
ISO/IEC 42001 Consulting and Certification
We take firms through ISO/IEC 42001 from AIMS scope and AI inventory through risk and impact assessment, policies, controls and evidence, to internal audit, management review and preparation for independent certification. Delivered with Hael and inside your existing GRC or compliance environment.
Built by compliance practitioners
Expert Guidance Through Every Stage of Your ISO 42001 Programme

Regulatory depth
The standard is built into how the programme is run: which AI activities sit within scope, what the AIMS needs to govern, how risks and impacts are assessed, which controls are selected, what belongs in the Statement of Applicability and what a certification auditor will expect to see in operation. The work is designed by practitioners who understand both AI governance and regulated operating environments.

One record, every output
AI inventory, risk assessments, impact assessments, objectives, controls, evidence, approvals, internal audit findings and management review actions are maintained as one programme. The certification pack, customer questionnaire response, EU AI Act mapping and next surveillance cycle can therefore draw from the same approved record.

Independence preserved
The independent certification body must be able to audit the AIMS objectively. Readiness, implementation and internal support are kept distinct from the external certification decision, so we build and test the management system while the certification body retains full responsibility for the audit and certificate.
Leading security compliance since 2013

.png)

.png)

.png)

Why firms use us for ISO 42001
A customer or board has asked for proof
Organisations increasingly need more than an AI principles statement. ISO/IEC 42001 provides a certifiable management-system structure for demonstrating that AI is governed systematically, with ownership, risk assessment, controls, monitoring and continual improvement.
AI use has grown faster than governance
Teams adopt models, copilots, embedded AI services and internally developed systems at different speeds. The result is often no authoritative inventory, inconsistent approval and unclear accountability. The AIMS creates one governance layer across those uses.
Templates do not create an AIMS
A policy set can make a programme look complete while the underlying decisions, risk treatment, evidence and monitoring do not exist. Certification auditors test whether the management system operates, not whether the organisation owns a folder containing AI policies.
The EU AI Act is creating a second deadline
Many organisations need both ISO 42001 and EU AI Act readiness. Running them separately duplicates inventories, risk processes, controls and evidence. A mapped programme allows the management system to support the regulatory work without pretending the standard and the law are identical.
One programme. Every output.
The AIMS is the operating system. The controls implement it. The evidence demonstrates that it is functioning and gives the certification auditor something real to test.
AIMS scope and context
The organisational boundary, AI activities, interested parties, internal and external issues and interfaces with existing management systems, decided and recorded at the start.
AI risk and impact framework
A repeatable method for identifying, analysing, evaluating and treating AI risks and for assessing the impacts of AI systems on individuals, groups and the organisation.
Control environment and Statement of Applicability
Controls selected against identified risks and compared with Annex A, with inclusion, exclusion and implementation status recorded in the Statement of Applicability.
Evidence and performance record
Objectives, metrics, competence, approvals, monitoring, internal audit, management review, nonconformities and corrective actions maintained as evidence of an operating management system.
Certification pack
Scope, core documented information, risk and impact records, Statement of Applicability, audit evidence and responsible owners prepared for Stage 1 and Stage 2 certification activity.
Our simple three-step process
We help AI companies, SaaS providers, fintechs and regulated firms build an AIMS that can reach certification and remain useful afterwards.
Step 1: Scope and Readiness
We confirm the AIMS boundary, identify relevant AI systems and stakeholders, assess current governance and evidence and map gaps against ISO/IEC 42001 requirements.
Step 2: Implementation and Evidence
We build the policies, objectives, risk and impact processes, controls, Statement of Applicability, ownership and evidence routines, then embed them with the teams that operate the AI systems.
Step 3: Audit and Certification
We support internal audit and management review, resolve readiness gaps, prepare people and evidence for the independent certification body and manage responses through the audit process.
Our ISO 42001 services
Full end-to-end support.
ISO 42001 readiness assessment
We assess your existing AI governance, risk processes, documentation and evidence against the AIMS requirements and set out the work required before certification.
Statement of Applicability and controls
We compare necessary risk treatment controls with Annex A, document the rationale and implementation status and ensure the record aligns with the wider AIMS.
AIMS implementation and remediation
We design the management system, prepare the required documentation and work with control owners to embed the processes rather than handing over templates.
Internal audit and certification readiness
We support or conduct appropriately independent internal audit activity, prepare management review and close findings before the external audit.
AI risk and impact assessment
We establish the methodology, facilitate assessments and connect resulting treatment decisions to control selection, ownership and evidence.
Continuous assurance
We maintain the AIMS between audits through evidence review, risk refresh, system change assessment, corrective action and preparation for surveillance and recertification.

