Alignment review
An independent view of how your current AI practice compares with ISO/IEC 42001, for organisations that want alignment before certification.
Alignment, readiness and certification for ISO/IEC 42001, the international standard for managing AI.
ISO/IEC 42001:2023 is the first international standard for an AI management system (AIMS). It sets out what you need to establish, run, maintain and keep improving a system that governs AI in your organisation. It applies to any organisation that builds, provides or uses AI-based products or services, whatever its size. The standard is new, and many organisations are only now starting on it. Vectra helps you at each stage: aligning your current practice with the standard, getting ready for audit and working towards certification.
ISO/IEC 42001 uses the same management system structure as ISO/IEC 27001. Clauses 4 to 10 set the core requirements. Annex A lists reference controls, and the other annexes give implementation guidance and examples of AI risk sources.
If you already run an ISO/IEC 27001 information security management system, much of its governance carries over.
Top management owns the AI management system, sets an AI policy and gives people clear roles.
You find, assess and treat the risks that come from developing, providing or using AI.
You assess how each AI system could affect people, groups and society. ISO/IEC 42005 gives guidance on how.
You pick controls from Annex A for data, development, use, suppliers and third parties, and record why.
You check the system with internal audits and management reviews, and fix what they find.
Governance sets the rules for AI. Security makes them hold.
ISO/IEC 42001 defines how you approve, manage and oversee AI. Our AI Security solution adds the runtime controls that find shadow AI and stop harmful agent activity.
Each stage reuses what you already have, such as an ISO/IEC 27001 management system.
Agree which AI systems, teams and roles are in scope, and whether you build, provide or use AI.
Compare your current policies, processes and records with each clause of the standard and the Annex A controls. List what is missing, most important first.
Assess the risks your AI systems create, and their possible impact on people, groups and society. Choose the treatment and the controls for each.
Write the AI policy, set roles, and put controls and records in place across the AI life cycle, from design and data to use and retirement.
Run an internal audit and a management review. Track corrective actions until they are closed, as the standard requires.
Prepare for the two-stage audit by an accredited certification body. Support your team through it and help close any findings.
An independent view of how your current AI practice compares with ISO/IEC 42001, for organisations that want alignment before certification.
A gap assessment against every clause and control, with a ranked plan of the work needed before a certification audit.
Methods and records for assessing AI risk and the impact of each AI system, built so you can repeat them as systems change.
AI policy, roles, procedures and a Statement of Applicability that explains which controls apply and why.
An internal audit of your AIMS and support for the management review, before the certification body arrives.
Help through the certification audit and the surveillance audits that follow.
A defined scope and an AI policy approved by leadership.
A repeatable way to assess AI risk and the impact of each AI system.
A Statement of Applicability that explains every control decision.
Records and evidence ready for a certification body to review.
An AI management system integrated with ISO/IEC 27001, not separate from it.
It is for any organisation that provides or uses products or services that rely on AI, regardless of size, type or sector. That includes developers of AI models, software providers adding AI features, and organisations using AI tools in daily operations.
No. Certification is voluntary. Some organisations align with the standard to improve how they govern AI. Others certify to give customers, partners and regulators independent assurance.
An independent, accredited certification body audits your AI management system and issues the certificate. ISO/IEC 42006 sets the rules for bodies that audit and certify against ISO/IEC 42001. Vectra prepares you for that audit and supports you through it.
Both standards share the same management system structure, with the same core clauses. If you already hold ISO/IEC 27001, much of your governance, audit and review process can be reused. ISO/IEC 42001 adds the parts that are specific to AI, such as the AI system impact assessment.
It sets how you govern AI: policy, risk, roles and oversight. It does not stop an attack on its own. Technical controls, such as monitoring what AI agents do on your endpoints, sit alongside it. Our AI Security solution covers that side.
Speak to us about your cyber governance and compliance requirements.