Which AI governance framework should an Australian business use?

Start with Australia's Guidance for AI Adoption: six essential practices published by the National AI Centre on 21 October 2025, replacing the Voluntary AI Safety Standard. Once AI tools are in real use, run risk management as an ongoing cycle using the NIST AI Risk Management Framework's Map, Measure and Manage functions. Pursue certification against AS ISO/IEC 42001 only when a contract, tender or enterprise customer requires it.

Australia's Guidance for AI Adoption: the starting point

The Guidance for AI Adoption condensed the ten guardrails of the 2024 Voluntary AI Safety Standard into six essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control. It comes in two editions: Foundations, for organisations getting started or using lower-risk tools, and Implementation Practices, for governance and technical teams deploying more complex systems. The Implementation Practices edition is explicitly aligned with the two main international frameworks, ISO/IEC 42001 and the NIST AI Risk Management Framework, so starting here does not create rework later.

The NIST AI RMF: how to keep governance running

The NIST AI Risk Management Framework (AI RMF 1.0, published January 2023 and still the current version) is where most businesses find the answer to "what do we actually do next" after the compliance basics. It defines four functions: Govern, a cross-cutting foundation of accountability and culture, plus a repeating operational loop applied to each AI use case: Map (identify where AI is used and what could go wrong in context), Measure (assess and track those risks) and Manage (act on them, in priority order, and monitor the result). A Generative AI Profile (NIST AI 600-1, July 2024) applies the same functions to tools like Copilot and ChatGPT specifically. The framework is voluntary and free, and it works at small scale: for a professional services firm the loop can be a register of AI tools in use, a short risk note per tool, and a quarterly review, rather than an enterprise programme.

AS ISO/IEC 42001: when certification is worth it

ISO/IEC 42001:2023, adopted in Australia as AS ISO/IEC 42001, is a certifiable AI management system standard, the AI equivalent of ISO 27001 for information security. Certification means building a documented management system and passing an external audit, with the ongoing cost that implies. That effort pays for itself when a customer, tender or regulator asks for certified evidence of AI governance, which is starting to appear in enterprise and government supply chains. If nobody is asking yet, the six essential practices plus the NIST loop deliver the substance without the audit overhead, and both map cleanly onto ISO/IEC 42001 if certification becomes necessary later.

How the three fit together

These are not competing choices. The Guidance for AI Adoption tells an Australian business what good practice looks like locally, and it is the framework Australian regulators and industry bodies point to. The NIST AI RMF supplies the operating rhythm that keeps governance alive after the policy is written. AS ISO/IEC 42001 is how you prove it to a third party when asked. Your legal obligations sit underneath all three and do not change: the Privacy Act 1988 and the Australian Privacy Principles when personal information is involved (see does the Privacy Act apply when your business uses AI tools?), and AML/CTF obligations in regulated sectors.

What this looks like at 10 to 300 staff

Experimenting: adopt the Foundations edition, write a one-page AI use policy and name an accountable owner. Adopting: keep a register of approved AI tools, record where each one's data goes, and put a human review step on AI output that affects people. Scaling, especially with agents that act across email, files and calendars: run the Map, Measure, Manage cycle on a set cadence, with agent access scoped and logged before go-live. A quick starting point is our free AI adoption self-assessment, which checks the guardrails above against your current setup.

Why Blue Arc IT Solutions

Blue Arc IT Solutions has supported Australian businesses since 2004, delivering nationally from Canberra. Clients complete a short survey after every job: we currently sit at 96% for response speed, 94% for resolution speed and 97% for overall satisfaction. We help clients set up practical AI governance sized to their business, not enterprise paperwork. See our managed services or talk to us.

Frequently asked questions

Is the NIST AI Risk Management Framework mandatory in Australia?

No. The NIST AI RMF is voluntary everywhere, including in the United States where it was published. It matters to Australian businesses because the implementation practices edition of Australia's Guidance for AI Adoption is aligned with it, so using its Map, Measure, Manage loop keeps you consistent with Australian good practice rather than adding a second, competing framework.

What replaced the Voluntary AI Safety Standard?

The Guidance for AI Adoption, published by the National AI Centre on 21 October 2025. It condensed the standard's ten guardrails into six essential practices and comes in two editions: Foundations for organisations getting started, and Implementation Practices for governance and technical teams.

Does an Australian business need ISO/IEC 42001 certification?

Most businesses of 10 to 300 staff do not. Certification against AS ISO/IEC 42001 involves building and auditing a full AI management system, which is worth the cost when a contract, tender or enterprise customer requires certified evidence. Until then, the six essential practices plus a regular risk-review loop cover good practice without the audit overhead.

Last reviewed: 6 August 2026. NIST has flagged a revision of the AI RMF and floated new profiles; this page will be updated if a new version or an Australian-relevant profile is published.