
Services / ISO/IEC 42001 AI Management Systems
ISO/IEC 42001 AI Management Systems
ISO/IEC 42001 is the first international standard for artificial intelligence management systems. It gives boards, clients and regulators a defensible answer to one question: how do you keep your AI safe, fair, transparent and accountable? We build that system around the AI you actually use — models you develop, tools you buy, and features you have quietly switched on.
Who it's for
- Software and product companies building or embedding AI features
- Professional services firms using AI on client work or client data
- Organisations answering AI assurance questions in tenders and due diligence
- Boards that need documented oversight before scaling AI further
- Teams already certified to ISO/IEC 27001 wanting an integrated AI extension
Our approach
A repeatable, evidence-based method refined over hundreds of engagements.
1. AI footprint & scope
We inventory every AI system in play — developed, embedded, or third-party — and agree an honest, defensible certification scope with your leadership team.
2. AI impact & risk assessment
Each use case is assessed for risk to individuals, groups and your business, using ISO/IEC 42001 requirements supported by ISO/IEC 23894 risk guidance.
3. Governance, policy & controls
AI policy, objectives, roles and accountability, data and model lifecycle controls, human oversight, transparency statements and supplier requirements — written to fit how your teams work.
4. Implementation & staff training
Role-based briefings for engineering, delivery, sales and leadership, plus acceptable-use rules so evidence builds naturally from everyday work.
5. Internal audit & management review
We run the mandatory internal audit and management review using ISO 19011:2026 guidance, then close findings before your certification body arrives.
6. Certification support
A lead consultant attends Stage 1 and Stage 2 assessment, manages the auditor and defends your evidence.
What you get
Every deliverable is fully branded to your organisation, plain-English and audit-ready.
- AI system inventory and certification scope statement
- AI policy, objectives and governance structure
- AI system impact assessment methodology and completed assessments
- AI risk register with treatment plans
- Data quality, provenance and model lifecycle procedures
- Human oversight and escalation procedures
- Transparency and disclosure statements for affected users
- Third-party and supplier AI due-diligence pack
- AI incident response and reporting process
- Internal audit programme, reports and management review pack
- Integration map to ISO/IEC 27001 where already certified
Typical timeline
Indicative durations — we tailor to your business, sites and existing maturity.
AI footprint & gap analysis
1–2 weeksDiscovery workshops, AI inventory and clause-mapped gap report.
Impact & risk assessment
2–3 weeksUse-case assessments, risk register and treatment decisions.
System build
4–8 weeksPolicy, procedures and controls authored and signed off.
Implementation & training
4–10 weeksRoll-out, staff briefings and evidence collection.
Internal audit & review
2 weeksIndependent internal audit and formal management review.
Stage 1 & Stage 2 assessment
4–8 weeksCertification body assessment with consultant attendance.
Outcomes you can expect
- Certifiable AI management system with no major non-conformities
- Clear, evidenced answers to AI assurance questions in tenders and audits
- Documented board-level oversight of AI risk
- A structured head start on EU AI Act and emerging UK AI expectations
Scope, editions and important clarifications
Formal title and what it covers
The standard is jointly published by ISO and IEC and is correctly cited as ISO/IEC 42001. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system, and applies to any organisation that develops, provides or uses AI — you do not need to build models yourself to be in scope.
It is certifiable, and it integrates
Unlike AI guidance documents such as ISO/IEC 23894 (AI risk management) and ISO/IEC 22989 (AI terminology), ISO/IEC 42001 is a management-system requirements standard, so an accredited certification body can certify you to it. It follows the same harmonised structure as ISO/IEC 27001 and ISO 9001, so it bolts onto an existing integrated management system rather than duplicating it.
Certification is not legal compliance
ISO/IEC 42001 certification demonstrates governance maturity and supports readiness for regimes such as the EU AI Act, but it is not in itself a statement of legal compliance with any AI regulation.
Disclaimer: References to the EU AI Act and other AI regulation are general guidance only and are not legal advice. Confirm your specific obligations with your legal adviser.
ISO/IEC 42001: frequently asked questions
What the AI management standard requires, who it applies to, and how it fits alongside ISO/IEC 27001 and AI regulation.
Ready to talk about ISO/IEC 42001 AI Management Systems?
A 20-minute call with one of our success team is usually enough to scope your route forward.

