ISO 42001 Implementation
Senior-led ISO 42001 implementation, aligned to your existing ISO 27001 ISMS.


operating since 2017.
AI adoption is moving faster than the governance around it. Customers, regulators, insurers, and prospective partners are increasingly asking how AI is being managed, and "we'll figure it out as we go" is becoming a harder answer to defend.
ISO 42001 is the international management system standard for artificial intelligence. Your implementation is led by experienced consultants who develop the AI Management System (AIMS) with you, identify AI-related risks, prepare core governance policies, and guide your team through to certification readiness.
Your consultants work with your AI and security teams to put guardrails in place that protect company assets and customer data while letting your business move at the pace it needs.
Where you're already ISO 27001 certified, the AIMS extends your existing Information Security Management System (ISMS) rather than running in parallel. The result is a single, integrated governance system that supports AI adoption rather than slowing it down.
Best for
Organisations bringing AI under formal governance, whether the driver is customer demand, emerging regulation, insurer expectations, or a leadership decision to manage AI risk deliberately rather than reactively.
Why choose us for your ISO 42001 implementation
We have ISO 42001 implementation expertise
Acumenis has not only assisted early adopters of ISO 42001 to implement the framework and pass certification audits, our team have spoken on the practicalities of implementing ISO 42001 at conferences such as AusCERT.
AI risk understood in technical and governance terms
Your consultants bring hands-on understanding of how AI systems are built, procured, deployed, and monitored. AI governance controls are designed to reflect how AI actually operates in your organisation, not just how it's described on paper.
Integrated with ISO 27001 where appropriate
For organisations already ISO 27001 certified (which most ISO 42001 clients are), the AIMS extends your existing security governance rather than running in parallel. This reduces duplication, simplifies audit, and produces a coherent and efficient governance system.
Governance that supports innovation rather than slowing it down
Clear AI policies, defined acceptable use, and structured risk treatment reduce the case-by-case decision-making that actually slows AI adoption. The framework acts as guardrails for safe innovation, not as brakes.
Internal audit included, with consultant segregation
The initial internal audit is conducted by a different consultant from the implementation lead, holding the ISO 42001 Lead Auditor credential, preserving the impartiality the standard requires and identifying gaps before the certification audit.
Senior consultants, based in Australia
Scoped and delivered by experienced consultants based in Brisbane and surrounds, working with clients across Australia. On-shore data handling, local context, and clear accountability.
How your ISO 42001 implementation runs
Every engagement follows the same four-phase approach, tailored to your environment and AI footprint. Phase durations depend on your scope, the AI footprint, and the maturity of existing AI governance practice.
Phase 1 - Plan
You and your lead consultant map out the AIMS scope, identify AI-related risks that need to be managed, and determine the strategies best suited to treating them. Where you're already ISO 27001 certified, integration points between the ISMS and AIMS are identified during this phase. The phase culminates in your AI risk register, AI risk treatment plan, and core AIMS policies.
Phase 2 - Do
Your consultant prepares the policies and processes required to implement the AI governance controls identified in planning. Training and awareness artefacts are tailored to the relevant readership across data science, engineering, product, procurement, legal, and risk. Where the AIMS integrates with an existing ISMS, controls are extended rather than duplicated.
Phase 3 - Check
Your consultant establishes the internal audit function for ISO 42001, conducts the initial internal audit with a different consultant from the implementation lead to ensure independence, and facilitates the initial Management Review Meeting so senior leadership can review AIMS performance against business objectives.
Phase 4 - Act
Your consultant reviews the outcomes of performance monitoring, internal audit, and management review, and applies the feedback to make final improvements. The focus is on ensuring you fully understand and feel confident with your AIMS processes so you can handle the certification audit independently. Optional audit assistance is available where you'd like additional support through the certification process.
ISO 42001 challenges you'll avoid
Pace of AI adoption outrunning governance
AI capabilities are being adopted across the organisation faster than the policies, controls, and oversight structures can keep up. Our implementation is designed to formalise governance without slowing adoption, giving teams clear guardrails so they can move confidently rather than waiting for case-by-case decisions.
A new standard with limited prior experience
ISO 42001 was published in late 2023, and most organisations haven't implemented an AIMS before. Your implementation draws on the same disciplined approach used for ISO 27001, which follows the same management system structure, so the path to certification is well-understood even if the subject is new.
AI risk that doesn't fit existing security frameworks
AI introduces risks (model failure, hallucination, bias, prompt injection, training data exposure, third-party AI service failure) that traditional security frameworks weren't built to address. The AIMS provides a structured way to identify, treat, and monitor these risks alongside the broader security and privacy controls you already have.
Concern about duplication with existing certifications
Most organisations approaching ISO 42001 are already ISO 27001 certified, and worry about running parallel governance systems. Where appropriate, the AIMS extends your existing ISMS rather than running alongside it, with integrated internal audit and management review reducing duplication and simplifying ongoing operation.
Customer, regulator, or board pressure for AI assurance
Customers are asking how AI is being managed, regulators are signalling expectations, and boards are asking for evidence of governance. The AIMS provides a recognised, certifiable framework for showing AI is being managed deliberately rather than reactively.
Outcomes
After your ISO 42001 implementation, you'll have:
- A practical, audit-ready AIMS tailored to your AI footprint
- AI risk register, AI risk treatment plan, and core AI governance policies
- Defined AI objectives aligned with your strategic goals
- Evidence the AIMS is operating, including internal audit and management review outputs
- Confidence to handle the certification audit independently
- A foundation that supports certification, customer assurance, and ongoing AI governance
Frequently asked questions.
Straight answers to the questions we hear most. Can't find yours? We're happy to help.
ISO 42001 was published in late 2023 and certification bodies in Australia are now actively certifying against it. Early adopters benefit from getting governance in place before regulatory pressure mandates it, and from being able to demonstrate to customers, partners, and investors that AI is being managed deliberately. Where AI is already material to your business, the question is less whether to formalise governance and more when.
Yes, and this is the most common approach. ISO 42001 follows the same management system structure as ISO 27001, and most organisations approaching ISO 42001 are already ISO 27001 certified. The AIMS extends your existing ISMS rather than running in parallel, with integrated risk assessment, internal audit, and management review.
Possibly. ISO 42001 applies to organisations that develop, provide, or use AI systems, so even if you're consuming AI through third-party services (which most organisations are) the standard is relevant. The scope and intensity of the implementation depends on how AI is used in your context, which is worked through during scoping.
Standard implementations run approximately six months from kick-off to certification readiness, similar to ISO 27001. Specific timeframes depend on your AI footprint, the maturity of existing AI governance practice, and your available internal capacity. Where you're integrating with an existing ISMS, parts of the work can be accelerated.
While we have certified lead auditors in our team, we don't perform certification audits for our clients to avoid a conflict of interest.
Yes! Acumenis can help implement ISO 27001 using compliance platforms such as Vanta or Drata.
Yes. We include an initial internal audit with your implementation, and can perform your internal audits each year after certification.
Our consultants are based in Australia, including a core group of Brisbane penetration testers, with engagements delivered both nationally and internationally. Testing, reporting, and walkthroughs are handled by the same senior consultant from start to finish. You get clear accountability, on-shore data handling, and the local context that comes from working with Australian organisations every day.
Proof in practice.
A snapshot of how we've helped Australian organisations strengthen security, meet stakeholder expectations, and move forward with confidence.





Let's talk about where you are and where you need to be.
Whether you're preparing for certification, validating your controls, or building security foundations for growth, we'll help you get there with clarity and confidence.
