ISO 42001 is the international standard for Artificial Intelligence Management Systems (AIMS) — published by ISO in December 2023, it provides a framework for organisations to develop, implement, maintain, and continually improve responsible AI governance. For Australian businesses deploying Microsoft 365 Copilot, ISO 42001 provides the governance structure for AI acceptable use policies, risk assessment, and ongoing AI performance monitoring required by regulators and enterprise clients.
What ISO 42001 covers — the seven key requirements
ISO 42001 follows the familiar management system structure, applied to artificial intelligence.
Context of the organisation. Document the internal and external factors that affect AI use — relevant legislation, stakeholder expectations, and organisational AI maturity.
Leadership and commitment. Board and executive accountability for AI governance, evidenced by an AI policy statement, defined roles and responsibilities, and allocated resources.
Planning. AI risk assessment — identifying and evaluating risks arising from the AI systems in use, including Microsoft 365 Copilot, and defining risk treatment plans.
Support. Competence, awareness, and communication — staff training on AI acceptable use, an AI literacy programme, and AI governance communication to clients and stakeholders.
Operations. AI system lifecycle management — requirements for deploying, monitoring, and retiring AI systems, including third-party AI tools introduced by individual teams.
Performance evaluation. Auditing AI governance effectiveness — internal audit of AI use against policy, and management review of AI risks.
Improvement. Corrective action for AI governance failures, and continual improvement of the AIMS itself.
ISO 42001 vs ISO 27001 — how they relate for Australian businesses
ISO 27001 covers information security management. ISO 42001 covers AI management. The two are designed to be complementary and share a common structure, because both follow the ISO Annex SL high-level structure.
Australian businesses already certified to ISO 27001 have a significant head start. The management system infrastructure — internal audit, risk assessment methodology, policy framework, and management review — is already in place and can be extended to cover AI governance rather than rebuilt.
The primary new requirements ISO 42001 adds beyond ISO 27001 are an AI-specific risk assessment methodology, an AI impact assessment for high-risk AI applications, AI transparency and explainability documentation, and an AI acceptable use policy covering generative AI tools. Microsoft 365 Copilot is classified as a generative AI system and therefore requires governance under ISO 42001 — it is not exempt because it is a Microsoft first-party product. The same discipline that underpins zero trust in Microsoft 365 applies here.
Who needs ISO 42001 certification in Australia
ISO 42001 certification is currently voluntary in Australia. There is no regulatory mandate equivalent to the EU AI Act, which applies to businesses operating in the EU. Four categories of Australian business nonetheless have strong reasons to pursue it.
Businesses selling to enterprise or government clients. Enterprise procurement teams are increasingly including AI governance requirements in tender specifications, alongside existing security questionnaires.
Defence contractors. DISP advisory is expanding to include AI governance as AI becomes embedded in defence supply chain operations.
Financial services and professional services. ASIC and professional body guidance is moving toward AI governance expectations for licensees.
Businesses deploying Microsoft 365 Copilot with sensitive client data. Law firms, accounting practices, and healthcare providers use ISO 42001 as the documented governance framework that satisfies professional indemnity and cyber insurance requirements for AI use. Where Essential Eight compliance answers "is the environment secure?", ISO 42001 answers "is the AI use governed?".
ISO 42001 and Microsoft 365 Copilot — practical alignment
ISO 42001 and Microsoft 365 Copilot deployment overlap heavily. The governance requirements of the standard largely align with the AI readiness prerequisites for Copilot.
AI policy (requirement 5.2, AI policy statement) maps directly to a Copilot acceptable use policy. AI risk assessment (requirement 6.1, AI risk identification and treatment) maps to a Copilot readiness assessment identifying overpermissioned SharePoint sites and data exposure risks. AI transparency (requirement 8.4, AI system transparency) maps to a Copilot disclosure policy for client communications. AI impact assessment (requirement 8.5, impact assessment for high-risk AI applications) maps to assessment of Copilot use in sensitive client contexts.
Mycelium 365's AI Readiness Assessment covers the operational Microsoft 365 requirements of ISO 42001 as part of the standard assessment scope — permissions, data classification, sensitivity labelling, and device posture — so the evidence produced serves both the Copilot rollout and the AIMS.
