Most Australian businesses that get asked about ISO 42001 get asked by a customer, not a regulator. A procurement questionnaire arrives, a larger client wants to know how AI is governed inside the supplier, and “we’re careful” stops being an acceptable answer. ISO/IEC 42001:2023 is the standard those questions usually point at, and it is worth understanding before the questionnaire lands.

What the standard actually is

ISO/IEC 42001 specifies requirements for an AI management system (AIMS). It is a management-system standard in the same family as ISO 27001 for information security: it doesn’t tell you which model to use or how to build anything. It asks whether your organisation has a repeatable way to decide where AI is used, assess the risks, assign owners, and show that the controls you claim are the controls running. It is certifiable, which means an independent body can audit you against it.

That structure matters for AI agents specifically. A chatbot answering FAQs is one kind of risk. An agent with credentials that reads records, drafts decisions and triggers actions is another, and the standard’s emphasis on roles, risk assessment, operational control and monitoring lands directly on it.

What an auditor will want to see for an agent deployment

Reading the standard as a buyer rather than a certifier, the evidence tends to cluster into five questions.

Who owns it? A named person accountable for each agent, and a documented AI policy that someone at leadership level has actually approved. “The IT team” is not an owner. This is the same gap as in who should own AI agent policy.

What can it touch? A register of the agents in operation, the systems each can reach, and the credentials it uses. Shared logins and inherited admin access are the fastest way to fail this one, which is why scoped identity comes first in any deployment we scope.

What could go wrong, and was that written down before launch? An impact and risk assessment per use case, not a generic one for “AI”. Include what happens when the agent is confidently wrong.

Where is a human in the loop? Defined approval points for consequential actions, with the thresholds recorded. See approval gates.

Can you prove what happened? Records of what the agent did, on what authority, with what outcome, retained for a stated period. A raw log is not this. The distinction is covered in logs versus an audit trail.

What “ready” does and doesn’t mean

Being ready for ISO 42001 is not being certified. Certification involves a formal audit of the whole management system, including parts that have nothing to do with agents: leadership commitment, internal audit, management review, continual improvement. Many businesses reasonably stop short of certification and still use the standard as the yardstick, because the same evidence answers customer questionnaires, insurer questions and internal board reporting.

The practical split we see is this. The management-system paperwork (policy, scope, roles, review cycles) is something a business can write itself or buy templates for. The operational evidence for agents (the register, the scoped credentials, the approval gates, the audit trail) has to exist in the running systems. Documents that describe controls that aren’t implemented are the most common reason an assessment goes badly.

A sensible first move

Don’t start with the whole standard. Pick one agent that is live or about to be, and see whether you can answer the five questions above for it with evidence rather than intent. If you can’t, the gaps you find are the actual readiness work, and they are almost always cheaper to close before a customer or auditor finds them.

If you’d like a structured version of that, the two-minute readiness check is a fast screen, and our standalone Security and Governance Audit does it properly against your real systems with findings ranked by exposure. You can also book a free intro call to talk through where you’d start.

This article is general information, not legal or certification advice. Check requirements against the current published standard and your own obligations.