ISO/IEC42001
Artificial Intelligence Management System (AIMS)
ISO 42001 Consulting
AI Management System
Build and use AI with governance you can prove, using the world’s first AI management system standard — and answer customers and regulators when they ask how you control AI risk.
- Published — the first AIMS standard
- 2023
- Reference controls in Annex A (selected per risk)
- 38
- Control objective areas
- 9
- Certificate cycle + annual surveillance
- 3 yrs
What is ISO 42001?
ISO/IEC 42001 is the international standard for an Artificial Intelligence Management System (AIMS), published in 2023. It defines how an organisation governs the responsible development, procurement and use of AI systems.
It follows the same structure as other ISO management system standards: the core requirements are clauses 4 to 10, and Annex A lists 38 reference controls in nine areas (AI policy, AI system impact assessment, AI system life cycle, data, third-party relationships) that organisations select based on their risk assessment and document in the Statement of Applicability.
Because the structure matches ISO 27001, organisations that already run an ISMS can build on it quickly, though additional work remains — particularly AI-specific risk and impact assessment, data governance, and AI system lifecycle management.
Deliverables
What you get
- An inventory of the AI systems you develop, procure or use, and your role in each
- A responsible AI policy and clearly assigned responsibilities
- AI risk assessment and AI system impact assessment for individuals and society
- A Statement of Applicability covering all 38 controls, with reasons
- Practices for training and test data, and monitoring of system performance
- Team training, internal audit and preparation for certification
ISO/IEC 42001
What ISO 42001 focuses on
What an auditor will ask beyond a general management system.
Impact assessment
Assess how an AI system could affect individuals, groups or society — fairness, privacy, safety — before it goes live.
AI system life cycle
Control design, development, testing, release, monitoring and retirement, with records that can be traced back.
Data quality
Know where training and test data come from, check quality and bias, and handle it within data protection law.
Transparency
Tell users and stakeholders what the AI system does and its limits, and keep people in control of important decisions.
Our Process
From day one to the day the auditor walks in
Every project follows these five steps. Timing depends on your size and scope — you’ll get a firm timeline once the readiness assessment is done.
Gap analysis
Compare your current practice with the requirements and define the certification scope.
~2–4 weeksSystem design
Write policies, procedures, forms and a risk register people will actually use.
~1–3 monthsRollout & training
Train your team and build up complete records and evidence.
~1–3 monthsInternal audit
Audit internally, fix nonconformities and hold the management review.
~2–4 weeksCertification audit
We stand beside you through the certification body’s or assessor’s audit until you’re certified.
per auditor schedule
Consultants cannot issue certificates — certificates come from an independent Certification Body. We help you choose one and make sure everything is ready.
FAQ
Frequently asked questions
We only use AI from outside providers. Do we need ISO 42001?
The standard applies both to organisations that build AI and to those that use AI from others; scope and controls differ by role. For users, the key points are selecting and controlling providers and assessing the impact on the people affected.
We already have ISO 27001. How much does that help?
A lot. Both standards share the clause 4–10 structure, so risk management, document control, internal audit and management review carry over, and the new work concentrates on AI-specific issues.
How does ISO 42001 help with AI regulation?
Certification does not replace legal compliance, but a management system covering risk assessment, transparency and human oversight makes it much easier to adapt to AI laws as they arrive, such as the EU AI Act.
How long until we are ready for certification?
It depends on scope, existing AI maturity, and available evidence. Organisations that already hold ISO 27001 typically need 5–8 months of preparation; those building from scratch may take longer. The timeline includes defining scope, assessing AI risks and impacts, building evidence, internal audit and management review. Certification timeline also depends on the certifying body's schedule.
Contact
Start with a free one-hour ISO 42001 readiness assessment
- Phone
- 086-654-0991
- Address
- 42/135 Chit Aree Ville 5, Lampang–Ngao Highway Rd., Chomphu, Mueang Lampang, Lampang 52100, Thailand
Call or email us and tell us where your organisation stands. We’ll tell you which standard to start with, roughly how long it will take, and what you need to prepare.
- Tax ID
- 0525568001095
- Address
- View map ↗