Hael
Book a meeting
ISO/IEC 42001 · Learn

ISO/IEC 42001: plain-English guides for the people who operate it.

ISO/IEC 42001, explained. ISO/IEC 42001 is the world's first international, certifiable standard for an Artificial Intelligence Management System (AIMS). Published in December 2023, it gives organisations a structured framework for governing AI responsibly across its lifecycle, and uniquely it can be independently audited and certified by an accredited body. The standard is built on the familiar Plan-Do-Check-Act cycle and the same high-level management-system shape as ISO 27001 and ISO 9001, so teams with existing governance recognise it immediately. It defines what an AI management system contains, leadership and policy, planning and risk assessment, support, operation, performance evaluation, and improvement, and pairs those clauses with a set of AI-specific controls in Annex A covering AI policy, the AI lifecycle, data for AI, transparency, and responsible use. Organisations adopt ISO 42001 for different reasons. AI vendors use it as a procurement signal, the equivalent of ISO 27001 for AI governance, that shortens enterprise sales cycles. Enterprises running many AI systems use it to bring consistency and a defensible governance posture across the business. Organisations in regulated sectors and those preparing for binding laws like the EU AI Act adopt it because the substance of the work overlaps and the certificate gives them independent proof. These guides are written for the people who have to operate the management system, not just describe it. The hub is organised into six sections: Introduction (what the standard is, who needs it, what an AIMS contains), Requirements (clauses and Annex A controls), Certification (process, cost, time, audit preparation), For vendors, For enterprise, and Comparisons against SOC 2 and the wider regulatory landscape.

