Certifying yourself vs certifying your company
These are two different things with two different price tags, and people arrive here looking for both. Getting yourself certified means earning an individual PECB credential — a course and an exam, from $399 + GST. Getting your company certified means building an AI management system and passing an audit by an accredited certification body, which is a project with its own budget and timeline.
Most of this guide is about the second one. If you want the first, these are the pages you want:
$399 + GST
ISO 42001 Foundation
Understand the standard — AI governance principles, the AIMS lifecycle, and where ISO 42001 meets ISO 27001.
$849 + GST
ISO 42001 Lead Implementer
Build the AIMS — scope it, run the AI risk and impact assessments, and take it to certification.
$849 + GST
ISO 42001 Lead Auditor
Audit the AIMS — plan and lead AI management system audits against ISO 19011.
Every ISO 42001 course includes the official PECB exam voucher and two attempts — the initial sit plus one free resit within 12 months — so there is no separate ISO 42001 exam cost to budget for. If you need the management system built or audited rather than a qualification, that is our ISO 42001 implementation service and internal audit service.
ISO 42001 course prices in Australia (2026)
Three official PECB tracks, all delivered by Aegentra Academy — Self-Study, live Online Class, or in-person Classroom in Melbourne & Sydney (available on request). Every enrolment includes the official PECB exam voucher and one free resit within 12 months.
| Course | Price (+ GST) | Best for |
|---|---|---|
| ISO 42001 Foundation | $399 + GST | Beginners, IT & risk staff, executives new to AI governance |
| ISO 42001 Lead Implementer | $849 + GST | AI, IT & compliance leads building an AIMS |
| ISO 42001 Lead Auditor | $849 + GST | Internal and external auditors, AI risk consultants |
What organisational ISO 42001 certification costs (2026)
Courses certify people. Certifying your company’s AIMS is a separate project — the realistic range for an Australian SMB:
| Cost item | Typical range (AUD) | Notes |
|---|---|---|
| Readiness / implementation | $22,000–$45,000 | With an existing ISO 27001 ISMS; greenfield runs higher |
| Stage 1 + Stage 2 certification audit | $10,000–$22,000 | Performed by an accredited certification body |
| Annual surveillance audit | Starting at $2,500 | Years 1 and 2 |
| Re-certification audit | $9,000–$17,000 | Year 3 |
Core Requirements of ISO 42001 (Clauses 4–10)
ISO/IEC 42001:2023 follows the Annex SL harmonised structure shared by ISO 27001 and other management-system standards, so its requirements sit across seven clauses. Alongside them, Annex A defines 38 controls covering AI impact assessment, data quality and bias management, third-party AI provider management, and transparency.
- Clause 4 — Context of the organisation. Define the explicit boundaries, internal and external issues, and the scope of your company’s AI applications.
- Clause 5 — Leadership & governance. Establish a clear AI policy, define roles, and enforce accountability for responsible AI development or deployment.
- Clause 6 — Planning & risk assessment. Conduct comprehensive AI risk assessments and AI impact assessments (AIIA) to map systemic, ethical, and compliance risks.
- Clause 7 — Support & competency. Provide the resources, team competencies across the AI lifecycle, and documented information the AIMS needs to run.
- Clause 8 — Operation & lifecycle controls. Execute data governance, design practices, system testing, monitoring, and human-in-the-loop mechanisms across the AI lifecycle.
- Clause 9 — Performance evaluation. Run internal audits, monitor KPIs, and hold periodic management reviews to measure the effectiveness of the AIMS.
- Clause 10 — Continual improvement. Implement corrective actions for nonconformities, algorithmic bias, and model-drift events.
Practical ISO 42001 Implementation Framework
Certification moves an organisation from ad-hoc AI use to structured, accountable governance. In practice, a readiness program runs in five steps.
- Establish AIMS scope. Define whether your governance targets internally developed AI models or third-party enterprise AI tools — or both.
- Perform a gap analysis. Evaluate your existing security and governance policies against the 38 technical controls in Annex A.
- Construct an AI risk register. Quantify operational, ethical, regulatory, data-provenance, and model-failure vulnerabilities.
- Deploy lifecycle controls. Enforce transparency safeguards, explainability requirements, and continuous drift monitoring.
- Internal audit & certification assessment. Run a pre-assessment internal audit before engaging an independent body for formal certification. Clause 9.2 requires an impartial auditor, so this is normally an independent ISO 42001 internal audit rather than a self-review.
Preparing the evidence and audit workpapers? Use the free ISO 42001 internal audit checklist for the Clause 9.2 evidence pack, sampling record and findings fields.
