ISO 42001 · AI Governance · Delivered Remotely · Australia · US · UK

ISO 42001 — implement now while you're ahead of the curve.

ISO 42001 is the global standard for AI governance. Enterprise procurement is starting to ask for it. EU AI Act enforcement is intensifying. We deliver your AI Management System (AIMS) in 8–12 weeks, inside your existing Microsoft 365 environment, while most of the market is still figuring out where to start.

  • 8–12 weeks
  • Early-mover specialisation
  • Microsoft 365 native
  • EU AI Act aligned
Sample ISO 42001 AI Management System dashboard showing model inventory with risk tiers and governance status

Three pressures converging. One framework that answers all of them.

Most Australian organisations are using more AI than they realise — and the questions are starting to arrive from three directions at once. ISO 42001 is the structured answer that addresses all three with a single programme.

Australian regulatory direction

The Australian Government's National AI Plan (December 2025) confirmed there will be no standalone AI Act — AI is governed through existing law, sector regulators and the National AI Centre's voluntary guidance instead. APRA, ASIC and the OAIC have each issued AI-specific guidance for the sectors they regulate, and government agencies already carry their own mandatory AI obligations. ISO 42001 maps directly onto that guidance, so implementing it now means the evidence exists whichever regulator — or customer — asks for it.

Enterprise procurement is asking

88% of organisations now use AI in at least one business function — but only 8% have a comprehensive governance framework in place. Large enterprise and government buyers know that gap exists, which is why standard vendor questionnaires (CAIQ, SIG Lite) now carry a dedicated AI section: model provenance, training data rights, who reviews AI outputs. Without a documented AI Management System, you respond with vague assurances. With ISO 42001, you respond with auditable evidence — and you win the comparison against vendors who don't have either.

EU AI Act supply chain reach

If you supply software, services, or AI-enabled products into Europe — or work with EU-domiciled enterprise customers — the EU AI Act reaches you regardless of where you're incorporated. General enforcement, including transparency duties and conformity assessments, starts 2 August 2026; high-risk (Annex III) obligations were since deferred a further 16 months to December 2027, but the documentation baseline still lands in 2026. ISO 42001 is the fastest path to demonstrating alignment and avoiding contractual exposure either way.

Why timing matters more than usual on this one

ISO 42001 was published in late 2023. The market is still early. That's an opportunity — but the window is closing.

Implement in 2026

First-mover positioning

  • Differentiate against competitors in tenders
  • Pre-empt EU AI Act enforcement deadlines
  • Answer enterprise procurement questions confidently
  • Build infrastructure once, scale governance later
  • Senior practitioner availability still strong

Position:

Ahead of the requirement

Implement in 2027+

Catch-up positioning

  • Customers start failing you on AI governance questions
  • EU AI Act exposure may already be contractual
  • Specialist consultant capacity stretched thin
  • Implementation timelines extend; costs increase
  • Competing against vendors who already have it

Position:

Behind the requirement

This isn't fear-mongering — it's the same pattern every framework follows. ISO 27001 buyers in 2015 paid less and waited less than buyers in 2020. The same dynamic is now starting for ISO 42001.

What an AI Management System actually contains

An AIMS is not a policy document. It's a live, auditable system of controls, registers, and processes that demonstrates your AI is being governed responsibly on an ongoing basis. Six components.

Model inventory & risk tiering

A complete register of every AI system in use — purpose, vendor, version, data inputs, decision impact. Includes third-party tools (Copilot, OpenAI, vendor ML), internally developed automation, and AI embedded in products. Risk-tiered so governance effort is proportionate.

AI risk & impact assessments

Structured assessment of AI-specific risks — bias, drift, misuse, opacity, third-party dependency. Each high-risk system gets a documented impact assessment with safeguards and residual risk sign-off. Linked to Privacy Act DPIAs where AI processes personal information.

Human oversight & escalation

Defined decision thresholds for when AI output requires human review, approval, or override. Escalation paths, dispute handling procedures, and accountability assignment — practical and auditable, not theoretical.

Monitoring & performance tracking

Ongoing monitoring of model quality, drift, bias indicators, and incidents. Periodic review cadence by risk tier. Incident log maintained. Audit trail demonstrating continuous oversight rather than point-in-time compliance theatre.

Policy, roles & training

AI governance policy covering acceptable use, prohibited applications, data quality obligations, and third-party AI oversight. Roles and responsibilities assigned. Training requirements proportionate to role and AI exposure.

