Certify Responsible AI
ISO 42001 AI Management System Certification
ISO 42001 is the first management system standard for artificial intelligence. We help you govern how you build and use AI, and certify that you do it responsibly.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
ISO/IEC 42001 sets out how to run an AI management system: the governance, risk controls, and oversight that keep artificial intelligence safe, fair, and accountable. It matters because AI now sits inside real products and decisions, and buyers want assurance you manage it well. The standard also lines up with the EU AI Act and NIST AI guidance. We help you build AI governance that satisfies auditors without slowing your teams down.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the ISO 42001 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and AI Inventory. We map the AI systems in scope and confirm your roles as a developer, provider, or user of each one. Activities: Inventory AI systems, models, and use cases; Confirm your role for each system; Set the AI management system scope; Identify interested parties and their expectations. Hands over AI System Inventory and Scope Statement. Phase 2, AI Risk and Impact Assessment. We assess each system for risks to safety, fairness, and rights, using the impact assessment approach the standard expects. Activities: Run AI impact assessments per system; Assess bias, safety, and rights risks; Score risks against your acceptance criteria; Agree treatment for each material risk. Hands over AI Risk and Impact Assessment Reports. Phase 3, AI Control Design. We design controls for data quality, human oversight, transparency, and the full AI lifecycle. Activities: Select applicable Annex A controls of ISO 42001; Design data quality and provenance controls; Define human oversight and escalation points; Write the AI policy and lifecycle procedures. Hands over AI Control Set and Statement of Applicability. Phase 4, Implementation and Monitoring. We help you embed the controls and set up ongoing monitoring of model behaviour and performance. Activities: Embed controls into the model development lifecycle; Set up monitoring of model drift and performance; Configure incident and feedback channels; Train teams on the AI governance procedures. Hands over Operating AI Controls and Monitoring Dashboard. Phase 5, Internal Audit and Review. We audit the AI management system against the standard, then run a management review of the results. Activities: Audit the AI management system against ISO 42001; Sample impact assessments and oversight records; Log nonconformities and corrective actions; Run the management review with leadership. Hands over Internal Audit Report and Management Review Record. Phase 6, Certification Support. We support you through the certification audit and help you keep pace as regulation matures. Activities: Prepare the evidence pack for the certification body; Support Stage 1 and Stage 2 audit interviews; Close findings raised during the audit; Track EU AI Act developments against your controls. Hands over ISO 42001 Certificate. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and AI Inventory
We map the AI systems in scope and confirm your roles as a developer, provider, or user of each one.
What Happens In This Phase
- Inventory AI systems, models, and use cases
- Confirm your role for each system
- Set the AI management system scope
- Identify interested parties and their expectations
The Handover
AI System Inventory and Scope Statement
The next phase starts from this.
Phase 01 Scoping and AI Inventory
We map the AI systems in scope and confirm your roles as a developer, provider, or user of each one.
What Happens In This Phase
- Inventory AI systems, models, and use cases
- Confirm your role for each system
- Set the AI management system scope
- Identify interested parties and their expectations
The Handover
AI System Inventory and Scope Statement
The next phase starts from this.
- 01
Scoping and AI Inventory
We map the AI systems in scope and confirm your roles as a developer, provider, or user of each one.
OutputAI System Inventory and Scope StatementActivities
- Inventory AI systems, models, and use cases
- Confirm your role for each system
- Set the AI management system scope
- Identify interested parties and their expectations
- 02
AI Risk and Impact Assessment
We assess each system for risks to safety, fairness, and rights, using the impact assessment approach the standard expects.
OutputAI Risk and Impact Assessment ReportsActivities
- Run AI impact assessments per system
- Assess bias, safety, and rights risks
- Score risks against your acceptance criteria
- Agree treatment for each material risk
- 03
AI Control Design
We design controls for data quality, human oversight, transparency, and the full AI lifecycle.
OutputAI Control Set and Statement of ApplicabilityActivities
- Select applicable Annex A controls of ISO 42001
- Design data quality and provenance controls
- Define human oversight and escalation points
- Write the AI policy and lifecycle procedures
- 04
Implementation and Monitoring
We help you embed the controls and set up ongoing monitoring of model behaviour and performance.
OutputOperating AI Controls and Monitoring DashboardActivities
- Embed controls into the model development lifecycle
- Set up monitoring of model drift and performance
- Configure incident and feedback channels
- Train teams on the AI governance procedures
- 05
Internal Audit and Review
We audit the AI management system against the standard, then run a management review of the results.
OutputInternal Audit Report and Management Review RecordActivities
- Audit the AI management system against ISO 42001
- Sample impact assessments and oversight records
- Log nonconformities and corrective actions
- Run the management review with leadership
- 06
Certification Support
We support you through the certification audit and help you keep pace as regulation matures.
OutputISO 42001 CertificateActivities
- Prepare the evidence pack for the certification body
- Support Stage 1 and Stage 2 audit interviews
- Close findings raised during the audit
- Track EU AI Act developments against your controls
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
What Is Examined, and What it Is Measured Against
Map
Map of the ISO 42001 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Credo AI, Holistic AI, OneTrust AI Governance, Vanta, Jira, Confluence, MLflow, Fiddler AI. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO/IEC 42001:2023, ISO/IEC 23894, ISO/IEC 22989, EU AI Act, NIST AI Risk Management Framework.
What We Run
8 tools
- Fiddler AI
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- AI ACTEuropean Union
Deliverables
What You Receive
- AI system inventory
- AI impact assessment reports
- AI management system policy set
- AI control mapping
- Certification audit support
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Who needs ISO 42001?
Any organisation that builds, provides, or relies on AI systems and wants to prove it governs them responsibly. It is especially useful ahead of EU AI Act obligations.
How does ISO 42001 relate to the EU AI Act?
The standard gives you a management system that supports many EU AI Act requirements. It is not automatic compliance, but it is a strong foundation.
Can we certify just one AI system?
Yes. You set the scope, so you can start with a single high-value system and widen it later. We help you choose a sensible boundary.
Keep Moving Through Compliance
Service 4 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.