Most organisations do not run these five steps alone. Our ISO 42001 implementation service builds the AIMS alongside your team inside your own Microsoft 365 tenant, and leaves your people owning it.
What is ISO 42001?
ISO/IEC 42001 is the first international management system standard for Artificial Intelligence Management Systems (AIMS). It was published in December 2023 by ISO and IEC. The standard tells an organisation how to govern AI: how to plan AI use cases, identify and treat AI-specific risks (bias, drift, opacity, privacy, safety, intellectual property), embed human oversight, manage data quality, audit performance, and continually improve.
Structurally, ISO 42001 mirrors ISO 27001 — the same Annex SL High-Level Structure runs through both: context of the organisation, leadership, planning, support, operation, performance evaluation, improvement. If you have already built an ISO 27001 Information Security Management System, the framework feels immediately familiar.
The difference is in the Annex A controls. ISO 42001 introduces a new set of AI-specific controls covering organisational policy for AI, internal capability and competence, the AI system lifecycle, data for AI, information for interested parties (transparency to users and regulators), AI system use, and third-party relationships. The controls do not prescribe how to build a specific AI feature — they prescribe how to govern AI as a portfolio.
Who needs ISO 42001 certification in Australia?
The Australian Government published the Voluntary AI Safety Standard in 2024, and is consulting on mandatory guardrails for high-risk AI use cases. ISO 42001 is the international certifiable companion that procurement teams and regulators can accept evidence against. Expect to see ISO 42001 referenced alongside ISO 27001 in tenders from 2026 onward.
The organisations most likely to need ISO 42001 in the next 12 months:
- SaaS companies that have shipped AI features — particularly LLM-powered assistants, classifiers, or decision-support inside their product. Enterprise buyers are now asking AI-specific questions in procurement.
- Companies selling into the EU — the EU AI Act's phased application makes ISO 42001 the most defensible evidence base for high-risk and limited-risk AI systems.
- Australian government suppliers using AI — federal AI assurance frameworks reference international standards; ISO 42001 is the obvious match.
- Healthcare, finance, and legal AI applications — regulators in these sectors are already asking how models are governed, monitored, and overseen by humans.
Industries that need ISO 42001 in Australia
Four sectors are driving early Australian ISO 42001 demand: SaaS shipping AI features into enterprise procurement, federal and state government AI users and suppliers, healthcare and TGA-regulated medical AI, and APRA/ASIC-regulated financial services using algorithmic decisioning. The regulatory pressure differs in each, but the management-system answer is the same.
SaaS companies shipping AI features
The Australian SaaS market shifted in 2024-2025 — enterprise procurement teams now include AI-specific questions in vendor security questionnaires. Buyers want evidence that LLM-powered assistants, classifiers, recommendation engines, and decision- support tools are governed end-to-end: trained on lawful data, monitored for drift, supervised by humans where it matters, and subject to incident response. ISO 42001 is the certifiable third-party framework that satisfies the question. For SaaS companies selling into Europe, ISO 42001 also becomes the most credible evidence base under the EU AI Act's phased application.
Federal and state government AI users and suppliers
The Policy for the responsible use of AI in government (DTA, 2024) imposes governance, accountability, and transparency expectations on Commonwealth agencies using AI. State governments (NSW AI Assurance Framework, Victoria's AI guidance) follow similar lines. Suppliers building or embedding AI for government inherit those expectations contractually. ISO 42001 is the international certifiable framework that satisfies them — and the most efficient way for a supplier to evidence AI governance maturity in a tender response.
Healthcare and TGA-regulated medical AI
Software as a Medical Device (SaMD) using machine learning is regulated by the Therapeutic Goods Administration under the medical-device framework. The TGA expects manufacturers of AI/ML-based SaMD to maintain documented governance over training data, model lifecycle, change management for retraining, and post-market monitoring. ISO 42001 provides the management system in which those obligations live. Clinical decision- support tools and digital-health vendors using AI face the same expectation through ADHA assessments.
APRA/ASIC-regulated financial services
APRA-regulated entities using AI in credit decisioning, fraud detection, insurance underwriting, or customer-service automation face prudential expectations on operational risk (CPS 230) and information security (CPS 234) that necessarily cover the AI systems. ASIC's guidance on algorithmic decision-making (touching RG 271 and broader consumer-protection obligations) reinforces the expectation. ISO 42001, layered on top of an ISO 27001 ISMS, is the cleanest documentary answer to both prudential and conduct regulators.