Audit-ready evidence

Evidence automated in Microsoft 365 — SharePoint registers, Purview audit trails, Power Automate workflows. Every control mapped to its ISO 42001 clause. On Checkpoint, a posture scan of your tenant proposes Statement of Applicability status for 10 Annex A controls directly from live Microsoft Graph signals — access to the systems, tooling and data an AI system depends on, operation monitoring, event logging, incident communication and supplier oversight. You confirm or dismiss every suggestion; nothing is written automatically. Evidence packs generated on demand for customer questionnaires, procurement reviews, and external audits.

AI governance is converging into one global expectation

Different regulators are taking different routes, but they're converging on the same underlying ask: know what AI you're running, who's accountable for it, and how you'd catch it going wrong. ISO 42001 is the one certifiable answer that satisfies all of them at once.

EU AI Act

The EU AI Act's extraterritorial reach means it applies to any AI system whose output is used in the EU, not just EU-headquartered companies. General enforcement — transparency duties, conformity assessment infrastructure — starts 2 August 2026; the bulk of high-risk (Annex III) obligations were deferred a further 16 months, to December 2027. ISO 42001 provides the management-system backbone a conformity assessment expects to find already in place, whichever deadline applies to you.

US state AI laws & FTC enforcement

There's no single federal US AI law, but Colorado, California and a growing list of states have enacted AI-specific obligations, and the FTC has made clear that deceptive or unfair AI claims fall under its existing enforcement powers. An AI system register and documented human-in-the-loop controls are the evidence that answers both.

UK's principles-based approach

Rather than one AI-specific statute, UK regulators (ICO, FCA, CMA) apply existing sector rules to AI through five cross-cutting principles — safety, transparency, fairness, accountability and contestability. ISO 42001's governance structure maps cleanly onto all five, giving UK-regulated organisations one evidence set instead of a different answer for each regulator.

Australia's approach — voluntary, not mandatory

Australia deliberately chose not to legislate mandatory AI guardrails — the December 2025 National AI Plan governs AI through existing law and the National AI Centre's voluntary guidance instead. Government agencies carry their own mandatory obligations, and the guidance's six essential practices — accountability, risk management, human oversight, testing, monitoring, documentation — map directly onto ISO 42001. With no local law forcing the issue, the real pressure is coming from enterprise procurement, insurers and EU-domiciled customers who ask for exactly this evidence today.

Who this is for

ISO 42001 is the right framework for organisations in one of these situations:

You're building AI into products

SaaS platforms with AI features, healthtech with diagnostic models, fintech with credit decisioning, govtech with automated processing. Your customers will ask how the AI is governed. ISO 42001 is your structured answer.

You sell into Europe or EU-linked customers

EU AI Act general enforcement — transparency duties, conformity assessments — starts 2 August 2026; high-risk (Annex III) obligations follow in December 2027. If you supply EU customers — directly or indirectly — your contracts will increasingly require evidence of alignment well before either deadline. ISO 42001 is the most credible international standard for demonstrating it.

You're using AI internally at scale

Microsoft Copilot rolled out org-wide, vendor AI embedded across the tech stack, internal automation accumulating faster than oversight. ISO 42001 brings structure to what's already happening and surfaces shadow AI you didn't know was in use.

You're already ISO 27001 certified

You have an ISMS, you have governance discipline, you have audit muscle. Adding ISO 42001 on top of an existing ISO 27001 base is significantly cheaper and faster than starting from scratch — and it consolidates your management system rather than fragmenting it.

What your deliverables look like

Your AI Management System lives inside Microsoft 365 alongside your existing security and privacy controls. Here's what a Risk Register and AIMS Statement of Applicability look like inside SharePoint.

Risk Register — AI, Privacy & Cybersecurity Risks

Risk Register in Microsoft SharePoint showing AI governance, privacy and cybersecurity risks with impact, likelihood and mitigation status

Statement of Applicability — ISO 42001 AIMS Controls

Statement of Applicability in SharePoint showing ISO 42001 AIMS controls including AI risk assessment, lifecycle management, data governance and human oversight

10 of the 38 Annex A controls above are proposed automatically from a Checkpoint posture scan of your Microsoft 365 tenant — the rest (AI policy content, impact assessments, design documentation) are process controls no live signal can honestly evidence, so they stay self-reported.

A typical 10-week implementation

Compressed for organisations with a single AI use case, extended for complex environments. Most mid-market engagements complete in 8–12 weeks.

Weeks 1–2

Discover & inventory

AI audit across the organisation, model inventory including third-party tools, risk tiering, gap assessment against ISO 42001 clauses.

