ISO/IEC 42001, published in 2023, is the first international standard for AI management systems. It follows the same high-level structure as ISO 27001 and ISO 9001, making it relatively straightforward to integrate with an existing ISMS. NZ government agencies and Crown entities deploying AI on official information are increasingly treating 42001 as the governance framework that fills the gap NZISM does not yet address specifically.
This post covers what ISO 42001 requires, how it maps to the NZISM obligations for AI systems covered in AI Governance for NZ Agencies, and the practical integration path for agencies that already operate an NZISM-aligned ISMS.
---
What ISO 42001 Covers
ISO 42001 establishes requirements for an AI management system — a structured approach to the responsible development, deployment, and monitoring of AI. The standard is organised around the Plan-Do-Check-Act cycle familiar from ISO 27001:
Context and leadership. Define the organisation's role in the AI value chain — is it a developer, a deployer, or both? Establish an AI policy, assign accountability to the executive level, and integrate AI governance into the existing management system.
Planning. Identify AI-specific risks and opportunities. Assess the impact of AI systems on people and processes. Establish an AI risk register distinct from the general technology risk register, since AI risks — bias, explainability, adversarial inputs, data provenance — are categorically different from traditional IT risks.
Support. Ensure staff deploying or using AI systems have appropriate competence. Maintain documentation of AI system design decisions, training data sources, model versions, and deployment configurations.
Operations. Implement controls for AI system lifecycle — data quality, model validation, bias assessment, human oversight, and incident response. The standard requires documented processes for each stage of the AI lifecycle from procurement to decommission.
Performance evaluation. Monitor AI system behaviour over time, not just at deployment. This includes tracking model drift, output quality, and the rate of human overrides. Internal audit of the AI management system at least annually.
Improvement. Respond to findings, near-misses, and incidents involving AI systems. Feed lessons back into the risk register and control set.
How 42001 Fills NZISM's AI Gap
NZISM does not currently have an AI-specific chapter. The existing controls — data classification, system certification, supplier assurance, logging — apply to AI systems but do not address AI-specific risks. The gaps 42001 fills:
- Model and data provenance. 42001 requires documented lineage of training data and model versions. NZISM has no equivalent control.
- Bias and fairness. 42001 explicitly requires assessment of discriminatory outcomes. NZISM does not address this.
- Human oversight design. 42001 requires documented human-in-the-loop or human-on-the-loop design for consequential decisions. NZISM does not specify this.
- AI-specific incident types. Prompt injection, model poisoning, and adversarial inputs are attack classes 42001 addresses. NZISM's incident categories predate widespread AI deployment.
- Explainability requirements. 42001 requires the organisation to be able to explain AI decisions to affected parties. NZISM has no equivalent.
For NZ agencies subject to the Privacy Act 2020 and the Algorithm Charter for Aotearoa New Zealand, 42001 provides a structured framework that maps to both. The OPC's AI guidance aligns closely with 42001's principles.
Integration with an Existing ISMS
The practical integration path for an agency with an existing NZISM-aligned ISMS:
1. Scope definition. Add AI systems to the ISMS scope document with a separate AI system register. List every AI system in use — including third-party SaaS that uses AI — with classification, purpose, and data sensitivity.
2. Risk register extension. Add an AI risk category to the existing risk register. The AI-specific risks to capture: training data quality and provenance, model performance degradation over time, bias in outputs affecting protected groups, adversarial input vulnerability, and supplier dependency on AI platform providers.
3. Control mapping. Map the 42001 control set against existing NZISM controls. Many overlap — supplier assurance, logging, access control. The gaps are the AI-specific controls that need to be added.
4. Policy update. Add an AI policy section to the information security policy, or create a standalone AI policy that references both 42001 and the Algorithm Charter commitments.
5. Supplier assurance extension. AI vendors should be assessed against 42001 in addition to standard NZISM supplier assurance criteria. ISO 42001 certification or an equivalent assessment is becoming a procurement requirement for AI services in government contexts.
6. Audit programme. Add AI system review to the annual internal audit scope. The questions an auditor asks: Is the AI system register current? Have bias assessments been completed for consequential AI systems? Are human override rates being tracked? Has the model been validated since last major update?
The Algorithm Charter Alignment
New Zealand's Algorithm Charter for Aotearoa New Zealand predates ISO 42001 but aligns closely with its principles. Agencies that have signed the Charter and are implementing 42001 will find most Charter commitments map directly to 42001 requirements:
- Transparency → 42001 documentation and explainability requirements
- Te Tiriti obligations → 42001 bias and fairness assessment, applied to Māori outcomes
- Human oversight → 42001 human-in-the-loop design requirements
- Peer review → 42001 internal audit and management review
- Appeal mechanisms → 42001 corrective action and affected party rights
Treating 42001 as the operational implementation of Algorithm Charter commitments is cleaner than maintaining them as separate governance streams.
Certification
ISO 42001 certification is available through accredited certification bodies. For NZ government agencies, certification is not currently mandated, but it is increasingly cited in procurement requirements and tender criteria for AI-related services. The certification process follows the same pattern as ISO 27001 — gap assessment, implementation, internal audit, and third-party certification audit.
For agencies not ready for full certification, a self-assessment against 42001 using the standard as a checklist is still valuable. The gap analysis alone produces an actionable AI governance improvement plan.
Practical Steps
- Inventory all AI systems in use, including third-party SaaS with AI features
- Run a gap assessment against ISO 42001 using the existing ISMS structure
- Add AI-specific risks to the risk register
- Update the information security policy to include AI governance
- Complete bias assessments for consequential AI systems before the next audit
- Add AI vendor 42001 status to supplier assurance criteria
- Integrate AI system review into the annual internal audit programme
Start a free AccreditAZ trial to bring AI system governance into your NZISM ISMS alongside ISO 42001 and Algorithm Charter obligations.
External references: