ISO/IEC 42001:2023 · AI Management Systems

ISO/IEC 42001 certification, audited by the team behind New Zealand’s first.

Cianaa is an independent certification and assessment body. We audit your AI management system against ISO/IEC 42001:2023. We do not build it, and we do not advise you how to build it, which is what makes the result worth something.

Stage 1 & Stage 2 audit 3 year certificate cycle Annual surveillance Audit only, never advisory

Why our audit carries weight

Assessed, not advised

What an ISO/IEC 42001 certificate is supposed to prove, and what stands behind ours.

Auditors who conducted the certification audit behind New Zealand’s first ISO/IEC 42001 certification
Qualified ISO/IEC 42001 lead auditors, with ISO/IEC 27001 and 27701 audit experience alongside
Ten DOI registered research papers on AI governance, ISO/IEC 42001 and the AI legal landscape
Dr Rizwan Ahmad, MSECB Auditor of the Year 2024 for Asia Pacific
Audits delivered across New Zealand, Australia, Asia Pacific, Europe, the United States and Canada

A PCI Qualified Security Assessor company on the PCI Security Standards Council register since 2014.

1stIn NZ

Proven at the frontier

Cianaa’s auditors conducted the certification audit behind New Zealand’s first ISO/IEC 42001 certification. Datacom’s Datascape, the AI enabled platform used by more than 90 councils across Australia and New Zealand, was certified to ISO/IEC 42001:2023 following an audit by Cianaa’s independent auditors, with the certificate issued by MSECB.

Read the announcement →
Trusted by AI and governance teams across ANZ
Spark Datacom Vodafone Humm Group CCL Fidelity Illion Plan B Xplore

Overview

What is ISO/IEC 42001?

ISO/IEC 42001 (published in 2023) is the world’s first international standard focused on AI management systems, created to guide organisations in the responsible development and use of AI. Officially titled “Information technology. Artificial intelligence. Management system”, it establishes requirements for setting up an Artificial Intelligence Management System (AIMS) within an organisation.

ISO/IEC 42001 provides a structured, risk based framework for governing AI, analogous to how ISO 9001 governs quality or ISO/IEC 27001 governs information security. Its significance lies in filling a crucial gap: as AI becomes foundational to business operations, there was a need for a formal AI governance standard to ensure AI is deployed safely, ethically and with accountability.

Cianaa audits and certifies AI management systems for organisations across New Zealand, Australia, Asia Pacific, Europe, the United States and Canada, through pre-audit, Stage 1, Stage 2 and ongoing surveillance.

Who it applies to

If your organisation uses AI, this standard is about you

“We only use AI, we do not build it, so ISO/IEC 42001 is not really about us.”

The organisation shall consider the intended purpose of the AI systems that are developed, provided or used by the organisation, and shall determine its roles with respect to those systems.

ISO/IEC 42001:2023, Clause 4.1

We hear that sentence in audits often enough that it is worth answering properly. It is a reasonable assumption and it is wrong. Clause 4.1 says “used”, and it says “shall”. Determining your role is not preparatory thinking, it is a requirement in its own right, and an auditor can raise a finding if you cannot show you have done it. You did not have to build a model to be inside the scope of this standard.

Your staff use an assistantClaude, ChatGPT, Gemini or Copilot, used to draft, summarise or analyse. Whether or not anyone approved it.
Your software added AILead scoring in the CRM, shortlisting in the HR system, triage in the service desk. You switched it on, you did not build it.
Your developers use a coding assistantAI generated code in your product, reviewed by people who did not write it.

There is an entire annex written for organisations that only use AI

If that is your position, you are an AI customer and your staff are AI users. That is a genuine role with genuine obligations, and Annex A.9, “Use of AI systems”, exists to cover it. Its objective is to make sure an organisation uses AI responsibly and in line with its own policies.

A.9.2Processes for the responsible use of AI systems.
A.9.3Objectives for the responsible use of AI systems.
A.9.4Using the system according to its intended use and its accompanying documentation.

A.9.4 is the one organisations find hardest, because it cannot be handed to the vendor. You have to show what the provider said the tool was for, and that you checked your own use against it. If you are using a summarisation feature to make decisions about people, you have gone beyond intended use, and that is yours to answer for. Alongside it, A.10.2 requires responsibilities across the AI life cycle to be allocated between you, your suppliers and your customers in writing, and A.10.3 covers your suppliers.

Start here

Before scope, settle your role

Your role decides which Annex A controls apply to you. It is the input to your Statement of Applicability, so if you get it wrong every inclusion and exclusion downstream rests on a wrong premise. Most organisations hold more than one role at once, and the obligations add together rather than cancelling out.

