AI Governance Framework
A lightweight, AI governance framework that extends your existing ISMS, without a full ISO 42001 implementation.


operating since 2017.
AI adoption is moving faster than most organisations' governance. Staff are using public AI tools, AI features are being built into products, and boards, customers, and regulators are starting to ask how it's all being managed.
ISO 42001 is the international standard for AI Management Systems (AIMS), but full implementation and certification is a significant commitment that not every organisation is ready for. The AI Governance Framework is a proportionate alternative comprised of AI-specific policies, processes, and risk treatments that extends your existing ISO 27001 ISMS to cover the AI-specific risks and obligations that sit outside its scope.
You get AI governance in place now, without a second management system to maintain. Where commercial or regulatory drivers later require certification, the framework can be expanded into a full ISO 42001 implementation.
Best for
Organisations with an existing ISO 27001 ISMS (or one in active implementation) who want to bring AI under formal governance quickly and proportionately, without committing to a second management system standard.
Why choose our AI Governance Framework
Proportionate to your AI footprint
Most organisations don't need full ISO 42001 implementation, and many won't ever need it. This framework provides a starting point that extends what you already have, rather than asking you to stand up a parallel system.
Extends your existing ISMS
The framework extends the policies and processes your team already follows - Acceptable Use, Risk Management, SDLC, Cloud Provider Security - rather than in a separate framework to be maintained independently.
Covers what ISO 27001 doesn't
Acceptable use of public AI tools, AI use case discovery, AI impact and threshold assessment, AI-specific incident response, and structured AI risk identification aren't well covered by ISO 27001 alone. This framework fills that gap without over-engineering it.
Optionality preserved
Clients who later face commercial or regulatory pressure to certify to ISO 42001 can progress from the framework to full implementation, with the framework artefacts forming the basis of the full AIMS foundation.
Senior consultants, based in Australia
Scoped and delivered by senior consultants based in Brisbane and surrounds, working with clients across Australia. On-shore data handling, local context, and clear accountability.
Outcomes
After your engagement, you'll have:
- AI governance processes embedded in your existing ISMS
- A discovered and documented view of how AI is being used across the organisation
- Updated policies bringing AI into scope of your existing governance
- Completed use case templates that make the framework concrete
- (Standard and above) AI risks identified, rated, and treatment-mapped in your risk register
- (Advanced) Staff trained on safe AI use, and the response process tested before it has to work for real
Frequently asked questions.
Straight answers to the questions we hear most. Can't find yours? We're happy to help.
If you have a commercial or regulatory driver requiring certification, you probably should. The framework is for organisations where the answer to "do we need ISO 42001 certification?" is "not yet, or not at all". It gets governance in place now without the operating overhead of a second management system.
An acceptable use clause covers staff use of AI tools but doesn't address AI use cases you deploy, AI risk assessment, AI incident response, or AI impact thresholds. The framework covers all of these and updates your acceptable use policy as one of several artefacts, rather than treating it as the only one.
It puts you on the path. The governance framework produced is ISO 42001-aligned and can be carried into a future implementation. It doesn't constitute certification readiness on its own though - a full implementation includes additional management system requirements the framework doesn't deliver.
The framework is designed to extend an existing ISMS rather than stand alone. Where you don't have one, we can provide a foundational information security governance framework along with the AI governance framework.
Our consultants are based in Australia, including a core group of Brisbane penetration testers, with engagements delivered both nationally and internationally. Testing, reporting, and walkthroughs are handled by the same senior consultant from start to finish. You get clear accountability, on-shore data handling, and the local context that comes from working with Australian organisations every day.
Proof in practice.
A snapshot of how we've helped Australian organisations strengthen security, meet stakeholder expectations, and move forward with confidence.


Let's talk about where you are and where you need to be.
Whether you're preparing for certification, validating your controls, or building security foundations for growth, we'll help you get there with clarity and confidence.
