ISO/IEC 42001

An AI management system that passes audit

Gap assessment, management-system build and certification readiness for ISO/IEC 42001 — with the inventory and controls designed to answer NIST, sector regulators and customer diligence from the same evidence.

Book a briefing
What it is

The AI management system standard.

ISO/IEC 42001 is to AI what ISO 27001 is to information security: a management system standard, certifiable by an accredited body, that asks you to demonstrate governance rather than describe it. Policy, roles, risk assessment, impact assessment, lifecycle controls, supplier management, monitoring and continual improvement.

Most organisations pursue it for one of two reasons. Enterprise customers have started asking for it in procurement, or the board wants an external mark that the AI estate is under control. Both are met by the same build.

Path to certification

How we get you there.

  1. 01

    Gap assessment

    Your current state against every clause and Annex A control, with the gaps sized and ranked.

  2. 02

    System build

    Scope, policy, roles, risk and impact assessment methods, and the control set that fits your estate.

  3. 03

    Operate

    The system runs for a period with real records: assessments, reviews, incidents, supplier checks.

  4. 04

    Audit support

    Internal audit, management review, evidence pack, and support through stage 1 and stage 2.

Deliverables

What the build produces.

  • Defined AIMS scope and a documented AI policy the board can sign
  • A complete AI system inventory with owners, purpose, and risk classification
  • AI risk assessment and AI system impact assessment methods, with the first pass completed
  • A control set mapped clause by clause, with the evidence each control produces named
  • Supplier and third-party model governance, including the questions to put to vendors
  • Monitoring, incident handling, internal audit and management review running on a calendar
Reuse

One build, several answers.

NIST AI RMF

The same inventory and risk records map onto NIST's govern, map, measure and manage functions for customers who ask for that framing instead.

Sector regulation

For financial institutions, the ISO inventory and validation records feed directly into OSFI E-23 model risk expectations.

Customer diligence

Security and AI questionnaires get answered from the evidence pack rather than reconstructed each time.

FAQ

Common questions.

How long does certification take?
Typically six to nine months end to end for a mid-sized estate: roughly eight to twelve weeks to build, an operating period long enough to generate records, then the certification audit itself.
We have ISO 27001 already. Does that help?
Considerably. The management system spine — scope, policy, internal audit, management review, corrective action — is reusable, and the build focuses on the AI-specific controls and impact assessment work.
Do we need it if we are not selling to enterprises?
Not necessarily. If nobody is asking for the certificate, the governance underneath it still matters, and we can build to the standard without taking you through audit.

Book a 30-minute briefing

A short conversation is usually enough to tell you whether this is the right first move — and what it would cost.

Book a briefing