Mapping ISO 42001 to Australian AI regulation
Australia's AI regulatory landscape is fragmented and rapidly evolving, but most of it can be satisfied with the same underlying AI management system. The table summarises how ISO 42001 maps to the policies and frameworks Aegentra is most often asked about.
| Policy / framework | What it requires | How ISO 42001 helps |
|---|---|---|
| Voluntary AI Safety Standard (DISR, 2024) | Ten voluntary guardrails for organisations developing or deploying AI, covering governance, risk, transparency, human oversight, data quality, and continuous improvement. | ISO 42001 is the certifiable companion. The DISR guardrails map onto ISO 42001 clauses and Annex A controls — a certified AIMS is the most efficient evidence base. |
| Australia's AI Ethics Principles | Eight principles (human, societal, environmental wellbeing; human-centred values; fairness; privacy; reliability; transparency; contestability; accountability). | The AIMS structure operationalises the principles — turning each from a statement into a control set with evidence, monitoring, and review. |
| Policy for responsible use of AI in government (DTA) | Federal agencies must designate accountable officials, maintain transparency on AI use, and operate governance appropriate to risk. | Suppliers building or embedding AI for government use ISO 42001 as the recognised framework for the governance evidence agencies expect to inherit through the contract. |
| Privacy Act 1988 (APPs) + OAIC AI guidance | APP 11 reasonable-steps obligation for protecting personal information, including in AI training and inference. OAIC AI guidance reinforces transparency expectations. | AIMS controls on data quality, training-data lineage, and transparency provide documentary evidence of reasonable steps under APP 11 for AI workloads. |
| APRA CPS 230 / CPS 234 | Operational risk and information-security obligations for APRA-regulated entities, which necessarily include AI workloads making consequential decisions. | ISO 42001 layered on top of an ISO 27001 ISMS is the standard pattern for satisfying both CPS 230 op-risk and CPS 234 information-security expectations as they apply to AI. |
| TGA AI/ML SaMD framework | Manufacturers of AI/ML-based Software as a Medical Device must maintain documented governance over training data, model lifecycle, change control, and post-market monitoring. | ISO 42001 provides the AI-specific management-system structure inside which the SaMD lifecycle obligations live. Combined with ISO 13485, it forms the standard evidence package. |
| EU AI Act | Binding EU law (in force 2024, phased through 2027) imposing tiered obligations on AI providers and deployers — particularly for high-risk AI systems. | ISO 42001 is widely expected to be one of the harmonised standards the Act references. For Australian SaaS companies selling AI into the EU, certification is the most efficient evidence base. |
| NIST AI RMF | Non-binding US guidance on AI risk management — used by US federal agencies and many US enterprise buyers. | ISO 42001 and NIST AI RMF are complementary: many Australian organisations use NIST AI RMF as the working model and ISO 42001 as the framework they audit against. |
The pattern across Australia's evolving AI policy landscape is the same: ISO 42001 is rarely a literal requirement (the policies are mostly voluntary or sector-specific), but it is the most efficient documentary answer to a procurement team, a regulator, or a board asking "show me your AI management system."
How long does ISO 42001 certification take?
For an Australian SMB that already has ISO 27001 in place, a realistic plan is 10–14 weeks of readiness followed by a Stage 1 / Stage 2 audit. That assumes a single AIMS scope covering a small portfolio of AI use cases. Add 4–6 weeks per additional major AI product line.
For an organisation starting from scratch (no ISMS, no formal AI register, no model inventory), 16–22 weeks is more realistic — most of the additional time is spent inventorying current AI use, classifying risk, and writing the governance documents that ISO 27001 implementers usually already have.
Audit booking remains the practical bottleneck. Most JAS-ANZ recognised certification bodies in Australia are still building ISO 42001 audit capability; book Stage 2 in week 1 of readiness, not week 11.
How much does ISO 42001 certification cost in Australia?
Individual PECB training (Aegentra Academy)
- ISO 42001 Foundation — $399 + GST
- ISO 42001 Lead Implementer — $849 + GST
- ISO 42001 Lead Auditor — $849 + GST
Organisational certification
Ranges below are typical for an Australian SMB of 10–50 staff that already operates an ISO 27001 ISMS. Greenfield (no ISMS) adds roughly 30–50% to readiness.
| Component | Typical AUD | Frequency |
|---|---|---|
| Readiness consulting (existing ISMS) | $22,000–$45,000 | Once |
| Stage 1 + Stage 2 audit | $10,000–$22,000 | Once (every 3 years) |
| Annual surveillance | Starting at $2,500 | Year 1 + Year 2 |
| Three-year re-certification | $9,000–$17,000 | Year 3 |
Note: ISO 42001 audit pricing is rising in 2026 because certification body capacity is still scaling up. Budget toward the higher end of the range.
