ISO 42001
Artificial Intelligence Management System Certification
ISO/IEC 42001:2023 is the first certifiable standard for AI management systems (AIMS). Praxis-Q delivers end-to-end certification - gap analysis through Stage 2 audit - and maps it onto your existing ISO 27001 ISMS so one governance system covers both.
ISO 42001
ISO 42001
Artificial Intelligence Management System Certification
The Problem
Enterprise buyers and regulators now ask how your AI is governed. Without a certified AI management system, AI features stall in procurement review and EU AI Act questions have no defensible answer.
What We Do
- Scope & Gap Analysis
- AI Risk & Impact Assessment
- AIMS Documentation
- Internal Audit
- Certification
What You Get
- First certifiable AI governance standard
- Answers enterprise AI procurement questionnaires
- Structures EU AI Act readiness work
- Shares Annex SL structure with ISO 27001
- Covers AI developers, providers and deployers
- Evidences responsible-AI claims to customers
- Reduces model, data and third-party AI risk
- Differentiates in AI-enabled product tenders
Who ISO 42001 Applies To
The standard is deliberately role-aware. It covers AI developers and providers who build or supply models and AI-enabled products, and equally the deployers who put third-party AI to work inside their own processes. If you fine-tune a model, embed a vendor API in a customer-facing product, or use AI in decisions that affect people, you are in scope. Praxis-Q begins every engagement by fixing the AI system inventory and the role you occupy for each, because scope drives which of the 38 Annex A controls are applicable and what your Statement of Applicability has to justify.
The 38 Annex A Controls and the Statement of Applicability
Annex A organises 38 controls under nine objectives - policies related to AI, internal organisation, resources for AI systems, assessing impacts of AI systems, AI system lifecycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. As with ISO 27001, controls are selected and justified in a Statement of Applicability rather than applied wholesale. Annex B gives implementation guidance, Annex C catalogues AI-specific risk sources, and Annex D addresses sector and domain use. We work control by control, producing the artefacts an auditor asks to see.
AI Risk Assessment and AI System Impact Assessment
ISO 42001 requires two distinct exercises that organisations often conflate. AI risk assessment looks inward at risks to the organisation and its objectives. The AI system impact assessment looks outward at consequences for individuals, groups and society - fairness, transparency, safety, and the effect of automated decisions on people. Both must be documented, repeatable and revisited as systems change. Praxis-Q supplies the methodology, runs the first cycle with your teams, and leaves you able to run subsequent cycles unaided.
ISO 42001 and the EU AI Act
The two are frequently mentioned together and should not be confused. ISO 42001 is a voluntary standard you can certify against; the EU AI Act is binding law with obligations that vary by risk classification. Certification does not confer a legal presumption of conformity. What it does is produce the governance spine - risk management, data governance, technical documentation, human oversight, lifecycle records - that Act readiness work draws on, which is why organisations preparing for the Act frequently start here. We are explicit about the boundary rather than selling certification as legal cover.
Integrating With an Existing ISO 27001 ISMS
If you already hold ISO 27001, most of the management system machinery is reusable. Annex SL means the clause structure, internal audit programme, management review cadence, corrective action process and document control can be extended to cover AI rather than duplicated. What is genuinely new is the AI-specific content: the AI policy, the system inventory, impact assessment, data provenance and quality controls, and third-party AI supplier management. Praxis-Q runs combined engagements so a single audit cycle and a single evidence set serve both certificates.
Frequently Asked Questions
Is ISO 42001 the same as the EU AI Act?
We already hold ISO 27001 - does that help?
What is ISO/IEC 42001:2023?
How long does ISO 42001 certification take?
Does ISO 42001 make us EU AI Act compliant?
We only use third-party AI - are we still in scope?
How does ISO 42001 differ from ISO 27001?
Ready to Get Started?
Free gap analysis · Proposal in 24hrs · Delivery in weeks