WHAT IT IS
AI Management
Governing AI responsibly across its lifecycle
CURRENT VERSION
ISO/IEC 42001:2023
The first edition of its kind
CERTIFIABLE?
Yes
Through an accredited certification body
BEST FOR
AI builders & adopters
Anyone embedding AI in a product
STANDARD EXPLANATION
What is ISO 42001?
ISO 42001 is the first international standard for an Artificial Intelligence Management System — an AIMS. Published in December 2023, it gives organisations a structured way to govern how they develop and use AI: managing risks like bias, lack of transparency, safety, and accountability, while still leaving room to actually innovate.
Like the other ISO management standards, it follows the harmonised high-level structure and is built around risk — including a specific AI system impact assessment that asks you to think through the effect your AI has on the people and groups it touches. It's deliberately broad enough to apply whether you're training your own models or building on top of someone else's.
It's a genuinely new field, and it pairs naturally with emerging AI regulation like the EU AI Act. For AI-native products especially, being able to point to a recognised governance framework is fast becoming a real commercial advantage rather than a nice-to-have.
Being early counts here. First certifications are still emerging, so for an AI-focused business an ISO 42001 certificate is a strong, differentiating trust signal — particularly when enterprise customers start asking how your AI is governed.
WHY PEOPLE COME TO US FOR IT
Do you actually need ISO 42001?
It's most relevant to organisations where AI is part of the product or a meaningful part of operations. The trigger usually looks like one of these.
01
Customers are asking how your AI is governed. Enterprise buyers and partners increasingly want assurance about how you manage AI risk — and "we're careful" isn't a satisfying answer.
02
You want to get ahead of AI regulation. Rules like the EU AI Act are arriving. A recognised management framework puts you in a much stronger position than starting from nothing.
03
You want internal guardrails as you scale. AI is moving fast inside your business and you want responsible, consistent practices before something goes wrong, not after.
HOW WE HELP
Two ways in. Same principle throughout.
Whether we're independently auditing your AIMS or helping you build it, you stay involved and walk away understanding it. Here's how that splits for ISO 42001.
Audit & Assessment · Independent
We check your system against the standard.
Impartial, evidence-based work — and kept separate from your certification body, so nobody's marking their own homework.
-
Gap analysis against ISO 42001 before you commit
-
Internal audits to satisfy clause 9.2 (required to certify)
-
Review of your AI risk and impact assessments
-
Clear findings — conformities, nonconformities, observations
Implementation Support · Collaborative
We help you build the AIMS — alongside you.
Hands-on help with the parts that genuinely need it, with your team driving the work so you can run it afterwards.
-
Scoping your AIMS around how you actually use AI
-
Building the AI risk and impact assessments
-
Writing AI governance policies with you, not for you
-
Lining it up with the EU AI Act and prepping for audit
COMMON QUESTIONS
ISO 42001 questions we hear a lot
What is ISO 42001, simply put?
It's the first international standard for managing AI responsibly — a structured way to govern how AI is developed and used in your organisation, covering risks like bias, transparency, and accountability. It was published in December 2023 and is set to slowly rise in popularity in the years to come.
Is ISO 42001 the same as the EU AI Act?
No. ISO 42001 is a voluntary management standard you can certify against. The EU AI Act is law, with its own obligations and penalties. They complement each other — a 42001 management system is a sensible foundation for demonstrating responsible AI under the Act, but it isn't the same thing.
Is it relevant for a small AI startup?
Yes. ISO 42001 is designed to be scalable, making it just as relevant for small AI startups as larger organisations, and because certification is still relatively uncommon, it can provide a valuable trust signal when engaging with larger, more risk-conscious customers and partners.
Is an internal audit required?
Yes. Clause 9.2 requires you to run internal audits of your AIMS at planned intervals. You need evidence of internal audits both to achieve certification and to keep it at each surveillance visit. Using an independent auditor keeps those findings credible — and is exactly the kind of work we do.
Can I run it alongside ISO 27001 or any other ISO standards?
Yes, and many do. Many ISO standards share the same high-level structure, so you can operate an integrated management system rather than two separate ones — less duplication, fewer audits. If done correctly, the standards can complement each other and help you grow your business in a mature and consistent way.
Do you issue the certificate?
No — and that separation matters. The certificate is issued by an accredited certification body after their own Stage 1 and Stage 2 audits. We're independent of that process. We help you get ready and run the internal audits the standard requires, but we don't mark our own work or yours.
RELATED STANDARDS
Often comes up alongside
ISO 27001
The security counterpart, frequently run as an integrated management system with ISO 42001.
Information Security
EU AI Act
The law arriving across EU. ISO 42001 gives you a framework to help meet it.
AI Regulation
ISO 27701
Where AI meets personal data - profiling and automated decisions overlap heavily.