The certification process, step-by-step
- 01AI inventory and scope
List every AI system in use, whether built in-house, embedded from a vendor (e.g. Azure OpenAI, Anthropic, AWS Bedrock), or buried inside a SaaS product. Decide which sit inside the AIMS scope.
- 02AI risk assessment
For each in-scope AI system, identify risks across the standard’s expected dimensions: bias, accuracy, robustness, transparency, accountability, privacy, safety, intellectual property. Document treatment decisions.
- 03AIMS design
Write the AI policy, the Statement of Applicability, the model lifecycle process, the human-oversight rules, the data-for-AI controls, and the supplier requirements for AI vendors.
- 04Control implementation
Operationalise the controls inside your engineering and product processes — model cards, evaluation suites, drift monitoring, human-in-the-loop checkpoints, change control for fine-tuning, prompt logging where applicable.
- 05Internal audit
An independent reviewer (not the implementer) audits every applicable control against your evidence. Often integrated with the ISO 27001 internal audit.
- 06Management review
Leadership formally reviews the AIMS performance, AI incidents, and improvement opportunities. Minutes go into the audit pack.
- 07Stage 1 audit
Documentation review by an accredited certification body. Remote, 1–2 days for an SMB.
- 08Stage 2 audit
Effectiveness audit. Evidence sampling against each applicable control, interviews with engineers and product owners. 2–4 days for an SMB.
- 09Certificate issued
Valid for three years. Annual surveillance in years one and two; full re-certification in year three.
Answers by role: procurement, vendors and CTOs
ISO 42001 looks different depending on which side of the deal you are on. These are the questions we are actually asked, answered plainly.
As a procurement team, how do we evaluate an ISO 42001 certification a supplier claims?
Ask for the certificate itself and check four things on it, in this order. The certification body and its accreditation — an unaccredited certificate is not worthless but it is not equivalent; look for JAS-ANZ or another IAF-recognised accreditation. The scope statement, which is where most of the value sits: a certificate scoped to one product line tells you nothing about the AI in the product you are buying. The issue and expiry dates, since certificates run three-year cycles with annual surveillance. Then ask for the Statement of Applicability.
That last request is the one that separates a real certification from a decorative one, and almost nobody makes it. The SoA lists all 38 Annex A controls with the supplier’s own justification for each — you can see immediately whether they thought about AI impact assessment and data provenance or ticked boxes. Ours is published in full so you can see what a complete one looks like before you ask.
As an AI vendor, how do we justify the cost of ISO 42001 certification?
Not as a compliance line item — that argument loses. Justify it in deal terms, because that is where it actually pays. The question is not what certification costs, it is what the security review costs you today. Count the engineering and executive hours currently spent answering bespoke AI questionnaires per deal, the deals that stall in review, and the deals lost outright because a buyer could not get comfortable.
Certification replaces that recurring, unpredictable cost with a fixed one. The second argument is timing: ISO 42001 was published in December 2023, so being certified now is still a differentiator. In two years it will be table stakes and the same spend will buy you parity rather than advantage. The third, if you sell into the EU, is that the AI Act work is coming regardless and an AIMS covers a large part of it.
As the CTO of an Australian SaaS company, how long does ISO 42001 certification take?
Plan on four to six months from kickoff to certificate for a company already running an ISO 27001 ISMS, and six to nine if you are starting from nothing. The management-system half is familiar if you hold ISO 27001 — same Annex SL clauses — so the time goes on the AI specifics: building an inventory of every AI system including the ones teams adopted without telling anyone, and running impact assessments on the ones that affect people.
The long-lead item is the certification body, which wants six to ten weeks of notice. Book that slot early, not when you feel ready.
As a founder, do we need ISO 42001 or is an AI policy enough?
A policy is enough until a buyer asks for evidence, and then it is not. The honest test: if an enterprise customer asked today how you govern the AI in your product, could you show them an inventory, an impact assessment, and a record of who reviewed what — or would you send them a document nobody has opened since it was written?
If AI is incidental to your product, a policy plus Australia’s ten voluntary guardrails is a reasonable place to stop. If AI is the product, or you sell to enterprise or government, certification is where this ends up and starting earlier is cheaper than starting under deal pressure.
Choosing a PECB ISO 42001 course
Three pathways are commonly taken in Australia, in order of depth: Foundation (week-long overview), Lead Implementer (practitioner course — the one your internal AIMS owner needs), and Lead Auditor (for internal auditors and certification body career paths). For the credential pathway itself — the experience tiers and what the role does day to day — see how to become an ISO 42001 Lead Implementer.
