AI Governance · ISO/IEC 42001
ISO 42001 Compliance
ISO/IEC 42001 is the first certifiable standard for an AI management system (AIMS). We help you build robust AI governance and reach certification without slowing your product teams down.
Why ISO 42001 is becoming unavoidable
Enterprise customers, investors and — soon — regulation (the EU AI Act) demand proof that your AI systems are under control. Answering security questionnaires case by case is no longer enough: you need a structured, verifiable management framework.
ISO/IEC 42001:2023 provides that framework. Like ISO 27001 for information security, it defines a management system — policies, roles, risk assessment, controls, continual improvement — dedicated to AI. Certification by an accredited body turns a fragile sales argument into defensible evidence.
The point is not to tick boxes, but to install governance proportionate to your real AI usage (in-house models, vendor APIs, embedded generative AI) without hurting your delivery pace.
Our 4-step approach
A pragmatic engagement, tailored for organisations without a dedicated compliance team.
Gap analysis
Mapping of your AI systems and current practices, measuring the gap against ISO 42001 requirements and prioritising work by risk.
AI management system (AIMS) design
AI policy, role governance, risk and impact assessment methodology, AI system inventory and selection of the Annex A controls that fit your context.
Implementation and enablement
Rolling procedures into your existing tools, training product and data teams, and embedding controls into your development lifecycle rather than beside it.
Audit preparation and support
Mock internal audit, management review, evidence build-up and support through the accredited body’s stage 1 and stage 2 certification audits.
What you get
- A prioritised gap-analysis report with effort estimates
- A documented AI management system (policies, procedures, registers)
- A risk and impact assessment of your AI systems
- The Statement of Applicability (SoA) for selected controls
- An internal audit plan and the evidence the certifier expects
- Support all the way to certification
Who is it for?
- Software vendors embedding AI in their product
- Banks, insurers and regulated organisations governing their AI uses
- Scale-ups under customer or investor pressure on AI governance
- Companies already ISO 27001 certified who want to leverage their ISMS
- Organisations in scope of the AI Act looking for a durable compliance framework
Frequently asked questions
What is the difference between ISO 42001 and the AI Act?
The AI Act is a binding EU regulation; ISO 42001 is a voluntary, certifiable standard. Implementing an ISO 42001 AIMS is one of the most effective ways to demonstrate compliance with several AI Act obligations and to organise your governance.
How long does certification take?
Depending on your starting maturity and scope, expect roughly 4 to 9 months from the gap analysis to the certification audit. An existing ISO 27001 foundation shortens this significantly.
Do I need to be ISO 27001 certified first?
No, it is not a prerequisite. But if you are, much of the governance, risk management and documentation is reusable, which reduces the effort.
Is it suitable for a small team?
Yes. The management system is scaled to your company’s real size and usage. The goal is proportionate governance, not a documentation factory.
Ready to scope your ISO 42001 project?
Let’s spend 30 minutes on your AI usage and deadlines. You leave with a clear view of the next steps.