Black Shard

ISO 42001 readiness in Australia.

An ISO 42001 readiness assessment: a gap analysis against ISO/IEC 42001, a prioritised remediation plan, and evidence preparation for certification audit, led by a certified ISO/IEC 27001:2022 Lead Auditor.

Organisations across Australia are adopting AI faster than they are governing it. ISO/IEC 42001:2023, the international standard for an AI management system, is where that readiness starts: the governance, risk and operating discipline an organisation runs around the AI it builds, buys or embeds in a product, reviewed the same way an information security management system is reviewed under ISO 27001.

Black Shard builds and operates production AI systems as well as assessing how other organisations govern theirs. Aurii, clinical software the firm built and operates, runs Azure AI Speech recognition and OCR pipelines and isolates tenant data with PostgreSQL row-level security in Azure's Australia East region. The firm's AI and automation engineering practice builds audit trails and guardrails around every automated action it ships. Readiness work for a client's AI management system is led from that engineering practice.

What ISO 42001 is, and who is asking for it

ISO/IEC 42001:2023 sets out what an organisation has to do to run AI responsibly and prove it: define the scope of its AI management system, assess and treat the risks each AI system carries, set policy and objectives, assign roles and competence, operate documented controls, monitor performance after deployment, run internal audits and hold management reviews. Like ISO 27001, it follows the common high-level management-system structure, and an accredited certification body audits it in two stages: a documentation review, then an audit of the system in operation.

The demand is coming from three directions at once. Customers and enterprise buyers are adding AI governance questions to security questionnaires and vendor due diligence, on the same footing as the information security questions already there. Tender panels are naming ISO 42001 directly in some briefs, and asking how AI use is governed where a supplier has none. Boards are being asked by their own risk committees, by insurers and by the regulators that oversee their sector to show how AI use across the organisation is controlled.

What an AI management system actually contains

The management system starts with an AI policy that states what the organisation permits, by whom, and under what oversight, and a system inventory that names every AI system in use or under development, from a customer-facing chat assistant to a model embedded inside a product, plus every third-party AI tool a team has adopted without anyone recording it.

Each system in that inventory is risk-assessed on its own terms. A statement that the organisation manages AI risk in general does not survive an auditor asking which system, used for what, assessed against which criteria. Where a system affects people, an impact assessment covers what that effect could be: a safety outcome, a decision that touches someone's rights, an output nobody checked before it reached them. Controls follow from both: over the AI life cycle from design to retirement, over the data the systems are trained or run on, over third-party and supplier AI, and over the human oversight built into each automated action. Monitoring closes the loop after deployment, tracking performance and drift and feeding incidents back into the risk register.

  • An AI policy stating what is permitted, by whom, and under what oversight
  • A system inventory naming every AI system in use or under development, including adopted third-party tools
  • Risk assessment scoped to each system's specific use
  • Impact assessment for systems that affect people, covering safety, rights and unreviewed outputs
  • Controls across the AI life cycle, data governance, third-party AI and human oversight
  • Monitoring after deployment, with performance and incidents feeding back into the risk register

The readiness assessment

Readiness starts with a gap analysis: the AI management system is scoped against the systems actually in use, and each clause and control in the standard is assessed as met, partial or missing against that environment. Certification, where that is the target, is a stage-two evidence audit in the same way ISO 27001 is. The auditor samples the internal audit, the management review, a risk assessment for a specific system, a monitoring record. A management system switched on weeks before the audit has nothing to sample.

The remediation plan is prioritised against whichever date is driving the work, a tender close, a board deadline, or a certification audit, and sequenced backwards from it: the machinery that needs elapsed time, the internal audit and management review cycle, starts first, so operating records accumulate while the rest of the gaps close.

  • A gap analysis against ISO/IEC 42001, assessed against the AI systems actually in use
  • A prioritised remediation plan sequenced against your target date, whether that is a tender, a board deadline or a certification audit
  • Evidence preparation for the certification audit, built as the gaps close
  • A gap analysis usable on its own, for organisations that need the governance uplift without pursuing certification

How this maps to the Voluntary AI Safety Standard

The Australian Government published the Voluntary AI Safety Standard in 2024: ten guardrails covering accountability and governance, a risk management process, data governance, testing and monitoring, human oversight, transparency to the people affected by an AI-enabled decision, a way for them to challenge it, transparency along the AI supply chain, record-keeping, and stakeholder engagement. It is voluntary and self-assessed. There is no accredited audit and no certificate.