The Lead Implementer course covers the standard end-to-end: scope, risk treatment, the Statement of Applicability, control implementation, internal audit preparation, and management review. The official PECB exam is included; the credential is accredited by ANAB under ANSI/ASTM E2659-24 and recognised internationally.
Aegentra Academy is an official PECB authorised training partner in Australia — verified on the PECB partner directory. Courses include the exam voucher and a free resit within 12 months. Available online, with instructor-led classroom sessions in Melbourne and Sydney on request.
ISO 42001 vs ISO 27001 and the EU AI Act
ISO 42001 is not a replacement for ISO 27001. The two standards are complementary. ISO 27001 governs information security across the whole organisation; ISO 42001 governs the AI subset specifically — adding controls for model lifecycle, bias and fairness, transparency to data subjects, human oversight, and AI-specific supplier obligations.
Most Australian AI-led SaaS companies pursuing certification do ISO 27001 first (because the wider buyer base already understands it) and then add ISO 42001 within 6–12 months. The integrated management system (one ISMS + AIMS, one set of policies, one internal audit programme) is the sustainable target.
On the EU AI Act: ISO 42001 is not a one-to-one match, but it is widely expected to be one of the harmonised standards European regulators reference. If your roadmap includes European customers in the next 24 months, ISO 42001 certification is the most efficient evidence base to point procurement and regulators at.
FAQs
Aegentra Academy offers accredited ISO 42001 training tracks starting at $399 + GST for Foundation, and $849 + GST for both Lead Implementer and Lead Auditor tracks. All options include official PECB examination vouchers and a 12-month free resit policy.
ISO 42001 specifies requirements across Clauses 4 to 10 (Annex SL structure) covering organizational context, leadership governance, AI risk and impact assessments, resource competency, operational lifecycle controls, performance evaluation, and continual improvement for AI Management Systems (AIMS).
No. ISO 42001 is voluntary in Australia, but it is the most widely recognised international management system standard for AI governance. The Australian Government published a Voluntary AI Safety Standard in 2024 covering similar ground; ISO 42001 is the certifiable companion that procurement teams can accept evidence against. Federal AI procurement requirements are evolving — expect ISO 42001 to be referenced in tenders from 2026 onward.
No, but it helps significantly. ISO 42001 is built on the same High-Level Structure as ISO 27001 — context, leadership, planning, support, operation, evaluation, improvement. If you already have a working ISMS, you have roughly 60% of the framework in place. If you do not, you can implement ISO 42001 standalone, but most practitioners do ISO 27001 first because the wider buyer base understands it.
The NIST AI Risk Management Framework (NIST AI RMF 1.0) is a U.S. guidance document — it tells you how to think about AI risk. ISO/IEC 42001 is a certifiable international management system standard — it tells you what to build, document, and audit. Many Australian organisations use NIST AI RMF as the working model and ISO 42001 as the framework they audit against.
The EU AI Act is binding law in the European Union (in force 2024, with phased application through 2027). ISO 42001 is a voluntary international standard. Compliance with ISO 42001 does not automatically equal EU AI Act compliance, but the Act explicitly references harmonised standards and ISO 42001 is widely expected to be one of them. For Australian SaaS companies selling AI products into the EU, an ISO 42001 certification is the practical fast lane.
You define the scope. ISO 42001 applies to any organisation developing, providing, or using AI systems. Scope typically covers the AI use cases inside a product, the data pipelines feeding them, the model lifecycle (development → deployment → retirement), the human oversight controls, and the supplier chain (cloud AI APIs you embed). Generative AI features, classifiers, recommendation engines, and decision-support systems are all common scopes.
No. The course certifies you as an individual to implement ISO 42001 — it does not certify your company. To certify your company you need to actually build the AIMS, run an internal audit, and pass a Stage 1/Stage 2 audit by an accredited certification body. The Lead Implementer course teaches you how to do that work.
Yes — that is the recommended approach. Both standards share the High-Level Structure (Annex SL), so the management system documents (context, leadership, risk treatment, internal audit, management review) can be unified. The Annex A controls are different and need to be implemented separately, but the governance loop is the same. Most Australian AI-led SaaS companies run a single integrated ISMS + AIMS.
Three years, identical to ISO 27001. Annual surveillance audits in years one and two; full re-certification audit in year three. Surveillance is lighter than the initial Stage 2 — usually a sample of controls plus a review of changes to the AI estate (new models deployed, new use cases scoped).