Our People
Our AI assurance team combines AI governance, information security, risk and regulatory compliance experience. The same practitioners who advise regulated firms through authorisation and supervision design management systems that connect board accountability with product, data, engineering, procurement and operational controls.
When you work with us, you gain direct access to senior professionals rather than an account manager. The programme is run by people who understand what a certification auditor will test, what enterprise customers ask for and how ISO 42001 can be mapped sensibly to the EU AI Act, ISO 27001 and other assurance frameworks.
Key information and requirements for ISO/IEC 42001
Key information
What ISO/IEC 42001 requires ISO/IEC 42001:2023 is the international management-system standard for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System. It is designed for organisations that develop, provide or use AI systems and provides a structured way to govern AI-related risks and opportunities. The value is not the existence of another policy library. It is the management discipline that requires AI objectives, risks, decisions, controls and improvement actions to be owned and reviewed across the organisation.
AIMS, not an AI product certificate. Certification assesses the organisation's AI management system within a defined scope. It is not a certification that every AI model is safe, accurate or legally compliant, and the scope shown on the certificate matters when customers assess what assurance it actually provides. The scope statement should therefore be written so a customer can understand what activities and organisational boundaries the certificate actually covers. Scope decisions made only to minimise audit effort often weaken the commercial value of certification.
Risk and impact assessment. The standard expects a structured approach to AI risk and to the impacts associated with AI systems. Those processes need to drive treatment decisions and controls rather than exist as standalone forms completed only before an audit. Impact assessment should be tied to the intended purpose and context of each relevant AI system. Material changes in use, affected people, data, suppliers or model behaviour should trigger reassessment rather than waiting for an annual review.
Statement of Applicability. Identified risks and the controls established to address them are reflected in a Statement of Applicability. The organisation compares necessary controls with Annex A and records why controls are included or excluded and how applicable controls are implemented. The SoA is also a useful assurance document because it shows the logic of the risk-treatment programme. Where controls are excluded, the rationale should be specific enough that an auditor can see the decision was deliberate and evidence-based.
Management-system requirements. The AIMS includes the familiar management-system disciplines of context, leadership, planning, support, operation, performance evaluation and improvement. In practice that means objectives, roles, competence, communication, operational control, monitoring, internal audit, management review and corrective action need to operate together. The strongest programmes reuse existing management-system infrastructure where it is effective, but they do not simply rename ISO 27001 processes as AI governance. AI introduces distinct issues around models, data, impacts, lifecycle decisions and human oversight that need explicit treatment.
Certification independence. ISO does not certify organisations. Certification is performed by an independent certification body, and the body remains responsible for its audit findings and certification decision. Internal audit should be sufficiently independent from the activities being audited, and management review should result in decisions and actions rather than a ceremonial meeting. Both are opportunities to detect weak ownership before the certification body does.
Continual improvement. Certification is not the end of the programme. The organisation needs to maintain and improve the AIMS as AI systems, suppliers, risks, objectives and regulatory expectations change. After certification, changes to AI systems and business scope should feed into risk, impact and control review. That prevents the certified AIMS from gradually drifting away from the AI estate it was created to govern.
Our services
Scoping. AIMS boundary, AI activities, relevant interested parties, interfaces and certification objectives confirmed and recorded.
Readiness assessment. Current governance, processes and evidence assessed against the standard with findings prioritised by certification impact.
Policies and AIMS documentation. The documented management system written to describe how the organisation actually governs and uses AI.
Risk, impact and control implementation. Assessment methods, treatment planning, Annex A comparison, Statement of Applicability and operating controls established and embedded.
Internal audit and management review. Evidence gathered, audit activity supported, findings resolved and management review prepared so leadership can make the decisions the AIMS requires.
Certification coordination. Certification body selection supported, evidence and people prepared and audit requests managed through Stage 1 & Stage 2.
Continuous assurance. Ongoing maintenance, surveillance preparation, change assessment, risk refresh and corrective-action support after certification.
