LeadAI logo| AIMS
Guide: ISO/IEC 42001

How to prepare for ISO/IEC 42001 certification

ISO/IEC 42001 is the international standard for an AI management system (AIMS). This guide explains, in plain steps, how to get from "we use AI" to a certificate that customers, partners and regulators can trust.

Why certify, and what it really means

ISO/IEC 42001 was published in December 2023. It sets out what an organisation needs to govern AI in a controlled and repeatable way. It does not tell you which AI to build. It tells you how to manage the risks, impacts and responsibilities that come with it.

Certification means an independent certification body has audited your AIMS and confirmed that it meets the standard. For most organisations, the real value is not the certificate itself. It is the ability to answer hard questions from customers, procurement teams, boards and regulators with evidence instead of promises.

Good to know. ISO/IEC 42001 uses the same high-level structure as ISO/IEC 27001 and ISO 9001. If you already run one of these, you can reuse much of your management system and often combine audits.

Phase 1

Define your starting point

Most delays in certification come from weak foundations. Get these five things right before you write a single policy.

Build an AI inventory

List every AI system in use or in development. Include models you build, AI features inside vendor software, and generative AI tools that staff use day to day. For each one, record its purpose, owner, data used, who it affects and its current status. You cannot scope, assess or control what you have not found.

Set the scope of your AIMS Clause 4.3

Decide which business units, locations, products and AI systems the management system covers. A narrow scope is faster to certify but may not satisfy customers who assume the whole company is covered. A very wide scope can stall the project. Write the scope down, explain any exclusions, and make sure it matches how you will describe the certificate in public.

Understand your role in the AI ecosystem Clause 4.1

The standard asks you to identify your role, because it shapes which risks and controls matter most. Many organisations hold more than one role at the same time.

AI provider

Offers AI products or services to others, such as a SaaS platform with AI features.

AI producer

Designs, develops, trains or tests AI systems and models.

AI customer or user

Uses AI systems built by others inside its own operations.

AI partner

Supports others, for example as a data supplier, integrator or evaluator.

Role names follow ISO/IEC 22989. If you are subject to the EU AI Act, map these roles to the Act's own terms, such as provider and deployer, as they are not identical.

Map context and interested parties Clauses 4.1, 4.2

Identify internal and external issues that affect your AI use, and the people who care about it. This usually includes customers, employees, people affected by AI decisions, investors, and regulators. In the UK, think about sector regulators such as the FCA and the ICO. If you serve EU markets, include the EU AI Act.

Run a gap assessment

Compare what you do today against clauses 4 to 10 and the Annex A controls. Rate each requirement as in place, partly in place or missing. The result becomes your project plan and a realistic view of time and cost.

Secure leadership commitment Clause 5

Auditors will look for real leadership involvement, not a signature on a form. Name an executive sponsor, agree a budget, assign AIMS roles and responsibilities, and have top management approve the AI policy. Without this, the rest of the programme struggles to get time from busy teams.

Phase 2

Build the management system

This is where governance moves from a plan into daily work. Aim for processes that teams actually use, not documents that sit in a folder.

Write the AI policy and set objectives Clauses 5.2, 6.2

The AI policy states your intent and principles for responsible AI. Objectives turn that intent into measurable targets, for example "all high-impact AI systems have a completed impact assessment before release."

Set up AI risk assessment and treatment Clauses 6.1.2, 6.1.3

Define a repeatable method to identify, analyse and evaluate AI risks. Cover risks to the organisation and to others, such as bias, lack of transparency, poor data quality, security weaknesses, model drift and misuse. For each risk, decide how to treat it and who owns the action.

Carry out AI system impact assessments Clause 6.1.4

This is one of the features that makes ISO/IEC 42001 different from ISO/IEC 27001. An impact assessment looks outward: how could this AI system affect individuals, groups and society? Run it for each relevant system, record the results, and repeat it when the system or its use changes.

Produce your Statement of Applicability Clause 6.1.3

Annex A contains 38 controls. The Statement of Applicability (SoA) lists each one, says whether it applies, explains why, and shows how it is implemented. Every exclusion needs a clear reason. Auditors read this document closely.

