You Don’t Need a Certificate to Have Real AI Governance

Every week seems to bring another headline about AI regulation, another client asking “are you ISO 42001 certified?”, another board member wanting reassurance that the company’s use of AI won’t blow up in the news. And every week, the honest answer from a lot of small and mid-sized companies is the same: not yet, and maybe not ever.

That’s not a failure. Full ISO 42001 certification is a serious undertaking: external audits, a certification body, ongoing surveillance audits, and a governance function robust enough to sustain all of it. For a startup, a scale-up, or a lean mid-market business, that can mean tens of thousands of dollars a year and months of internal effort before the first audit even happens. For many companies, it simply isn’t the right investment yet, or ever.

The good news is that certification was never really the point. The point was always the governance itself; i.e. knowing what your AI systems do, who’s accountable for them, and what controls stand between “it seemed like a good idea” and a genuine incident. You can build that without a certificate on the wall.

AI governance doesn't need to be all encompassing. Choose a right fit solution for your business.
AI governance doesn’t need to be all encompassing. Choose a right fit solution for your business.

The false choice between “nothing” and “ISO 42001”

Too many companies treat AI governance as binary: either you go all in on formal certification, or you do nothing and hope for the best. That framing pushes smaller organisations toward the second option by default, simply because the first looks unaffordable, or the ROI just isn’t there.

There’s a middle path that gets skipped over far too often: building a governance structure that is *aligned* with ISO 42001 or the NIST AI RMF, without pursuing certification at all. You adopt the same underlying logic of risk assessment, defined roles, documented controls, monitoring, incident response, but you scope it to what your organisation actually needs, and you skip the audit machinery.

This isn’t a lesser version of governance. It’s the same governance, without the certificate.

Why alignment works

Both ISO 42001 and the NIST AI RMF are, at their core, structured ways of asking sensible questions: what AI systems do we have, what could go wrong, who owns the risk, what controls are in place, and how do we know they’re working. Certification adds a formal audit trail on top of that structure. The third-party verification that you’re doing what you say you’re doing.

Building a lighter-touch program aligned to these frameworks means you keep the substance and shed the overhead. You can:

  • Pick the controls that are proportionate to your actual risk profile, rather than implementing the full breadth of a standard built to cover every possible organisation.
  • Move at your own pace, refining the program as your AI use matures, rather than working to an audit deadline.
  • Redirect the budget you would have spent on external audits into the controls themselves i.e. the things that actually reduce risk.

And critically, alignment isn’t a dead end. A well-built, framework-aligned program is essentially certification-ready. If the business grows, a client demands it, or the regulatory environment tightens, you’re extending an existing structure rather than starting from zero. Nothing is wasted.

What you actually get, even without certification

If your organisation never pursues certification, and plenty of perfectly responsible organisations never will, an aligned governance program still delivers two things that matter.

The first is structured AI governance: a clear inventory of your AI systems, defined ownership, documented risk assessments, and controls that are proportionate to what those systems actually do. This is the difference between “we think someone’s keeping an eye on this” and being able to point to exactly who is accountable for what, and why.

The second, and arguably the more important one when things go wrong, is defensible governance. No governance program eliminates risk entirely. AI systems will sometimes behave in ways nobody predicted. What a structured, framework-aligned program gives you is evidence. If a regulator, a customer, or a court ever asks “what did you do to prevent this,” you have a documented, concerted effort to identify risks and put controls in place to protect the people affected by your AI; employees, customers, and the public. That evidence is worth a great deal more than good intentions, and it’s exactly what separates a company that gets criticised for negligence from one that gets credit for having tried in good faith.

Let’s be honest about certification

None of this is knocking the ISO 42001 certification itself, or the NIST AI RMF for that matter. For companies operating in regulated sectors, selling into large enterprises with strict procurement requirements, or competing on trust as a differentiator, certification is a legitimate and valuable goal. But it isn’t a realistic starting point for everyone, and treating it as the only “real” form of AI governance discourages smaller companies from doing anything at all. A lighter-touch, framework-aligned program is a credible, honest, and proportionate response to where most companies actually are today.

Where to start

The hardest part of building an aligned governance program usually isn’t the controls themselves, it’s working out how much governance is actually enough for your situation. Too little, and you’re exposed. Too much, and you’ve built an ISO 42001 program in all but name, at a cost you were trying to avoid in the first place.

That’s where Governance Works can help. We advise companies on exactly how much AI governance they need for their size, sector, and risk profile, scoping a program that’s aligned to ISO 42001 and/or the NIST AI RMF. An AI Governance model must be proportionate to your actual use of AI, and built so it can grow with you if and when full certification makes sense. If you’re not sure where your organisation should sit on that spectrum, get in touch. That conversation is where every good governance program starts.


.

DEWR’s default answer is No

Since September 2025, eleven providers have applied to use AI in DEWR service delivery. As at Senate estimates in June 2026, none had been approved. The framework’s default position is no, and that costs you whether your application is weak or excellent. Here’s what boards need to ask this quarter.

Read More »

You Don’t Just Need AI. You Need a REASON to Use AI.

If your organisation has decided it needs to “do something with AI” but can’t yet say what, you’re in very good company. The problem usually isn’t governance — it’s that nobody has identified a use case. Here’s how to find yours, build a real AI strategy, and govern it from day one.

Read More »