What we provide
Scoping and readiness. AIMS boundary, gap assessment and implementation roadmap with named owners and dates.
Implementation. Policies, governance, risk and impact processes, control design and Statement of Applicability.
Evidence and platform. Evidence plan, GRC configuration where used, control ownership and pre-audit review.
Audit support. Internal audit readiness, management review support, certification pack and management of external auditor requests.
Continuous assurance. Surveillance preparation, evidence refresh, change assessment and continual-improvement support.
What we provide
Scope and classification. A complete AI inventory, role map, risk classification and applicability record for every material system.
Implementation. Policies, governance, risk processes, controls, ownership and operational procedures aligned to the obligations in scope.
Documentation and evidence. A structured compliance record tying obligations to evidence, system owners, review dates and supporting artefacts.
Readiness support. Internal challenge, gap closure, control-owner briefing and preparation for conformity, customer or regulator review.
Ongoing compliance. Monitoring of systems and use cases, evidence refresh and governance updates as the AI estate changes.
Other important information
ISO 42001 and the EU AI Act overlap but are different. ISO 42001 can provide governance, risk, impact, monitoring and continual-improvement structure that supports EU AI Act work. The Regulation contains legal duties that still need to be mapped separately by system and role. A combined control architecture is especially valuable for SaaS and fintech firms that already maintain security evidence. The same governance calendar and evidence owners can support both standards while the distinct AI content is added where required.
ISO 27001 can share management-system infrastructure. Where an organisation already operates an ISMS, common processes such as document control, risk governance, internal audit, management review, competence and corrective action can often be reused rather than duplicated. Certification bodies and customers read the scope closely. If a revenue-critical AI service sits outside it, the certificate may have far less procurement value than management expected.
Certification scope changes commercial value. A narrow AIMS may be easier to certify but may not answer what a customer wants assurance over. Scope should be designed around the services, AI lifecycle activities and organisational boundaries that matter commercially. The platform is best used as the workflow and evidence layer. Decisions on risk significance, impact, control design and accountability still require competent people who understand the organisation and its AI use.
Platforms help with evidence, not judgement. GRC and compliance platforms can organise controls, tasks and evidence. They do not decide the right AIMS boundary, resolve ambiguous risk treatment or create accountable operating processes on their own. This is why operating evidence should come from real product, engineering, procurement, risk and governance processes. An audit-ready AIMS should look recognisably like the business it governs.
The evidence should look like the business. Auditors can distinguish between a management system built into real processes and a generic template set. The best evidence is produced naturally by approvals, reviews, testing, monitoring and corrective action as work happens. Where a control or process is not working, corrective action should address the cause rather than simply closing the audit finding. Continual improvement is strongest when the organisation uses nonconformities as management information rather than audit administration.
Our Security Assurance Publications
Frequently Asked Questions about ISO 42001
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is an international management-system standard for artificial intelligence. It sets requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System, or AIMS. It is relevant to organisations that develop, provide or use AI systems and need a structured governance framework around them. The standard is intentionally broad enough to work for both developers and users of AI. The scope and risk context determine how its requirements are implemented in a particular organisation.
Is ISO 42001 a certification?
The standard itself is a set of requirements, while an organisation can choose to have its AIMS independently certified against those requirements. ISO does not issue the certificate. An independent certification body audits the management system and decides whether certification can be granted for the defined scope. The certificate gives third parties independent assurance over the management system, but it should always be read together with its scope. Certification does not transfer responsibility for AI decisions to the certification body.
Who needs ISO 42001?
It is particularly relevant to AI companies, SaaS providers, enterprise technology vendors, regulated firms and organisations deploying AI at scale. It becomes commercially important where customers, boards or investors want independent evidence of responsible AI governance. Organisations can also adopt the standard without seeking certification. It is particularly useful where the organisation has moved beyond isolated experiments and needs common governance across business units, suppliers and products. It can also create a credible foundation for customer AI questionnaires and regulatory readiness.