The guardrails were written to align with international standards including ISO/IEC 42001, and the overlap is substantial. An AI policy and accountable roles satisfy the governance guardrail, the risk assessment and treatment work satisfies the risk management guardrail, the system inventory and monitoring work satisfies testing and monitoring, and the human oversight controls satisfy the guardrail written for exactly that. An organisation that only needs to answer the Voluntary AI Safety Standard gets there through the same gap-analysis method, without certification-body cost. An organisation pursuing ISO 42001 certification gets the guardrails covered as part of the readiness work.

ISO 42001 and ISO 27001 together

The two standards share the same high-level management-system structure: scope, leadership, risk assessment, objectives, competence, operational controls, monitoring, internal audit and management review sit in both. For a firm that already holds or is pursuing ISO 27001, standing up the AI management system as a separate, unrelated program duplicates work the information security management system already does. The internal audit schedule, the management review cadence, the risk register, and a share of the Annex A controls (access control, logging, secure development and supplier management among them) cover ground both standards need. An integrated management system runs both on one set of management machinery instead of two.

Readiness work here is led by a director who holds the Exemplar Global Certified Lead Auditor credential for ISO/IEC 27001:2022. That credential's management-system audit discipline, scoping, risk treatment, control mapping and evidence-based internal audit applies to ISO/IEC 42001 the same way. Certification itself is issued by an accredited certification body: Black Shard prepares the organisation and its evidence for that audit.

What does ISO 42001 readiness cost?

Readiness runs as a defined program with milestones toward your target date, quoted before work starts. The drivers are the scope, how many AI systems sit inside the boundary, including any that are self-hosted, fine-tuned, or embedded as a third-party tool in a workflow; the starting position, how much AI governance, risk assessment or vendor due diligence already exists; the gap depth, how much of the standard is a policy and process change and how much needs engineering work in a live system; and the runway, whether the target date leaves room for the internal audit and management review cycle to generate records. Certification-body fees, where certification is the target, are separate, paid to the certification body directly, and recur on an annual and three-year cycle.

Send a brief to [email protected] with the AI systems you have in mind, who is asking for ISO 42001 or the Voluntary AI Safety Standard, and your target date.

Questions, answered

What does the Lead Auditor credential bring to ISO 42001 work?
The credential is for ISO/IEC 27001:2022. What it brings to ISO 42001 readiness is management-system audit discipline, scoping, risk treatment, control mapping and evidence-based internal audit, applied to the AI standard.
Can Black Shard certify us against ISO 42001?
No. Certification is issued by accredited certification bodies after a documentation review and an audit of the management system in operation. A firm that did the readiness work cannot audit its own work. We prepare organisations for that audit; the certificate comes from the certification body.
Do we need ISO 42001 if we already meet the Voluntary AI Safety Standard, or the other way round?
Depends what is asking. The Voluntary AI Safety Standard is self-assessed with no certificate, so it answers a buyer or board that wants to see AI governed responsibly. ISO 42001 is independently audited and certified, which is what an enterprise or government tender is more likely to name. The guardrails and the standard's clauses overlap substantially, so readiness work toward one covers most of the other.
How long does ISO 42001 readiness take?
The gap-closing work is rarely the constraint. Where certification is the target, the management system has to operate long enough to generate the records a stage-two audit samples: an internal audit, a management review, a risk assessment tied to a real system. We sequence that machinery first so records accumulate while the rest of the gaps close, and we say early if a target date does not leave room for it.
Do you work with organisations outside Brisbane?
Yes. An Australian firm, head office in Brisbane, delivering Australia-wide. Readiness work is largely remote: scoping, the gap analysis against your AI systems, documentation, and the management cycle all run without anyone travelling.

Tell us which AI systems you run, and who is asking for ISO 42001.

Brisbane head office. Work delivered across Australia.

Open a brief[email protected]