What Is ISO 42001? The AI Governance Standard Australian Businesses Need to Act On in 2026

Published

11 Jan 2025

ISO 42001 is the international standard for AI management systems. It defines how organisations should govern, manage risk around, and be accountable for the AI systems they build or deploy, covering fairness, transparency, explainability, and ethics alongside technical security. It is not a cybersecurity standard; that is ISO 27001's job. ISO 42001 is specifically about how you run AI responsibly as an organisation.

That distinction matters a lot in practice, and it is one reason the standard gets mischaracterised. If you have been thinking of ISO 42001 purely as a security checklist, you are missing the governance half of what it actually requires.

I work in lottery and gaming, an industry that sits at the intersection of regulated consumer data, automated decision-making, and real-money effects. AI governance is not an abstract conversation in that context. It is an operational necessity. This post is my attempt to explain what ISO 42001 actually covers, where the 2026 certification landscape sits, what it means for Australian businesses navigating the Privacy Act and emerging responsible AI expectations, and how the rise of agentic AI changes the picture.

I am a software engineer and AI practitioner, not a lawyer. Nothing here is legal advice. Speak to a technology law specialist if your regulatory exposure is significant.

What ISO 42001 actually covers

ISO 42001 was published by ISO in December 2023. It is structured as a management system standard, the same format as ISO 27001 for information security and ISO 9001 for quality management. That means it is not a technical specification for how to build AI systems; it is a framework for how to govern them.

The standard covers:

  • AI risk management: identifying, assessing, and mitigating risks specific to AI, including bias, adversarial vulnerability, and unintended behaviour
  • Organisational roles and accountability: who is responsible for AI decisions and outcomes, including at executive and board level
  • Transparency and explainability: requirements to document how AI systems make decisions and communicate that to affected stakeholders
  • Fairness and bias mitigation: active processes to identify and address discriminatory or unfair outcomes
  • Data governance for AI: how training data is sourced, managed, and protected
  • Continuous monitoring: ongoing auditing of AI system behaviour, not just at deployment
  • Supplier and third-party AI risk: governance obligations that extend to AI tools and models your organisation uses but did not build

The last point is the one most Australian organisations underestimate. If you are using a third-party foundation model or AI platform, ISO 42001 expects you to understand and manage the risks that flow from that dependency. You cannot simply point at your vendor's terms of service and call it done. As the AI liability landscape makes clear, the business deploying AI owns the liability for what that AI does, regardless of who built the underlying model.

ISO 42001 vs. ISO 27001: complementary, not interchangeable

A question I get regularly: if we have ISO 27001, do we need ISO 42001?

They address different things:

  • ISO 27001 governs information security: how you protect data from unauthorised access, breaches, and loss. It applies to your entire information environment.
  • ISO 42001 governs AI management systems: how you make decisions about AI, how you assess AI-specific risk, and how you remain accountable for AI outcomes. It applies wherever you build or deploy AI.

An organisation can have excellent information security posture (ISO 27001 certified) and still have no meaningful governance around the AI systems making decisions inside that secure environment. ISO 42001 fills that gap. The two standards are designed to coexist; if you have ISO 27001 infrastructure in place, the controls and audit mechanisms transfer cleanly and the marginal lift to achieve ISO 42001 certification is lower.

ISO 42001 also complements ISO 38507, which focuses on board-level governance of AI, covering the oversight and strategic direction responsibilities that sit above the management system. If you are a Head of AI or CTO at an organisation where the board is starting to ask questions about AI risk, ISO 38507 is worth understanding alongside ISO 42001.

The 2026 certification landscape

The first ISO 42001 certifications were issued in mid-2024. As of mid-2026, certification activity has grown significantly across financial services, healthcare, and technology sectors in the UK, Europe, and North America. Australian uptake has been slower, but is accelerating.

A few things to understand about certification as it sits today:

Certification is voluntary in Australia. There is no current regulatory requirement to be ISO 42001 certified. What the standard does is provide a credible, internationally recognised framework for demonstrating that your AI governance is structured and documented, which matters increasingly for enterprise procurement, insurance underwriting, and board-level risk assurance.

Certification signals are starting to appear in procurement. I am seeing this in the enterprise software space and increasingly in regulated industries: RFPs and vendor assessment questionnaires are beginning to include questions about AI governance frameworks and whether organisations are aligned to ISO 42001. This is ahead of any regulatory mandate, but it reflects where enterprise risk functions are heading.

Gap analysis is the right starting point, not a full implementation project. The standard's requirements are not all-or-nothing. A gap analysis against your current AI governance posture will identify where you have existing controls that map to ISO 42001 requirements and where the genuine gaps are. Most organisations that have done any serious AI governance work are closer to compliance than they assume.

