Isology

Services / ISO/IEC 42001 AI Management Systems

ISO/IEC 42001 AI Management Systems

ISO/IEC 42001 is the first international standard for artificial intelligence management systems. It gives boards, clients and regulators a defensible answer to one question: how do you keep your AI safe, fair, transparent and accountable? We build that system around the AI you actually use — models you develop, tools you buy, and features you have quietly switched on.

Who it's for

  • Software and product companies building or embedding AI features
  • Professional services firms using AI on client work or client data
  • Organisations answering AI assurance questions in tenders and due diligence
  • Boards that need documented oversight before scaling AI further
  • Teams already certified to ISO/IEC 27001 wanting an integrated AI extension

Our approach

A repeatable, evidence-based method refined over hundreds of engagements.

1. AI footprint & scope

We inventory every AI system in play — developed, embedded, or third-party — and agree an honest, defensible certification scope with your leadership team.

2. AI impact & risk assessment

Each use case is assessed for risk to individuals, groups and your business, using ISO/IEC 42001 requirements supported by ISO/IEC 23894 risk guidance.

3. Governance, policy & controls

AI policy, objectives, roles and accountability, data and model lifecycle controls, human oversight, transparency statements and supplier requirements — written to fit how your teams work.

4. Implementation & staff training

Role-based briefings for engineering, delivery, sales and leadership, plus acceptable-use rules so evidence builds naturally from everyday work.

5. Internal audit & management review

We run the mandatory internal audit and management review using ISO 19011:2026 guidance, then close findings before your certification body arrives.

6. Certification support

A lead consultant attends Stage 1 and Stage 2 assessment, manages the auditor and defends your evidence.

What you get

Every deliverable is fully branded to your organisation, plain-English and audit-ready.

  • AI system inventory and certification scope statement
  • AI policy, objectives and governance structure
  • AI system impact assessment methodology and completed assessments
  • AI risk register with treatment plans
  • Data quality, provenance and model lifecycle procedures
  • Human oversight and escalation procedures
  • Transparency and disclosure statements for affected users
  • Third-party and supplier AI due-diligence pack
  • AI incident response and reporting process
  • Internal audit programme, reports and management review pack
  • Integration map to ISO/IEC 27001 where already certified

Typical timeline

Indicative durations — we tailor to your business, sites and existing maturity.

  1. AI footprint & gap analysis

    1–2 weeks

    Discovery workshops, AI inventory and clause-mapped gap report.

  2. Impact & risk assessment

    2–3 weeks

    Use-case assessments, risk register and treatment decisions.

  3. System build

    4–8 weeks

    Policy, procedures and controls authored and signed off.

  4. Implementation & training

    4–10 weeks

    Roll-out, staff briefings and evidence collection.

  5. Internal audit & review

    2 weeks

    Independent internal audit and formal management review.

  6. Stage 1 & Stage 2 assessment

    4–8 weeks

    Certification body assessment with consultant attendance.

Outcomes you can expect

  • Certifiable AI management system with no major non-conformities
  • Clear, evidenced answers to AI assurance questions in tenders and audits
  • Documented board-level oversight of AI risk
  • A structured head start on EU AI Act and emerging UK AI expectations

Scope, editions and important clarifications

Formal title and what it covers

The standard is jointly published by ISO and IEC and is correctly cited as ISO/IEC 42001. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system, and applies to any organisation that develops, provides or uses AI — you do not need to build models yourself to be in scope.

It is certifiable, and it integrates

Unlike AI guidance documents such as ISO/IEC 23894 (AI risk management) and ISO/IEC 22989 (AI terminology), ISO/IEC 42001 is a management-system requirements standard, so an accredited certification body can certify you to it. It follows the same harmonised structure as ISO/IEC 27001 and ISO 9001, so it bolts onto an existing integrated management system rather than duplicating it.

Certification is not legal compliance

ISO/IEC 42001 certification demonstrates governance maturity and supports readiness for regimes such as the EU AI Act, but it is not in itself a statement of legal compliance with any AI regulation.

Disclaimer: References to the EU AI Act and other AI regulation are general guidance only and are not legal advice. Confirm your specific obligations with your legal adviser.

ISO/IEC 42001: frequently asked questions

What the AI management standard requires, who it applies to, and how it fits alongside ISO/IEC 27001 and AI regulation.

Ready to talk about ISO/IEC 42001 AI Management Systems?

A 20-minute call with one of our success team is usually enough to scope your route forward.

Book a consultation