ISO 42001 certification, sized for the AI you actually run.
ISO/IEC 42001 implementation, internal audit leadership, and Stage 1 / Stage 2 certification audit support — led by a PECB-certified ISO/IEC 42001 Lead Auditor, built on the AI Governance & Security substrate. Body-independent across the EU.
Overview
A management system for AI — not an AI Act shortcut.
ISO/IEC 42001:2023 is the first certifiable international standard for an Artificial Intelligence Management System (AIMS). It specifies the requirements for establishing, implementing, maintaining, and continually improving an AIMS — regardless of the size of the organisation, the sector, or the role it plays (deployer, provider, GPAI integrator).
The standard has two components. The management framework — 10 clauses built on the Annex SL backbone (the same backbone used by ISO 27001), covering how your organisation plans, implements, monitors, and improves its AIMS. Annex A — a reference set of 38 AI-specific controls across 9 categories (policies, internal organisation, resources, AI system impact assessment, AI system lifecycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships). You select, implement, and document control applicability based on your AI risk assessment in a Statement of Applicability.
ISO 42001 sits alongside — not on top of — EU AI Act compliance. The standard treats the AI Act as an interested-party requirement input: the AIMS must operate within the regulatory environment, but ISO 42001 certification itself does not constitute AI Act conformity assessment. The AI Governance & Security service produces the AI Act-specific evidence pack; ISO 42001 Certification wraps the same governance work into a certifiable AIMS and takes it through the audit.
Who ISO 42001 is for
Voluntary today — but increasingly a procurement and assurance differentiator for organisations whose AI footprint is now material.
SaaS companies and AI-product vendors
Enterprise procurement processes are starting to ask vendors for AI governance evidence. ISO 42001 is the most defensible single answer. The AIMS also wraps cleanly around the Article 17 QMS that the AI Act requires of Providers.
Regulated-AI deployers
Financial-services credit scoring, emergency patient triage, recruiting and HR screening platforms, education assessment, critical-infrastructure operators, public-sector decision-making systems. The AIMS structures the governance their Article 26 obligations now require.
Companies shipping AI features on foundation models
Internal copilots, customer-facing chatbots, AI agents, retrieval-augmented apps. An AIMS scoped to GPAI integration produces the documented model-selection, evaluation, and monitoring practices that procurement and insurers ask for.
Suppliers to enterprises with AI vendor assurance
Large EU enterprises now extend AI governance requirements down their supply chain. ISO 42001 is a recognised way to meet that bar without bespoke audits per customer.
Public-sector AI tenderers
EU and national procurement frameworks are starting to list AI management evidence as a qualification for AI-related IT and data-processing contracts. ISO 42001 maps directly to that requirement.
Any business seeking AI-related cyber insurance
Insurers are pricing AI-related cyber risk separately. A certified AIMS is a clear signal of managed AI governance for underwriters.
The 10 management clauses
What every AIMS must demonstrate.
- 01Clause 4
Context of the organisation
Business environment, AI systems in scope, interested parties (the EU AI Act sits here as a regulatory interested-party requirement), AIMS scope statement.
- 02Clause 5
Leadership
Top-management commitment, the AI policy, AI roles and responsibilities and authorities.
- 03Clause 6
Planning
AI risk assessment (ISO/IEC 23894-aligned), AI system impact assessment, risk treatment plan, AI objectives.
- 04Clause 7
Support
Resources, AI-specific competence, awareness, communication, documented information control.
- 05Clause 8
Operation
Operational planning and control, AI system lifecycle (design, data, validation, deployment, monitoring), third-party AI relationships.
- 06Clause 9
Performance evaluation
Monitoring, measurement, analysis, internal audit (mandatory), management review.
- 07Clause 10
Improvement
Non-conformities, corrective actions, continual improvement of the AIMS.
- 08Annex A
38 controls across 9 categories
Policies (A.2), internal organisation (A.3), resources (A.4), AI system impact assessment (A.5), AI system lifecycle (A.6), data for AI systems (A.7), information for interested parties (A.8), use of AI systems (A.9), and third-party and customer relationships (A.10). Selected and justified in the Statement of Applicability.
Consequences (non-fines)
No statutory penalties — but commercial cost compounds.
ISO/IEC 42001 is voluntary, so there are no statutory fines for non-certification. The cost of lacking certification, however, compounds: disqualification from procurement tenders that increasingly require AI governance evidence, inability to meet enterprise client AI vendor-assurance requirements, exposure to AI-related cyber-insurance gaps, and friction with EU and national public-sector procurement frameworks that are starting to require AI management evidence.
Certified organisations also use ISO 42001 to meet substantial portions of EU AI Act obligations — the AIMS structure maps directly to Article 17 QMS for Providers, Article 9 risk management, Article 10 data governance, Annex IV technical documentation, and the broader management-system requirements that sit under both Chapter III (Provider) and Article 26 (Deployer) duties. The AIMS is the most cost-effective single foundation for AI Act readiness.
AI Act Art. 17
Large overlap
the AIMS structure maps onto most provider QMS obligations.
AI Act Chapter III
Substantial
of provider obligations supported by a well-scoped AIMS.
AI Act Art. 26
Partial
deployer duties supported; the rest is AI Act-specific.
Our approach
AIMS certification, designed for SMB scale.
What we deliver
- Gap analysis against the 10 management clauses and Annex A — costed roadmap to certification
- AIMS scope and context — sized for your AI estate, not enterprise-bloated
- AI risk assessment (ISO/IEC 23894), AI system impact assessment, treatment plan, and Statement of Applicability
- AIMS policy stack — AI policy, AI roles, competence and awareness framework
- Annex A control design pack — 38 controls scoped through the SoA, implemented by your teams and vendors
- Mandatory internal audit (Clause 9.2) — ISO/IEC 19011-aligned, led by a PECB ISO/IEC 42001 Lead Auditor
- Management review (Clause 9.3) and pre-certification readiness review
- Certification body selection guidance — body-independent across the EU
- Stage 1 / Stage 2 audit support and Phase 6 surveillance retainer
Typical timeline
8–12 months for most SMBs starting from a low baseline. Clients with prior AI Governance & Security history finish meaningfully faster — the substrate is already in place.
Weeks 1–4
Gap analysis & AIMS scope
Current state vs ISO 42001 requirements, AIMS scope definition, interested-parties analysis, prioritised costed action plan.
Months 2–6
AIMS build
AI risk assessment and treatment, AI system impact assessment, AI policy stack, Annex A control design with your team, Statement of Applicability, awareness programme rollout.
Month 7
Internal audit & management review
Independent internal audit against all clauses and selected Annex A controls, led by a PECB ISO/IEC 42001 Lead Auditor. Management review. Corrective actions resolved before the external auditor sees the AIMS.
Months 8–11
Certification audit
Stage 1 (document review) then Stage 2 (on-site assessment) with your chosen accredited certification body.
FAQ