Certification scope matters. You do not have to certify your entire AI estate at once. Many organisations scope their initial certification to a specific AI system or product line, particularly useful if you want to demonstrate governance maturity in a specific regulated context before expanding.

The agentic AI dimension: why ISO 42001 governance is more urgent now

When ISO 42001 was published in December 2023, "agentic AI" was mostly a research concept. By mid-2026, it is a deployment reality: systems connected via protocols like MCP (Model Context Protocol) that can send emails, write to databases, call APIs, and take actions against production systems, not as drafts for human review, but as live operations.

This changes the ISO 42001 picture in important ways.

Classic AI governance focused on decision support: the AI makes a recommendation, a human decides what to do with it. Most of ISO 42001's original framing reflects this model. Agentic AI collapses that gap. The model is not waiting for a human. It is executing the action. And when something goes wrong, the harm has already happened.

The standard's risk management requirements (Clause 6.1 and the annexes on AI risk) apply directly here: the question is how you identify and mitigate the risks of an AI system that acts rather than recommends. The governance patterns that work for agentic AI map reasonably directly onto ISO 42001's controls framework:

  • Least-privilege access (limit what the agent can do to only what is needed for its task) corresponds to the standard's risk treatment requirements
  • Approval gates for irreversible actions correspond to the human oversight requirements
  • Immutable audit logs for all consequential AI actions correspond to the documentation and monitoring requirements
  • Named accountability for each AI system and its configuration corresponds to the roles and responsibilities requirements

If you are running or evaluating agentic AI systems and wondering what "appropriate governance" looks like, an ISO 42001-aligned management system is a concrete answer to that question. It is also the kind of documented, structured governance that holds up under legal scrutiny when something goes wrong, which is increasingly the standard courts and regulators are applying, even in the absence of AI-specific legislation.

The Australian regulatory context in 2026

Australia does not yet have AI-specific legislation. What we have is a set of existing frameworks that create real exposure for organisations deploying AI without adequate governance, plus a rapidly developing responsible AI policy environment.

The Privacy Act 1988 (Cth) creates obligations around automated decision-making that affects individuals. If an AI system makes or influences decisions about people (marketing targeting, credit risk, player protection, hiring), the Privacy Act's requirements around collection, use, and disclosure apply, and the individual's right to understand how decisions about them are made is increasingly relevant. The Privacy Act reforms that passed in 2024 strengthened some of these requirements and the Attorney-General's Department has signalled further reforms to address AI specifically.

The Australian Government's Voluntary AI Safety Standard (2024) introduced ten guardrails that the government expects AI developers and deployers to follow. These guardrails, covering risk accountability, transparency, human oversight, testing, and incident reporting, map closely to ISO 42001's management system requirements. Alignment with ISO 42001 is a practical way to demonstrate compliance with the voluntary standard, and a reasonable hedge against those guardrails becoming mandatory, which the policy environment suggests is likely.

Sector-specific regulators are increasingly active. ASIC has published guidance on AI in financial services. The ACCC has taken positions on algorithmic pricing and consumer harm. The OAIC has issued guidance on privacy and AI. AUSTRAC has flagged AI use in anti-money-laundering contexts. In lottery and gaming, state licensing bodies are beginning to ask questions about AI use in player-facing systems. None of these constitute a unified AI regulatory regime, but they collectively create significant regulatory surface area for organisations deploying AI without documented governance.

The responsible AI framing that is emerging from government, through the Department of Industry's AI Ethics Framework and the National AI Centre's guidance, consistently uses ISO 42001 as a reference point. That signal matters: it tells you what "reasonable governance" looks like from a regulatory perspective, even before any specific AI regulation passes.

The short version: you do not need to be ISO 42001 certified to operate legally in Australia today. But the combination of Privacy Act obligations, voluntary safety standards, sector-specific regulatory attention, and emerging litigation risk means that organisations running AI without documented governance are taking on real and growing exposure. ISO 42001 provides a credible, internationally benchmarked framework for managing that exposure. The AI liability picture suggests that "we had a framework and followed it" is a meaningfully better legal position than "we didn't."

This is commentary on the regulatory environment, not legal advice. Consult a specialist in Australian technology law for advice specific to your situation.

Core governance areas ISO 42001 addresses

Here is what the standard actually requires your organisation to do, in practical terms:

Data governance and privacy by design

AI systems run on data, and ISO 42001 requires that data governance be built into AI system design from the start, not added after the fact. This means documented provenance for training data, encryption and access controls appropriate to data sensitivity, and explicit alignment between data use in AI and privacy law obligations. In Australia, that last requirement connects directly to the Privacy Act and, for lottery and gaming, to the data handling requirements in state licensing conditions.

