Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Compliance13 services in this practice area

Certify Responsible AI

ISO 42001 AI Management System Certification

ISO/IEC 42001 is the first management system standard for artificial intelligence. We help you govern how AI is built, bought and used, and certify that governance for customers and regulators.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

ISO/IEC 42001, published in December 2023, sets out how to run an AI management system: the governance, risk assessment, impact assessment and lifecycle controls that keep artificial intelligence accountable. It follows the same management system structure as ISO 27001, so risk assessment, internal audit and management review work the same way, and its Annex A adds AI-specific controls covering policy, roles, data for AI, system lifecycle, transparency and third-party providers. It matters because AI now sits inside products and decisions, buyers ask how it is governed, and the EU AI Act places duties on providers and deployers who touch the EU market. We help Indian AI, SaaS and services companies build governance that stands up to both an auditor and a customer's due diligence.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the ISO 42001 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and AI Inventory. We map the AI systems in scope and confirm your roles as a developer, provider, or user of each one. Activities: Inventory AI systems, models, and use cases; Confirm your role for each system; Set the AI management system scope; Identify interested parties and their expectations. Hands over AI System Inventory and Scope Statement. Phase 2, AI Risk and Impact Assessment. We assess each system for risks to safety, fairness, and rights, using the impact assessment approach the standard expects. Activities: Run AI impact assessments per system; Assess bias, safety, and rights risks; Score risks against your acceptance criteria; Agree treatment for each material risk. Hands over AI Risk and Impact Assessment Reports. Phase 3, AI Control Design. We design controls for data quality, human oversight, transparency, and the full AI lifecycle. Activities: Select applicable Annex A controls of ISO 42001; Design data quality and provenance controls; Define human oversight and escalation points; Write the AI policy and lifecycle procedures. Hands over AI Control Set and Statement of Applicability. Phase 4, Implementation and Monitoring. We help you embed the controls and set up ongoing monitoring of model behaviour and performance. Activities: Embed controls into the model development lifecycle; Set up monitoring of model drift and performance; Configure incident and feedback channels; Train teams on the AI governance procedures. Hands over Operating AI Controls and Monitoring Dashboard. Phase 5, Internal Audit and Review. We audit the AI management system against the standard, then run a management review of the results. Activities: Audit the AI management system against ISO 42001; Sample impact assessments and oversight records; Log nonconformities and corrective actions; Run the management review with leadership. Hands over Internal Audit Report and Management Review Record. Phase 6, Certification Support. We support you through the certification audit and help you keep pace as regulation matures. Activities: Prepare the evidence pack for the certification body; Support Stage 1 and Stage 2 audit interviews; Close findings raised during the audit; Track EU AI Act developments against your controls. Hands over ISO 42001 Certificate. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and AI Inventory

We map the AI systems in scope and confirm your roles as a developer, provider, or user of each one.

What Happens In This Phase

  • Inventory AI systems, models, and use cases
  • Confirm your role for each system
  • Set the AI management system scope
  • Identify interested parties and their expectations

The Handover

AI System Inventory and Scope Statement

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and AI Inventory

    We map the AI systems in scope and confirm your roles as a developer, provider, or user of each one.

    OutputAI System Inventory and Scope Statement

    Activities

    • Inventory AI systems, models, and use cases
    • Confirm your role for each system
    • Set the AI management system scope
    • Identify interested parties and their expectations
  2. 02

    AI Risk and Impact Assessment

    We assess each system for risks to safety, fairness, and rights, using the impact assessment approach the standard expects.

    OutputAI Risk and Impact Assessment Reports

    Activities

    • Run AI impact assessments per system
    • Assess bias, safety, and rights risks
    • Score risks against your acceptance criteria
    • Agree treatment for each material risk
  3. 03

    AI Control Design

    We design controls for data quality, human oversight, transparency, and the full AI lifecycle.

    OutputAI Control Set and Statement of Applicability

    Activities

    • Select applicable Annex A controls of ISO 42001
    • Design data quality and provenance controls
    • Define human oversight and escalation points
    • Write the AI policy and lifecycle procedures
  4. 04

    Implementation and Monitoring

    We help you embed the controls and set up ongoing monitoring of model behaviour and performance.

    OutputOperating AI Controls and Monitoring Dashboard

    Activities

    • Embed controls into the model development lifecycle
    • Set up monitoring of model drift and performance
    • Configure incident and feedback channels
    • Train teams on the AI governance procedures
  5. 05

    Internal Audit and Review

    We audit the AI management system against the standard, then run a management review of the results.

    OutputInternal Audit Report and Management Review Record

    Activities

    • Audit the AI management system against ISO 42001
    • Sample impact assessments and oversight records
    • Log nonconformities and corrective actions
    • Run the management review with leadership
  6. 06

    Certification Support

    We support you through the certification audit and help you keep pace as regulation matures.

    OutputISO 42001 Certificate

    Activities

    • Prepare the evidence pack for the certification body
    • Support Stage 1 and Stage 2 audit interviews
    • Close findings raised during the audit
    • Track EU AI Act developments against your controls

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the ISO 42001 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Credo AI, Holistic AI, OneTrust AI Governance, Vanta, Jira, Confluence, MLflow, Fiddler AI. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO/IEC 42001:2023, ISO/IEC 23894, ISO/IEC 22989, EU AI Act (Regulation (EU) 2024/1689), NIST AI Risk Management Framework.

