The first certifiable management system standard for artificial intelligence. It governs AI inventory, impact assessment, data provenance and human oversight.
ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence. Published in 2023 by ISO and IEC, it sets requirements for an Artificial Intelligence Management System — an AIMS — covering how an organisation develops, provides or uses AI responsibly.
It governs the risks conventional security standards do not reach. ISO 27001 manages information security risk very well, but it has nothing to say about whether a model is biased, whether anyone can account for the data it was trained on, or whether a human can meaningfully intervene in a decision it makes. Those are governance questions, and they are what 42001 addresses.
If you need a practical way to map AI risks before or alongside a certifiable management system, NIST AI RMF gives the team a governance framework to work from.
It follows the same Annex SL structure as other modern ISO standards — context, leadership, planning, support, operation, performance evaluation, improvement — so an organisation already running a management system is not starting from scratch. What changes is the subject matter.
Three requirements consistently catch organisations off guard:
Certification is voluntary. The pressure to hold it is commercial, and it is arriving faster than most organisations expected.
Enterprise and government procurement now asks about AI governance by name. A paragraph in the acceptable use policy no longer clears that question, and the vendor without an answer loses time it cannot recover.
Credit, hiring, triage, eligibility, pricing. Where a decision materially affects a person, the questions of who is accountable and how a human intervenes have regulators behind them, and the answers need to be documented rather than assumed.
If staff are using AI tools across the business and nobody can produce a list of where it runs or what data reaches it, that is the gap. It is also the most common situation we encounter.
AI risk is being written into third-party risk assessments alongside security and privacy, particularly by APRA-regulated entities managing material service providers.
The right starting point follows the scale and consequence of AI use. An organisation beginning with a low-stakes pilot can establish its inventory, policy and governance foundations first. As AI becomes material to operations, affects consequential decisions or enters customer and procurement requirements, those foundations provide a direct path into a certifiable management system.
Five to eight months is typical. Where an ISO 27001 management system already exists, the shared Annex SL clauses are largely satisfied and the work concentrates on the AI-specific requirements.
Enumerate every AI system in use or development, including models embedded inside third-party products. This step routinely takes longer than planned and routinely surfaces systems the executive did not know were running. It is also the single most useful deliverable of the engagement, independent of certification.
The standard distinguishes between organisations that provide, produce and use AI systems, and obligations differ accordingly. Most organisations occupy more than one role at once.
Assess risk to the organisation and, separately, impact on affected individuals and society. Impact assessments are performed for consequential systems and are the evidence an auditor will scrutinise most closely.
AI policy and acceptable use, the inventory as a maintained register, an impact assessment procedure, data provenance and quality controls, human oversight and escalation design, incident handling for AI failures, and AI-specific supplier due diligence.
Oversight has to be exercised, and it has to leave records. Expect an auditor to ask to see a specific decision where a human actually intervened. "A person reviews the output" is not evidence; a logged intervention is.
Both mandatory before Stage 2, and the internal audit must be impartial.
Documentation and readiness first, then operating effectiveness against evidence.
Soveriq builds the AI management system inside your existing environment, with AI risks entering the same register as security and privacy risks rather than sitting in a separate document. Where ISO 27001 is also in scope, AI suppliers pass through the existing due diligence pathway instead of a parallel one.
Engagements are scoped against published price floors.
On internal audit. Where Soveriq has built your management system, we do not then audit it and present that as an independent internal audit. What we provide is readiness validation — clearly labelled as such, and not a substitute for the impartial audit Clause 9.2 requires. Where an independent internal audit is needed after a Soveriq build, it is performed by someone independent of that build and the arrangement is disclosed in writing. The same applies to any retainer including an audit component.
Clear roles through certification. Soveriq prepares the AI management system, evidence and organisation for certification. The certificate and final certification decision come from an independent certification body, keeping implementation and certification roles clear. Soveriq supports your team through Stage 1 and Stage 2 without pre-empting that independent decision.
ISO 42001 work follows the same five-module structure as every other Soveriq engagement.
Price floors for each module are published on the pricing page. Certification body fees are separate and paid directly to that body.
Where ISO 27001 is already in place or being built at the same time, the Annex SL clauses are shared and the AI work is a smaller increment rather than a second programme.
No. ISO 42001 can be certified on its own. In practice most organisations building AI products also need 27001 for the same customers, and building both together is materially cheaper than building them separately, because they share Clauses 4 to 10.
Yes, and this is widely misunderstood. The standard covers organisations that use AI systems, not only those that develop them. If AI influences decisions that affect people, the governance obligations attach regardless of who trained the model.
No. The EU AI Act is legislation with legal force in the European Union. ISO 42001 is a voluntary certifiable standard. They overlap substantially in what they ask for, so a certified AI management system is a good starting position for EU obligations, but certification is not legal compliance and should not be presented as such.
It goes in the inventory like anything else, and the governance sits in supplier due diligence — what the vendor's model does, what data reaches it, and whether you are told when it changes. Most organisations find this is where the majority of their AI exposure actually lives.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope