Skip to main content

infosecacademy Eğitim Danışmanlık Hizmetleri

ISO/IEC 42001:2023 consulting

ISO 42001 consulting: a certifiable way to govern AI

As AI moves into production processes, quality control, logistics planning and customer operations, procurement teams and regulators are asking how it is governed. We answer that with a certifiable AI management system, led personally by an ISO/IEC 42001 Lead Auditor — and integrated with your existing ISMS where one exists.

ISO/IEC 42001:2023EU AI ActAI impact assessmentAnnex A controls
In brief

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the first international management system standard for artificial intelligence. It specifies requirements for an AI management system (AIMS) covering AI policy and objectives, roles and accountability, AI system impact assessment, data governance for training and inference, lifecycle controls, supplier management, monitoring and incident handling, with a set of Annex A controls. It is a practical governance vehicle for demonstrating that obligations under the EU AI Act — Regulation (EU) 2024/1689 — are being managed, by developers and deployers alike.

Why it matters

Why ISO/IEC 42001 now

The EU AI Act

Obligations fall on deployers as well as developers. ISO/IEC 42001 gives you a structured way to manage and evidence them.

Procurement questions

“How do you govern AI?” is an increasingly common procurement question — and a certificate answers it.

AI is already in use

AI is routinely used more widely than management expects: in tools, suppliers’ products and operational processes.

Impact-based control

Impact assessment focuses control where a failure would have safety, quality, financial or privacy consequences.

Supplier AI

Third-party AI inside your processes is governed through supplier controls, not ignored.

Integrates with ISO/IEC 27001

Shared context, risk method, document control and audit programme, with an AI-specific annex.

How we deliver

From AI inventory to certification

Delivered as an extension of your existing management system where one exists.

  1. AI inventory and scoping

    Identify where AI is actually in use — routinely broader than management expects — and classify it by impact.

  2. Gap analysis

    Assessment against the ISO/IEC 42001 requirements and Annex A controls.

  3. AI system impact assessment

    System-level impact assessments for high-consequence use, with an assessment process you can repeat.

  4. Governance and documentation build

    AI policy, accountability framework, data governance, lifecycle and supplier controls.

  5. Implementation and awareness

    Controls embedded with the teams who build, buy and operate AI; responsible-use training.

  6. Integration and internal audit

    Folded into the existing audit programme and management review.

  7. Certification support

    Support through the certification audit where you want third-party assurance.

Engagement summary

Standard
ISO/IEC 42001:2023
Regulation
EU AI Act — Regulation (EU) 2024/1689
Delivered as
Word and Excel; version-controlled, metadata cleaned, document IDs applied
Language
English by default for EU clients; Turkish available

Our approach

  • Built as an extension of your ISMS where one exists
  • AI inventory that includes supplier and embedded AI, not only in-house models
  • Impact assessment proportionate to consequence
  • Documentation written to how AI is actually used in your processes
  • Clear line between management system controls and legal advice on the AI Act
What you receive

What you hold at the end of the engagement

  • AI inventory and impact classification
  • AIMS scope and context analysis
  • AI policy and objectives
  • AI roles and accountability framework
  • AI system impact assessment procedure and completed assessments
  • AI risk assessment and treatment plan
  • Data governance procedure for training and inference data
  • AI lifecycle controls
  • Supplier and third-party AI controls
  • AI incident handling procedure
  • Responsible-use awareness training and records
  • Internal audit report and management review pack
Frequently asked questions

Questions we are asked

We only use third-party AI tools. Is ISO/IEC 42001 relevant?

Often, yes. The larger group of organisations using the standard are deployers of third-party AI inside operational processes, where a failure would have safety, quality, financial or privacy consequences. The standard’s supplier and impact controls are designed exactly for that situation.

Does ISO/IEC 42001 certification mean we comply with the EU AI Act?

No single certificate equals legal compliance. ISO/IEC 42001 gives you the governance structure — roles, impact assessment, lifecycle and supplier controls, records — through which AI Act obligations can be managed and evidenced. Which obligations apply to you depends on your role and the risk classification of each system.

Can it be combined with ISO/IEC 27001?

Yes. Both follow the same harmonised management system structure. We add the AI management system as an extension of the existing ISMS: shared context, risk method, document control and audit programme, plus an AI-specific annex and impact assessment process.

Where do we start?

With an AI inventory. Most organisations discover AI in more places than expected — embedded in software, in suppliers’ services, in individual teams’ tools. The inventory and impact classification define a proportionate scope for everything that follows.

Let us start with a scoping conversation

Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.