Most commonYou use AI

Staff assistants, AI features inside your SaaS, coding assistants. You are an AI customer and your staff are AI users. Annex A.9 is written for exactly this.

Often missedYou put AI in front of customers

If people outside your organisation use an AI capability you deployed, you are an AI provider to them, whoever trained the model underneath.

The boundaryYou shape how it behaves

Fine tuning on your own data, building an agent, or assembling a retrieval system around a model makes you an AI producer, even though you did not train the model.

Work out your role, free

Six questions. Nothing is submitted anywhere, it runs entirely in your browser.

Key requirements

What ISO/IEC 42001 requires

ISO/IEC 42001:2023 uses the High Level Structure and organises AIMS requirements across context, leadership, AI risk management, support, operation, evaluation and improvement.

Clause 4

Context and AI use cases

Organisational context, interested parties, scope of the AIMS, and the AI systems and use cases in scope.

Clause 5

Leadership and AI policy

Top management commitment, AI policy, organisational roles, responsibilities for AI governance and authorities.

Clause 6

AI risk management

AI risk assessment, AI impact assessment, AI objectives, change management, and risk and opportunity handling.

Clause 7

Support

Resources, competence in AI ethics and machine learning, awareness, communication, and documented information management.

Clause 8

Operation

Operational planning and control, AI system lifecycle management, AI risk treatment, data quality, third party AI components.

Clauses 9 and 10

Performance and improvement

Monitoring AI performance, internal audit, management review. Nonconformity and corrective action, and continual improvement of AI controls.

Process

The certification process, step by step

Pre-audit, Stage 1, Stage 2, certification and annual surveillance, led by qualified ISO/IEC 42001 lead auditors with an AI governance background.

1
Optional

Pre-audit

An independent look at your current AI policies, governance and processes against ISO/IEC 42001 requirements, so you know where you stand before the certification audit begins.

2
Year 1

Stage 1 audit

Documentation review against ISO/IEC 42001. Confirms you are prepared for Stage 2, whether you came through a pre-audit or straight to the initial audit.

3
Year 1

Stage 2 audit

On site or remote audit of AIMS implementation, AI risk management, the effectiveness of controls, and interviews with the people who operate them.

4
Year 1

Certificate issued

Successful Stage 1 and Stage 2 audits result in certification. The certificate is issued once the assurance team is satisfied the evidence supports it.

5
Years 2 and 3

Surveillance audits

Surveillance audits are performed annually. Continued certification is subject to successful surveillance.

6
Year 4

Recertification

A full recertification audit renews your ISO/IEC 42001 certificate and maintains your certified status.

Free tool

See where you stand before we do

A self-check built from the clauses and Annex A controls of ISO/IEC 42001:2023. Answer honestly and it returns a maturity level, a score for each area of the standard, and the specific things an auditor is likely to raise. It runs entirely in your browser and nothing is submitted anywhere.

Open the pre-audit self-check
  • Only the questions that apply to your role
  • A maturity level per area, from Absent to Embedded
  • The likely audit findings, each tied to its clause
  • A printable report you can take to your board

Why Cianaa

Why organisations bring their AIMS to us

No sales fluff and no upsells. Just what we do and how we do it.

Audit only, by design

We do not design, implement or consult on the management systems we audit. That separation is what ISO/IEC 17021-1 requires of a certification body, and it is the reason a certificate means anything to the person reading it.

We have done it first

Our auditors conducted the audit behind New Zealand’s first ISO/IEC 42001 certification. AI governance auditing is new ground for most assessors. It is not new to us.

Published, not just claimed

Ten DOI registered papers on AI governance, ISO/IEC 42001 and the AI legal landscape, openly licensed and permanently citable. You can read the thinking before you hire the auditor.

One audit, several standards

Where you hold ISO/IEC 27001, 27701 or 9001 alongside 42001, we triangulate evidence across the standards rather than auditing the same control four times.

Reports you can act on

Nonconformities prioritised, opportunities for improvement stated plainly, and findings traced to the clause they came from. Written to be used, not filed.

Predictable timelines

Typically three to six months from Stage 1 to Stage 2, planned around your calendar so your team is not waiting on ours.

A note on what we will not do

We will not write your AI policy, build your risk register or prepare your Statement of Applicability, and we will not certify a system we helped create. If you need that work done, we will say so and point you elsewhere. An auditor who helped build the thing cannot then tell you it is sound, and a certificate issued on that basis is worth less than no certificate at all.

Read before you decide

Our thinking is public

You should not have to take an assessor’s word for their competence. Here is ours, in the open.

