Free consultation

ISO/IEC42001

Artificial Intelligence Management System (AIMS)

ISO 42001 Consulting
AI Management System

Build and use AI with governance you can prove, using the world’s first AI management system standard — and answer customers and regulators when they ask how you control AI risk.

Published — the first AIMS standard
2023
Reference controls in Annex A (selected per risk)
38
Control objective areas
9
Certificate cycle + annual surveillance
3 yrs

What is ISO 42001?

ISO/IEC 42001 is the international standard for an Artificial Intelligence Management System (AIMS), published in 2023. It defines how an organisation governs the responsible development, procurement and use of AI systems.

It follows the same structure as other ISO management system standards: the core requirements are clauses 4 to 10, and Annex A lists 38 reference controls in nine areas (AI policy, AI system impact assessment, AI system life cycle, data, third-party relationships) that organisations select based on their risk assessment and document in the Statement of Applicability.

Because the structure matches ISO 27001, organisations that already run an ISMS can build on it quickly, though additional work remains — particularly AI-specific risk and impact assessment, data governance, and AI system lifecycle management.

Deliverables

What you get

  • An inventory of the AI systems you develop, procure or use, and your role in each
  • A responsible AI policy and clearly assigned responsibilities
  • AI risk assessment and AI system impact assessment for individuals and society
  • A Statement of Applicability covering all 38 controls, with reasons
  • Practices for training and test data, and monitoring of system performance
  • Team training, internal audit and preparation for certification

ISO/IEC 42001

What ISO 42001 focuses on

What an auditor will ask beyond a general management system.

Impact assessment

Assess how an AI system could affect individuals, groups or society — fairness, privacy, safety — before it goes live.

AI system life cycle

Control design, development, testing, release, monitoring and retirement, with records that can be traced back.

Data quality

Know where training and test data come from, check quality and bias, and handle it within data protection law.

Transparency

Tell users and stakeholders what the AI system does and its limits, and keep people in control of important decisions.

Our Process

From day one to the day the auditor walks in

Every project follows these five steps. Timing depends on your size and scope — you’ll get a firm timeline once the readiness assessment is done.

  1. Gap analysis

    Compare your current practice with the requirements and define the certification scope.

    ~2–4 weeks
  2. System design

    Write policies, procedures, forms and a risk register people will actually use.

    ~1–3 months
  3. Rollout & training

    Train your team and build up complete records and evidence.

    ~1–3 months
  4. Internal audit

    Audit internally, fix nonconformities and hold the management review.

    ~2–4 weeks
  5. Certification audit

    We stand beside you through the certification body’s or assessor’s audit until you’re certified.

    per auditor schedule

Consultants cannot issue certificates — certificates come from an independent Certification Body. We help you choose one and make sure everything is ready.

FAQ

Frequently asked questions

We only use AI from outside providers. Do we need ISO 42001?

The standard applies both to organisations that build AI and to those that use AI from others; scope and controls differ by role. For users, the key points are selecting and controlling providers and assessing the impact on the people affected.

We already have ISO 27001. How much does that help?

A lot. Both standards share the clause 4–10 structure, so risk management, document control, internal audit and management review carry over, and the new work concentrates on AI-specific issues.

How does ISO 42001 help with AI regulation?

Certification does not replace legal compliance, but a management system covering risk assessment, transparency and human oversight makes it much easier to adapt to AI laws as they arrive, such as the EU AI Act.

How long until we are ready for certification?

It depends on scope, existing AI maturity, and available evidence. Organisations that already hold ISO 27001 typically need 5–8 months of preparation; those building from scratch may take longer. The timeline includes defining scope, assessing AI risks and impacts, building evidence, internal audit and management review. Certification timeline also depends on the certifying body's schedule.

Contact

Start with a free one-hour ISO 42001 readiness assessment

Address
42/135 Chit Aree Ville 5, Lampang–Ngao Highway Rd., Chomphu, Mueang Lampang, Lampang 52100, Thailand

Call or email us and tell us where your organisation stands. We’ll tell you which standard to start with, roughly how long it will take, and what you need to prepare.

Tax ID
0525568001095