ISO 42001 AI Management System: 2026 Certification Guide
ISO/IEC 42001:2023 is the world's first AI Management System standard. The controls list, certification process, and PECB-accredited training, with Australian guidance where it applies.
Certify your AI governance
From $399 AUD
PECB-accredited ISO 42001 courses: exam, free resit, and 12 months access included.
Quick answer
ISO/IEC 42001 is the world's first international standard for AI management systems (AIMS), published by ISO and IEC in December 2023. It gives organisations that develop, provide, or use AI a certifiable framework for managing AI-specific risks โ bias, transparency, data governance, human oversight, and accountability. Certification is currently voluntary in Australia, and its Annex A defines 38 controls across 9 categories that an organisation implements to demonstrate responsible AI governance.
What is ISO 42001?
ISO/IEC 42001:2023 is the world's first international standard for Artificial Intelligence Management Systems (AIMS). Published in December 2023 by ISO/IEC Joint Technical Committee 1, Subcommittee 42 (Artificial Intelligence), it provides a systematic framework for organisations that develop, provide, or use AI systems to manage the risks and opportunities that AI presents.
The standard applies to any organisation regardless of size, type, or AI maturity. Whether you are training machine learning models, deploying generative AI tools, or procuring AI-powered services from vendors, ISO 42001 provides the governance structure to do so responsibly. It covers the entire AI system lifecycle: from design and development through deployment, monitoring, and decommissioning.
Australia adopted the standard as AS ISO/IEC 42001:2023 through Standards Australia. Unlike guidelines-only standards such as ISO 31000, ISO 42001 is a certifiable management system standard. Organisations can be audited by accredited certification bodies and receive formal certification, demonstrating to customers, regulators, and stakeholders that their AI practices meet internationally recognised requirements.
Why does ISO 42001 matter for Australian organisations?
AI regulation is accelerating globally. The EU AI Act (2024) established the first comprehensive legal framework for AI. In Australia, the government published the Voluntary AI Safety Standard in 2024 and has proposed mandatory guardrails for high-risk AI systems. Organisations that wait for regulation to arrive will find themselves scrambling. Those that adopt ISO 42001 now will already have the governance framework in place.
Without a structured approach, organisations deploying AI face significant risks: algorithmic bias in hiring or lending decisions, lack of transparency in automated decision-making, data governance failures, and regulatory non-compliance. ISO 42001 provides a risk-based methodology to identify, assess, and treat these AI-specific risks before they become incidents.
Certification also signals trust. As enterprise procurement teams and government agencies increasingly ask vendors about their AI governance practices, ISO 42001 certification provides verifiable evidence of responsible AI. The standard is new. Certified organisations and professionals are scarce, which gives early movers a significant competitive advantage.
What does ISO 42001 cover?
What are the ISO 42001 requirements (Clauses 4โ10)?
Like other ISO management system standards, ISO 42001 follows the Harmonized Structure (formerly Annex SL) with clauses 4 through 10:
- Context of the organisation (Clause 4): Understanding internal and external factors, stakeholder needs, and the scope of the AIMS.
- Leadership (Clause 5): Top management commitment, AI policy, and organisational roles and responsibilities.
- Planning (Clause 6): AI risk assessment, AI system impact assessment, and objectives for the AIMS.
- Support (Clause 7): Resources, competence, awareness, communication, and documented information.
- Operation (Clause 8): AI system lifecycle management, including design, development, deployment, and monitoring.
- Performance evaluation (Clause 9): Monitoring, measurement, internal audit, and management review.
- Continual improvement (Clause 10): Nonconformity handling, corrective actions, and ongoing enhancement of the AIMS.
What are the ISO 42001 Annex A controls?
ISO 42001 includes 38 controls organised across nine categories in Annex A. These controls address the specific governance, technical, and operational requirements for managing AI responsibly:
- AI policies: Establishing and communicating the organisation's AI governance policies.
- Internal organisation: Defining roles, responsibilities, and accountability for AI governance.
- Resources for AI systems: Ensuring adequate data, computing, and human resources for AI operations.
- AI system impact assessment: Assessing the potential impact of AI systems on individuals, groups, and society.
- AI system lifecycle: Managing AI systems from design through development, testing, deployment, and decommissioning.