Free tool

AI Role Selector

Six questions that show which ISO/IEC 22989 roles your organisation holds, the Annex A controls that follow, and a shared responsibility matrix for the AI tools you use.

Open the tool →
Guidance

AI provider or AI user?

The Clause 4.1 requirement most organisations miss, the six roles under ISO/IEC 22989, and what an auditor will ask you to show.

Read the article →
Guidance

Cloud AI and responsibility

Allocating responsibility between you and your AI vendors before the audit, under Annex A.10.2 and A.10.3.

Read the article →
Research

Ten DOI registered papers

Original research on AI governance, ISO/IEC 42001 adoption and the AI legal landscape, openly licensed under CC BY 4.0 and indexed via Zenodo.

Browse the research →
Market data

ISO/IEC 42001 adoption in NZ and AU

How many organisations are certified, what both governments decided, and the outlook for the year ahead.

Read the research →
Comparison

ISO/IEC 42001 vs NIST AI RMF

They are complementary, not alternatives. Which one you need, and what each is actually for.

Compare them →

Complimentary · no obligation

Scope your ISO/IEC 42001 certification

A 30 minute call with one of our ISO/IEC 42001 lead auditors to establish what is in scope, what evidence you already hold, and a realistic path to a Stage 2 audit. It is a scoping conversation, not a consulting engagement.

Book a scoping call
30 minute callISO/IEC 42001 lead auditorNo obligation
  • Scope, definedWhich AI systems and use cases belong inside the AIMS boundary.
  • Your role, determinedThe Clause 4.1 question, settled before it becomes an audit finding.
  • A realistic timelineEffort and calendar estimate through to the Stage 2 audit.
  • Where your standards overlapWhere existing ISO/IEC 27001 or 9001 evidence carries across to 42001.

Certify the AI you are already running

Talk to the auditors who certified New Zealand’s first ISO/IEC 42001 AI management system about scoping yours.

FAQ

Frequently asked questions

What is ISO/IEC 42001?

ISO/IEC 42001 (published in 2023) is the world’s first international standard focused on AI management systems. It establishes requirements for setting up an Artificial Intelligence Management System (AIMS) within an organisation.

Why is ISO/IEC 42001 important?

As AI becomes foundational to business operations, ISO/IEC 42001 fills a crucial gap by providing a formal AI governance standard to ensure AI is deployed safely, ethically and with accountability. It is analogous to how ISO 9001 governs quality or ISO/IEC 27001 governs information security.

We only use AI, we do not build it. Does 42001 apply to us?

Yes. Clause 4.1 requires you to determine your role, and using AI makes you an AI customer with your staff as AI users. Annex A.9, “Use of AI systems”, is written for exactly that position, and A.10.2 requires responsibilities to be allocated between you and your suppliers in writing. Our free AI Role Selector will work out which roles you hold.

What does the certification process involve?

An optional pre-audit of your AI policies, governance and processes, then a Stage 1 and Stage 2 audit, or a direct initial audit. Certification is issued once the assurance team is satisfied. Surveillance audits follow annually.

How does AIMS recertification work?

Surveillance audits are performed every year and continued certification is subject to successful surveillance. A full recertification audit takes place in year four.

Can Cianaa help us implement ISO/IEC 42001 as well as certify it?

No, and that is deliberate. Under ISO/IEC 17021-1 a certification body must not audit a management system it designed or implemented. We can tell you what the standard requires and what we will look for, but we will not write your policies, build your risk register or prepare your Statement of Applicability. Keeping that line is what makes the certificate credible to the customer, regulator or board that asks to see it.

Do you train our team as well?

Yes, and it is kept separate from certification on purpose. We deliver the ISO/IEC 42001 Foundation, Lead Implementer and Lead Auditor courses as generic public training on the standard itself. What we will not do is train your people on your system, help build it, and then audit it. Generic training on a standard is permitted for a certification body. Consultancy on the management system we certify is not. See all ISO/IEC 42001 training courses.

Does ISO/IEC 42001 align with the EU AI Act?

ISO/IEC 42001 is designed to support compliance with emerging AI regulation, including the EU AI Act and similar frameworks. While not a regulatory document itself, AIMS implementation provides much of the governance evidence regulators expect.

How does ISO/IEC 42001 compare to the NIST AI RMF?

They are complementary: the NIST AI RMF is a voluntary risk framework, while ISO/IEC 42001 is a certifiable management system standard. Read our full ISO 42001 vs NIST AI RMF comparison.

Where does Cianaa deliver ISO/IEC 42001 audits?

Across New Zealand, Australia, Asia Pacific, Europe, the United States and Canada. ISO/IEC 42001 is an international standard with no national equivalent, so buyers in any of those markets need an assessment body wherever it is based.