ISO/IEC 42001

How Australian organisations can use ISO/IEC 42001 alongside the National AI Centre’s six essential AI practices.

Why consider ISO/IEC 42001 in Australia?

ISO/IEC 42001:2023 specifies requirements for an AI management system for organisations that develop, provide, or use AI systems. For an Australian company, its value is a repeatable way to govern an expanding portfolio of AI uses: who may approve a use, how impacts are assessed, what evidence supports deployment, and when a decision must be revisited.

The Australian Government’s essential AI practices address accountability, impacts, risk, transparency, testing, and human control. They are guidance for responsible AI adoption. ISO/IEC 42001 and those practices can inform the same operating model, but following either one does not establish compliance with every applicable Australian law or customer requirement.

Start with two levels of governance

At the organisational level, define an AI policy, decision rights, risk criteria, training, and an escalation path. At the system level, record the intended use, owner, supplier, affected people, data, limitations, testing, human oversight, and monitoring plan. The National AI Centre’s implementation guidance distinguishes organisation-wide arrangements from actions needed for individual systems and uses.

That distinction matters when one model supports several products. A model may be suitable for drafting low-impact internal text but require very different assessment when used in a decision that affects a person. Record each material use and its context rather than treating a vendor or model name as a complete risk assessment.

Turn the six practices into operating records

Use the Australian guidance as a practical review sequence: decide who is accountable; understand impacts; measure and manage risks; share essential information; test and monitor; and maintain human control. Assign an owner and an evidence source for each decision. For example, an impact assessment can name affected groups, a test plan can define acceptance criteria, and a release record can show who approved deployment after reviewing results.

Connect these records to the AI management system’s scope, objectives, internal review, and improvement process. Existing privacy, information security, and procurement controls may supply part of the evidence. AI-specific questions about output quality, misuse, human intervention, and changed use still need explicit answers.

What should a buyer or assessor be able to see?

A credible evidence set includes the scoped AI inventory, responsibilities, risk and impact decisions, supplier records, testing results, deployment approvals, monitoring, incidents, exceptions, and management review. Evidence should show that the process operates for the systems within scope. A policy alone cannot demonstrate how a particular system was evaluated or corrected.

Independent ISO/IEC 42001 certification is optional and is performed by a certification body, not ISO. If certification is a goal, agree the scope and assessment route with that body. Keep separate records for legal duties and contractual commitments; an AI management system supports their management but is not itself a legal approval.

Put it into practice

  • List AI products, internal uses, and supplier features within a proposed AIMS scope.
  • Assign an accountable owner and review trigger to each material use.
  • Apply the six Australian practices to one live use case and record the resulting decisions.
  • Test whether deployment approvals and monitoring results can be traced to the assessed risks.
  • Maintain separate maps for legal duties, customer terms, and management system requirements.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources