AI Governance

ISO/IEC 42001 for Boards: What an AI Management System Actually Asks of You

AI governance is moving from principles to auditable systems. Here is what ISO 42001 means in practice — and the five questions every Board should be asking now.

Muhammad Anwar
· 3 min read

Most organisations I speak with already have an “AI principles” page. Fairness, transparency, accountability — the words are right. What’s usually missing is the system that turns those words into decisions, evidence and accountability. That’s the gap ISO/IEC 42001 is designed to close.

From principles to a management system

ISO/IEC 42001:2023 is the first international standard for an AI Management System (AIMS). If you’ve lived through ISO 27001, the structure will feel familiar: context, leadership, planning, support, operation, performance evaluation and improvement. The difference is what sits inside it.

Instead of protecting information assets, an AIMS governs how your organisation develops, provides or uses AI — including the AI quietly embedded in the SaaS products you already buy.

The standard doesn’t ask whether your AI is good. It asks whether you can prove you are managing it responsibly.

What it asks of you in practice

Stripping away the clause numbers, an AIMS expects four things:

  1. An AI inventory. You can’t govern what you can’t see. That includes shadow AI, vendor features and internal experiments.
  2. AI risk and impact assessments. Not just security risk — impacts on individuals, groups and society, including bias, explainability and misuse.
  3. Lifecycle controls. Annex A covers data quality, system documentation, human oversight, third-party relationships and responsible use.
  4. Accountable ownership. Named owners, defined roles, and a reporting line that reaches the executive.

Five questions every Board should ask

When I brief executives, I suggest they start here:

  • Where are we using AI today — including through suppliers? If nobody can answer within a week, that’s your first finding.
  • Who owns AI risk? “IT” or “everyone” is not an answer.
  • How do we decide an AI use case is acceptable? Look for a documented, repeatable assessment — not a one-off approval email.
  • What happens when an AI system gets it wrong? Incident response, human override and customer remediation should already be defined.
  • How will we know it’s working? Ask for KRIs and KCIs, not anecdotes.

Where it fits with what you already have

ISO 42001 doesn’t replace your existing frameworks — it plugs into them. If you hold ISO 27001, much of the management-system scaffolding already exists (my free ISO 27001 internal audit workbook is a quick way to check its health). If you’re in Australia’s critical infrastructure or Defence supply chain, AI risks increasingly surface inside SOCI risk management programs and security assessments. The smart move is integration, not another silo.

A pragmatic starting point

You don’t need to certify on day one. A realistic first 90 days looks like:

  • Build the AI inventory and classify use cases by risk.
  • Run a gap assessment against ISO 42001 clauses and Annex A.
  • Appoint an accountable executive and define the decision forum.
  • Pilot an AI impact assessment on one high-value use case.

Governance done well doesn’t slow AI down. It’s what gives your organisation the confidence to move faster than competitors who are still hoping nothing goes wrong.


Frequently asked questions

What is ISO 42001?

ISO/IEC 42001 is the international standard for an AI management system (AIMS). It sets requirements for governing how an organisation develops, provides or uses AI — covering risk and impact assessment, lifecycle controls, supplier relationships and accountability.

Is ISO 42001 certification mandatory in Australia?

No. It’s voluntary, but it is fast becoming the benchmark that customers, regulators and Boards use to judge whether AI is being governed responsibly.

How long does ISO 42001 readiness take?

A focused readiness program typically starts with a 90-day sprint: AI inventory, gap assessment, accountable ownership and a pilot impact assessment. Certification timelines then depend on scope and maturity.


If you’re starting your AI governance journey, I’m happy to compare notes. Explore AI governance services or talk to my AI agent.

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader specialising in the ISM, PSPF, NIST SP 800-53, SOCI Act and AI governance (ISO 42001). Views are my own.