How long does ISO 42001 certification take?
The timeline depends on scope, the maturity of existing governance, the number and complexity of AI systems and how much evidence already exists. A focused organisation with mature ISO 27001 or other management-system processes can move faster than a business starting from no inventory, risk process or governance structure. We normally establish the implementation plan after a readiness assessment rather than promise a generic certification date. The certification body's availability also affects the final timetable, so audit dates should be reserved early once the scope is stable. Rushing directly into Stage 1 before the management system has operated usually creates avoidable findings and delay.
What is an Artificial Intelligence Management System?
An AIMS is the organisation-wide management framework used to set AI policies and objectives, allocate responsibilities, assess and treat risks and impacts, control AI-related processes, monitor performance and improve over time. It connects leadership decisions to the way AI systems are developed, purchased, deployed and monitored. The management system should therefore be visible in normal operations, not only in certification documents. The AIMS should be proportionate to the business. A twenty-person AI vendor and a global bank do not need identical committee structures, but both need clear ownership, repeatable decisions and evidence that the system is being managed.
Does ISO 42001 require a Statement of Applicability?
Yes. The risk treatment process is reflected in a Statement of Applicability that records relevant controls and the organisation's decisions around them. It provides traceability between identified risks, control selection and implementation. A credible SoA is specific to the organisation rather than a copied list of every Annex A control marked applicable. The SoA should be treated as a living management record rather than a one-time certification document. Changes in risk, system design, suppliers or operating context can change the control decisions recorded in it.
Does ISO 42001 require AI impact assessments?
The standard includes AI system impact assessment as part of its governance approach. The method should be proportionate to the systems and contexts involved and should connect to risk treatment, approvals and monitoring. Where legal frameworks such as the EU AI Act require additional or differently framed assessments, those obligations should be mapped separately. Where impact and risk assessments overlap, we design the workflow so teams do not answer the same questions repeatedly. The output should still preserve the distinct purpose of each assessment and any legal requirements that sit alongside the standard.
Can ISO 42001 help with EU AI Act compliance?
Yes, materially, but it is not a substitute for legal compliance. An effective AIMS can provide the inventory, governance, risk, impact, control, monitoring and improvement structure needed to support AI Act implementation. The legal obligations still need to be mapped to each AI system and each role the organisation holds under the Regulation. The most efficient approach is to maintain one control and evidence library with explicit mappings to each framework. That gives auditors and customers the framework-specific view they need without forcing control owners to operate duplicate processes.
Can we integrate ISO 42001 with ISO 27001?
Yes. Both are management-system standards and many governance processes can be integrated, including document control, internal audit, management review, risk oversight, competence and corrective action. The AI-specific risk, impact and lifecycle requirements still need their own content, but the shared infrastructure can materially reduce duplication. We also distinguish between remediation that must be completed before certification and improvements that can be managed through the continual-improvement cycle. That keeps the programme commercially realistic without lowering the audit-readiness standard.
What happens during ISO 42001 certification?
The certification body normally assesses whether the AIMS scope and documented system are ready and then tests implementation and effectiveness through the certification audit process. It will review evidence and speak with responsible people rather than relying solely on written policies. Any findings need to be addressed in accordance with the certification body's process before certification is granted. The external audit normally includes document review, interviews and sampling of operating evidence. Control owners should therefore be able to explain what they do and point to real records rather than rely on the consultant to answer for them.
What happens after ISO 42001 certification?
The AIMS continues to operate. Risks, impacts, objectives, systems and controls need to be reviewed, internal audits and management reviews continue, and nonconformities and corrective actions need to be managed. The certification body also carries out ongoing surveillance according to its certification programme, so stopping evidence production after the first audit creates problems at the next review. Surveillance should be treated as part of normal governance, not as another project. When evidence, risk review and corrective action continue throughout the year, the next audit is a verification exercise rather than a reconstruction.


