The world's first international standard for AI management. ISO 42001 lets organisations that build or deploy AI prove they do so responsibly — increasingly relevant as the EU AI Act and similar regimes take effect.
ISO/IEC 42001:2023 is the first certifiable standard for an Artificial Intelligence Management System (AIMS). It applies the familiar ISO management-system structure — governance, risk assessment, lifecycle controls, continual improvement — to the specific risks of developing and using AI.
It addresses concerns that general security standards don't: model governance, data quality, transparency, human oversight, and the impact of AI decisions on individuals.
For organisations already certified to ISO 27001, the shared management-system backbone makes ISO 42001 a natural and efficient extension.
Companies developing or fine-tuning AI systems that need to demonstrate responsible governance.
Organisations preparing for the EU AI Act and similar emerging regulation.
Businesses embedding AI into operations that need assurance over its risks.
Delivered through our specialist network. As a newer standard, ISO 42001 benefits from an experienced implementer — we scope the AIMS to your actual AI footprint and build only the governance you need, not a generic template.
We define the boundary of your programme — systems, locations, and teams in scope — and agree the timeline and responsibilities up front, so there are no surprises later.
A structured assessment of your current posture against every requirement, producing a prioritised remediation plan with realistic effort estimates.
We write the policies, procedures, and controls, and work alongside your engineering team on a weekly cadence to implement them — not a stack of templates left for you to figure out.
The management system runs and generates evidence. We drive the internal audit and management review so the programme is demonstrably working before any external scrutiny.
We prepare the evidence package and sit alongside you through assessment, answering the assessor's questions directly rather than leaving you to defend the work alone.
Not strictly, but it helps. The two share the same management-system structure, so if you already hold ISO 27001 a large part of the foundation is reusable, which shortens the ISO 42001 engagement considerably.
No — they're distinct. ISO 42001 is a voluntary management-system certification; the EU AI Act is binding law. But a well-built AIMS gives you much of the governance the Act expects, which is why the two are increasingly pursued together.
Book a free advisory session and we'll map your fastest credible route to compliance.
Book a free advisory session