Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Certify Responsible AI

ISO 42001 AI Management System Certification

ISO 42001 is the first management system standard for artificial intelligence. We help you govern how you build and use AI, and certify that you do it responsibly.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

ISO/IEC 42001 sets out how to run an AI management system: the governance, risk controls, and oversight that keep artificial intelligence safe, fair, and accountable. It matters because AI now sits inside real products and decisions, and buyers want assurance you manage it well. The standard also lines up with the EU AI Act and NIST AI guidance. We help you build AI governance that satisfies auditors without slowing your teams down.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the ISO 42001 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and AI Inventory. We map the AI systems in scope and confirm your roles as a developer, provider, or user of each one. Activities: Inventory AI systems, models, and use cases; Confirm your role for each system; Set the AI management system scope; Identify interested parties and their expectations. Hands over AI System Inventory and Scope Statement. Phase 2, AI Risk and Impact Assessment. We assess each system for risks to safety, fairness, and rights, using the impact assessment approach the standard expects. Activities: Run AI impact assessments per system; Assess bias, safety, and rights risks; Score risks against your acceptance criteria; Agree treatment for each material risk. Hands over AI Risk and Impact Assessment Reports. Phase 3, AI Control Design. We design controls for data quality, human oversight, transparency, and the full AI lifecycle. Activities: Select applicable Annex A controls of ISO 42001; Design data quality and provenance controls; Define human oversight and escalation points; Write the AI policy and lifecycle procedures. Hands over AI Control Set and Statement of Applicability. Phase 4, Implementation and Monitoring. We help you embed the controls and set up ongoing monitoring of model behaviour and performance. Activities: Embed controls into the model development lifecycle; Set up monitoring of model drift and performance; Configure incident and feedback channels; Train teams on the AI governance procedures. Hands over Operating AI Controls and Monitoring Dashboard. Phase 5, Internal Audit and Review. We audit the AI management system against the standard, then run a management review of the results. Activities: Audit the AI management system against ISO 42001; Sample impact assessments and oversight records; Log nonconformities and corrective actions; Run the management review with leadership. Hands over Internal Audit Report and Management Review Record. Phase 6, Certification Support. We support you through the certification audit and help you keep pace as regulation matures. Activities: Prepare the evidence pack for the certification body; Support Stage 1 and Stage 2 audit interviews; Close findings raised during the audit; Track EU AI Act developments against your controls. Hands over ISO 42001 Certificate. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and AI Inventory

We map the AI systems in scope and confirm your roles as a developer, provider, or user of each one.

What Happens In This Phase

  • Inventory AI systems, models, and use cases
  • Confirm your role for each system
  • Set the AI management system scope
  • Identify interested parties and their expectations

The Handover

AI System Inventory and Scope Statement

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and AI Inventory

    We map the AI systems in scope and confirm your roles as a developer, provider, or user of each one.

    OutputAI System Inventory and Scope Statement

    Activities

    • Inventory AI systems, models, and use cases
    • Confirm your role for each system
    • Set the AI management system scope
    • Identify interested parties and their expectations
  2. 02

    AI Risk and Impact Assessment

    We assess each system for risks to safety, fairness, and rights, using the impact assessment approach the standard expects.

    OutputAI Risk and Impact Assessment Reports

    Activities

    • Run AI impact assessments per system
    • Assess bias, safety, and rights risks
    • Score risks against your acceptance criteria
    • Agree treatment for each material risk
  3. 03

    AI Control Design

    We design controls for data quality, human oversight, transparency, and the full AI lifecycle.

    OutputAI Control Set and Statement of Applicability

    Activities

    • Select applicable Annex A controls of ISO 42001
    • Design data quality and provenance controls
    • Define human oversight and escalation points
    • Write the AI policy and lifecycle procedures
  4. 04

    Implementation and Monitoring

    We help you embed the controls and set up ongoing monitoring of model behaviour and performance.

    OutputOperating AI Controls and Monitoring Dashboard

    Activities

    • Embed controls into the model development lifecycle
    • Set up monitoring of model drift and performance
    • Configure incident and feedback channels
    • Train teams on the AI governance procedures
  5. 05

    Internal Audit and Review

    We audit the AI management system against the standard, then run a management review of the results.

    OutputInternal Audit Report and Management Review Record

    Activities

    • Audit the AI management system against ISO 42001
    • Sample impact assessments and oversight records
    • Log nonconformities and corrective actions
    • Run the management review with leadership
  6. 06

    Certification Support

    We support you through the certification audit and help you keep pace as regulation matures.

    OutputISO 42001 Certificate

    Activities

    • Prepare the evidence pack for the certification body
    • Support Stage 1 and Stage 2 audit interviews
    • Close findings raised during the audit
    • Track EU AI Act developments against your controls

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the ISO 42001 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Credo AI, Holistic AI, OneTrust AI Governance, Vanta, Jira, Confluence, MLflow, Fiddler AI. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO/IEC 42001:2023, ISO/IEC 23894, ISO/IEC 22989, EU AI Act, NIST AI Risk Management Framework.

What We Run

8 tools

  • Credo AI
  • Holistic AI
  • OneTrust AI Governance
  • Vanta
  • Jira
  • Confluence
  • MLflow
  • Fiddler AI

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • ISO/IEC 42001:2023
  • ISO/IEC 23894
  • ISO/IEC 22989
  • AI ACTEuropean Union
  • NIST AI Risk Management Framework
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • AI system inventory
  • AI impact assessment reports
  • AI management system policy set
  • AI control mapping
  • Certification audit support

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Who needs ISO 42001?

Any organisation that builds, provides, or relies on AI systems and wants to prove it governs them responsibly. It is especially useful ahead of EU AI Act obligations.

How does ISO 42001 relate to the EU AI Act?

The standard gives you a management system that supports many EU AI Act requirements. It is not automatic compliance, but it is a strong foundation.

Can we certify just one AI system?

Yes. You set the scope, so you can start with a single high-value system and widen it later. We help you choose a sensible boundary.

Keep Moving Through Compliance

Service 4 of 13 in this practice area