ISO/IEC 42001 AI Management Systems

ISO/IEC 42001 is the world's first international standard for managing artificial intelligence, a framework for using and developing AI responsibly, transparently, and with the right controls in place.

Certified by a JASANZ-accredited body, responsible AI isn't just something you claim. It's proof your customers, your partners, and regulators can trust; the recognised mark that you take the risks and responsibilities of AI seriously, and have built the system to manage them.

‍

Purple circular logo with text: Certified with Impact, ISO 42001, AI Management, by A Good Certification Group.
Trusted by CLIENTS AROUND THE WORLD

What is ISO/IEC 42001?

ISO/IEC 42001 is the world's first international standard for AI management systems. Published at the end of 2023, it's the recognised framework for governing artificial intelligence responsibly and as AI moves from experiment to everyday business tool, it's fast becoming the way organisations prove they're using it well.

The most important thing to understand is that ISO 42001 isn't a standard for the AI models themselves. It's a management system standard, in the same family as ISO 9001 and ISO 27001. It applies to any organisation that develops, provides, or uses AI systems, which today means almost everyone. You don't have to be an AI company to need it; if AI is making or shaping decisions in your business, 42001 is how you govern that responsibly.

The standard gives you a structured way to address the real challenges AI brings like ethics, accountability, transparency, and data privacy, rather than leaving them to chance. It helps you move from ad hoc AI use to structured, accountable AI management: knowing where AI is used across your organisation, understanding the risks, putting the right controls and human oversight in place, and improving as the technology (and the rules around it) evolve.

Four colleagues gathered around laptops, smiling and collaborating in a modern office meeting room.

DO WE NEED ISO/IEC 42001?

ISO/IEC 42001 is how you prove your organisation uses AI responsibly, and stay ahead of what's coming.

TCrust and transparency - AI is only as valuable as the trust people place in it. ISO/IEC 42001 shows your customers, partners, and regulators that the way you develop and use AI is governed, accountable, and transparent, not a black box nobody's watching.

Ready for what's coming - AI regulation is arriving fast, and expectations are tightening even faster. ISO 42001 gives you a structured framework that helps you meet emerging obligations more effectively, so you're prepared for new rules rather than scrambling to catch up.

A genuine market advantage - As AI becomes part of due diligence, more customers and tenders are asking how you govern it. Certification answers that question with independent proof, setting you apart from competitors who can only offer reassurances.

Real risk management - AI brings risks that other systems don't: bias, unintended outcomes, data misuse, decisions no one can explain. ISO 42001 helps you identify those risks across your organisation, put the right controls and human oversight in place, and manage them deliberately rather than hoping for the best.

Confidence to innovate - Good governance isn't a handbrake, it's what lets you move faster with less fear. With clear oversight and accountability in place, your team can adopt and scale AI knowing the guardrails are there.

Accountability across your organisation - ISO 42001 moves you from ad hoc AI use to a structured system: knowing where AI is used, who's responsible, and how it's controlled. That clarity protects your organisation and your people as AI becomes embedded in how you work.

EVERY AUDIT WE RUN IS
DESIGNED TO DO THREE THINGS.

01

GOOD FOR YOUR TEAM.

Practical improvements. Human-to-human conversations. Flexible, remote-first, and built around how and your team actually work.

02

Good ASSESSORS

People who are passionate about improving your business and genuinely invested in your growth, year after year.

03

Good for the world

Every audit funds health, community, and
environmental impact through our Good Fund. We're a B Corp and a 1% for the Planet member. This isn't a side project; it's embedded into everything we do.

THIS IS WHAT CERTIFICATION LOOKS LIKE WHEN IT GIVES A DAMN.
WELCOME TO BEING CERTIFIED WITH IMPACT™.

Six reasons we're
‍your partner

Internationally recognised

JASANZ and IAF accreditation. Recognised in 100+ countries. Listed on the IAF CertSearch register, giving clients, regulators, and government tenders the proof they need.

Collaborative by design

We look for conformity first. Where there's a gap, we work with your team to close it through practical recommendations in plain language, not a clause-by-clause finding list.

Flexible audits, built around yoU

Stage 1 is usually remote. Stage 2 is scheduled around your team, with asynchronous elements built in wherever possible. We adapt to you, not the other way around.

Consultant, DIY & platform-friendly

We play well with others. GRC platforms, internal consultants or your own internal setup - we fit seamlessly into your existing setup and keep things moving.

You’ll know us by name

From first enquiry to certificate, you'll have a dedicated point of contact at every stage. Our leadership team is hands-on; a member of our senior team attends every opening or closing meeting personally to say g’day. Call us, WhatsApp us, email us. Our door is always open.

People who are invested in your growth

We only work with auditors who are genuinely passionate about improving your business and invested in your business, year after year.

From G'day to
getting started.

Let's have a chat
‍

Book a discovery call with José, our CEO. This is really an opportunity to say G’day, have a conversation to understand your business, and see if we're the right fit.

