Compliance
ISO/IEC 42001:2023 is the first international standard for AI Management Systems (AIMS). Published in December 2023, it defines how organisations establish, implement, and continually improve a governance framework for AI, covering risk assessment, AI policy, impact evaluation, supplier controls, and performance monitoring. Enterprise procurement teams and regulators increasingly reference it as evidence of AI governance maturity.
Unlike GDPR or HIPAA, ISO 42001 is a voluntary standard, but it maps directly to the EU AI Act's risk management requirements under Article 9. Organisations building high-risk AI systems that need documented conformity assessments will find that an ISO 42001 implementation covers most of what Article 9 requires. We implement the AIMS and prepare you for certification by an accredited body.
Tell us what you're building.
The standard is structured around five key clause groups. Each clause requires documented processes and operational evidence, not just policy statements.
Document every AI system the organisation operates, the stakeholders affected, and the applicable legal and regulatory obligations. This includes mapping internal and external context for AI use, identifying who is affected by AI decisions, and confirming which regulations (GDPR, EU AI Act, HIPAA, sector-specific rules) apply to each AI system. The output is a documented scope boundary for the AIMS.
Establish a formal AI risk assessment process that identifies risks associated with each AI system and a corresponding AI impact assessment. Clause 6.1.2 specifically requires risk assessment for the intended use of AI, including risks of bias, fairness failures, and unintended outcomes. Treatment plans must be documented for each identified risk before the system goes live.
AI system design requirements must be documented before development begins, covering data requirements, performance objectives, and fairness criteria. Clause 8.4 addresses AI system data, training data quality, data provenance, and data management practices. Clause 8.6 covers supplier and third-party AI controls, requiring you to assess AI risks in your supply chain including LLM providers.
Ongoing monitoring of AI system outputs against documented objectives. Internal audits of the AIMS at planned intervals, typically annually. Clause 9.1 requires you to define what monitoring means for each AI system: which metrics, at what frequency, and who is responsible. Management reviews must consider AI-specific performance data, not just generic business metrics.
Nonconformities in AI systems (unexpected outputs, bias findings, performance degradation) must be handled through a documented corrective action process. Clause 10.2 requires root cause analysis for each nonconformity, corrective action, and verification that the action was effective. Continual improvement of the AIMS itself is also required, not just of individual AI systems.
These are the specific deliverables we produce for ISO 42001 implementation. Each one maps to specific clauses of the standard and produces evidence an auditor can inspect.
A complete register of every AI system in scope, with system description, intended use, affected stakeholders, data inputs, decision outputs, and applicable regulations. This is the foundation of Clause 4 context documentation and the starting point for every subsequent AIMS process.
A documented risk assessment methodology aligned to Clause 6.1.2, covering AI-specific risk categories (bias, fairness, safety, security, privacy) with likelihood and impact scales calibrated to your sector. We build the assessment templates and run the first round of assessments against your existing AI systems.
Per-system AI impact assessment templates that capture intended use, affected populations, potential harms, mitigation measures, and residual risk acceptance. These feed directly into Clause 6 planning requirements and serve as the evidence base for both ISO 42001 and EU AI Act conformity assessments.
Clause 8.6 requires you to assess AI risks from third-party providers, including LLM vendors. We develop a supplier questionnaire covering model cards, bias testing, data governance, and security controls, and run the initial questionnaire process against your current vendor list.
Technical implementation of audit logging for AI system decisions, recording inputs, outputs, model versions, confidence scores, and timestamps. This supports Clause 9 performance evaluation and provides the evidence base for internal audits. Logs are structured to support both automated analysis and human review.
Effective ISO 42001 implementation requires tooling that produces operational evidence, not just documentation. These are the platforms we use for monitoring, risk assessment, and model governance.
Tool selection depends on your existing cloud environment. We work within your stack rather than requiring you to adopt new platforms where existing ones cover the requirement.
SageMaker Model Cards and Clarify for bias detection. Useful for Clause 9 performance evaluation and Clause 6 risk assessment evidence.
Azure AI Foundry includes responsible AI tooling (fairness assessment, model cards, and explainability) relevant to Clauses 6 and 8.
Vertex AI Explainability and Model Monitoring for Clause 9 performance evaluation. Model Registry for version control required by Clause 8.
ML experiment tracking and model lineage. Supports Clause 8 documentation requirements for training data and model development.
Model monitoring and observability platform for production AI systems. Maps to Clause 9.1 ongoing monitoring requirements.
ISO 42001 implementation has a specific profile. We are direct about when it is the wrong engagement.
Organisations that need specific regulatory compliance only
ISO 42001 is a management system standard. It governs how you manage AI across the organisation. HIPAA, GDPR, and the EU AI Act are legal obligations with specific technical requirements. If you have a specific regulatory requirement, start there. ISO 42001 is a sensible next step once you have a baseline compliance programme, or if your procurement process requires it specifically.
Teams who want paper compliance without implementing controls
ISO 42001 certification requires a third-party audit by an accredited certification body. Auditors test whether your AIMS is actually operating, whether risk assessments are being done, whether nonconformities are being handled, whether performance monitoring is producing real data. Documentation without operational evidence does not pass a certification audit.
Organisations with a single AI system and no enterprise requirements
The overhead of a full AIMS is proportionate to the scale and risk of your AI portfolio. If you operate one low-risk internal AI tool and have no customer or regulatory requirement for ISO 42001, the investment is unlikely to be justified. We will tell you this on the discovery call rather than sell you a programme you don't need.