What We Run

8 tools

  • Credo AI
  • Holistic AI
  • OneTrust AI Governance
  • Vanta
  • Jira
  • Confluence
  • MLflow
  • Fiddler AI

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • ISO/IEC 42001:2023
  • ISO/IEC 23894
  • ISO/IEC 22989
  • AI ACTEuropean Union
  • NIST AI Risk Management Framework
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • AI system inventory
  • AI impact assessment reports
  • AI management system policy set
  • AI control mapping
  • Certification audit support

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Who needs ISO 42001?

Any organisation that develops, provides or relies on AI systems and needs to show it governs them responsibly. In practice the demand comes from three directions. Enterprise customers now ask how AI features in your product are trained, monitored and overseen, often in the same questionnaire as SOC 2 and ISO 27001. Regulated buyers need assurance before they can use your system in their own risk-managed process. And companies facing the EU AI Act want a management system that makes those duties repeatable rather than ad hoc. It is equally relevant to organisations that only deploy third-party AI, since governance of what you buy, how staff use it and what data it sees is a large part of the standard. For companies that already hold ISO 27001 or SOC 2, the incremental work is usually smaller than expected, because the management system exists and only AI-specific governance is added. That makes certification a faster answer to buyer questions than building a bespoke AI policy set nobody recognises.

How does ISO 42001 relate to the EU AI Act?

The standard is a management system; the Act is law. ISO 42001 gives you the governance machinery the Act's duties need: an inventory of AI systems, risk and impact assessment, data governance, documentation, human oversight, monitoring after deployment and supplier controls. Certification is not compliance with the Act, and no certification body can grant that. The Act's obligations depend on your role as provider or deployer and on the risk classification of each system, and conformity assessment for high-risk systems follows its own route. What ISO 42001 does is make the evidence exist and stay current, so the Act's technical documentation, oversight and monitoring requirements are produced by a working system rather than assembled in a rush. We map the standard's controls to the specific duties your systems carry. We also keep the mapping current, because the Act's timetable has already changed once and harmonised standards are still arriving, and a governance system that tracks those changes is worth more than a one-off gap report.

Can we certify a single AI system rather than the whole company?

Yes. You define the scope of the management system, so it can cover one product, one business unit or the whole organisation, as long as the boundary is coherent and defensible. Starting narrow is common and sensible: it gets the governance working around the AI that matters most commercially, proves the model to customers and auditors, and creates patterns you can extend. The scope statement has to be honest about what is inside and outside, because your certificate names it and a customer will read it. Where AI systems share data pipelines, models or teams, drawing the line too tightly can create more work than it saves. We help you choose a boundary that is meaningful to buyers and practical to run, then widen it in later cycles. We also document what sits outside the scope and why, so a customer reading the certificate understands its limits rather than assuming it covers every model you run. That honesty avoids a difficult conversation later in procurement.

What does an AI impact assessment cover?

It looks at what an AI system does to people and organisations affected by it, not just at risks to your business. A typical assessment records the system's purpose and context, the individuals or groups affected, the data used to train and run it, foreseeable harms such as unfair outcomes, inaccuracy, privacy intrusion or over-reliance, the controls in place, and the residual risk someone accountable accepts. It also records human oversight: who can review, override or switch the system off. This is the document that most often does not exist before we arrive, and it is the one auditors, enterprise buyers and EU AI Act obligations all lean on. We run assessments with the product and data teams, so conclusions reflect how the system actually behaves. We also set a review trigger, so an assessment is repeated when the model, its data or its purpose changes materially rather than only at audit time. A stale assessment is treated by auditors as no assessment at all.

How long does ISO 42001 certification take?

For most organisations, four to six months to a first certificate, following our phases. Scoping and the AI inventory take one to two weeks, risk and impact assessment two to three, control design three to four, implementation and monitoring four to eight, and the internal audit and management review one to two, before the certification body's audit. Companies that already hold ISO 27001 move faster, because the management system structure, risk process and audit routine exist and only AI-specific controls are added. What stretches the timeline is usually the inventory: teams routinely find AI in features, vendor tools and internal workflows nobody had catalogued. We confirm a timeline after the inventory and risk assessment, when the number of systems in scope is known. Booking the certification body early helps, since accredited bodies offering ISO 42001 are still fewer than for ISO 27001 and audit slots can be several weeks out. We plan that window with you during scoping.

Who issues the certificate, and what does the work cost?

An accredited certification body issues it after auditing your AI management system, and it must be independent of whoever built that system. SecureRoot is not a certification body; we build the system and support you through the audit. We do not publish a price, because scope drives the effort: how many AI systems are in scope, whether you are a provider, a deployer or both, how much data governance already exists, whether an ISO 27001 management system is available to build on, and how many impact assessments are needed. The certification body's fee and your team's time sit outside our fee. Pursuing ISO 42001 alongside ISO 27001 lowers the total, because the management system is shared. We scope first, then quote a fixed price in writing. Where your buyers are asking about AI in a security questionnaire rather than demanding a certificate, we will say so, and scope a lighter governance engagement instead of a certification programme you do not yet need.

Keep Moving Through Compliance

Service 4 of 13 in this practice area