Implement the Annex A controls

The controls are grouped into nine areas. Annex B of the standard gives guidance on how to implement each one.

AreaWhat it covers in practice
A.2 PoliciesAn AI policy, how it fits with other policies, and regular review.
A.3 Internal organisationClear roles and a way for staff to report concerns about AI.
A.4 ResourcesRecords of data, tools, computing, people and skills used for each AI system.
A.5 Impact assessmentA defined process for assessing and documenting impacts on people and society.
A.6 AI system life cycleResponsible design, development, testing, release, monitoring and retirement.
A.7 DataData quality, where data comes from, how it is prepared and its provenance.
A.8 Information for interested partiesUser documentation, incident reporting and communication with affected people.
A.9 Use of AI systemsIntended use, human oversight and processes for responsible use.
A.10 Third partiesSuppliers, customers and how responsibilities are shared across the AI supply chain.

Embed governance into the AI life cycle

Controls work best when they sit inside existing workflows. Add governance checkpoints to your delivery process: an approval gate before a new AI use case starts, a data review before training, test and fairness checks before release, and monitoring after go-live. Treat third-party AI the same way through procurement and vendor reviews.

Train people by role Clauses 7.2, 7.3

Everyone in scope needs to know the AI policy and their part in it. Developers, data scientists, product owners, risk teams and senior leaders need deeper, role-based training. Keep records of competence, because auditors will ask for them.

Control documents and collect evidence Clause 7.5

Set up version control, approval and access rules for AIMS documents. From day one, keep evidence that processes run: meeting minutes, completed assessments, test results, training logs and tickets. Evidence collected as you go is far cheaper than evidence rebuilt before an audit.

Phase 3

Prove that it works

Auditors certify a system that is running, not a system that is planned. Give your AIMS time to operate and produce records before you book the audit.

Operate, measure and monitor Clauses 8, 9.1

Run your processes for a period and track the measures you set against your objectives. Most organisations need a few months of operation to show a credible track record.

Complete an internal audit Clause 9.2

Audit the full AIMS using someone independent of the work being audited. This can be an internal team or an external specialist. Record findings and fix them before the certification audit.

Hold a management review Clause 9.3

Top management should formally review AIMS performance, audit results, risks, incidents and resources, and record their decisions. This is a required input for certification.

Manage nonconformities Clause 10.2

For every gap found, record the root cause, the correction and the action to stop it happening again. A clear corrective action log shows auditors that your system can find and fix its own problems.

Choose a certification body

Pick an accredited body with real AI audit experience. In the UK, check accreditation with UKAS. In Türkiye, check TÜRKAK. Confirm that ISO/IEC 42001 is inside the body's accredited scope, and ask about auditor competence against ISO/IEC 42006, the standard that sets requirements for bodies auditing AI management systems. Some organisations also book an optional pre-assessment to test readiness.

Pass the two-stage certification audit

Stage 1: readiness review

The auditor reviews your scope, policy, risk and impact assessment methods, SoA and core documents. They confirm whether you are ready for Stage 2 and flag any concerns.

Stage 2: implementation audit

The auditor tests whether the system works in practice. Expect interviews, sampling of evidence and walk-throughs of real AI systems in scope.

Findings are usually graded as major nonconformities, minor nonconformities and opportunities for improvement. Major findings must be closed before the certificate is issued. Minor findings need an agreed action plan.

Phase 4

Keep it alive after certification

A certificate is the start of an ongoing cycle, not the end of a project.

  1. Year 1Initial certification audit. Certificate issued, valid for three years.
  2. Year 2First surveillance audit, checking a sample of the AIMS.
  3. Year 3Second surveillance audit, then recertification before expiry.

