SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
A Good Certification Group wins AI standard accreditation

A Good Certification Group wins AI standard accreditation

Thu, 10th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

A Good Certification Group has become one of four certification bodies worldwide accredited by the Joint Accreditation System of Australia and New Zealand to certify against ISO/IEC 42001:2023, the standard for AI management systems.

The accreditation places the Australian-owned company among a small group able to assess organisations against what is described as the first international standard for AI management systems. It comes as businesses face growing scrutiny over how they deploy AI in products, operations and decision-making.

ISO/IEC 42001 sets out a framework for organisations developing or using AI. Certification is intended to give companies an independent way to show their AI governance is backed by auditable processes rather than internal policy statements alone.

Demand for that kind of external assurance has grown alongside the spread of AI tools. Research cited by the company from Deloitte found that 69% of Australian organisations are already using agentic AI, while only 22% have a highly advanced model for governing AI agents.

Separate research from KPMG and the University of Melbourne found that 83% of Australians would be more willing to trust AI systems when assurances are in place, including adherence to international AI standards and responsible AI governance practices.

Early certification

One of the first organisations to secure certification through A Good Certification Group is Revio, a cybersecurity and AI risk advisory firm operating across Australia and New Zealand. The move offers an early example of how firms advising clients on AI risk are also seeking external review of their own governance systems.

Revio said it pursued certification so its advisory work on AI governance would be informed by direct operational experience. The decision reflects a broader market shift as service providers seek to show their recommendations are grounded in their own internal controls and oversight processes.

Jose Bishop, Chief Executive Officer of A Good Certification Group, said: "For too long, certification has been viewed as something businesses have to get to remain commercially competitive, rather than something that genuinely helps them improve and manage risk. We built A Good Certification Group to challenge this perception, combining human, value-adding conversations with innovative technology to deliver accredited audits that are rigorous, efficient and, most importantly, leave organisations better than we found them. ISO/IEC 42001 represents a next step in that mission. Traditionally, certification has been seen as a 'trust signal', but many organisations are now building with AI and modelling their approach on ISO/IEC 42001 to help ensure they do so responsibly. This standard gives organisations an internationally recognised way to demonstrate they have the governance and oversight to use AI effectively. Our role is to make that process impartial, practical and focused on delivering genuine value for the organisation, not simply providing a certificate."

Market pressure

The new accreditation comes as companies face pressure from customers, regulators and other stakeholders to show how AI systems are governed. In practice, that can include documenting how AI is used, identifying risks, setting controls, ensuring human oversight, and creating processes for review and accountability.

Certification bodies play a gatekeeping role because they audit against formal standards. With JASANZ accreditation for ISO/IEC 42001, A Good Certification Group can now issue certifications tied to a recognised external assessment framework.

The business has expanded sharply since its transformation from Certification Oceania and now operates across 17 countries, extending beyond its original Australian focus as demand rises for certification in areas linked to risk, compliance and governance.

That growth has coincided with broader debate over whether existing corporate governance structures are keeping pace with AI adoption. Many businesses have moved quickly to test or deploy AI systems, but formal controls have often lagged behind implementation.

John Baird, Founder and Chief Executive Officer of Revio, said: "We sit at the intersection of cybersecurity, AI and risk management, and we didn't want to ask clients to do something we hadn't done ourselves. So we built an AI management system, got it certified to ISO 42001, and now we can speak from experience, not just theory."

Baird added: "The biggest lesson for us was that governing AI responsibly is less about restricting it and more about being able to explain it: clear processes, appropriate guardrails, meaningful human oversight. This experience has strengthened how we advise clients, because we can share practical insights from building a framework that works in the real world."