We'll send you a quote within THE DAY

We’re upfront about our pricing. Transparent pricing based on your team size and business complexity. There are no hidden fees or surprises. And as a B Corp, we never want price to be a barrier. If you receive a more competitive quote from another JASANZ-accredited body, let us know, and we'll do our best to match it.

We get started
‍

Once you sign your fee proposal, our team will call you to welcome you to A Good Certification Group and walk you through the plan - tentative dates, your assessor, and everything you need to know before we kick off.

What our clients say

Certification Oceania were fantastic with our Surveillance audit! A Pleasure to work with, I couldn't recommend them more highly to anyone looking for a certification partner.

Natalia S, CEO
ISO 27001

I had a great experience working with Good Certification Group/Certification Oceania to achieve our ISO 14001 and ISO 45001, and maintain our ISO 9001 certifications. Their team was professional, knowledgeable, and easy to work with throughout the entire process.They provided clear guidance and practical support, making what can be a complex process feel smooth and well-managed.

Christabel W, Systems & Communications Manager
ISO 9001, ISO 45001 & ISO 14001

We recently completed our ISO 9001 certification with Certification Oceania and had a genuinely positive experience throughout the process. A special mention to our auditor, Niko Tovia, who was exceptional. His approach was not just about compliance, but about helping us truly understand our systems.

‍

Shikha P, Operations Manager
ISO 9001

Certification Oceania have been so professionally flexible, and able to adjust their auditing arrangements to suit our busy business ramp up. The process of audits is well explained in advance, and they are very genuine in finding and explaining tangible gaps within a Quality Management System that actually drive an improvement your business will grow from.

Jason H, Business Development Manager
ISO 9001

Jose, and all the team at Certification Oceania, are supportive and customer focused. Actevate will always recommend this company for their dedication to their clients and for making the certification process feel achievable and a lot less daunting.

Robert Migliore, Director/Founder
ISO 9001

How it works

YEAR 1

Stage 1

This is usually remote, and we can do this whenever you're ready

Think of this as your gap analysis. We review your documentation, identify what's looking good, flag any areas of concern, and make sure you're show-ready for Stage 2.

YEAR 1

Stage 2

We recommend roughly 1-4 weeks after Stage 1

This is where your system steps onto the main stage. Your assessor will review your operations, meet your team, and assess your management system against the requirements of your chosen standard. This can be done remotely, on-site or a hybrid of the two - we'll confirm what's right for your business during audit planning.

Your certificate will be issued within 2 weeks of your Stage 2.

‍

YEAR 2

Surveillance 1

We return to check progress, make sure your system is being maintained, and identify new opportunities to improve. We look at what's working well and where small tweaks could make a big difference, keeping your system strong, your team confident, and your certification meaningful.

‍

YEAR 3

Surveillance 2

This is about consistency and ongoing value. We assess long-term performance, review trends, follow up on previous improvements, and help you keep your system lean, effective, and useful. Because great certification isn't just about the moment you achieve it, it's about what you do with it over time.

YEAR 4

Recertification

Following two surveillance audits, you will have a recertification audit, where we will review all the requirements of your chosen standard(s) and reissue your certificate to reflect a new three-year certification cycle.

FAQs

Yes, quite possibly. ISO 42001 is for any organisation that uses AI, not just those that build it. If AI tools are helping make or shape decisions in your business, such as in hiring, customer service, analysis, content, (basically anything) then how you govern that use is exactly what the standard covers. You don't need to be developing your own models to have real responsibilities around the AI you rely on.

How you manage them. This is the most important thing to understand about the standard: ISO 42001 doesn't certify an individual AI model or tool as "safe" or "unbiased." It certifies that your organisation has a proper management system around AI including clear accountability, risk controls, human oversight, and transparency. It's about governance, not a stamp of approval on the technology itself.

That's exactly why a management system helps. ISO 42001 isn't tied to any particular AI tool or technique, it's built on continual improvement, designed to keep pace as the technology and the rules around it evolve. Rather than locking you into today's approach, it gives you a structure that adapts. Certifying now also positions you as an early mover on responsible AI, at a moment when customers and regulators are just starting to ask the question.

Any organisation, in any sector, that develops, provides, or uses AI: technology companies, financial services, healthcare, manufacturers, public bodies, and professional services alike. It's built to scale to organisations of any size, and to whatever role AI actually plays in your business, from a core product feature to a handful of tools your team uses day to day.

Yes! ISO 42001 shares the same underlying management-system structure as standards like ISO 9001 and ISO 27001, so it integrates neatly with certifications you may already hold. If you're certified to 27001 for information security in particular, you'll find a lot of common ground and we can look at auditing them together. Tell us what you already have and we'll work out the most efficient path.

Three years, like other ISO management system standards. After initial certification, we carry out lighter surveillance audits each year to confirm your AI management system is working in practice, then a recertification audit at the three-year mark.

Get Certified with impactTM