ISO 42001 · AI Governance · Delivered Remotely · Australia · US · UK
ISO 42001 — implement now while you're ahead of the curve.
ISO 42001 is the global standard for AI governance. Enterprise procurement is starting to ask for it. EU AI Act enforcement is intensifying. We deliver your AI Management System (AIMS) in 8–12 weeks, inside your existing Microsoft 365 environment, while most of the market is still figuring out where to start.
- 8–12 weeks
- Early-mover specialisation
- Microsoft 365 native
- EU AI Act aligned
Three pressures converging. One framework that answers all of them.
Most Australian organisations are using more AI than they realise — and the questions are starting to arrive from three directions at once. ISO 42001 is the structured answer that addresses all three with a single programme.
Australian regulatory direction
The Australian Government's National AI Plan (December 2025) confirmed there will be no standalone AI Act — AI is governed through existing law, sector regulators and the National AI Centre's voluntary guidance instead. APRA, ASIC and the OAIC have each issued AI-specific guidance for the sectors they regulate, and government agencies already carry their own mandatory AI obligations. ISO 42001 maps directly onto that guidance, so implementing it now means the evidence exists whichever regulator — or customer — asks for it.
Enterprise procurement is asking
88% of organisations now use AI in at least one business function — but only 8% have a comprehensive governance framework in place. Large enterprise and government buyers know that gap exists, which is why standard vendor questionnaires (CAIQ, SIG Lite) now carry a dedicated AI section: model provenance, training data rights, who reviews AI outputs. Without a documented AI Management System, you respond with vague assurances. With ISO 42001, you respond with auditable evidence — and you win the comparison against vendors who don't have either.
EU AI Act supply chain reach
If you supply software, services, or AI-enabled products into Europe — or work with EU-domiciled enterprise customers — the EU AI Act reaches you regardless of where you're incorporated. General enforcement, including transparency duties and conformity assessments, starts 2 August 2026; high-risk (Annex III) obligations were since deferred a further 16 months to December 2027, but the documentation baseline still lands in 2026. ISO 42001 is the fastest path to demonstrating alignment and avoiding contractual exposure either way.
Why timing matters more than usual on this one
ISO 42001 was published in late 2023. The market is still early. That's an opportunity — but the window is closing.
Implement in 2026
First-mover positioning
- Differentiate against competitors in tenders
- Pre-empt EU AI Act enforcement deadlines
- Answer enterprise procurement questions confidently
- Build infrastructure once, scale governance later
- Senior practitioner availability still strong
Position:
Ahead of the requirement
Implement in 2027+
Catch-up positioning
- Customers start failing you on AI governance questions
- EU AI Act exposure may already be contractual
- Specialist consultant capacity stretched thin
- Implementation timelines extend; costs increase
- Competing against vendors who already have it
Position:
Behind the requirement
This isn't fear-mongering — it's the same pattern every framework follows. ISO 27001 buyers in 2015 paid less and waited less than buyers in 2020. The same dynamic is now starting for ISO 42001.
What an AI Management System actually contains
An AIMS is not a policy document. It's a live, auditable system of controls, registers, and processes that demonstrates your AI is being governed responsibly on an ongoing basis. Six components.
Model inventory & risk tiering
A complete register of every AI system in use — purpose, vendor, version, data inputs, decision impact. Includes third-party tools (Copilot, OpenAI, vendor ML), internally developed automation, and AI embedded in products. Risk-tiered so governance effort is proportionate.
AI risk & impact assessments
Structured assessment of AI-specific risks — bias, drift, misuse, opacity, third-party dependency. Each high-risk system gets a documented impact assessment with safeguards and residual risk sign-off. Linked to Privacy Act DPIAs where AI processes personal information.
Human oversight & escalation
Defined decision thresholds for when AI output requires human review, approval, or override. Escalation paths, dispute handling procedures, and accountability assignment — practical and auditable, not theoretical.
Monitoring & performance tracking
Ongoing monitoring of model quality, drift, bias indicators, and incidents. Periodic review cadence by risk tier. Incident log maintained. Audit trail demonstrating continuous oversight rather than point-in-time compliance theatre.
Policy, roles & training
AI governance policy covering acceptable use, prohibited applications, data quality obligations, and third-party AI oversight. Roles and responsibilities assigned. Training requirements proportionate to role and AI exposure.
