What it is
ISO/IEC 42001, published in December 2023, is the first international standard for an AI management system. Like ISO/IEC 27001 for information security, it does not tell you which AI to build. It sets out how an organisation should govern the AI it develops, provides or uses: roles, policies, risk and impact assessment, controls, monitoring and continual improvement.
What it asks for
- Context and scope. Which AI systems are covered and who the stakeholders are.
- Leadership and policy. A board-endorsed AI policy and clear accountability.
- Risk and impact assessment. Systematic assessment of risks to the organisation and impacts on people.
- Controls. A reference set of controls in Annex A covering areas such as data, the AI system life cycle, third parties and the use of AI systems.
- Performance evaluation. Monitoring, internal audit and management review.
- Improvement. Handling nonconformities and improving over time.
How it fits with Australian guidance
Australia's Guidance for AI Adoption sets out six essential practices: accountability, understanding impacts, managing risk, sharing information, testing and monitoring, and maintaining human control. ISO/IEC 42001 provides a management system that puts those practices into a structure auditors recognise. Organisations regulated by APRA, or selling to government and large enterprises, increasingly reference it.
Do you need certification?
Not always. Many organisations benefit from aligning with the standard without certifying. Certification makes sense when customers, regulators or tenders ask for independent assurance.
A practical path
- Build an AI register of systems in use and in development.
- Run a gap review against the standard's clauses and Annex A.
- Adopt an AI policy and assign accountable owners.
- Introduce risk and impact assessments for new and high-impact systems.
- Monitor, audit internally and improve, then decide on certification.
