AI Frameworks / FOCUSED SERVICE

ISO/IEC 42001 Readiness

Scoping your AI management system, a gap assessment against the full ISO/IEC 42001 standard, control build-out, and an internal audit before the certification audit.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service is for an organization whose customers want an ISO/IEC 42001 certificate and needs a real management system around its AI, not just a policy. We define what the AI management system covers: which systems and sites are in scope and whether you build, deploy, or use AI. We assess your current state against the whole standard through evidence requests, document review, and interviews, rating gaps by severity and effort. Then we build what is missing: the AI policy, defined roles, risk assessment and treatment, an impact review procedure, the record of applicable controls, and life-cycle and data-handling procedures. Before your audit we run the internal audit and facilitate the management review. Certificates are issued by an independent body; we prepare you and never audit our own work.

WHEN THIS IS THE RIGHT FIT

Companies selling AI products or AI-enabled services to enterprise or public-sector buyers who name ISO/IEC 42001 in tenders. Also organizations already holding ISO/IEC 27001 that want to extend their management system to AI before a customer requires it.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Set the scope and build on what you have

We define the scope by AI system, site, and whether you build, deploy, or use AI, then list interested parties and their requirements. Where you already hold ISO/IEC 27001, we build on what the two standards share, so your existing context, leadership, risk, and audit processes are extended rather than rebuilt. An AI inventory and a named owner are the inputs to begin.

Assess every control, then build the gaps

Through evidence requests, document review, and interviews we rate your current state against every requirement and control in the standard. Then we write the missing pieces with their owners: the AI policy, defined roles, an impact review procedure, and life-cycle and data-management practices. We complete the transparency, responsible-use, and third-party requirements, and the record of which controls apply and why.

Run the internal audit and index the evidence

We run the internal audit, record any nonconformities and corrective actions, and facilitate the management review. You receive the audit report, the minutes, the risk treatment plan, and an evidence index ready for the certification audit’s design review and effectiveness testing. We add notes on confirming that the auditor you choose holds the right accreditation for AI management systems.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Companies selling AI products or services to buyers who name ISO/IEC 42001 in tenders
  • Organizations already certified to ISO/IEC 27001 extending their management system to AI
  • AI developers and deployers needing a certifiable management system, not just a policy
  • Vendors under buyer pressure to show an independent AI management system certificate
WHEN IT’S TIME TO ENGAGE
  • A tender or contract names ISO/IEC 42001 as a requirement
  • A prospect makes AI management system certification a condition of the deal
  • You hold ISO/IEC 27001 and want to add AI before a customer requires it
  • Leadership commits to a certification timeline and needs the AIMS built
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • AI management system scope statement by system, site, and whether you build, deploy, or use AI

  • Gap assessment against every requirement and control in ISO/IEC 42001, rated by severity and effort

  • AI risk assessment and treatment, with an impact review procedure for individual AI systems

  • A record of which AI controls apply, each with its justification and current implementation status

  • Life-cycle, data-management, transparency, responsible-use, and third-party procedures for your AI systems

  • Internal audit and management review of the AI management system, with findings feeding corrective actions

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$15,000–$27,000

Under 100 employees, one or two AI products, or already ISO 27001 certified

About 100–180 hours
Mid-size
$27,000–$45,000

100–1,000 employees, several AI systems, building and deploying AI

About 180–300 hours
Large
$45,000–$72,000

1,000+ employees or many AI systems across sites, no existing ISO program

About 300–480 hours
WHAT MOVES THE PRICE
  • Number of AI systems and whether you build, deploy, or only use AI
  • Whether an ISO 27001 management system already exists to extend
  • Number of sites and business units in scope
  • Maturity of data-handling and model life-cycle practices
TYPICAL TIMELINE

4–7 months with an existing ISO 27001 program; 6–12 months from a standing start

Stage 1 and Stage 2 certification audits are billed by an accredited certification body, typically $20,000–$50,000 for smaller organizations and more for large ones.

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • AI management system scope statement and gap report, each gap with an owner, a severity, and an effort estimate
  • AI policy, procedures, the record of which controls apply, risk and impact assessments, and measurable objectives
  • Internal audit report, management review minutes, and risk treatment plan ready for the certification audit
  • Evidence index organized for the certification audit, with notes on confirming your auditor’s accreditation status

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

Can we build our AI management system on our ISO/IEC 27001 program?

Yes, and it shortens the work considerably. ISO/IEC 42001 shares its structure with ISO/IEC 27001, so much of what you already run can be extended rather than duplicated. That means one risk method, one internal audit program, and one management review with AI added to the agenda. What is new is the AI-specific content: the AI controls, the impact review procedure, and life-cycle and data-management practices for models. Expect your existing documents to gain sections rather than your organization to gain a second management system.

Who certifies us, and can the same firm help us prepare?

An independent certification body decides certification, first reviewing your documentation and then auditing how the system operates, with annual surveillance over a three-year cycle. Certification bodies are being newly accredited for AI management systems, so ask any body you shortlist about its accreditation status. We are not a certification body and issue no certificates, and the firm that helps you build the system should not also audit it. We prepare you, run the internal audit on your behalf, and help you brief the body you select. Certification itself is never something we can promise.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security