- Data for AI systems: Data quality, provenance, preparation, and governance throughout the AI pipeline.
- Information for interested parties: Transparency, explainability, and communication with affected stakeholders.
- Use of AI systems: Responsible use policies, human oversight, and monitoring of AI system outputs.
- Third-party and customer relationships: Managing AI-related risks in supply chains, partnerships, and customer interactions.
Each category groups several individual controls that you select and justify in a Statement of Applicability, the same way you do for ISO 27001 Annex A. For a control-by-control breakdown, see the full list of all 38 ISO 42001 Annex A controls.
What is ISO 42001 Annex B?
Annex B provides practical guidance for implementing each Annex A control, helping organisations translate requirements into operational practices. It is informative (not normative), meaning it supports implementation without adding mandatory requirements.
What's the difference between ISO 42001 and ISO 27001?
ISO 42001 and ISO 27001 are complementary management system standards that address different, but overlapping, risk domains. Understanding the relationship between them helps you determine which standards your organisation needs.
Many organisations will implement both standards. ISO 27001 secures your information assets, including the data that feeds your AI systems. ISO 42001 adds the governance layer for AI-specific concerns: fairness, transparency, explainability, and human oversight. If your organisation already holds ISO 27001 certification, ISO 42001 builds naturally on your existing management system structure.
Is ISO 42001 mandatory in Australia?
Standards Australia adopted ISO 42001 as AS ISO/IEC 42001:2023, making it the national standard for AI management systems. Australian organisations seeking certification work with JAS-ANZ accredited or internationally recognised certification bodies.
The Australian regulatory landscape is moving toward AI governance:
- Voluntary AI Safety Standard (2024): Published by the Department of Industry, Science and Resources, this standard outlines 10 guardrails for the safe and responsible use of AI. ISO 42001 provides the management system framework to operationalise these guardrails.
- Proposed mandatory guardrails: The Australian Government has flagged mandatory requirements for high-risk AI systems. Organisations with ISO 42001 certification will be well-positioned to demonstrate compliance.
- Defence and government: The ASD and Defence are increasingly focused on AI governance for autonomous systems and decision-support tools.
- Financial services: APRA-regulated entities using AI in credit decisions, fraud detection, or customer interactions face growing expectations around AI governance and explainability.
- Healthcare: AI in clinical decision support, diagnostics, and patient management creates unique governance requirements around safety and accountability.
Australia's early adoption of the standard (as AS ISO/IEC 42001:2023) and the growing regulatory momentum make ISO 42001 certification increasingly relevant for organisations operating in regulated sectors.
How do you get ISO 42001 certified? (step by step)
There are two distinct certifications, and it helps to keep them separate. An organisation certifies its AI management system against ISO 42001; an individual certifies their competence through PECB training. The organisation path below follows the same rhythm as an ISO 27001 project โ most teams put their own people through the PECB Lead Implementer course first so they can run the implementation in-house rather than outsourcing it.
Scope and gap analysis
Define which AI systems, teams, and processes are in scope, then assess your current practices against the ISO 42001 requirements to see where the gaps are. Inventory the AI systems you develop, deploy, or procure.
AI risk and impact assessment
Run the AI risk assessment and AI system impact assessment the standard requires (Clause 6). This is where AI-specific concerns โ bias, fairness, transparency, human oversight, and effects on individuals and society โ are identified and prioritised.
Build the AI management system
Establish the AIMS across Clauses 4 to 10: AI policy, roles and responsibilities, objectives, competence, documented information, and the operational controls for the AI system lifecycle.
Select Annex A controls and write the Statement of Applicability
Choose the applicable controls from the 38 in Annex A based on your risk assessment, implement them, and record which you have included or excluded (and why) in a Statement of Applicability.
Internal audit and management review
Verify the AIMS is working as intended through an internal audit, then hold a management review so leadership confirms the system is effective and resourced before the external audit.
Stage 1 and Stage 2 certification audit
Engage an accredited certification body for a Stage 1 (documentation review) and Stage 2 (implementation) audit. Once any non-conformities are closed, you are certified, with annual surveillance audits maintaining the certificate.
The individual PECB path is much faster: complete the relevant self-paced course and pass the remote-proctored exam.
