ISO 42001 consulting: a certifiable way to govern AI
As AI moves into production processes, quality control, logistics planning and customer operations, procurement teams and regulators are asking how it is governed. We answer that with a certifiable AI management system, led personally by an ISO/IEC 42001 Lead Auditor — and integrated with your existing ISMS where one exists.
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the first international management system standard for artificial intelligence. It specifies requirements for an AI management system (AIMS) covering AI policy and objectives, roles and accountability, AI system impact assessment, data governance for training and inference, lifecycle controls, supplier management, monitoring and incident handling, with a set of Annex A controls. It is a practical governance vehicle for demonstrating that obligations under the EU AI Act — Regulation (EU) 2024/1689 — are being managed, by developers and deployers alike.
Why ISO/IEC 42001 now
The EU AI Act
Obligations fall on deployers as well as developers. ISO/IEC 42001 gives you a structured way to manage and evidence them.
Procurement questions
“How do you govern AI?” is an increasingly common procurement question — and a certificate answers it.
AI is already in use
AI is routinely used more widely than management expects: in tools, suppliers’ products and operational processes.
Impact-based control
Impact assessment focuses control where a failure would have safety, quality, financial or privacy consequences.
Supplier AI
Third-party AI inside your processes is governed through supplier controls, not ignored.
Integrates with ISO/IEC 27001
Shared context, risk method, document control and audit programme, with an AI-specific annex.
From AI inventory to certification
Delivered as an extension of your existing management system where one exists.
AI inventory and scoping
Identify where AI is actually in use — routinely broader than management expects — and classify it by impact.
Gap analysis
Assessment against the ISO/IEC 42001 requirements and Annex A controls.
AI system impact assessment
System-level impact assessments for high-consequence use, with an assessment process you can repeat.
Governance and documentation build
AI policy, accountability framework, data governance, lifecycle and supplier controls.
Implementation and awareness
Controls embedded with the teams who build, buy and operate AI; responsible-use training.
Integration and internal audit
Folded into the existing audit programme and management review.
Certification support
Support through the certification audit where you want third-party assurance.
Engagement summary
- Standard
- ISO/IEC 42001:2023
- Regulation
- EU AI Act — Regulation (EU) 2024/1689
- Delivered as
- Word and Excel; version-controlled, metadata cleaned, document IDs applied
- Language
- English by default for EU clients; Turkish available
Our approach
- Built as an extension of your ISMS where one exists
- AI inventory that includes supplier and embedded AI, not only in-house models
- Impact assessment proportionate to consequence
- Documentation written to how AI is actually used in your processes
- Clear line between management system controls and legal advice on the AI Act
What you hold at the end of the engagement
- AI inventory and impact classification
- AIMS scope and context analysis
- AI policy and objectives
- AI roles and accountability framework
- AI system impact assessment procedure and completed assessments
- AI risk assessment and treatment plan
- Data governance procedure for training and inference data
- AI lifecycle controls
- Supplier and third-party AI controls
- AI incident handling procedure
- Responsible-use awareness training and records
- Internal audit report and management review pack
Questions we are asked
We only use third-party AI tools. Is ISO/IEC 42001 relevant?
Often, yes. The larger group of organisations using the standard are deployers of third-party AI inside operational processes, where a failure would have safety, quality, financial or privacy consequences. The standard’s supplier and impact controls are designed exactly for that situation.
Does ISO/IEC 42001 certification mean we comply with the EU AI Act?
No single certificate equals legal compliance. ISO/IEC 42001 gives you the governance structure — roles, impact assessment, lifecycle and supplier controls, records — through which AI Act obligations can be managed and evidenced. Which obligations apply to you depends on your role and the risk classification of each system.
Can it be combined with ISO/IEC 27001?
Yes. Both follow the same harmonised management system structure. We add the AI management system as an extension of the existing ISMS: shared context, risk method, document control and audit programme, plus an AI-specific annex and impact assessment process.
Where do we start?
With an AI inventory. Most organisations discover AI in more places than expected — embedded in software, in suppliers’ services, in individual teams’ tools. The inventory and impact classification define a proportionate scope for everything that follows.
Let us start with a scoping conversation
Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.