AI governance (ISO/IEC 42001)

They’re using AI but can’t quite explain how it’s controlled.

What’s included

01

AI governance (ISO/IEC 42001)

  • Gap assessment against ISO/IEC 42001:2023
  • AI management system built with your team, not handed over as a binder
  • Internal audit and Stage 1 readiness
  • Fixed fee, 8 weeks to Stage 1, timeline in writing

Fixed fee — ask

How ISO 42001 goes, week by week

Fixed fee. 8 weeks to Stage 1.

01


30 mins

Do you need 42001, and is now the time? If not, I’ll tell you.

02


weeks 1–2

Where your AI use actually is versus what the standard expects. Written report, no surprises later.

03


weeks 3–6

Policies, risk assessment, impact assessment, controls — written with your people so they own it.

04


week 7

We run the audit before BSI does.

05


week 8

Certification body audit. You have a timeline in writing from day one.

Who it’s for

  • Legal
  • Professional services
  • Any UK firm with production AI

Questions

ISO 27001 is actually a great starting point, however, it doesn’t cover the risks that are specific to AI. 27001 protects the confidentiality, integrity and availability of your information. ISO 42001 goes further and asks whether your AI systems are used responsibly: whether outputs are reliable, whether bias or harm to people has been assessed, how AI suppliers are governed, and who is accountable when an AI-assisted decision goes wrong.

The good news is that both standards share the same high-level structure, so your existing policies, risk process, internal audits and management reviews can be extended rather than rebuilt. Most 27001-certified organisations can integrate 42001 into their current management system and cut the effort significantly. The main new work is an AI impact assessment, an AI-specific risk assessment, and a Statement of Applicability against the 42001 Annex A controls.

Whether you need it usually depends on your customers, tender requirements and sector. I can help you work out if it’s worth it for you.

Stage 1 is a readiness review. An auditor wants to confirm that your AI management system exists on paper and is ready to be tested properly at Stage 2. They’ll typically look at:

  • Scope: which AI systems, teams and locations are covered, and whether any noted exclusions are actually justified
  • Context: your AI role (developer, provider or user), stakeholders, and the legal and regulatory requirements you’ve identified
  • Core documents: your AI policy, objectives, roles and responsibilities
  • Risk and impact: your methodology for AI risk assessment and AI impact assessment, and evidence they’ve been carried out
  • Statement of Applicability: which Annex A controls apply and why
  • The management cycle: evidence that internal audit and management review are planned or already done

Stage 1 isn’t a test, it’s simply your starting point. You’ll get a report listing any gaps to fill that would register as nonconformities at Stage 2 if they aren’t fixed. Going in well prepared means fewer surprises and a shorter path to certification.

It means that you’re using AI, and the risks are real, even with these models. ISO 42001 applies to organisations that use AI, not just those that build it. For most businesses, everyday tools like ChatGPT and Microsoft Copilot are where the real exposure sits: staff pasting client data into consumer accounts, Copilot surfacing documents people shouldn’t see because of loose SharePoint permissions, or AI-generated content going out unchecked.

The good news is that your AI governance can be proportionate. As an AI user, the scope is much lighter than one for an AI developer. Typically it will need to cover:

  • an acceptable use policy
  • a list of approved tools and licence tiers
  • data handling rules
  • a permissions review before Copilot rollout
  • human review of outputs
  • basic staff training

If you trade in the EU, the AI Act already requires organisations using AI to ensure their staff have adequate AI literacy. You may not need full certification. Many clients start with a lightweight governance framework aligned to 42001 and decide on certification later.