SECOMPSSECOMPS
Home/Services/ISO 42001 AI Governance
CMP 05

ISO 42001 AI governance.

The first international standard for artificial intelligence management systems. If you build or deploy AI, enterprise procurement will start asking for this, and today almost nobody can answer.

At a glance

Standard
ISO/IEC 42001:2023
Covers
AI management system across the full lifecycle
Timeline
4 to 8 months, faster if ISO 27001 exists
Pairs with
ISO 27001, EU AI Act readiness
Why now
Procurement questionnaires are already asking
01Overview

What this actually is.

Every enterprise security questionnaire we see is growing an AI section. Most vendors answer it with a paragraph of reassurance. ISO 42001 lets you answer it with a certificate, and right now that is close to a unique position in almost every market.

02Scope

What we cover.

AI system inventoryEvery model, service and third-party AI capability in use, including the ones adopted by teams without central approval.
AI policy and governanceRoles, accountability and decision rights for AI development, procurement and deployment.
Impact assessmentAssessment of AI system consequences for individuals and groups, which is the heart of the standard.
Data governance for AITraining data provenance, quality, bias evaluation, retention and the lawful basis for using it.
Lifecycle controlsRequirements, design, verification, deployment, monitoring and decommissioning of AI systems.
Third-party AI riskModel providers, APIs and embedded AI in your vendors' products, with the contractual terms to match.
Transparency and documentationWhat the system does, its limitations and how decisions can be explained to users and regulators.
Monitoring and incident responseDetecting drift, degradation and harmful output, and responding when an AI system behaves unexpectedly.
03Fit

Who needs this.

  • Companies building AI features into products sold to enterprise
  • Businesses deploying AI in regulated decisions such as credit, hiring or clinical support
  • Vendors already receiving AI questions in security questionnaires
  • Organisations preparing for the EU AI Act
  • Anyone who wants a genuine procurement differentiator while the field is empty
04Questions

Frequently asked.

Is anyone actually asking for ISO 42001 yet?

Increasingly, and earlier than most vendors expect. The pattern matches SOC 2 a decade ago: a handful of large buyers ask, it becomes a differentiator, then it becomes a requirement. The advantage belongs to whoever moves before the second phase.

How does this relate to the EU AI Act?

They are different instruments. The AI Act is law with risk-tiered obligations. ISO 42001 is a voluntary management system standard. Building the 42001 management system produces much of the governance evidence the Act expects, which is why we usually approach them together.

We already have ISO 27001. Does that help?

Substantially. ISO 42001 uses the same harmonised management system structure, so your existing scope, risk methodology, internal audit and management review largely carry across. The incremental effort is the AI-specific controls.

We only use third-party AI models. Does this still apply?

Yes, and this is the most common misunderstanding. Deploying someone else's model is still deploying an AI system. Your obligations around impact, transparency, monitoring and vendor risk apply regardless of who trained it.

Find out what stands between you and certification.

Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.