4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Insights & News

ISO 42001 Explained for Australian SMEs

ISO/IEC 42001:2023 is the international standard for an artificial intelligence management system, published in December 2023. It is to AI what ISO 27001 is to information security: a certifiable management system covering how your organisation decides what AI it uses, assesses the risk and impact, controls the lifecycle and proves all of it to an auditor. For Australian SMEs it matters for two reasons, and only one of them is certification.

Printed documents and a laptop on an office desk.

Key facts

  • ISO/IEC 42001:2023 was published in December 2023 and is the first international AI management system standard.
  • It uses the ISO harmonised structure, clauses 4 to 10, which is the same skeleton as ISO 27001 and ISO 9001, so the three integrate rather than duplicate.
  • Annex A provides 38 reference controls grouped into nine objectives, A.2 through A.10, covering AI policy, internal organisation, resources, impact assessment, lifecycle, data, information for interested parties, use of AI systems, and third-party relationships.
  • As with ISO 27001, the Annex A controls are applicability-based: you justify which apply through risk and impact assessment and record the reasoning in a Statement of Applicability.
  • Certification is voluntary, carried out by accredited bodies through a Stage 1 and Stage 2 audit, typically valid for three years with annual surveillance audits.
  • Australia's Voluntary AI Safety Standard guardrails were explicitly crosswalked to ISO/IEC 42001 and the NIST AI Risk Management Framework, which is why 42001 is a safe structure to build on while Australian standards are still moving.

What does ISO 42001 actually require?

Clauses 4 to 10 are the management system itself and they will look familiar to anyone who has been through ISO 27001. Understand the context you operate in and who your interested parties are. Get leadership commitment and an AI policy. Plan: assess risks, set objectives. Support: resources, competence, documented information. Operation: run the processes, including an AI system impact assessment. Check: monitor, audit internally, review at management level. Improve: fix nonconformities and keep going.

The piece that is genuinely new is the AI system impact assessment. Risk assessment asks what could go wrong for the organisation. Impact assessment asks what could go wrong for the people affected by the system's outputs, which is a different question and the one most businesses have never written down.

What is in Annex A?

Thirty-eight controls, nine objectives. In plain terms:

  • A.2 Policies related to AI. You have an AI policy, it is approved, and it is reviewed.
  • A.3 Internal organisation. Someone owns this, roles are defined, and there is a route for reporting concerns.
  • A.4 Resources for AI systems. You have documented the data, tooling, compute and people each AI system depends on.
  • A.5 Assessing impacts of AI systems. Impact assessments exist and are done at the right time.
  • A.6 AI system life cycle. Responsible design, development, verification, deployment, operation and monitoring, with technical documentation and event logs.
  • A.7 Data for AI systems. Data quality, provenance, preparation and privacy across the pipeline.
  • A.8 Information for interested parties. What users, customers, regulators and affected people are told.
  • A.9 Use of AI systems. Responsible use, including what staff may and may not do.
  • A.10 Third-party and customer relationships. The controls for AI you buy rather than build, which for most SMEs is all of it.

That last objective is the one SMEs underestimate. If your AI is Copilot, ChatGPT Business and a transcription tool, A.10 and A.9 carry most of your weight, and A.6 shrinks to almost nothing because you are not developing models.

Does an Australian SME need to certify?

Usually not, and anyone telling a thirty-person business it must certify is selling something. Certification is a real programme: external audits, a Statement of Applicability, documented evidence, a three-year cycle with annual surveillance. It earns its cost when a major client or a tender requires it, when you sell an AI-enabled product, or when AI is central to your service delivery and your clients are enterprises.

The much more common position is using ISO/IEC 42001 as the structure without certifying. You get the AI policy, the register, the impact assessment and the third-party controls, which is roughly ninety per cent of the practical benefit, and you can certify later because the groundwork matches.

The one group for whom the maths changes is businesses already certified to ISO 27001. The shared harmonised structure means the context, leadership, internal audit and management review machinery already exists, so adding 42001 is an extension rather than a new build.

How does it relate to the Australian rules?

Australia has no AI Act. The National AI Plan of December 2025 chose existing technology-neutral laws over a standalone statute, then the Government moved again through 2026 with an Australian Standards for AI framework and an Office of AI, with mandatory standards flagged for legislation in early 2027.

Through all of that, the Voluntary AI Safety Standard guardrails have stayed published and they were crosswalked to ISO/IEC 42001 from the start. That is the practical argument for using 42001 now: it is the stable thing in a moving picture, and work you do against it should map across to whatever lands.

Frequently asked questions

What is the difference between ISO 42001 and ISO 27001?

ISO 27001 certifies an information security management system and has 93 Annex A controls. ISO 42001 certifies an AI management system and has 38, aimed at AI risk, the impact on people and behaviour across the AI lifecycle. They share the same clause structure, so they run together rather than competing, and most organisations that hold both treat them as one management system with two scopes.

How much does ISO 42001 certification cost in Australia?

It varies too widely for a figure to be useful: it depends on headcount, scope, how many AI systems are in scope and whether you already hold another ISO certification. The cost drivers are the implementation effort first and the audit fee second, and an existing ISO 27001 certification reduces both substantially. Get quotes from accredited bodies rather than relying on published numbers.

Do we need ISO 42001 if we only use Copilot and ChatGPT?

You do not need to certify, but the standard is still the best available checklist. If you only consume third-party AI, the objectives that matter are A.9 on use of AI systems and A.10 on third-party relationships, plus an AI policy and a register. That is a week of work, not a programme.

Is ISO 42001 mandatory in Australia?

No. It is a voluntary international standard. Australia has no AI Act, and ISO certification of any kind is not legally required here. It becomes effectively mandatory only when a client or tender makes it a condition of doing business, which is where most of the current demand comes from.

How long does implementation take?

For an SME consuming AI rather than building it, three to six months is realistic to be certification-ready, and far less if you only want the structure without the audit. The long pole is almost always evidence: having done the impact assessments and kept the records, rather than writing the policy.

If a client has asked whether you have an AI management system and you are not sure what to say, start with the register and the policy. We can tell you in a short conversation whether certification is worth it for your business or whether the structure alone will do.

Brett Muscio

About the author

Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on governance and compliance, including AI governance, ISO aligned management systems, Privacy Act obligations and the Essential Eight, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.

Recent Posts

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Book a meeting

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details