How to prepare for ISO 42001 in Australia
1. Gap assessment. Review current AI governance against ISO 42001 requirements. Most Australian businesses have no documented AI governance at all, so the first output is usually a list of missing artefacts rather than remediation actions.
2. AI inventory. Document every AI tool in use — Microsoft 365 Copilot, ChatGPT, GitHub Copilot, Power Platform AI Builder, and third-party AI tools embedded in SaaS products — and classify each by risk level.
3. AI policy development. Draft an AI acceptable use policy, an AI risk assessment methodology, and an AI incident response procedure.
4. Management system integration. Integrate AI governance into an existing ISO 27001 or equivalent management system, or establish a standalone AIMS.
5. Certification audit. Engage an accredited certification body — Bureau Veritas, SGS, BSI, and LRQA are the primary ISO certification bodies operating in Australia.
Full ISO 42001 certification typically takes 6–12 months for Australian organisations already operating a management system, and 12–18 months for organisations starting from scratch.
How Mycelium 365 supports ISO 42001 readiness
Mycelium 365's AI Readiness Assessment covers the Microsoft 365 operational requirements that underpin ISO 42001 — permissions, data governance, sensitivity labelling, and device compliance. We deliver a Copilot deployment governance framework that documents who can use Copilot, over what data, and with what oversight. We provide an AI acceptable use policy template that maps to ISO 42001 clause requirements, and align the underlying security controls with Microsoft 365 Defender and Essential Eight baselines. Talk to us before your first Copilot licence is purchased, not after.
ISO 42001 vs ISO 27001 — what is the difference for Australian organisations?
Australian organisations often compare ISO 42001 and ISO 27001 because both deal with governance, risk and controls. They are related, but they are not interchangeable.
ISO 27001 is an information security management system standard. Its focus is protecting the confidentiality, integrity and availability of information. It applies broadly across systems, people, suppliers and processes. For many businesses, this covers core areas such as identity, endpoint security, email protection, logging, backup, incident response and access control. In practical Microsoft environments, that often links closely with security services, Managed Defender and baseline management of Microsoft 365 and Azure estates.
ISO 42001 is different. It is an AI management system standard. Its focus is the governance, oversight and responsible use of AI systems across their lifecycle. That includes how AI is selected, designed, deployed, monitored and reviewed, including impacts on people, decisions, privacy, transparency and accountability.
For Australian organisations, the distinction matters because an AI tool can be secure yet still poorly governed. For example:
- a generative AI assistant may have strong authentication and encryption, satisfying parts of an information security program
- the same tool may still create governance issues around human oversight, prompt handling, output accuracy, bias, recordkeeping or use in regulated decision-making
- a business may have mature cyber controls but no formal process for approving AI use cases or assessing downstream harms
A useful way to think about it is:
- ISO 27001 asks: is information protected?
- ISO 42001 asks: is AI being governed responsibly and systematically?
There is also overlap. Both standards expect documented policies, risk assessments, control implementation, internal review and continual improvement. Existing ISO 27001 maturity can make ISO 42001 preparation easier because many supporting disciplines already exist:
- asset inventories
- supplier due diligence
- access management
- incident processes
- internal audit practices
- governance forums
However, ISO 42001 introduces additional requirements that many Australian businesses have not formalised, including:
- AI-specific risk criteria
- use case approval and classification
- defined roles for AI accountability
- output monitoring and validation
- transparency and user awareness
- review of legal, ethical and operational impacts
In practice, organisations using Microsoft technologies often need both perspectives. Microsoft 365, Azure and Copilot deployments should sit inside existing security and compliance foundations, while AI-enabled capabilities are governed through a specific AI management framework. That combination is usually more realistic than treating ISO 42001 as a replacement for ISO 27001 or as a purely technical exercise handled only by IT.
How to prepare for ISO 42001 certification in Australia — a practical roadmap
For Australian organisations, ISO 42001 preparation is less about producing a single AI policy and more about building an operating model that can stand up to audit. The work usually spans governance, legal, risk, security, technology and business operations.