Audit-ready evidence
Evidence automated in Microsoft 365 — SharePoint registers, Purview audit trails, Power Automate workflows. Every control mapped to its ISO 42001 clause. On Checkpoint, a posture scan of your tenant proposes Statement of Applicability status for 10 Annex A controls directly from live Microsoft Graph signals — access to the systems, tooling and data an AI system depends on, operation monitoring, event logging, incident communication and supplier oversight. You confirm or dismiss every suggestion; nothing is written automatically. Evidence packs generated on demand for customer questionnaires, procurement reviews, and external audits.
AI governance is converging into one global expectation
Different regulators are taking different routes, but they're converging on the same underlying ask: know what AI you're running, who's accountable for it, and how you'd catch it going wrong. ISO 42001 is the one certifiable answer that satisfies all of them at once.
EU AI Act
The EU AI Act's extraterritorial reach means it applies to any AI system whose output is used in the EU, not just EU-headquartered companies. General enforcement — transparency duties, conformity assessment infrastructure — starts 2 August 2026; the bulk of high-risk (Annex III) obligations were deferred a further 16 months, to December 2027. ISO 42001 provides the management-system backbone a conformity assessment expects to find already in place, whichever deadline applies to you.
US state AI laws & FTC enforcement
There's no single federal US AI law, but Colorado, California and a growing list of states have enacted AI-specific obligations, and the FTC has made clear that deceptive or unfair AI claims fall under its existing enforcement powers. An AI system register and documented human-in-the-loop controls are the evidence that answers both.
UK's principles-based approach
Rather than one AI-specific statute, UK regulators (ICO, FCA, CMA) apply existing sector rules to AI through five cross-cutting principles — safety, transparency, fairness, accountability and contestability. ISO 42001's governance structure maps cleanly onto all five, giving UK-regulated organisations one evidence set instead of a different answer for each regulator.
Australia's approach — voluntary, not mandatory
Australia deliberately chose not to legislate mandatory AI guardrails — the December 2025 National AI Plan governs AI through existing law and the National AI Centre's voluntary guidance instead. Government agencies carry their own mandatory obligations, and the guidance's six essential practices — accountability, risk management, human oversight, testing, monitoring, documentation — map directly onto ISO 42001. With no local law forcing the issue, the real pressure is coming from enterprise procurement, insurers and EU-domiciled customers who ask for exactly this evidence today.
Who this is for
ISO 42001 is the right framework for organisations in one of these situations:
You're building AI into products
SaaS platforms with AI features, healthtech with diagnostic models, fintech with credit decisioning, govtech with automated processing. Your customers will ask how the AI is governed. ISO 42001 is your structured answer.
You sell into Europe or EU-linked customers
EU AI Act general enforcement — transparency duties, conformity assessments — starts 2 August 2026; high-risk (Annex III) obligations follow in December 2027. If you supply EU customers — directly or indirectly — your contracts will increasingly require evidence of alignment well before either deadline. ISO 42001 is the most credible international standard for demonstrating it.
You're using AI internally at scale
Microsoft Copilot rolled out org-wide, vendor AI embedded across the tech stack, internal automation accumulating faster than oversight. ISO 42001 brings structure to what's already happening and surfaces shadow AI you didn't know was in use.
You're already ISO 27001 certified
You have an ISMS, you have governance discipline, you have audit muscle. Adding ISO 42001 on top of an existing ISO 27001 base is significantly cheaper and faster than starting from scratch — and it consolidates your management system rather than fragmenting it.
What your deliverables look like
Your AI Management System lives inside Microsoft 365 alongside your existing security and privacy controls. Here's what a Risk Register and AIMS Statement of Applicability look like inside SharePoint.
Risk Register — AI, Privacy & Cybersecurity Risks
Statement of Applicability — ISO 42001 AIMS Controls
10 of the 38 Annex A controls above are proposed automatically from a Checkpoint posture scan of your Microsoft 365 tenant — the rest (AI policy content, impact assessments, design documentation) are process controls no live signal can honestly evidence, so they stay self-reported.
A typical 10-week implementation
Compressed for organisations with a single AI use case, extended for complex environments. Most mid-market engagements complete in 8–12 weeks.
Weeks 1–2
Discover & inventory
AI audit across the organisation, model inventory including third-party tools, risk tiering, gap assessment against ISO 42001 clauses.
Weeks 3–6
Policy & risk framework
AI governance policy, roles and responsibilities, risk and impact assessment methodology, human oversight model, Privacy Act / DPIA integration.
