Skip to content

Guide

ISO 42001 implementation, made practical

ISO 42001 is the international standard for managing AI responsibly, and the one procurement teams increasingly ask for. This guide is how you actually implement it, step by step, with realistic timelines and costs, written by an ISO 42001 Lead Implementer.

We are ISO 42001 Lead Implementer certified.

We build to ISO 42001 as standard, and implement it alongside your team, from first audit through certification-readiness.

The short version

What implementing ISO 42001 actually means

ISO/IEC 42001 is the AI equivalent of ISO 27001: a certifiable standard for an AI Management System. Implementing it is not writing a policy and filing it. It is standing up a working system, an inventory, risk and impact assessment, controls, human oversight, monitoring and an evidence trail, that you run continuously and can prove to an auditor. The good news is that it is proportionate: a small deployment needs a light version, not a committee.

Who it is for

When ISO 42001 is worth implementing

You sell AI, and buyers now ask

Enterprise procurement and security teams increasingly require ISO 42001, or evidence of it, before they will sign. Certification pre-answers the questionnaire.

You are regulated, or soon will be

If the EU AI Act, a sector regulator or a customer contract is coming for your AI, ISO 42001 gives you the management system to answer them in a structure they recognise.

You want to prove governance

You already try to run AI responsibly. ISO 42001 turns that into an auditable system you can point to, rather than a set of good intentions.

The implementation

How to implement ISO 42001, step by step

A proportionate, defensible sequence. Each step links to a deeper how-to where we have one.

1

Define scope and context

Set the boundary of your AI Management System: which AI systems and uses it covers, the internal and external issues that affect it, and the interested parties (customers, regulators, staff) whose needs it has to meet. This is clause 4, and it decides how big the rest of the job is.

2

Get leadership behind it, and write the AI policy

ISO 42001 is a leadership standard. Top management has to own the AI policy, assign roles and accountability, and back the system with real authority. The AI policy is the top-level document everything else hangs off.

How to write an AI policy
3

Build the AI system register

Inventory every AI system, model and tool you use or build, including the shadow AI nobody signed off. You cannot govern, or certify, what you cannot see, and the register is the foundation the whole system sits on.

The AI system register: what to track
4

Assess risk and impact, and build the Statement of Applicability

Classify each system by risk, run an AI impact assessment on the ones that need it, and use the results to select the Annex A controls that apply, documented in a Statement of Applicability. This is where the standard becomes proportionate rather than box-ticking.

How to run an AI impact assessment
5

Implement the controls

Put the selected controls into operation: human oversight, data governance, lifecycle management, supplier and third-party management, transparency and the standing evidence trail. This is the bulk of the work, and where a real management system is separated from a binder of policies.

What an AIMS actually contains
6

Build competence and AI literacy

Make sure the people using and overseeing AI understand it well enough to do so responsibly. This satisfies clause 7 and, if the EU AI Act applies, its Article 4 literacy duty at the same time.

7

Monitor, audit and review

Measure whether the controls are working, run an internal audit, and hold a management review that re-prioritises as things change. This check step is what keeps the system alive and is exactly what an external auditor will look for.

8

Certify, if it earns its place

If you want the certificate, an accredited body runs a two-stage audit: stage 1 reviews your documentation, stage 2 checks the system is really operating. You then run a three-year cycle with annual surveillance. Certification is optional, but it is the strongest external proof you can hold.

Do you need ISO 42001? An honest answer

How long it takes

For most small and mid-sized organisations, a proportionate AI Management System takes a few weeks to a few months to stand up, then runs continuously. Certification adds the audit cycle on top. The biggest accelerator is reusing an existing management system, if you already run ISO 27001, much of the machinery carries straight over.

What drives the cost

There is no fixed price. It scales with the amount of AI in scope, how much governance already exists, whether you build it internally or with support, and, if you certify, the certification body’s fees. We scope and price implementation per engagement, so you see the number before you commit, and we design the smallest system that genuinely meets the standard, not the heaviest.

Where do you stand against ISO 42001?

A free, self-serve check that reads your maturity against the standard and shows the gaps to close.

10 min No email
Take the check

ISO 42001 implementation: common questions

What is ISO 42001? +

ISO/IEC 42001 is the first international standard for an AI Management System (AIMS), published in 2023. It is the AI equivalent of ISO 27001 for information security: a certifiable framework for governing, monitoring and improving your AI. It sets out what a responsible AI management system must contain, and lets you prove your approach through independent certification.

How long does ISO 42001 implementation take? +

For a small or mid-sized organisation, a proportionate AI Management System typically takes a few weeks to a few months to stand up, then runs continuously. Certification adds an audit cycle on top (a stage 1 and stage 2 audit). How long depends on how much AI you use, how much governance you already have, and whether you can reuse an existing management system such as ISO 27001.

How much does ISO 42001 cost? +

There is no fixed price. The cost depends on the scope of your AI, how much governance already exists, whether you build it internally or with support, and, if you certify, the certification body’s audit fees. Reusing an existing ISO 27001 system reduces it substantially. We scope and price implementation per engagement, so you see the number before you commit.

Do you have to be certified, or can you just build to ISO 42001? +

You can do either. Many organisations build an AI Management System using ISO 42001 as the blueprint without ever certifying, and get most of the benefit: the governance, the evidence, the ability to answer a customer or regulator. Certification is a separate, optional step where an accredited body audits the system you are already running. Build first; certify when a customer or regulator makes it worth it.

Can we reuse our ISO 27001 system for ISO 42001? +

Yes, and you should. ISO 42001 shares the same high-level structure as ISO 27001 and ISO 9001, so the leadership, risk, documentation, internal audit and management-review machinery can largely be reused and extended to cover AI. If you already run one of those standards, implementing ISO 42001 is meaningfully faster.

Who should own ISO 42001 implementation? +

It needs a named owner accountable for the AI Management System overall, with genuine authority and leadership backing, plus owners for each AI system. ISO 42001 is explicit that top management must be involved; it is not a project you can delegate entirely to IT and forget. We often act as the Lead Implementer alongside an internal owner.

Implementing ISO 42001?

We implement it alongside your team, from first audit to certification-readiness, as a Lead Implementer. Let’s scope it.