ISO/IEC 42001 AI Management Systems
ISO/IEC 42001 is the world's first international standard for managing artificial intelligence, a framework for using and developing AI responsibly, transparently, and with the right controls in place.
Certified by a JASANZ-accredited body, responsible AI isn't just something you claim. It's proof your customers, your partners, and regulators can trust; the recognised mark that you take the risks and responsibilities of AI seriously, and have built the system to manage them.




















What is ISO/IEC 42001?
ISO/IEC 42001 is the world's first international standard for AI management systems. Published at the end of 2023, it's the recognised framework for governing artificial intelligence responsibly and as AI moves from experiment to everyday business tool, it's fast becoming the way organisations prove they're using it well.
The most important thing to understand is that ISO 42001 isn't a standard for the AI models themselves. It's a management system standard, in the same family as ISO 9001 and ISO 27001. It applies to any organisation that develops, provides, or uses AI systems, which today means almost everyone. You don't have to be an AI company to need it; if AI is making or shaping decisions in your business, 42001 is how you govern that responsibly.
The standard gives you a structured way to address the real challenges AI brings like ethics, accountability, transparency, and data privacy, rather than leaving them to chance. It helps you move from ad hoc AI use to structured, accountable AI management: knowing where AI is used across your organisation, understanding the risks, putting the right controls and human oversight in place, and improving as the technology (and the rules around it) evolve.

DO WE NEED ISO/IEC 42001?
ISO/IEC 42001 is how you prove your organisation uses AI responsibly, and stay ahead of what's coming.
TCrust and transparency - AI is only as valuable as the trust people place in it. ISO/IEC 42001 shows your customers, partners, and regulators that the way you develop and use AI is governed, accountable, and transparent, not a black box nobody's watching.
Ready for what's coming - AI regulation is arriving fast, and expectations are tightening even faster. ISO 42001 gives you a structured framework that helps you meet emerging obligations more effectively, so you're prepared for new rules rather than scrambling to catch up.
A genuine market advantage - As AI becomes part of due diligence, more customers and tenders are asking how you govern it. Certification answers that question with independent proof, setting you apart from competitors who can only offer reassurances.
Real risk management - AI brings risks that other systems don't: bias, unintended outcomes, data misuse, decisions no one can explain. ISO 42001 helps you identify those risks across your organisation, put the right controls and human oversight in place, and manage them deliberately rather than hoping for the best.
Confidence to innovate - Good governance isn't a handbrake, it's what lets you move faster with less fear. With clear oversight and accountability in place, your team can adopt and scale AI knowing the guardrails are there.
Accountability across your organisation - ISO 42001 moves you from ad hoc AI use to a structured system: knowing where AI is used, who's responsible, and how it's controlled. That clarity protects your organisation and your people as AI becomes embedded in how you work.
EVERY AUDIT WE RUN IS
DESIGNED TO DO THREE THINGS.
GOOD FOR YOUR TEAM.
Practical improvements. Human-to-human conversations. Flexible, remote-first, and built around how and your team actually work.
Good ASSESSORS
People who are passionate about improving your business and genuinely invested in your growth, year after year.
Good for the world
Every audit funds health, community, and
environmental impact through our Good Fund. We're a B Corp and a 1% for the Planet member. This isn't a side project; it's embedded into everything we do.
THIS IS WHAT CERTIFICATION LOOKS LIKE WHEN IT GIVES A DAMN.
WELCOME TO BEING CERTIFIED WITH IMPACT™.
Six reasons we're
your partner
Internationally recognised
JASANZ and IAF accreditation. Recognised in 100+ countries. Listed on the IAF CertSearch register, giving clients, regulators, and government tenders the proof they need.
Collaborative by design
We look for conformity first. Where there's a gap, we work with your team to close it through practical recommendations in plain language, not a clause-by-clause finding list.
Flexible audits, built around yoU
Stage 1 is usually remote. Stage 2 is scheduled around your team, with asynchronous elements built in wherever possible. We adapt to you, not the other way around.
Consultant, DIY & platform-friendly
We play well with others. GRC platforms, internal consultants or your own internal setup - we fit seamlessly into your existing setup and keep things moving.
You’ll know us by name
From first enquiry to certificate, you'll have a dedicated point of contact at every stage. Our leadership team is hands-on; a member of our senior team attends every opening or closing meeting personally to say g’day. Call us, WhatsApp us, email us. Our door is always open.
People who are invested in your growth
We only work with auditors who are genuinely passionate about improving your business and invested in your business, year after year.
From G'day to
getting started.
Let's have a chat
Book a discovery call with José, our CEO. This is really an opportunity to say G’day, have a conversation to understand your business, and see if we're the right fit.
We'll send you a quote within THE DAY
We’re upfront about our pricing. Transparent pricing based on your team size and business complexity. There are no hidden fees or surprises. And as a B Corp, we never want price to be a barrier. If you receive a more competitive quote from another JASANZ-accredited body, let us know, and we'll do our best to match it.
We get started
Once you sign your fee proposal, our team will call you to welcome you to A Good Certification Group and walk you through the plan - tentative dates, your assessor, and everything you need to know before we kick off.
What our clients say
How it works
FAQs
We only use AI tools like ChatGPT or Copilot, we don't build our own. Do we still need this?
Yes, quite possibly. ISO 42001 is for any organisation that uses AI, not just those that build it. If AI tools are helping make or shape decisions in your business, such as in hiring, customer service, analysis, content, (basically anything) then how you govern that use is exactly what the standard covers. You don't need to be developing your own models to have real responsibilities around the AI you rely on.
Does ISO 42001 certify our AI systems, or how we manage them?
How you manage them. This is the most important thing to understand about the standard: ISO 42001 doesn't certify an individual AI model or tool as "safe" or "unbiased." It certifies that your organisation has a proper management system around AI including clear accountability, risk controls, human oversight, and transparency. It's about governance, not a stamp of approval on the technology itself.
Isn't it too early to certify? The technology is moving so fast.
That's exactly why a management system helps. ISO 42001 isn't tied to any particular AI tool or technique, it's built on continual improvement, designed to keep pace as the technology and the rules around it evolve. Rather than locking you into today's approach, it gives you a structure that adapts. Certifying now also positions you as an early mover on responsible AI, at a moment when customers and regulators are just starting to ask the question.
What kinds of organisations is ISO 42001 for?
Any organisation, in any sector, that develops, provides, or uses AI: technology companies, financial services, healthcare, manufacturers, public bodies, and professional services alike. It's built to scale to organisations of any size, and to whatever role AI actually plays in your business, from a core product feature to a handful of tools your team uses day to day.
Can we combine ISO/IEC 42001 with our other certifications?
Yes! ISO 42001 shares the same underlying management-system structure as standards like ISO 9001 and ISO 27001, so it integrates neatly with certifications you may already hold. If you're certified to 27001 for information security in particular, you'll find a lot of common ground and we can look at auditing them together. Tell us what you already have and we'll work out the most efficient path.
How long is an ISO/IEC 42001 certificate valid?
Three years, like other ISO management system standards. After initial certification, we carry out lighter surveillance audits each year to confirm your AI management system is working in practice, then a recertification audit at the three-year mark.