How long does ISO 42001 certification take?
It depends on which certification you mean. Individual PECB certification is quick: the Foundation course is roughly 14 hours of study, and Lead Implementer or Lead Auditor candidates typically complete their self-paced course and sit the exam within a few weeks around normal work.
Organisation certification takes longer because it involves building and operating a real management system. For most Australian small-to-mid organisations the end-to-end project runs three to nine months, driven mainly by AI maturity and scope โ a business with existing ISO 27001 governance and a small number of AI systems moves faster than one starting from scratch across a large AI portfolio. After certification, expect annual surveillance audits in years two and three, with a full recertification audit every three years.
How much does ISO 42001 certification cost?
There are two separate cost buckets โ individual training and organisation certification โ and they are priced very differently.
Individual PECB training through Mindset Cyber is fixed and transparent: A$399 for Foundation and A$849 for Lead Implementer or Lead Auditor, with the official PECB exam voucher, digital study materials, a free resit, and 12 months of eLearning access included in every course. This is the cost most teams start with, because upskilling one or two people is what lets you run the implementation internally.
Organisation certification is quoted separately by an accredited certification body and scales with your size, the scope of the AIMS, and the number of AI systems in scope โ typically several thousand dollars across the Stage 1 and Stage 2 audits for a small-to-mid business, plus surveillance-audit fees in later years. The larger cost is usually internal: the effort to build the AIMS, run the risk assessments, and implement the Annex A controls.
Does the EU AI Act affect Australian organisations?
It can, even without an Australian mandate. The EU AI Act applies extraterritorially: an Australian organisation that places an AI system on the EU market, or whose AI output is used in the EU, falls within its scope โ the same reach the GDPR has for data. For high-risk AI systems the Act expects documented risk management, data governance, transparency, human oversight, and post-market monitoring.
ISO 42001 is the management-system standard that maps closely to those expectations, so implementing it puts most of that governance in place. It is worth being precise, though: ISO 42001 is not itself an EU harmonised standard and does not, on its own, grant a presumption of conformity with the Act โ that role falls to a dedicated harmonised standard (EN 18286) being developed separately by CEN-CENELEC and built on ISO 42001. Certifying now covers most of the governance the Act expects and shortens the path to conformity once those standards are finalised. Domestically, ISO 42001 also maps cleanly to Australia's Voluntary AI Safety Standard and its 10 guardrails (see above). For an Australian AI vendor or exporter, certifying now is a credible, portable way to show customers and regulators in both markets that your AI governance is real โ before the proposed mandatory guardrails arrive.
Which ISO 42001 course should I take? Foundation vs Lead Implementer vs Lead Auditor
PECB offers three ISO 42001 certification levels, each targeting a different professional role, so the right course depends on what you will actually do with the standard. Mindset Cyber is an authorised PECB training partner delivering all three as self-paced eLearning.
The Foundation course is the best starting point if you are new to ISO 42001. It covers AIMS concepts, key clauses, and Annex A controls in approximately 14 hours of self-paced study.
The Lead Implementer certification prepares you to design, deploy, and manage an AI Management System end-to-end. Ideal for professionals responsible for building their organisation's AIMS.
The Lead Auditor certification qualifies you to plan, conduct, and report AIMS audits. Ideal for professionals moving into AI system auditing, compliance, or consulting.
All courses include the official PECB exam voucher, digital study materials, and 12 months of eLearning access.
Who needs ISO 42001?
ISO 42001 is relevant to any organisation that develops, deploys, or procures AI systems. It is increasingly expected in the following contexts:
- AI developers: Organisations building machine learning models, natural language processing systems, computer vision, or generative AI tools.
- AI deployers: Organisations using AI in decision-making: hiring, credit scoring, healthcare diagnostics, customer service, fraud detection.
- Government agencies: Commonwealth and state agencies using or procuring AI-powered systems for public services, law enforcement, or defence.
- AI service providers: Consultancies, managed service providers, and SaaS vendors offering AI-powered products or services to enterprise clients.
- Regulated industries: Financial services, healthcare, energy, and critical infrastructure where AI governance is becoming a regulatory expectation.
