AI governance & ISO 42001
Responsible, trustworthy AI, governed with the same rigour as your information security.
AI is transforming how organisations work, but it also introduces new risks to your data, your customers, and your reputation. We help you put practical, proportionate AI governance in place using ISO/IEC 42001 and the NIST AI Risk Management Framework, through independent consulting and auditing.
What is ISO/IEC 42001?
ISO/IEC 42001 is the world’s first international standard for an Artificial Intelligence Management System (AIMS). Published in December 2023, it sets out the requirements for establishing, implementing, maintaining, and continually improving the policies, processes, and controls an organisation uses to develop, provide, or use AI responsibly.
Built on the same harmonised structure as ISO 27001, it covers:
- AI policy, leadership, roles, and accountability
- AI risk assessment and risk treatment
- AI system impact assessments on individuals, groups, and society
- Data governance and data quality for AI
- Controls across the AI system lifecycle (Annex A)
- Third-party, supplier, and customer relationships
- Monitoring, internal audit, and continual improvement
Because it is certifiable, independent certification gives customers, partners, regulators, and investors evidence that your AI is governed responsibly.
Why it is important
AI brings real opportunity, but also new risks: biased or unfair outcomes, lack of transparency, leakage of confidential or personal data, security threats such as prompt injection and data poisoning, intellectual property issues, and reputational harm. Customers, investors, and regulators increasingly expect evidence that these risks are being managed.
- Build trust: demonstrate responsible, transparent, and accountable use of AI
- Prepare for regulation: a strong foundation for obligations such as the EU AI Act and the UK’s evolving approach to AI
- Win business: AI governance questions now feature in procurement, tenders, and supplier due diligence
- Manage risk consistently: a structured, repeatable approach rather than ad-hoc decisions
- Build on what you have: integrates with ISO 27001 and ISO 27701, so an existing management system can be extended rather than duplicated
Who it is for
ISO/IEC 42001 applies to organisations of any size, in any sector, that develop, provide, or use AI systems, including:
- AI developers and product companies building machine learning or AI into their products and services
- Technology and SaaS providers embedding third-party AI models or large language models
- Organisations using AI to support decisions in areas such as HR, finance, customer service, or operations
- Regulated organisations in financial services, critical infrastructure, healthcare, and the public sector
- Organisations already certified to ISO 27001 or ISO 27701 that want to extend their management system to cover AI
Whether you are an early adopter experimenting with generative AI or an established AI company, the standard scales to your context and risks.
NIST AI Risk Management Framework
The NIST AI Risk Management Framework (AI RMF 1.0), published by the US National Institute of Standards and Technology, is a voluntary, sector-agnostic framework for managing AI risks and building trustworthy AI. It is organised around four core functions:
- Govern: cultivate a culture of AI risk management, with clear policies, accountability, and oversight
- Map: establish the context of each AI system and identify its risks and impacts
- Measure: analyse, assess, and track AI risks using appropriate methods and metrics
- Manage: prioritise and act on risks, and monitor them over time
The framework describes the characteristics of trustworthy AI: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed. NIST has also published a Generative AI Profile (NIST AI 600-1) addressing risks specific to generative AI.
The AI RMF complements ISO/IEC 42001. Many organisations use it to deepen AI risk assessment within a certifiable ISO 42001 management system, or as a practical starting point before certification.
How we can help
Consulting
- AI governance gap analysis against ISO/IEC 42001 and the NIST AI RMF
- AI system inventory, risk assessments, and AI impact assessments
- Design and implementation of your AI management system, policies, and procedures
- Integration with your existing ISO 27001, ISO 27701, or ISO 22301 management systems
- Certification readiness support
Auditing
- Internal audits of your AI management system against ISO/IEC 42001
- Pre-certification (readiness) audits
- 2nd-party audits of AI suppliers and service providers