AI governance (ISO/IEC 42001): Why it matters now
When ISO/IEC 42001 was published in December 2023, it was the first international standard for managing AI responsibly, and for most organisations it looked like something to consider later.
That has changed quickly. In the EU, the AI Act’s transparency duties now apply to everyday generative AI use, and firms deploying AI in higher-risk areas such as recruitment and credit decisions have a firm compliance date of December 2027. In the UK, the Data (Use and Access) Act has rewritten the rules on automated decision-making, and the ICO is preparing a statutory code of practice on AI. At the same time, insurers are ending “silent AI” cover, adding AI exclusions at renewal and asking for evidence of how AI risk is managed. Clients and procurement tenders are asking the same questions. ISO 42001 gives you one structured, auditable answer to all of them: a management system that shows who is accountable for your AI, what risks you have assessed, and how you control them.
What’s included
01
AI governance (ISO/IEC 42001)
- Gap assessment against ISO/IEC 42001:2023
- AI management system built with your team, not handed over as a binder
- Internal audit and Stage 1 readiness
- Fixed fee, ~12 weeks to Stage 1, timeline in writing
Fixed fee — ask
How ISO 42001 goes, week by week
What building your AI Management System involves
A typical engagement runs around twelve weeks. In weeks one and two we set the foundations: we agree the scope, build an inventory of the AI tools and systems you actually use (including the ones staff have adopted informally), define your role as a user, provider or developer of AI, and draft an AI policy that leadership signs off.
Weeks three to five are the analytical core. We carry out an AI risk assessment and an AI impact assessment, looking at the effects your AI use could have on clients, staff and the wider public, and we produce a Statement of Applicability setting out which of the standard’s Annex A controls apply to you and why.
Weeks six to nine turn that analysis into practice. We put in place the controls and procedures your risks call for, typically an acceptable use policy, rules on data handling, supplier checks for AI vendors, human review of AI outputs, incident handling and staff training, and we set measurable AI objectives. Where you already hold ISO 27001 or ISO 9001, we build on your existing management system rather than creating a parallel one.
In weeks ten to twelve the system runs for real: we help you gather evidence, carry out an internal audit and hold a management review, then assemble a Stage 1 readiness pack so you go into your certification audit knowing what the auditor will see.
Who it’s for
- Legal & Professional services
- SME or Enterprise
- Any UK firm with using AI anywhere in its business functions