Weeks 7–9
Controls & evidence
SharePoint AIMS infrastructure, monitoring workflows, incident logging, evidence automation in Microsoft 365, internal audit preparation.
Weeks 10+
Audit-ready
Internal audit, corrective actions, customer-facing evidence pack, operational handover. External certification pursued where formal certification is the objective.
Common questions
Answered plainly. If you have a question not covered here, the fastest way to get a real answer is a 30-min call.
How long does it take?
8–12 weeks for most Australian mid-market organisations. Single-AI-use-case engagements can complete in 6–8 weeks. Organisations already certified to ISO 27001 have a significant head start and typically finish faster.
What does it cost?
Fixed-price, ranging $18k–$100k depending on company size and number of AI systems in scope. Organisations already ISO 27001 certified typically see 30–40% lower cost due to shared management system structure.
Do we need a dedicated AI governance platform?
No. We build inside your existing Microsoft 365 environment, on Checkpoint — our own console, included in the engagement. SharePoint registers, Purview audit trails, Power Automate workflows. Some third-party GRC platforms have started releasing AI modules but they're immature and add annual licence cost. M365-native is the more durable approach.
What AI systems does this apply to?
All AI in your organisation — third-party tools like Microsoft Copilot or OpenAI APIs, vendor ML models embedded in your tech stack, internally developed AI, and AI embedded in products you sell. Risk-tiered so governance effort matches actual risk.
Does this cover the EU AI Act?
ISO 42001 is closely aligned with the EU AI Act and provides a strong foundation for compliance. For Australian organisations supplying EU customers, ISO 42001 is the fastest path to demonstrating alignment — general enforcement (transparency duties, conformity assessments) starts 2 August 2026, though high-risk system obligations were since deferred to December 2027.
Can we combine with ISO 27001 or ISO 27701?
Yes — and we recommend it. ISO 42001 uses the same Annex SL structure, so policy, risk, evidence, and audit infrastructure can be shared. Combined engagements typically reduce total cost by 30–40% versus sequential delivery.
Do we need formal external certification?
No — and for many organisations, formal certification isn't the right objective. ISO 42001 can be implemented and maintained as an internal governance framework without pursuing external certification. The evidence, documentation, and governance structure still satisfy enterprise procurement requirements and provide a defensible posture for regulators. We build whichever path fits your situation: internal governance only, or the full certification route with an accredited certification body.
What's our responsibility vs our AI vendor's?
Your obligation under ISO 42001 covers how you select, deploy, monitor, and govern AI systems — including third-party tools. Your vendor is responsible for the model itself. You are responsible for the use case, the oversight, and the impact on people affected by the output. The model inventory and risk assessment process makes this distinction explicit for every AI system in scope — so there are no grey areas when procurement or a regulator asks.
Real ISO 42001 results
ISO 42001 AI governance delivered alongside Essential Eight and ISO 27701 — in 10 weeks.
Why Compliance365
Nobody else gives you a live EU AI Act classifier tied to your actual AI inventory.
Every AI governance platform will sell you a policy template. Checkpoint — the console included with this engagement — auto-classifies every AI system in your register against Article 5, Annex III and Article 50 the moment you document it, and shows you exactly which ISO 42001 controls it evidences and which EU AI Act obligations apply. Not a static PDF matrix you fill in once before audit and never open again — live, and it updates the moment the system changes.
Try the classifier on the right with a real AI system you use today. It's the same engine, not a marketing simplification of it.
Is your AI system high-risk under the EU AI Act?
Tick everything that applies. Every question maps to one specific clause of Article 5, Annex III or Article 50 — nothing here is a vague judgement call. Instant tier, plain-English obligations.
Screening aid based on our reading of the EU AI Act — not legal advice. Confirm borderline or high-stakes classifications with counsel.
Related frameworks
ISO 42001 integrates directly with the rest of your management system. Most clients combine it with ISO 27001 and ISO 27701 for shared evidence and reduced total cost.
Keep reading — ISO 42001
Guides, checklists and case studies
Get a realistic scope in 30 seconds
Three questions. Instant estimate including the third-party platform licence costs you'll avoid. No sign-up.
Estimate based on typical engagement patterns. Precise scope confirmed on call after reviewing your environment.
Ready to get ahead on AI governance?
A free 30-minute call will tell you whether ISO 42001 is the right framework for your AI exposure, what the fastest path to readiness looks like, and what it would cost. No sales pitch. If you don't need it yet, we'll tell you.