Bias and fairness with documented processes

The standard requires active, ongoing processes to identify and mitigate bias in AI outputs, not a one-time assessment at deployment. In my industry, this shows up most concretely in player protection systems: if an AI is making decisions about responsible gambling interventions, marketing eligibility, or player risk classification, those decisions have to be fair, and you have to be able to demonstrate that with data. ISO 42001 requires that demonstration to be systematic and documented. The same logic applies to any AI system making consequential decisions about people. Pitching AI as a cost cutter often papers over the bias and fairness work that has to happen for the system to be actually governable.

Explainability and accountability

If your AI system makes a decision that affects someone, you need to be able to explain it. ISO 42001 requires that explainability be designed into systems, not reverse-engineered after the fact when someone asks. In practice, this means maintaining documentation of model behaviour, decision logic (at whatever level of detail is feasible), and the criteria by which the AI's outputs are validated. In regulated industries, this is not optional: regulators increasingly expect it, and courts are moving in the same direction.

Adversarial robustness

AI systems can be deceived. Adversarial inputs designed to cause incorrect outputs are a real threat. ISO 42001 requires that you assess this risk and implement proportionate controls. For systems connected to external tools and data (agentic systems with MCP servers, for example), adversarial robustness includes prompt injection risks, specifically malicious content in a resource the agent reads that attempts to redirect the agent's behaviour. Separation between AI reasoning and the systems AI uses to take actions is a key control here; even if the AI is compromised, it should not automatically have the authentication credentials to do something damaging.

Governance structure and organisational accountability

This is the part most technology teams underweight. ISO 42001 requires that AI governance be embedded in your organisation's governance structure, not just documented in a policy nobody reads. That means named roles with accountability for AI risk, a process for escalating AI incidents, executive visibility into AI risk, and regular review of how AI systems are performing against governance expectations. Depending on the size and complexity of your AI estate, this might be a formal AI governance committee, or it might be a defined accountability model within an existing risk or technology governance function.

How to get started

The path from "we should do something about ISO 42001" to a certification-ready management system is not a single project. It is a maturity journey. Here is the practical sequence:

1. Gap analysis first

Before planning an implementation, understand where you actually sit. A gap analysis compares your current AI governance practices against ISO 42001's requirements and identifies both your existing controls that map to the standard and the genuine gaps. Most organisations are surprised to find they have more mapped than they expected (documented processes, existing audit mechanisms, data governance work) alongside specific gaps that need deliberate effort. Do the gap analysis before estimating the implementation investment.

2. Scope your management system

You do not have to include every AI system in scope for your initial ISO 42001 management system. Scoping to a specific product, service, or AI use case is legitimate and lets you build governance maturity in a bounded context before expanding. For an Australian organisation, a natural scope might be your highest-risk AI application, specifically the one with the most regulatory exposure or the most consequential impact on people.

3. Establish governance structure and documentation

The standard requires a documented governance structure: who is responsible for what, how decisions about AI are made, how incidents are reported and investigated. This does not have to be elaborate, but it does have to be real. A policy that nobody follows is not a control. The governance structure also needs executive sponsorship; ISO 42001 has explicit top management requirements, which means the Head of AI, CTO, or equivalent needs to be formally accountable for the management system, not just aware of it.

4. Implement risk management processes

AI-specific risk assessments need to cover the failure modes that are unique to AI: model drift, bias emergence over time, adversarial vulnerability, and increasingly the blast radius of agentic systems that have real-world tool access. For each significant AI system in scope, document the identified risks, the controls in place to mitigate them, and the monitoring approach that will tell you when the risk profile has changed.

5. Set up continuous monitoring and audit

ISO 42001 is not a "pass once and forget" certification. The management system requires ongoing monitoring, internal audits, and management review. Build the audit mechanisms into how AI systems run, not as afterthought compliance activities. Automated bias monitoring, model performance tracking, and immutable audit logs for consequential AI actions are the infrastructure that makes continuous compliance sustainable.

6. Engage stakeholders beyond the technical team

Effective AI governance requires legal, compliance, operations, and (depending on your industry) regulatory affairs involvement. ISO 42001 is explicit about organisational accountability; if the governance structure only lives in the engineering team, it will not satisfy the standard's requirements. In practice, this means the gap analysis and implementation need cross-functional input, and the ongoing management system review needs cross-functional participation.

Frequently asked questions

What is ISO 42001 in plain language?

