Cyber security intelligence, AI governance, practitioner analysis
Flagship certification
ISO/IEC 42001 Implementation and Remediation
Full-cycle AI management system consultancy: gap analysis, AIMS implementation, remediation, and pre-audit review from first inventory to certification, led by an ISO/IEC 42001 Lead Auditor.
ISO/IEC 42001 is becoming the reference standard for AI governance, and buyers have started asking for it in procurement. This engagement takes you from first AI inventory to certification: implementation of the AI management system, remediation of fragments that already exist, and pre-audit review by a Lead Auditor.
Frameworks covered
ISO/IEC 42001
Full clause coverage and the Annex A control set
ISO/IEC 27001 harmonisation
An existing ISMS becomes a head start, not a parallel system
EU AI Act crosswalk
Certification evidence reused for regulatory conformity
How the engagement runs
1
AI inventory and scoping
Every AI system you build, buy, or quietly use, inventoried and classified; the AIMS boundary drawn wide enough to survive audit scrutiny.
2
Gap analysis
Clauses 4 to 10 and every Annex A control assessed, with applicability justifications an auditor will accept.
3
AIMS implementation
AI policy, impact assessment process, Statement of Applicability, and supplier controls, built to operate rather than to sit in a folder.
4
Operate and evidence
The system runs for long enough to generate real evidence: impact assessments completed, reviews held, incidents handled.
5
Pre-audit and certification
A pre-audit run exactly as the certification body will run it, findings closed, then audit-day support.
What you walk away with
AI system inventory with risk classification
Gap report against every clause and control
AI policy, impact assessment process, and Statement of Applicability
AI supplier control set and contractual language
Pre-audit report and certification support
How this plays out
Example scenario
A healthcare AI vendor faced NHS procurement questionnaires that asked directly about ISO 42001 status.
The work: Inventory and gap analysis in month one, AIMS built on top of their existing 27001 ISMS, impact assessments run on both clinical products.
Certification achieved in seven months; the procurement answer changed from a gap to a differentiator.
Example scenario
A software firm had fragments of AI governance: a policy here, a register there, nothing an auditor would certify.
The work: Remediation rather than restart: existing fragments mapped to the standard, gaps closed in priority order, evidence pipelines added.
Audit-ready in four months without discarding the work already done, and a governance rhythm the team sustains.
Start the conversation
A short call to understand your situation; a clear scope if the engagement fits, and a straight answer if it does not.
ISO 42001 is a management system standard, and the word management carries the
weight. It does not tell you which AI systems are acceptable, what accuracy is
sufficient, or where to draw a line on automated decisions. It requires that
you have a process for reaching those answers, that somebody owns it, that the
reasoning is recorded, and that the whole thing is reviewed rather than
written once.
An assessor is not evaluating your models. They are evaluating whether you can
demonstrate control over them. That is a lower bar than most organisations
fear and a different one from what they prepare for.
Where an ISO 27001 head start actually helps
Clauses 4 to 10 are the harmonised structure common to every modern ISO
management system, so internal audit, management review, document control and
corrective action largely transfer. That saves months.
What does not transfer is the subject matter, and it is the part that takes
the time: the AI system inventory, the impact assessment on individuals and
society, and data provenance.
There is a deeper difference underneath the clause mapping. An information
security management system protects the organisation from the world. An AI
management system is substantially concerned with protecting the world from
the organisation. A risk register built on the first assumption records only
risks to the business, and an assessor notices within an hour.
Record every requirement in one of three states
Two states, present and absent, is what most readiness assessments use, and it is why they overstate. A written procedure nobody has run is not a control. An assessor does not ask whether a document exists; they ask when it last ran.
The requirement most often answered incorrectly
The AI system impact assessment is the clearest difference between this
standard and an information security management system, and it is routinely
satisfied by relabelling a data protection impact assessment.
A DPIA examines privacy. This examines fairness, contestability, and what
happens to a person when the system is wrong. A model can be entirely
compliant on data protection and still be discriminatory, unexplainable and
impossible to appeal. Relabelling produces a document that satisfies neither
requirement, and it is visible immediately.
ISO 42005, published in 2025, is the guidance on how to conduct one properly.
It is not certifiable and nobody audits you against it, and its value is that
it removes the argument about what the assessment should contain.
Why timing is the binding constraint
Nine to fifteen months from a standing start, and the limit is operating
history rather than documentation.
A risk management system is evidenced by having operated. Data governance is
evidenced by decisions recorded when the data was chosen. An internal audit
and a management review both need to have genuinely happened before a stage 2
audit is worth booking. None of that can be produced retrospectively, and no
budget compresses it.
Which is the argument for starting the parts that accrue time early, even
where the decision to certify has not been made. The inventory and the
ownership model are useful whether or not a certificate is ever pursued.
One thing worth checking about your certification body
ISO 42006, also published in 2025, sets the requirements for bodies auditing
and certifying AI management systems. It is what makes a certificate mean the
same thing from one body to the next.
So the question to ask anybody quoting for the work is under what
accreditation they are issuing it. A certificate from a body not accredited
for AI management systems is a different product from the one a procurement
team believes it is receiving, and the difference surfaces at the wrong
moment.