Weeks 3–6

Policy & risk framework

AI governance policy, roles and responsibilities, risk and impact assessment methodology, human oversight model, Privacy Act / DPIA integration.

Weeks 7–9

Controls & evidence

SharePoint AIMS infrastructure, monitoring workflows, incident logging, evidence automation in Microsoft 365, internal audit preparation.

Weeks 10+

Audit-ready

Internal audit, corrective actions, customer-facing evidence pack, operational handover. External certification pursued where formal certification is the objective.

Common questions

Answered plainly. If you have a question not covered here, the fastest way to get a real answer is a 30-min call.

How long does it take?

8–12 weeks for most Australian mid-market organisations. Single-AI-use-case engagements can complete in 6–8 weeks. Organisations already certified to ISO 27001 have a significant head start and typically finish faster.

What does it cost?

Fixed-price, ranging $18k–$100k depending on company size and number of AI systems in scope. Organisations already ISO 27001 certified typically see 30–40% lower cost due to shared management system structure.

Do we need a dedicated AI governance platform?

No. We build inside your existing Microsoft 365 environment, on Checkpoint — our own console, included in the engagement. SharePoint registers, Purview audit trails, Power Automate workflows. Some third-party GRC platforms have started releasing AI modules but they're immature and add annual licence cost. M365-native is the more durable approach.

What AI systems does this apply to?

All AI in your organisation — third-party tools like Microsoft Copilot or OpenAI APIs, vendor ML models embedded in your tech stack, internally developed AI, and AI embedded in products you sell. Risk-tiered so governance effort matches actual risk.

Does this cover the EU AI Act?

ISO 42001 is closely aligned with the EU AI Act and provides a strong foundation for compliance. For Australian organisations supplying EU customers, ISO 42001 is the fastest path to demonstrating alignment — general enforcement (transparency duties, conformity assessments) starts 2 August 2026, though high-risk system obligations were since deferred to December 2027.

Can we combine with ISO 27001 or ISO 27701?

Yes — and we recommend it. ISO 42001 uses the same Annex SL structure, so policy, risk, evidence, and audit infrastructure can be shared. Combined engagements typically reduce total cost by 30–40% versus sequential delivery.

Do we need formal external certification?

No — and for many organisations, formal certification isn't the right objective. ISO 42001 can be implemented and maintained as an internal governance framework without pursuing external certification. The evidence, documentation, and governance structure still satisfy enterprise procurement requirements and provide a defensible posture for regulators. We build whichever path fits your situation: internal governance only, or the full certification route with an accredited certification body.

What's our responsibility vs our AI vendor's?

Your obligation under ISO 42001 covers how you select, deploy, monitor, and govern AI systems — including third-party tools. Your vendor is responsible for the model itself. You are responsible for the use case, the oversight, and the impact on people affected by the output. The model inventory and risk assessment process makes this distinction explicit for every AI system in scope — so there are no grey areas when procurement or a regulator asks.

Why Compliance365

Nobody else gives you a live EU AI Act classifier tied to your actual AI inventory.

Every AI governance platform will sell you a policy template. Checkpoint — the console included with this engagement — auto-classifies every AI system in your register against Article 5, Annex III and Article 50 the moment you document it, and shows you exactly which ISO 42001 controls it evidences and which EU AI Act obligations apply. Not a static PDF matrix you fill in once before audit and never open again — live, and it updates the moment the system changes.

Try the classifier on the right with a real AI system you use today. It's the same engine, not a marketing simplification of it.

365 Free tool · No sign-up

Is your AI system high-risk under the EU AI Act?

Tick everything that applies. Every question maps to one specific clause of Article 5, Annex III or Article 50 — nothing here is a vague judgement call. Instant tier, plain-English obligations.

Suggested tier: Minimal

Screening aid based on our reading of the EU AI Act — not legal advice. Confirm borderline or high-stakes classifications with counsel.

This exact engine tracks every AI system in your inventory automatically, tied straight to ISO 42001 evidence, inside Checkpoint. See Checkpoint in action

Related frameworks

ISO 42001 integrates directly with the rest of your management system. Most clients combine it with ISO 27001 and ISO 27701 for shared evidence and reduced total cost.

365 Free scoping tool

Get a realistic scope in 30 seconds

Three questions. Instant estimate including the third-party platform licence costs you'll avoid. No sign-up.

Pick one from each row to unlock

Ready to get ahead on AI governance?

A free 30-minute call will tell you whether ISO 42001 is the right framework for your AI exposure, what the fastest path to readiness looks like, and what it would cost. No sales pitch. If you don't need it yet, we'll tell you.

Microsoft Teams