company training or fine-tuning its own models
AI providerLifecycle controls over the systems you supply, transparency to customers, incident handling, downstream guidanceSaaS platforms with AI features embedded in the product
AI deployer or userProcurement due diligence on AI vendors, human oversight, use policies, monitoring outcomes, shadow AI controlAny organisation using third-party AI tools across its operations

Shadow AI is the risk nobody has scoped

Ask a room of employees whether they use AI at work and you will hear one answer. Look at what is actually happening and you will find a different one. Staff paste client information into consumer chatbots, run drafts through translation tools, and use AI features embedded in software the organisation never assessed for that purpose.

This is a governance problem before it is a security problem, and it is one of the more common reasons organisations come to us. An AIMS gives you a defensible position: an inventory of approved tools, a route for staff to request new ones, use policies that reflect what people actually need to do, and monitoring that tells you when the picture changes.

Banning AI does not work. Every organisation that has tried it has discovered the usage simply moved somewhere it could not see.

What the standard requires

ISO/IEC 42001:2023 follows the same high-level structure as ISO 9001, ISO 27001 and ISO 45001, so if you hold any of those the shape will be familiar. Clauses 4 to 10 cover context, leadership, planning, support, operation, evaluation and improvement. Annex A adds 38 AI-specific controls across nine categories:

● Policies related to AI

● Internal organisation and accountability

● Resources for AI systems, including data, tooling and human resources

● Assessing impacts of AI systems on individuals and society

● AI system lifecycle management

● Data for AI systems

● Information for interested parties, including transparency to users

● Use of AI systems, including responsible use policies

● Third-party and customer relationships

The AI system impact assessment is the control that carries the most weight in practice, and it is the one Australian buyers most often ask to see evidence of.

How Nathan ISO Consulting assists

ServiceWhat we deliver
AI inventoryEvery AI system your organisation develops, supplies or uses, including the embedded features and the tools nobody registered
Role mappingWhere you sit as developer, provider or deployer for each system, since that determines which controls apply
Gap assessmentAssessment against ISO/IEC 42001:2023 and the 38 Annex A controls, plus alignment to current Australian guidance
AI governance frameworkAI policy, accountability structure, decision rights, and the committee or forum that will actually meet
AI impact assessment methodologyThe assessment process, templates and thresholds, plus completed assessments for your highest-risk systems
AI risk managementRisk criteria covering bias, transparency, data quality, security, drift and misuse, integrated with your existing risk framework
Data governance for AIProvenance, quality, retention and lawful basis for training, fine-tuning and inference data
Human oversight designWhere a human must be in the loop, what they can actually override, and how that is evidenced
Shadow AI controlApproved tool register, request pathway, acceptable use policy, and monitoring that reflects real workplace behaviour
Third-party AI assuranceDue diligence process for AI vendors, and the contractual terms that make it enforceable
Monitoring and evaluationPost-deployment performance monitoring, drift detection expectations, and incident handling for AI-specific failures
Internal audit and certification supportFull internal audit, management review, certification body selection, and attendance at Stage 1 and Stage 2

Why organisations choose Nathan

We tell you the truth about Australian AI regulation. There is no AI Act and the mandatory guardrails did not pass. Selling ISO 42001 on the threat of imminent regulation is both inaccurate and unnecessary, because the procurement case is strong enough on its own.

We start with an inventory, not a policy. An AI policy written before anyone has listed what AI the organisation actually uses is a document about an imagined company.

We integrate rather than duplicate. If you hold ISO 27001, a large proportion of the governance, risk and audit machinery is already built. We extend it instead of running a parallel system.

We treat shadow AI as in scope. Most AIMS projects quietly ignore the tools staff use without permission. Those are precisely the ones creating exposure.

We write impact assessments that a buyer would accept. The AI impact assessment is what enterprise procurement asks to see. It needs to be substantive, not a form with the risk field set to low.

We handle the EU AI Act question honestly. If you sell into Europe, ISO 42001 helps but does not discharge conformity assessment obligations there. We will tell you where the gap sits rather than implying the certificate closes it.

Where we work

AI governance work runs almost entirely remotely, which suits a client base concentrated in technology precincts but not confined to them.

LocationWho we typically work with
SydneySaaS and platform businesses, fintech, insurtech, health technology, professional services deploying AI internally
MelbourneEnterprise software, retail and e-commerce, education technology, superannuation and financial services
CanberraCommonwealth suppliers facing AI assurance questions in government procurement
BrisbaneHealth technology, logistics platforms, government suppliers, defence-adjacent technology
PerthResources technology, remote operations and autonomous systems, engineering software
AdelaideDefence and space supply chain, research commercialisation, health technology
Elsewhere in AustraliaDelivered remotely across all states and territories, including regional technology and services businesses

FAQ'S

No. There is no Australian AI Act, and the mandatory guardrails proposed in 2024 for high-risk AI were not legislated. Certification is voluntary. Demand is driven by enterprise procurement, government tenders and vendor security reviews rather than by regulation.

Guidance published by the Department of Industry, Science and Resources in October 2025 setting out six essential practices for safe and responsible AI. It evolves the earlier Voluntary AI Safety Standard and its ten guardrails. It is guidance, not law, and it aligns closely with ISO 42001.

No. It certifies that your organisation has a management system for governing AI responsibly across the lifecycle. It assesses governance, accountability, risk and oversight, not the technical accuracy or fairness of any individual model.

Yes, and this is the most common situation we see. As a deployer your focus shifts to vendor due diligence, human oversight, use policies, monitoring outcomes and controlling unapproved tools. The project is usually smaller than for a developer.

They overlap substantially around risk management, data governance, transparency and human oversight, but ISO 42001 is not a harmonised standard under the Act. If you place AI systems on the European market, certification helps considerably but does not discharge conformity assessment obligations.

Yes, and you should if you hold ISO 27001. Both follow the same high-level structure and share governance, risk methodology, internal audit and management review. Adding an AIMS to an existing ISMS is a much smaller project than building either alone.

Typically 14 to 22 weeks. The AI inventory and impact assessments take the most elapsed time, particularly in organisations where AI use has spread informally and nobody has a complete picture of what is in use.

All states and territories. Our AI governance clients concentrate in Sydney, Melbourne, Canberra, Brisbane, Perth and Adelaide, but delivery is largely remote so location rarely affects the project or the timeline.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance

  • ISO certification success rate chart

    0

    Projects

  • ISO certification statistics graphic

    0

    Services

  • ISO certification growth statistics graphic

    0

    Clients Serving

  • ISO certification success rates infographic

    0

    Countries Serving