⏱ 9 min read · 1,719 words

ISO/IEC 42001 Explained for NZ Boards: AI Governance in Plain English

ISO/IEC 42001 Explained for NZ Boards: AI Governance in Plain English

August 9, 2026
ISO/IEC 42001 AI governance explained for NZ boards
⏱ 4 min read · 749 words

Your organisation is almost certainly using AI somewhere — in products, in delivery teams, in vendors’ tooling — and someone at board level now owns the question “how do we know it’s under control?” ISO/IEC 42001 is the first management-system standard built to answer that question. Here’s what it is, what it requires, and what NZ directors should actually do with it — without the vendor gloss.

TL;DR — ISO/IEC 42001 certifies how your organisation governs AI, not whether any model is safe. Boards should start with an AI inventory, named accountability, and independent testing of the systems that matter most.

What ISO/IEC 42001 is

Published in December 2023, ISO/IEC 42001 defines an AI Management System (AIMS) — the AI equivalent of what ISO 27001 is for information security. It doesn’t certify that any individual model is safe or accurate. It certifies that your organisation has a working system for governing AI: policies, risk assessment, impact assessment, defined roles, lifecycle controls, monitoring, and continual improvement. The distinction matters — it governs the organisation, not the algorithm.

Why it’s reached NZ board agendas

Three forces are converging. First, the Public Service AI Framework sets expectations for responsible AI use across government, and agencies are translating those expectations into procurement questions for their vendors. Second, directors’ existing duties — care, diligence, oversight of material risk — extend naturally to AI; a governance standard gives that oversight a defensible shape. Third, enterprise customers have started asking suppliers the same question government asks: show us how you govern AI. An organisation that can point to an ISO/IEC 42001-aligned management system answers in one sentence.

What it requires, in plain terms

  • Know your AI. An inventory of where AI is used, by whom, and for what — including AI embedded in vendor products, which is where most surprises live.
  • Assess risk and impact. Structured assessment of what could go wrong for the organisation and for the people affected by each AI system, before deployment and as systems change.
  • Assign ownership. Named accountability for AI outcomes — not a working group, a person.
  • Control the lifecycle. Requirements, data governance, testing and validation, deployment gates, monitoring, and decommissioning for AI systems, proportionate to their risk.
  • Keep humans in the loop where it matters. Defined points where human judgement can override, and evidence the override actually works.
  • Improve continually. Incidents feed back into controls; the system is audited and updated, not written once and framed.

Certification, alignment, or neither?

Formal certification requires an accredited external audit and suits organisations whose customers will ask for the certificate. Alignment — building the management system to the standard without pursuing the certificate — delivers most of the governance value and is where we’d point most NZ organisations first. Resync operates its own AIMS aligned to ISO/IEC 42001, documented publicly in the Resync AI Assurance Framework, because we don’t think anyone should ask clients to trust AI governance they don’t practise themselves.

Questions boards should ask this quarter

  1. Do we have an inventory of AI in use, including inside vendor products?
  2. Who is accountable — by name — for AI outcomes?
  3. Which of our AI systems could affect individuals’ rights, finances, or safety, and what assessment did those get?
  4. When an AI system misbehaves, how would we find out, and how fast?
  5. Have our AI systems been tested by anyone who didn’t build them?

That last question is where governance meets evidence. A management system says the right things happen; independent AI testing and assurance — accuracy evaluation, bias testing, human-oversight review — checks that they did. If your board needs either the governance or the evidence, talk to us.

Frequently asked questions

Is ISO/IEC 42001 mandatory in New Zealand?

No. It’s a voluntary standard. But the Public Service AI Framework, procurement expectations, and directors’ existing risk-oversight duties are pushing NZ organisations toward exactly the governance practices the standard codifies, so alignment is increasingly treated as evidence of responsible AI use.

Does ISO/IEC 42001 certify that our AI is safe or unbiased?

No. It certifies your management system — that you assess, control, and monitor AI risk systematically. Whether a specific system is accurate or fair is an evidence question, answered by testing and evaluation of that system.

What’s the difference between ISO/IEC 42001 and the Public Service AI Framework?

The Public Service AI Framework sets expectations for NZ government agencies’ use of AI. ISO/IEC 42001 is an international management-system standard any organisation can implement or certify against. They’re complementary: the framework says what responsible use looks like; the standard gives you the operating system to deliver it.