The challenge behind the engagement.
This service is for an organization whose customers want an ISO/IEC 42001 certificate and needs a real management system around its AI, not just a policy. We define what the AI management system covers: which systems and sites are in scope and whether you build, deploy, or use AI. We assess your current state against the whole standard through evidence requests, document review, and interviews, rating gaps by severity and effort. Then we build what is missing: the AI policy, defined roles, risk assessment and treatment, an impact review procedure, the record of applicable controls, and life-cycle and data-handling procedures. Before your audit we run the internal audit and facilitate the management review. Certificates are issued by an independent body; we prepare you and never audit our own work.
Companies selling AI products or AI-enabled services to enterprise or public-sector buyers who name ISO/IEC 42001 in tenders. Also organizations already holding ISO/IEC 27001 that want to extend their management system to AI before a customer requires it.
What we do.
What you can use.
Set the scope and build on what you have
We define the scope by AI system, site, and whether you build, deploy, or use AI, then list interested parties and their requirements. Where you already hold ISO/IEC 27001, we build on what the two standards share, so your existing context, leadership, risk, and audit processes are extended rather than rebuilt. An AI inventory and a named owner are the inputs to begin.
Assess every control, then build the gaps
Through evidence requests, document review, and interviews we rate your current state against every requirement and control in the standard. Then we write the missing pieces with their owners: the AI policy, defined roles, an impact review procedure, and life-cycle and data-management practices. We complete the transparency, responsible-use, and third-party requirements, and the record of which controls apply and why.
Run the internal audit and index the evidence
We run the internal audit, record any nonconformities and corrective actions, and facilitate the management review. You receive the audit report, the minutes, the risk treatment plan, and an evidence index ready for the certification audit’s design review and effectiveness testing. We add notes on confirming that the auditor you choose holds the right accreditation for AI management systems.
Who it’s for.
When you need it.
- Companies selling AI products or services to buyers who name ISO/IEC 42001 in tenders
- Organizations already certified to ISO/IEC 27001 extending their management system to AI
- AI developers and deployers needing a certifiable management system, not just a policy
- Vendors under buyer pressure to show an independent AI management system certificate
- A tender or contract names ISO/IEC 42001 as a requirement
- A prospect makes AI management system certification a condition of the deal
- You hold ISO/IEC 27001 and want to add AI before a customer requires it
- Leadership commits to a certification timeline and needs the AIMS built
What the scope can include.
- 01
AI management system scope statement by system, site, and whether you build, deploy, or use AI
- 02
Gap assessment against every requirement and control in ISO/IEC 42001, rated by severity and effort
- 03
AI risk assessment and treatment, with an impact review procedure for individual AI systems
- 04
A record of which AI controls apply, each with its justification and current implementation status
- 05
Life-cycle, data-management, transparency, responsible-use, and third-party procedures for your AI systems
- 06
Internal audit and management review of the AI management system, with findings feeding corrective actions
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
Under 100 employees, one or two AI products, or already ISO 27001 certified
About 100–180 hours100–1,000 employees, several AI systems, building and deploying AI
About 180–300 hours1,000+ employees or many AI systems across sites, no existing ISO program
About 300–480 hours- Number of AI systems and whether you build, deploy, or only use AI
- Whether an ISO 27001 management system already exists to extend
- Number of sites and business units in scope
- Maturity of data-handling and model life-cycle practices
4–7 months with an existing ISO 27001 program; 6–12 months from a standing start
Stage 1 and Stage 2 certification audits are billed by an accredited certification body, typically $20,000–$50,000 for smaller organizations and more for large ones.
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- AI management system scope statement and gap report, each gap with an owner, a severity, and an effort estimate
- AI policy, procedures, the record of which controls apply, risk and impact assessments, and measurable objectives
- Internal audit report, management review minutes, and risk treatment plan ready for the certification audit
- Evidence index organized for the certification audit, with notes on confirming your auditor’s accreditation status
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Can we build our AI management system on our ISO/IEC 27001 program?
Yes, and it shortens the work considerably. ISO/IEC 42001 shares its structure with ISO/IEC 27001, so much of what you already run can be extended rather than duplicated. That means one risk method, one internal audit program, and one management review with AI added to the agenda. What is new is the AI-specific content: the AI controls, the impact review procedure, and life-cycle and data-management practices for models. Expect your existing documents to gain sections rather than your organization to gain a second management system.
Who certifies us, and can the same firm help us prepare?
An independent certification body decides certification, first reviewing your documentation and then auditing how the system operates, with annual surveillance over a three-year cycle. Certification bodies are being newly accredited for AI management systems, so ask any body you shortlist about its accreditation status. We are not a certification body and issue no certificates, and the firm that helps you build the system should not also audit it. We prepare you, run the internal audit on your behalf, and help you brief the body you select. Certification itself is never something we can promise.
- AI Risk Management Framework | NIST
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)
- NIST AI RMF Playbook
- ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system
- NIST SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile
- GenAI Incident Response Guide 1.0 - OWASP Gen AI Security Project
- AI Act | Shaping Europe’s digital future