ISO 42001 is an international standard that defines how organisations should govern their AI systems. Think of it as the AI equivalent of ISO 27001 for cybersecurity: a structured management system for identifying AI risks, implementing controls, documenting accountability, and demonstrating ongoing compliance. It covers fairness, explainability, bias mitigation, and data governance alongside technical security.

Is ISO 42001 certification required in Australia?

Not yet. There is no Australian regulation currently mandating ISO 42001 certification. The Australian Government's voluntary AI Safety Standard (2024) uses similar principles, and several sector regulators are beginning to reference AI governance frameworks in their guidance. Certification is increasingly appearing in enterprise procurement and insurance underwriting requirements. The most accurate framing is: voluntary today, likely significant in procurement and risk contexts within the next two to three years, and a useful hedge against regulatory requirements that appear to be developing.

How does ISO 42001 apply to agentic AI systems?

Agentic AI systems (those that take actions rather than just generating recommendations) significantly raise the stakes for ISO 42001 governance. The standard's risk management requirements apply directly: you need to document the failure modes, implement controls proportionate to the risk (including human approval gates for consequential actions and least-privilege access to external systems), and monitor whether those controls are actually working. The governance patterns for MCP-connected agents map directly to ISO 42001's operational controls framework.

What is the difference between ISO 42001 and the EU AI Act?

They address different things. ISO 42001 is a voluntary management system standard that you can certify to: it defines how you govern AI internally. The EU AI Act is binding law that applies to AI systems used by people in the EU, with specific requirements for high-risk AI applications (hiring, credit, medical, critical infrastructure) and prohibitions on certain AI uses. For Australian businesses with European exposure, both are relevant: ISO 42001 certification provides a credible governance foundation that maps to many EU AI Act requirements, but it does not substitute for EU AI Act compliance if your systems are in scope.

Does ISO 42001 apply to AI tools we use but did not build?

Yes. This is one of the most commonly misunderstood aspects of the standard. If your organisation uses a third-party AI model, platform, or tool, ISO 42001 expects you to assess and manage the risks that flow from that dependency, including the supplier's own governance practices. You cannot simply rely on a vendor's terms of service. In practice, this means including AI tools in your risk assessment scope, asking suppliers about their own governance frameworks, and understanding what controls are contractually available to you if something goes wrong. As AI liability analysis shows, the deploying business owns the liability for what its AI does, regardless of the supply chain.

How does ISO 42001 connect to the Privacy Act?

ISO 42001's data governance requirements align closely with Privacy Act obligations, particularly around collection, use, and automated decision-making. In practice, building a Privacy Act-compliant data handling approach for AI systems addresses many of ISO 42001's data governance requirements. The two frameworks are complementary, and the work done to address one tends to support the other. Where they diverge is in the AI-specific requirements: fairness, explainability, and adversarial robustness are not Privacy Act concepts, but they are ISO 42001 requirements.

What should a Head of AI or CTO do first?

Start with a gap analysis, not a full implementation project. Understand what AI systems your organisation is running or evaluating, what governance controls are already in place, and where the genuine gaps are. Then scope your first management system effort to your highest-risk AI application, get executive and legal visibility into the governance picture, and build from there. The standard is designed to be scaled to organisational complexity; a mid-sized Australian business deploying AI does not need the same governance apparatus as a global financial institution, but it does need a documented, accountable, and monitored approach.


Final thoughts

ISO 42001 is often framed as a compliance exercise: something you do because a regulator might eventually ask for it, or because procurement teams are starting to request it. That is a valid reason to engage with it, but it is the least interesting one.

The more compelling reason is operational: a documented, structured AI management system makes your AI deployments more reliable, more defensible, and more trustworthy, from your board and regulators to your enterprise customers and the people whose lives your AI affects. In lottery and gaming, where AI touches player protection, responsible gambling, and real-money decisions, that governance infrastructure is not optional. But the same logic applies to any organisation running AI that makes consequential decisions.

The 2026 context adds urgency. Agentic AI systems that act rather than recommend are being deployed today. The liability picture is sharpening. Australian regulators are developing positions. Enterprise procurement is asking governance questions. The organisations that build the management system now, documenting their AI risks, implementing proportionate controls, and creating genuine human oversight for consequential AI actions, will be better positioned than those that wait for a mandate.

ISO 42001 is not a silver bullet. Certification does not mean your AI systems are safe or fair. What it means is that you have a structured, documented, and audited approach to managing AI risk, which is a very different position to "we are thinking about it."


Related reading: AI Liability: Who Is Responsible When AI Gets It Wrong · Governing Agentic AI: Human-in-the-Loop Patterns When Tools Can Act · MCP Explained: How AI Models Talk to Your Tools · If You're Selling AI as a Cost Cutter, You're Selling It Wrong

Similar articles