AI governance (ISO/IEC 42001): Why it matters now

When ISO/IEC 42001 was published in December 2023, it was the first international standard for managing AI responsibly, and for most organisations it looked like something to consider later.

That has changed quickly. In the EU, the AI Act’s transparency duties now apply to everyday generative AI use, and firms deploying AI in higher-risk areas such as recruitment and credit decisions have a firm compliance date of December 2027. In the UK, the Data (Use and Access) Act has rewritten the rules on automated decision-making, and the ICO is preparing a statutory code of practice on AI. At the same time, insurers are ending “silent AI” cover, adding AI exclusions at renewal and asking for evidence of how AI risk is managed. Clients and procurement tenders are asking the same questions. ISO 42001 gives you one structured, auditable answer to all of them: a management system that shows who is accountable for your AI, what risks you have assessed, and how you control them.

What’s included

01

AI governance (ISO/IEC 42001)

  • Gap assessment against ISO/IEC 42001:2023
  • AI management system built with your team, not handed over as a binder
  • Internal audit and Stage 1 readiness
  • Fixed fee, ~12 weeks to Stage 1, timeline in writing

Fixed fee — ask

How ISO 42001 goes, week by week

What building your AI Management System involves
A typical engagement runs around twelve weeks. In weeks one and two we set the foundations: we agree the scope, build an inventory of the AI tools and systems you actually use (including the ones staff have adopted informally), define your role as a user, provider or developer of AI, and draft an AI policy that leadership signs off.

Weeks three to five are the analytical core. We carry out an AI risk assessment and an AI impact assessment, looking at the effects your AI use could have on clients, staff and the wider public, and we produce a Statement of Applicability setting out which of the standard’s Annex A controls apply to you and why.
Weeks six to nine turn that analysis into practice. We put in place the controls and procedures your risks call for, typically an acceptable use policy, rules on data handling, supplier checks for AI vendors, human review of AI outputs, incident handling and staff training, and we set measurable AI objectives. Where you already hold ISO 27001 or ISO 9001, we build on your existing management system rather than creating a parallel one.

In weeks ten to twelve the system runs for real: we help you gather evidence, carry out an internal audit and hold a management review, then assemble a Stage 1 readiness pack so you go into your certification audit knowing what the auditor will see.

01


30 mins

Do you need 42001, and is now the time? If not, I’ll tell you.

02


weeks 1–2

Where your AI use actually is versus what the standard expects. Written report, no surprises later.

03


weeks 3–6

Policies, risk assessment, impact assessment, controls — written with your people so they own it.

04


week 7

We run the audit before BSI does.

05


week 8

Certification body audit. You have a timeline in writing from day one.

Who it’s for

  • Legal & Professional services
  • SME or Enterprise
  • Any UK firm with using AI anywhere in its business functions

Questions

ISO 27001 is actually a great starting point, however, it doesn’t cover the risks that are specific to AI. 27001 protects the confidentiality, integrity and availability of your information. ISO 42001 goes further and asks whether your AI systems are used responsibly: whether outputs are reliable, whether bias or harm to people has been assessed, how AI suppliers are governed, and who is accountable when an AI-assisted decision goes wrong.

The good news is that both standards share the same high-level structure, so your existing policies, risk process, internal audits and management reviews can be extended rather than rebuilt. Most 27001-certified organisations can integrate 42001 into their current management system and cut the effort significantly. The main new work is an AI impact assessment, an AI-specific risk assessment, and a Statement of Applicability against the 42001 Annex A controls.

Whether you need it usually depends on your customers, tender requirements and sector. I can help you work out if it’s worth it for you.

Stage 1 is a readiness review. An auditor wants to confirm that your AI management system exists on paper and is ready to be tested properly at Stage 2. They’ll typically look at:

  • Scope: which AI systems, teams and locations are covered, and whether any noted exclusions are actually justified
  • Context: your AI role (developer, provider or user), stakeholders, and the legal and regulatory requirements you’ve identified
  • Core documents: your AI policy, objectives, roles and responsibilities
  • Risk and impact: your methodology for AI risk assessment and AI impact assessment, and evidence they’ve been carried out
  • Statement of Applicability: which Annex A controls apply and why
  • The management cycle: evidence that internal audit and management review are planned or already done

Stage 1 isn’t a test, it’s simply your starting point. You’ll get a report listing any gaps to fill that would register as nonconformities at Stage 2 if they aren’t fixed. Going in well prepared means fewer surprises and a shorter path to certification.

It means that you’re using AI, and the risks are real, even with these models. ISO 42001 applies to organisations that use AI, not just those that build it. For most businesses, everyday tools like ChatGPT and Microsoft Copilot are where the real exposure sits: staff pasting client data into consumer accounts, Copilot surfacing documents people shouldn’t see because of loose SharePoint permissions, or AI-generated content going out unchecked.

The good news is that your AI governance can be proportionate. As an AI user, the scope is much lighter than one for an AI developer. Typically it will need to cover:

  • an acceptable use policy
  • a list of approved tools and licence tiers
  • data handling rules
  • a permissions review before Copilot rollout
  • human review of outputs
  • basic staff training

If you trade in the EU, the AI Act already requires organisations using AI to ensure their staff have adequate AI literacy. You may not need full certification. Many clients start with a lightweight governance framework aligned to 42001 and decide on certification later.