Secure Trust Accounting & Finances
ES WhatsApp
42001

ISO/IEC 42001:2023

Artificial Intelligence Management System

AI governance for organisations already using it.

Current edition: ISO/IEC 42001:2023.

What it is

What the standard covers

ISO/IEC 42001 sets out how an organisation governs the development and use of artificial intelligence systems: AI system inventory, impact assessment, data and model control, human oversight, transparency to users and AI supplier management. It applies both to developers and to organisations that only use third-party tools.

Who it is for

  • Companies building AI-enabled products
  • Organisations that embedded AI into internal processes
  • Service providers using AI on client data
  • Institutions facing technology governance requirements

Problems it helps manage

  • AI tools used without policy or inventory
  • Client data processed on platforms without assessment
  • Automated decisions without oversight or traceability
  • Client or regulator questions about AI use with no formal answer

Business benefits

  • Inventory and classification of AI systems in use
  • Documented impact and risk assessment
  • Human oversight and decision traceability
  • A solid position with clients, auditors and regulators

Sectors

Where it applies

Technology and softwareFinancial servicesHealthcareBPO and contact centresPublic sectorEducation

Support

What the engagement includes

  • Documented initial gap analysis
  • Management system design
  • Complete, tailored documentation
  • Implementation support, on site or remote
  • Training for the key team
  • Internal audit and closure of findings
  • Readiness and support through the certification audit

Integration with other standards

This standard commonly integrates with: ISO/IEC 27001, ISO 9001, ISO/IEC 20000-1. An integrated system reduces duplicated documentation and audit time.

Stages

How the project runs

Gap analysis and planning

We review the real operation, not a questionnaire. We identify gaps against the standard, critical processes, existing evidence and regulatory risk.

Selecting the standard or combination

We define which standard answers the organisation's risk and objective. The choice is technical, not a matter of popularity.

Management system design

We structure processes, responsibilities, indicators and controls according to size, sector and applicable regulation.

Documentation development

We write policy, procedures, records and matrices tailored to the operation. No generic templates.

Guided implementation

We work with each process owner until the system is used day to day, not only stored in a folder.

Team training

We train the key team on the standard, on the system and on their role during the audit.

FAQ

Frequently asked questions — ISO/IEC 42001

Does it apply if we only use AI rather than build it?
Yes. The standard distinguishes roles and covers organisations that use third-party AI systems.
Is ISO/IEC 27001 required first?
Not mandatory, but mature information security materially accelerates implementation.
Does it cover AI regulatory compliance?
It provides structure, evidence and control that support compliance, but legal assessment is performed under each applicable jurisdiction.

Next step

Every organisation is different. The right system starts with a gap analysis.

Write to us and we will arrange a strategy meeting: we review your current situation, define the right system, set scope and timelines and resolve technical and regulatory questions.

A certification done properly is not chased. It is built.

WhatsApp