Insight · AI governance

ISO/IEC 42001 explained: the AI management system standard for boards

Boards no longer ask whether the organisation uses AI. They ask how it is governed. ISO/IEC 42001 is the international answer to that question.

Published 5 October 20267 minute read

Abstract artwork for the article: ISO/IEC 42001 explained

What it is

ISO/IEC 42001, published in December 2023, is the first international standard for an AI management system. Like ISO/IEC 27001 for information security, it does not tell you which AI to build. It sets out how an organisation should govern the AI it develops, provides or uses: roles, policies, risk and impact assessment, controls, monitoring and continual improvement.

What it asks for

  • Context and scope. Which AI systems are covered and who the stakeholders are.
  • Leadership and policy. A board-endorsed AI policy and clear accountability.
  • Risk and impact assessment. Systematic assessment of risks to the organisation and impacts on people.
  • Controls. A reference set of controls in Annex A covering areas such as data, the AI system life cycle, third parties and the use of AI systems.
  • Performance evaluation. Monitoring, internal audit and management review.
  • Improvement. Handling nonconformities and improving over time.

How it fits with Australian guidance

Australia's Guidance for AI Adoption sets out six essential practices: accountability, understanding impacts, managing risk, sharing information, testing and monitoring, and maintaining human control. ISO/IEC 42001 provides a management system that puts those practices into a structure auditors recognise. Organisations regulated by APRA, or selling to government and large enterprises, increasingly reference it.

Do you need certification?

Not always. Many organisations benefit from aligning with the standard without certifying. Certification makes sense when customers, regulators or tenders ask for independent assurance.

A practical path

  1. Build an AI register of systems in use and in development.
  2. Run a gap review against the standard's clauses and Annex A.
  3. Adopt an AI policy and assign accountable owners.
  4. Introduce risk and impact assessments for new and high-impact systems.
  5. Monitor, audit internally and improve, then decide on certification.
How we helpTalk to us about ai governance & compliance, or start with the free AI readiness check.

FAQ

Quick answers

Anything else? Email contact@sovereignsystemslabs.com.

Is ISO/IEC 42001 mandatory in Australia?

No. It is voluntary, but it is increasingly used to demonstrate AI governance to boards, customers and regulators.

How long does readiness take?

A gap review takes weeks. Building and operating the management system to certification standard typically takes several months.

Book a free strategy call