In the Australian market, three buyer profiles are moving first. AI SaaS and product companies pursue certification because enterprise and government buyers now ask about AI governance in procurement and security questionnaires โ a certificate shortens those sales cycles. Government suppliers and consultancies selling AI-enabled services to Commonwealth and state agencies use it to evidence responsible-AI claims against the Voluntary AI Safety Standard. And enterprises deploying AI internally โ banks and insurers using models in credit, fraud, or claims decisions, and health providers using clinical decision support โ adopt it to manage bias, explainability, and accountability risk before a regulator or an incident forces the question.
For professionals, ISO 42001 certification is relevant to CISOs, CTOs, Chief AI Officers, AI project leads, GRC managers, compliance officers, internal auditors, data scientists, and ML engineers who need to understand or implement AI governance frameworks.
Resources
Continue your ISO 42001 journey with these resources:
- ControlStack: Browse ISO 27001, Essential Eight, and ISM controls alongside AI governance guidance.
- Free resources: Download templates, checklists, and implementation guides.
- All courses: Browse the full catalogue of PECB eLearning and live training options.
- ISO 27001 Certification Guide: The complementary information security standard that many organisations implement alongside ISO 42001.
- ISO 31000 Risk Management Guide: The enterprise risk management framework that underpins risk assessment in both ISO 42001 and ISO 27001.
- NIST Cybersecurity Framework: The NIST CSF and NIST AI Risk Management Framework complement ISO 42001's AI governance requirements.
Frequently Asked Questions
Common questions about ISO 42001 and AI Management Systems.
What is ISO 42001?
ISO/IEC 42001:2023 is the world's first international standard for AI management systems (AIMS). Published by ISO and IEC in December 2023, it provides a certifiable framework for any organisation that develops, provides, or uses AI systems to manage AI-specific risks such as bias, transparency, data governance, human oversight, and accountability. Organisations can be independently audited and certified against it, and individuals can certify their competence through PECB-accredited Foundation, Lead Implementer, and Lead Auditor training.
How many controls are in ISO 42001 Annex A?
ISO/IEC 42001 Annex A contains 38 controls organised into 9 categories (A.2 to A.10): AI policies, internal organisation, resources for AI systems, assessing AI system impacts, the AI system lifecycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. The controls are implementation guidance you select from based on your AI risk assessment โ you justify inclusions and exclusions in a Statement of Applicability, the same way you do for ISO 27001 Annex A.
How do you get ISO 42001 certified in Australia?
There are two distinct certifications. For your organisation: run a gap analysis, implement an AI management system covering ISO 42001 Clauses 4 to 10 plus the applicable Annex A controls, complete an internal audit and management review, then engage an accredited certification body for a Stage 1 (documentation) and Stage 2 (implementation) audit. For individuals: complete PECB-accredited ISO 42001 training and pass the exam โ Mindset Cyber delivers this as self-paced eLearning from A$399 (Foundation) to A$849 (Lead Implementer or Lead Auditor), exam voucher included, so your team can lead the implementation in-house.
How much does ISO 42001 certification cost?
Individual PECB certification through Mindset Cyber ranges from A$399 (ISO 42001 Foundation) to A$849 (Lead Implementer or Lead Auditor), with the official PECB exam voucher and 12 months of eLearning access included in every course. Organisation-level certification is priced separately by the certification body and depends on your size, scope, and the number of AI systems in scope โ typically several thousand dollars for a small-to-mid business across the Stage 1 and Stage 2 audits, plus internal implementation effort.
What is the difference between ISO 42001 and ISO 27001?
ISO 27001 is the standard for information security management (protecting the confidentiality, integrity, and availability of information), while ISO 42001 is the standard for AI management (governing AI-specific risks like bias, fairness, transparency, and human oversight). They share the same Annex SL management-system structure โ Clauses 4 to 10, a risk-based approach, and an Annex A control set with a Statement of Applicability โ so they integrate cleanly. You do not need ISO 27001 before ISO 42001; 42001 is standalone, though many organisations run both because data governance underpins responsible AI.
Ready to start your AI governance journey?
Whether you are building an AI Management System, auditing AI systems, or starting your AI governance career, we can help you choose the right training path. Explore our PECB-accredited courses or get in touch for guidance.