A practical roadmap starts with scope. Define which parts of the organisation, which AI-enabled processes and which platforms are in scope. For many businesses, this includes Microsoft 365, Azure AI services, automation platforms and any third-party applications using embedded AI. If AI is already being used informally, discovery is essential before documentation begins.
A workable sequence is:
-
Establish governance ownership
Assign accountable roles for AI oversight, risk acceptance and control operation. This should include business and technology stakeholders, not just IT. -
Create an AI system and use case register
Record where AI is used, what data it touches, who owns it, what decisions it influences and whether human review exists. -
Perform a gap assessment
Compare current policies, risk processes and controls against ISO 42001 requirements. This is often best handled as part of a broader governance review through advisory services. -
Define an AI risk methodology
Set criteria for impact, likelihood, data sensitivity, regulatory exposure, user impact and control effectiveness. -
Build the management system documents
Typical artefacts include:- AI governance policy
- acceptable use guidance
- risk assessment templates
- supplier review criteria
- incident and escalation procedures
- monitoring and review schedules
- training records
-
Implement supporting technical controls
AI governance depends on underlying platform discipline. In Microsoft environments that often means reviewing tenant configuration, data security, identity controls, endpoint posture and retention settings across Microsoft 365 and Azure. -
Run pilot assessments on real use cases
Test the framework on actual workflows such as drafting, summarisation, search, analytics or customer communications. -
Train staff and decision-makers
Users need guidance on prompts, data handling, verification and escalation. Managers need to understand accountability and approval thresholds. -
Conduct internal review before certification
Check whether evidence exists for what policies claim. Auditors will look for records, approvals, reviews and corrective actions, not just documents.
Common delays in Australia usually come from incomplete asset discovery, unclear AI ownership and weak evidence of operational control. Certification readiness improves when governance is tied to actual platforms, actual business processes and actual review forums. Businesses with distributed teams across Melbourne, Sydney, Brisbane and Perth also need consistency in training, documentation and escalation paths so the management system works the same way across locations.
ISO 42001 and Microsoft 365 Copilot — how AI governance aligns with AI tool deployment
Microsoft 365 Copilot is often one of the first AI tools Australian organisations deploy at scale because it sits inside familiar applications such as Word, Excel, Outlook, Teams and PowerPoint. That convenience makes governance more important, not less. ISO 42001 provides a structure for managing that deployment in a disciplined way.
The key issue is that Copilot does not operate in isolation. Its outputs depend on the quality of underlying data, existing permissions, retention settings, labelling, sharing practices and user behaviour. If content is overshared in SharePoint or Teams, AI-assisted discovery can expose that problem faster. If users rely on generated summaries without review, operational and compliance risks increase.
From an ISO 42001 perspective, a Copilot rollout should usually include:
- a defined business purpose for each use case
- assessment of data sources and access models
- user guidance for prompting and verification
- rules for restricted, personal or confidential information
- monitoring of adoption, issues and control effectiveness
- clear accountability for approvals and exceptions
This is where AI governance aligns directly with Microsoft platform work. Practical controls often sit across several layers:
-
Identity and access
Review least privilege, group membership and guest access. -
Information protection
Check sensitivity labels, retention, data loss prevention and sharing settings. -
Endpoint and device management
Confirm managed device posture and session controls, often supported through Managed Intune. -
Threat protection and monitoring
Strengthen visibility into suspicious behaviour and risky activity using services such as Managed Defender. -
Workload configuration
Validate settings in Exchange, SharePoint, OneDrive and Teams before broad Copilot enablement.
ISO 42001 also helps separate approved and non-approved use of AI. Many organisations already have staff experimenting with public AI tools outside formal controls. A governed Copilot deployment can reduce shadow AI risk, but only if policy, training and technical restrictions are aligned.
A sensible operating model includes staged rollout rather than whole-of-business activation. Start with selected teams, documented use cases and measurable review points. For example, a professional services firm may begin with meeting summaries, drafting assistance and internal knowledge search, while excluding high-risk legal, HR or customer decision workflows until extra controls are defined.
For organisations already investing in Microsoft 365 and broader security uplift, ISO 42001 adds the governance layer needed to show that AI deployment is not just enabled technically, but managed responsibly across the full lifecycle of use.