Guides
ISO/IEC 42001 · Introduction
ISO 42001 Explained
What an AI management system is, the 38 Annex A controls, how certification works, and why buyers ask for it.
7 min readRead guide →
ISO/IEC 42001 · Certification
What Is ISO 42001 Certification?
Who issues the certificate, how the two-stage audit runs, what accreditation means, and what it costs.
8 min readRead guide →
ISO/IEC 42001 · Compliance
ISO 42001 compliance
What compliance requires, the five stages of a programme, what it costs, and what has to keep running.
8 min readRead guide →
ISO/IEC 42001 · Services
ISO 42001 consultancy services
The six workstreams, what a consultancy cannot do, typical fees, and the one that recurs every year.
8 min readRead guide →
ISO/IEC 42001 · Services
ISO 42001 Readiness and Compliance Services
What a readiness assessment should contain, when to run it, what it finds, and what follows it.
8 min readRead guide →
ISO/IEC 42001 · Consultants
ISO 42001 Compliance Consultants
Where consultants come from, what credentials mean in a young market, and the two documents that reveal capability.
8 min readRead guide →
ISO/IEC 42001 · Internal audit
ISO 42001 - Internal Audit Consultants
Who can run the Clause 9.2 audit, who cannot, what a good one produces, and what it costs each cycle.
7 min readRead guide →
ISO/IEC 42001 · United Kingdom
UK ISO 42001 consultants
UKAS accreditation since January 2026, how the standard sits with UK regulators, and costs in sterling.
7 min readRead guide →
ISO/IEC 42001 · United States
US ISO 42001 consultants
Microsoft SSPA Section K, enterprise procurement, the state law position, and what certification costs in dollars.
8 min readRead guide →
ISO/IEC 42001 · Services
ISO 42001 vCISO Services
What a fractional AI governance officer owns under the standard, what a retainer costs, and what sits outside it.
7 min readRead guide →
ISO/IEC 42001 · Selection
ISO 42001 consultant recommendation
Where recommendations come from, what to ask the person recommending, and the verification that beats a reference.
7 min readRead guide →
ISO/IEC 42001 · Selection
Recommendations for a Good ISO 42001 Compliance consultant
Seven marks of a good consultant, how to test each one, and what a proper proposal contains.
8 min readRead guide →
ISO/IEC 42001 · Cost
The budget-friendly ways to get ISO 42001 certified
Where the money goes, which costs are avoidable, and the eight decisions that reduce a first-year bill.
8 min readRead guide →
ISO/IEC 42001 · Programme
How Best to Proceed with ISO 42001
The right order to run a programme, the decision that belongs at each stage, and what sets the timeline.
8 min readRead guide →
ISO/IEC 42001 · Buyer intent
What is ISO/IEC 42001?
The foundational explainer: what ISO/IEC 42001 is, what an AI management system covers, and what certification actually proves.
6 min readRead guide →
ISO/IEC 42001 · Buyer intent
How much does ISO/IEC 42001 certification cost?
The honest cost picture: the audit fee is the main external cost, annual surveillance follows, but internal effort is the largest true cost.
6 min readRead guide →
ISO/IEC 42001 · Buyer intent
How long does ISO/IEC 42001 certification take?
Three to six months typical. The variable that decides it is how much of the management system already exists.
6 min readRead guide →
ISO/IEC 42001 · Decision
Do we need ISO/IEC 42001?
Three patterns make it necessary; a fourth makes the AIMS worth building even without the certificate.
6 min readRead guide →
ISO/IEC 42001 · Buyer intent
ISO/IEC 42001 vs the EU AI Act
The distinction the market gets wrong: management-system certification is not product conformity. Stated plainly.
6 min readRead guide →
ISO/IEC 42001 · Buyer intent
ISO/IEC 42001 vs ISO/IEC 27001
Shared High-Level Structure means most of the management system carries over. AI-specific risk, impact and lifecycle controls are the genuinely new parts.
6 min readRead guide →
ISO/IEC 42001 · Buyer intent
ISO/IEC 42001 vs the NIST AI Risk Management Framework
Different jobs. NIST supplies the risk practice; ISO 42001 supplies the certifiable structure around it.
6 min readRead guide →
ISO/IEC 42001 · Implementation
The ISO/IEC 42001 Statement of Applicability
The centrepiece document. Applicability, exclusion rationale, residual-risk acceptance — auditor-ready.
6 min readRead guide →
ISO/IEC 42001 · Implementation
ISO/IEC 42001 Annex A controls, explained
Thematic tour of Annex A — organisational policy, lifecycle, data governance, suppliers, impact, oversight. No verbatim reproduction.
6 min readRead guide →
ISO/IEC 42001 · Implementation
The ISO/IEC 42001 AI system inventory
The register that everything else — SoA, risk, oversight, supplier controls — depends on. Shadow AI is the most common blocker.
6 min readRead guide →
ISO/IEC 42001 · Implementation
ISO/IEC 42001 risk and impact assessment
Two related-but-distinct assessments. What each covers, how they differ from a DPIA, what evidence auditors expect.
6 min readRead guide →
ISO/IEC 42001 · Implementation
ISO/IEC 42001 internal audit and management review
Clauses 9.2 and 9.3. Left too late by most organisations, checked first by every auditor.
6 min readRead guide →
ISO/IEC 42001 · Decision
How to choose an ISO/IEC 42001 certification body
Only accredited bodies certify. A body that built your AIMS cannot then audit it (ISO/IEC 17021). How to verify and what to ask.
6 min readRead guide →
ISO/IEC 42001 · Decision
ISO/IEC 42001 for startups
Proportionate implementation. Scope is the lever — a ten-person startup and a bank certify to the same standard, on very different footprints.
6 min readRead guide →
ISO/IEC 42001 · Implementation
Common ISO/IEC 42001 audit failures
Where audits actually fail. Incomplete inventory, missing exclusion rationale, records that don't operate, no real review, rubber-stamp oversight.
6 min readRead guide →
ISO/IEC 42001 · Buyer intent
Who is ISO/IEC 42001 certified?
The public list and what it signals. When the largest AI providers certify, procurement expectations shift for everyone.
6 min readRead guide →
ISO/IEC 42001 · Introduction
Who needs ISO 42001 certification?
A guide to who benefits from ISO 42001 certification, from AI vendors and enterprises to regulated sectors, and when it is worth pursuing.
6 min readRead guide →
ISO/IEC 42001 · Introduction
What is an AI management system (AIMS)?
An explanation of what an AI management system (AIMS) is, the concept at the heart of ISO 42001, and how it governs AI across an organisation.
6 min readRead guide →
ISO/IEC 42001 · Requirements
ISO 42001 requirements explained
A guide to the requirements of ISO 42001, walking through the management-system clauses and the AI-specific Annex A controls.
7 min readRead guide →
ISO/IEC 42001 · Requirements
A guide to the ISO 42001 Annex A controls
A guide to the AI-specific controls in ISO 42001's Annex A, explaining the main control areas and how organisations select and apply them.
7 min readRead guide →
ISO/IEC 42001 · Certification
The ISO 42001 certification process: a step-by-step roadmap
A step-by-step roadmap to ISO 42001 certification, from building the management system through the two-stage audit and ongoing surveillance.
7 min readRead guide →
ISO/IEC 42001 · Certification
How much does ISO 42001 certification cost?
An explanation of what drives the cost of ISO 42001 certification, the main expense categories, and how readiness affects the total.
6 min readRead guide →
ISO/IEC 42001 · Certification
How long does ISO 42001 certification take?
An explanation of how long ISO 42001 certification takes, the phases that consume the time, and what makes the timeline shorter or longer.
6 min readRead guide →
ISO/IEC 42001 · Certification
ISO 42001 compliance checklist
A step-by-step ISO 42001 compliance checklist covering scope, policy, risk assessment, controls, evidence, internal audit, and certification.
6 min readRead guide →
ISO/IEC 42001 · Certification
How to prepare for an ISO 42001 audit
A practical guide to preparing for an ISO 42001 certification audit, covering documentation, evidence, internal audit, and readiness.
6 min readRead guide →
ISO/IEC 42001 · Certification
The ISO 42001 audit: internal and external audits explained
An explanation of the audits in ISO 42001: the internal audits an organisation runs and the external two-stage certification and surveillance audits.
6 min readRead guide →
ISO/IEC 42001 · Introduction
5 benefits of ISO 42001 certification
The five main benefits of ISO 42001 certification, from verifiable proof of responsible AI to faster sales and regulatory readiness.
5 min readRead guide →
ISO/IEC 42001 · Comparisons
ISO 42001 vs SOC 2: what is the difference?
A clear comparison of ISO 42001 and SOC 2, covering what each assesses, certification versus attestation, AI versus security focus, and how they fit together.
6 min readRead guide →
ISO/IEC 42001 · For vendors
ISO 42001 for AI vendors: turning certification into deals
A guide for AI vendors on how ISO 42001 certification accelerates enterprise sales by providing independent proof of responsible AI governance.
5 min readRead guide →
ISO/IEC 42001 · For enterprise
ISO 42001 for enterprises: governing AI at scale
A guide for enterprises on using ISO 42001 to govern AI consistently across the organisation and to evidence responsible AI to regulators and customers.
6 min readRead guide →
Free check

See where you stand on ISO/IEC 42001, free.

Answer a short set of questions and see what ISO/IEC 42001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO/IEC 42001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO/IEC 42001.

Or speak to us about your deadline. Book a meeting.