Hael
Book a meeting

ISO/IEC 42001 ADVISORY AND CERTIFICATION SUPPORT

ISO/IEC 42001 certification, built on governance that works.

Hael leads the programme from initial scope and readiness through implementation, internal audit, management review and certification support.

We help you establish an AI management system that works in practice, stands up to independent assessment and remains current as your use of AI evolves.

THE VALUE OF ISO/IEC 42001

A recognised management system for governing AI with confidence.

ISO/IEC 42001 brings the governance of AI into one coherent management system. It gives leadership a structured way to define accountability, manage risk, oversee the use of AI and improve controls as the organisation changes.

For customers, boards and other stakeholders, independent certification provides credible assurance that the management system has been assessed against an international standard.

A coherent operating model

Bring policies, ownership, risk decisions, operational controls and oversight into a management system that people across the organisation can follow.

Clear management oversight

Give leadership a reliable view of where AI is used, who is accountable, how material risks are treated and where action remains outstanding.

Credible external assurance

Demonstrate that your AI management system has been independently assessed, without presenting certification as a substitute for legal compliance or sound judgement.

HOW WE WORK

ISO/IEC 42001 in practice

Certification is a milestone, not the objective. The point is a management system that stands up when a customer, board or regulator asks what the organisation is doing about AI. We work with the people responsible for AI decisions to make that answer real.

OUR APPROACH

One programme from readiness assessment to certification.

Hael provides the specialist capacity, structure and judgement needed to move the programme forward. We work across leadership, legal, risk, security, product and engineering, while ensuring that ownership remains within your organisation.

Define the scope and governance model

We establish the intended scope of the AI management system, the entities and AI systems involved, the organisation’s role in the AI lifecycle and the governance already in place.

The result is a clear scope, readiness assessment and implementation plan, with named responsibilities and decisions for leadership.

Implement the management system

We develop and embed the policies, objectives, accountability, AI inventory, risk and impact assessment processes, control framework, Statement of Applicability and supporting operating procedures.

The work is designed around how your organisation functions, not around a generic set of templates.

Build the evidence and prepare for audit

We help teams operate the controls, assemble the evidence, complete internal audit with appropriate independence, conduct management review and resolve findings before external assessment.

We then support preparation for Stage 1 and Stage 2, including evidence coordination, interview readiness and remediation.

CERTIFICATION SUPPORT

Independent certification, carefully prepared.

Hael does not issue the certificate. Our role is to prepare your organisation for assessment by an independent certification body and to ensure the management system presented for audit is supported by real ownership, operating controls and reliable evidence.

We help you select an appropriately accredited certification body, prepare the audit plan, coordinate evidence, brief the people who will be interviewed and support the response to findings. Certification decisions remain entirely with the certification body.

Once certification has been achieved, we can continue to support the surveillance cycle, internal audit, management review, corrective action and controlled expansion of scope.

PLANNING YOUR PROGRAMME

A clear plan, based on your starting point.

The route to certification depends on the intended scope, the number and maturity of the AI systems involved, the governance already operating and the quality of available evidence. Certification-body availability also affects the final audit timetable.

We establish these facts before committing to a delivery plan. You receive a defined scope, workstreams, responsibilities, timetable and fee, based on the organisation you have rather than a generic certification promise.

Where ISO/IEC 27001, SOC 2 or established risk-management processes are already in place, we reuse relevant structures and evidence. We identify what transfers, what needs adapting and what must be created specifically for the governance of AI.

WHY HAEL

Specialist AI governance advice, led by experienced practitioners.

Hael is the specialist AI governance and compliance practice within Buckingham Group, drawing on fifteen years of work across governance, risk and compliance. Our focus is deliberately specific: helping organisations put credible governance around the AI they develop, provide and use.

We advise AI providers preparing for enterprise scrutiny, as well as established and regulated organisations introducing AI across complex operating environments. We understand that these organisations have different commercial, regulatory and operational priorities. The scope and delivery model are designed accordingly.

Our work can cover readiness, scope, governance design, policy and control implementation, AI inventory, risk and impact assessment, evidence, internal audit, management review, certification preparation and ongoing improvement. We can lead the complete programme or work alongside your existing legal, risk, security, product and engineering teams.

Every engagement has a named practitioner and an agreed scope, timetable and fee. We do not take commission from certification bodies. Certification is assessed and issued independently. Where the Hael platform supports an engagement, it maintains the underlying systems, controls, evidence, decisions and review record. It supports practitioner judgement and operational continuity; it does not replace either.

CONNECTED REQUIREMENTS

Make ISO/IEC 42001 part of a coherent assurance programme.

ISO/IEC 42001 should strengthen existing governance rather than create a parallel compliance structure. We map relevant controls, processes and evidence across related frameworks while preserving the distinct purpose of each one.

EU AI Act

Connect the management system to the obligations that apply to your role and AI systems, without presenting certification as a substitute for legal compliance.

NIST AI RMF

Align practical AI risk-governance activities with the organisation’s wider management system and decision-making processes.

GDPR for AI

Integrate data-protection accountability, assessments and evidence into the governance of AI systems that process personal data.

ISO/IEC 27001

Reuse compatible management-system structures, risk processes and control evidence where they are relevant, while addressing the additional requirements specific to AI.

DISCUSS YOUR ISO/IEC 42001 PROGRAMME

Start with a clear view of scope, readiness and the route to certification.

In an initial scoping call, a Hael practitioner will review why you are pursuing ISO/IEC 42001, the AI systems and entities that may sit within scope, the governance already in place and your intended audit window.

We will then set out the recommended scope, principal workstreams, responsibilities, timetable and fee. You will know what the programme involves before deciding whether to proceed.