AI Security, Privacy and Compliance

Do You Need ISO 42001 Certification, or Just to Prove You Govern AI?

Last updated 16 September 2026 · 6 min read

Direct Answer

For most Australian small and medium businesses, no — you need to be able to prove you govern AI, and certification is only one, relatively expensive way to do that. AS ISO/IEC 42001:2023, the Australian adoption of the international AI management system standard, is entirely voluntary; nobody is legally required to hold it. Formal certification against it — through a JAS-ANZ-accredited body such as Intertek, which was accredited in July 2025 — typically runs a small AU business $20,000 to $60,000 in the first year across gap analysis, implementation, and audit fees, plus annual surveillance audits afterwards. A documented AI register, a written policy, a risk assessment, and per-run evidence records get most businesses genuinely credible proof of governance without any of that spend. Certification becomes the right call when a specific customer, tender, or contract explicitly demands the certificate itself — not because informal evidence is inherently insufficient.

Detailed Explanation

The honest answer sits between two extremes that dominate the search results for this question. One side — mostly certification bodies and consultants who sell the audit — implies every business handling AI needs to get certified soon or risk falling behind. The other treats "AI governance" as a vague, unfalsifiable virtue nobody actually checks. Neither is right. Certification is a specific, optional, paid pathway to prove something. The thing it proves — that you actually govern AI, not just talk about it — is what actually matters, and most small businesses can prove it without the certificate.

AS ISO/IEC 42001:2023 is Standards Australia's identical adoption of the international AI management system standard, published 16 February 2024. It sets out requirements for an AI management system: policies, a documented AI inventory, risk and impact assessments, a Statement of Applicability selecting relevant controls from Annex A, supplier evaluation, and ongoing internal review. Getting certified against it means an accredited external body audits your business against those requirements and issues a certificate, typically valid for three years with annual surveillance audits in between. Nothing in Australian law requires this. It's a voluntary, market-driven credential — the same category as ISO 27001 or SOC 2 — not a licence to operate.

What Certification Actually Costs and Takes

For an Australian SME of roughly 10–50 staff, a realistic first-year budget runs $20,000 to $60,000, covering a gap analysis, the work of actually building the management system (the AI inventory, risk assessments, policies, and Statement of Applicability — usually the larger line item, not the audit itself), and the certification body's Stage 1 and Stage 2 audit fees, which alone can run from roughly $5,000 up to $50,000 depending on the registrar and the scope. Timelines typically run three to eight months. A business already running an ISO 27001 information security management system has a meaningful head start — the documentation and audit habits transfer — while a business starting from nothing should budget toward the higher end. Certification isn't a one-off cost either: annual surveillance audits typically run 30–40% of the initial audit fee, every year the certificate stays current.

As of mid-2026, certification is genuinely available in Australia, not just theoretical. Intertek received formal JAS-ANZ accreditation to certify businesses against ISO/IEC 42001:2023 in July 2025, and other accredited bodies have followed — so a business that decides certification is worth it can pursue a real, locally recognised certificate, not just an international one issued by a body with no Australian standing.

When Certification Is Actually Worth the Spend

Certification earns its cost in a narrow set of situations: a specific customer, government tender, or panel contract explicitly names ISO/IEC 42001 certification as a requirement to bid or to remain a supplier; your business sells AI products or AI-enabled services at a scale where the certificate is a genuine sales asset across many deals, not just one; or a regulator or insurer in your specific sector treats the certificate as meaningful evidence. Outside those cases, the certificate mostly buys reassurance a customer rarely asks to see verified in detail.

For most businesses using AI tools day to day — not building or selling AI systems — a documented, evidenced governance practice covers the actual risk at a fraction of the cost: see what evidence do you actually need to show you're governing AI for what that looks like in practice, and what actually goes in an AI register for the foundational document most of that evidence sits on top of.

Things to Consider

  • A certificate answers "did an auditor check this," not "is your AI safe." Certification confirms a management system exists and was followed — it doesn't test or guarantee that any specific AI tool your business uses is accurate, unbiased, or safe. Don't let a certificate substitute for the practical controls (human review, data-handling limits, vendor vetting) that actually manage the risk.
  • An unaccredited "certificate" can be worse than none. A document that looks official but wasn't issued through a JAS-ANZ-accredited audit provides false comfort — a customer or investor who checks its provenance finds nothing behind it, which reads worse than honestly having no certificate at all.
  • The readiness work has value even if you never certify. Building the AI inventory, the risk assessment, and the Statement of Applicability produces genuinely useful internal documents regardless of whether you ever pay for the audit — several businesses do the readiness work, decide the certificate itself isn't worth it yet, and keep the documentation as their evidence base.
  • Revisit the decision as the business changes. A business that starts as an AI tool user and later builds or resells AI-enabled products may cross the threshold where certification starts paying for itself — this isn't a one-time decision to file away.

Common Mistakes

  • Assuming certification is mandatory somewhere it isn't. No Australian law currently requires ISO 42001 certification for using or offering AI-enabled services — confirm the actual source of a "we need to be certified" instruction (a specific customer clause, a genuine regulatory requirement, or just assumption) before committing budget to it.
  • Buying from an unaccredited issuer to save money. A cheaper "certification" from a body without JAS-ANZ accreditation isn't a discount version of the real thing — it's a different, much less credible document, and presenting it as equivalent to an accredited certificate risks the exact reputational damage the certificate was meant to prevent.
  • Treating the audit as the whole cost. The audit fee is often the smaller line item; underestimating the implementation effort (the AI inventory, risk assessments, and ongoing internal reviews) is the most common way an ISO 42001 project runs over budget and over time.
  • Skipping the ISO 27001 head-start check. A business already certified to ISO 27001 that starts an ISO 42001 project from scratch, without reusing existing documentation and audit habits, pays for duplicate work it didn't need to.

Frequently Asked Questions

Is ISO 42001 an Australian Standard, or only an international one?
Both — AS ISO/IEC 42001:2023 is Standards Australia's identical adoption of the international ISO/IEC 42001:2023, published 16 February 2024. It carries the same requirements as the international standard, badged as an Australian Standard, and Australian businesses can be certified against it locally through an accredited certification body rather than needing to go offshore.
Can any consultant issue an ISO 42001 certificate?
No — a credible certificate has to come from a certification body accredited to issue it, in Australia through JAS-ANZ (the Joint Accreditation System of Australia and New Zealand). A certificate from an unaccredited issuer, or a "badge" sold by a training or consulting firm that never involved an independent audit, carries none of the same weight with a customer or auditor checking it, even though it may look similar at a glance.
If we're already ISO 27001 certified, is 42001 a small add-on?
It's a genuine head start, not a formality — a business already running an ISO 27001 information security management system already has the audit-and-documentation discipline, risk-assessment process, and management-review habits ISO 42001 also requires, which meaningfully cuts implementation time and cost. It's still a distinct management system focused on AI-specific risks (model behaviour, training data, AI-specific impact assessment) that 27001 doesn't cover, so treat it as build-on-what-you-have rather than assume it's included.

References

Related Questions