GRC Advisory & Audit

AI Governance Framework

A lightweight, AI governance framework that extends your existing ISMS, without a full ISO 42001 implementation.

We hold the standards we help you meet.
Australian-owned &
operating since 2017.

AI adoption is moving faster than most organisations' governance. Staff are using public AI tools, AI features are being built into products, and boards, customers, and regulators are starting to ask how it's all being managed.

ISO 42001 is the international standard for AI Management Systems (AIMS), but full implementation and certification is a significant commitment that not every organisation is ready for. The AI Governance Framework is a proportionate alternative comprised of AI-specific policies, processes, and risk treatments that extends your existing ISO 27001 ISMS to cover the AI-specific risks and obligations that sit outside its scope.

You get AI governance in place now, without a second management system to maintain. Where commercial or regulatory drivers later require certification, the framework can be expanded into a full ISO 42001 implementation.

Why choose our AI Governance Framework

Proportionate to your AI footprint

Most organisations don't need full ISO 42001 implementation, and many won't ever need it. This framework provides a starting point that extends what you already have, rather than asking you to stand up a parallel system.

Extends your existing ISMS

The framework extends the policies and processes your team already follows - Acceptable Use, Risk Management, SDLC, Cloud Provider Security - rather than in a separate framework to be maintained independently.

Covers what ISO 27001 doesn't

Acceptable use of public AI tools, AI use case discovery, AI impact and threshold assessment, AI-specific incident response, and structured AI risk identification aren't well covered by ISO 27001 alone. This framework fills that gap without over-engineering it.

Optionality preserved

Clients who later face commercial or regulatory pressure to certify to ISO 42001 can progress from the framework to full implementation, with the framework artefacts forming the basis of the full AIMS foundation.

Senior consultants, based in Australia

Scoped and delivered by senior consultants based in Brisbane and surrounds, working with clients across Australia. On-shore data handling, local context, and clear accountability.

Frequently asked questions.

Straight answers to the questions we hear most. Can't find yours? We're happy to help.

Why not just go straight to ISO 42001 implementation?

If you have a commercial or regulatory driver requiring certification, you probably should. The framework is for organisations where the answer to "do we need ISO 42001 certification?" is "not yet, or not at all". It gets governance in place now without the operating overhead of a second management system.

We already have an acceptable use policy covering AI. Isn't that enough?

An acceptable use clause covers staff use of AI tools but doesn't address AI use cases you deploy, AI risk assessment, AI incident response, or AI impact thresholds. The framework covers all of these and updates your acceptable use policy as one of several artefacts, rather than treating it as the only one.

Will this prepare us for ISO 42001 certification later?

It puts you on the path. The governance framework produced is ISO 42001-aligned and can be carried into a future implementation. It doesn't constitute certification readiness on its own though - a full implementation includes additional management system requirements the framework doesn't deliver.

What if we don't have ISO 27001 yet?

The framework is designed to extend an existing ISMS rather than stand alone. Where you don't have one, we can provide a foundational information security governance framework along with the AI governance framework.

Where is your team based?

Our consultants are based in Australia, including a core group of Brisbane penetration testers, with engagements delivered both nationally and internationally. Testing, reporting, and walkthroughs are handled by the same senior consultant from start to finish. You get clear accountability, on-shore data handling, and the local context that comes from working with Australian organisations every day.

Case Studies

Proof in practice.

A snapshot of how we've helped Australian organisations strengthen security, meet stakeholder expectations, and move forward with confidence.

Two Askable team members working at a screen in their Brisbane office
"There’s being secure, and there’s appearing to be secure, and Acumenis has really achieved both of those things for us."
scott-goleby
Scott Goleby
Co-founder and Director
Acumenis

Let's talk about where you are and where you need to be.

Whether you're preparing for certification, validating your controls, or building security foundations for growth, we'll help you get there with clarity and confidence.

Contact Form

Acumenis is committed to protecting and respecting your privacy, and we'll only use your contact information to provide services and information to you. For more details, please review our Privacy Policy.

Success
Thanks for getting in touch.
Your message has come through and one of our senior consultants will respond within one business day.
If it's urgent, you're welcome to call us on 1300 450 970.
Follow the team, join the conversation, and see what we’re working on across Australian cyber security.
Oops! Something went wrong while submitting the form.