What ongoing oversight looks like

  • Keep the AI inventory current as new systems and vendor tools appear.
  • Re-run risk and impact assessments when a system, its data or its use changes in a meaningful way.
  • Monitor models in production for drift, errors, incidents and complaints.
  • Track regulatory change, such as EU AI Act deadlines and UK sector guidance.
  • Repeat internal audits and management reviews at planned intervals.
  • Use findings and incidents to improve the system over time Clause 10.1

ISO/IEC 42001 and the EU AI Act. The standard gives a strong governance base for many AI Act duties, such as risk management, data governance, documentation and human oversight. It is not the same as legal compliance. Treat it as a foundation, then map specific legal requirements on top.

Getting ahead of AI regulation that hasn't landed yet

AI law is still being written in most countries. Rules that are guidance today may be enforceable duties in two years. Building an AIMS now gives you a running start on whatever comes next, rather than a scramble once a new law takes effect.

ISO/IEC 42001 does this by giving you a complete framework for ethical and responsible AI, not a list of today's rules. Because the policies, risk processes and controls you put in place are built around the same principles most AI regulation is built on, transparency, human oversight, accountability and risk management, they tend to stay relevant as specific laws change around them. You are not rewriting your governance every time a new regulation appears. You are mapping a new requirement onto a system that already asks the right questions.

This matters most in three ways:

  • Your policies age well. An AI policy built on transparency and accountability principles does not need a rewrite every time a regulator publishes new guidance. You adjust the mapping, not the foundation.
  • You can show your work. Impact assessments, risk registers, audit trails and the Statement of Applicability are exactly the kind of evidence regulators and auditors ask for when they want proof of compliance, not just a promise of it.
  • Non-compliance risk drops. Organisations that already run risk management and human oversight as routine practice have far less to fix, and far less exposure to penalties, when a new law arrives than organisations starting from nothing.

The standard is a foundation, not a substitute for legal advice. ISO/IEC 42001 will not certify you as compliant with the EU AI Act, UK sector rules, or any other specific law. What it gives you is the governance muscle, the processes, the records, the accountability, that makes meeting those laws far faster and cheaper when they do apply to you.

Documents auditors will expect

The standard requires documented information in a number of places. At a minimum, prepare the following.

Document or recordClause
AIMS scope4.3
AI policy5.2
AI risk assessment process and results6.1.2, 8.2
AI risk treatment process, plan and results6.1.3, 8.3
Statement of Applicability6.1.3
AI system impact assessment process and results6.1.4, 8.4
AI objectives6.2
Evidence of competence7.2
Operational planning and control records8.1
Monitoring and measurement results9.1
Internal audit programme and results9.2
Management review results9.3
Nonconformities and corrective actions10.2

Annex A controls add further records depending on your SoA, for example AI system documentation, data provenance records and supplier agreements.

Common mistakes to avoid

  • Missing shadow AI. Staff use of public generative AI tools and AI inside vendor software is often left out of the inventory.
  • Treating it as paperwork. Policies with no evidence of use are one of the fastest routes to a major nonconformity.
  • Confusing risk and impact assessments. They answer different questions. You need both.
  • Weak SoA exclusions. Excluding a control because it is inconvenient, rather than because it does not apply, will be challenged.
  • Booking the audit too early. Without internal audit, management review and some months of records, Stage 2 is hard to pass.
  • A scope that does not match the story. If sales materials suggest company-wide certification but the scope covers one product, trust suffers.

Readiness checklist

Tick items as you complete them. Your progress is saved in this browser only.

0 of 0 complete
1. Define
2. Build
3. Prove
4. Sustain

How LeadAI helps

LeadAI combines ISO/IEC 42001 consultancy with the LeadAI AIMS platform, so your governance programme and your evidence live in one place.

  • Readiness and scoping. Gap assessment, AI inventory and scoping workshops to set a realistic plan.
  • Implementation. AI policy, risk and impact assessment methods, Statement of Applicability and life cycle controls that fit how your teams already work.
  • Audit support. Internal audit, management review preparation and support through Stage 1 and Stage 2.
  • Ongoing oversight. A platform to keep your inventory, assessments and evidence current between surveillance audits.

We work in English and Turkish.

Talk to us about a readiness assessment.