Regulation moves at the speed of parliaments. Procurement moves at the speed of quarterly reviews, and that is why ISO/IEC 42001 matters more with each passing month. It is the international standard for AI management systems: certifiable, auditable, structured around thirty-eight controls covering how an organisation governs the AI it builds and buys. No Australian law requires it. An increasing number of enterprise customers, insurers and government panels are asking for it anyway, or asking questions that only an organisation running something like it can answer.

This is how standards win in practice: not by mandate but by becoming the easiest honest answer to "how do you govern your AI". The organisations fielding that question weekly have noticed that assembling a bespoke answer every time costs more than having a management system whose answer is a certificate and a statement of applicability.

Certification is not the point. Being the kind of organisation that could pass tomorrow is the point.

What the standard actually asks

Strip the clause numbers and 42001 asks for things no serious operator resents: know what AI you have and what data it touches; assess impacts before you deploy, not after the incident; put a named human in charge of each system; test and monitor; manage your suppliers, because most organisations' AI risk arrives through vendors; keep records that would let an outsider reconstruct what you did and why. It is a management system, not a moral philosophy, and that is its strength: management systems are checkable.

The Australian angle

Everything signalled locally, the voluntary standard, the six essential practices, the AI Safety Institute's testing remit, rhymes with the same structure: registers, risk assessment, human accountability, evidence. Whatever shape mandatory rules eventually take here, an organisation aligned to 42001 will find the delta small, because governments do not invent governance frameworks from nothing; they harden the ones already circulating. Alignment now is the cheapest hedge available against whatever "mandatory" turns out to mean.

Our advice is unromantic: do the gap assessment, fix what is embarrassing, and decide on certification commercially, based on who is asking for it in your pipeline. The assessment costs weeks. The retrofit after a lost tender, or a regulator's letter, costs quarters.

What to do about it

  • Run a gap assessment against 42001's controls, honestly scored, with owners against each gap.
  • Close the gaps that are cheap and the ones that are dangerous. They are rarely the same list.
  • Decide on certification by looking at your customers' questionnaires, not your competitors' press releases.
  • Keep the management system live: a binder assembled for an audit is not a system, it is scenery.

We run these assessments as the entry point of our AI governance practice, and the finding is always the same shape: less is missing than feared, and what is missing is exactly what a regulator would ask for first.