Advisory

ISO/IEC 42001 AI Management

Alignment, readiness and certification for ISO/IEC 42001, the international standard for managing AI.

Govern how you build and use AI.

ISO/IEC 42001:2023 is the first international standard for an AI management system (AIMS). It sets out what you need to establish, run, maintain and keep improving a system that governs AI in your organisation. It applies to any organisation that builds, provides or uses AI-based products or services, whatever its size. The standard is new, and many organisations are only now starting on it. Vectra helps you at each stage: aligning your current practice with the standard, getting ready for audit and working towards certification.

ISO/IEC 42001 AI Management

What the standard asks of you.

ISO/IEC 42001 uses the same management system structure as ISO/IEC 27001. Clauses 4 to 10 set the core requirements. Annex A lists reference controls, and the other annexes give implementation guidance and examples of AI risk sources.

If you already run an ISO/IEC 27001 information security management system, much of its governance carries over.

  • Leadership and policy

    Top management owns the AI management system, sets an AI policy and gives people clear roles.

  • AI risk assessment

    You find, assess and treat the risks that come from developing, providing or using AI.

  • AI system impact assessment

    You assess how each AI system could affect people, groups and society. ISO/IEC 42005 gives guidance on how.

  • Controls across the life cycle

    You pick controls from Annex A for data, development, use, suppliers and third parties, and record why.

  • Audit and improvement

    You check the system with internal audits and management reviews, and fix what they find.

Governance sets the rules for AI. Security makes them hold.

ISO/IEC 42001 defines how you approve, manage and oversee AI. Our AI Security solution adds the runtime controls that find shadow AI and stop harmful agent activity.

From first review to certification audit.

Each stage reuses what you already have, such as an ISO/IEC 27001 management system.

  1. Step 1: Scope and context

    Agree which AI systems, teams and roles are in scope, and whether you build, provide or use AI.

  2. Step 2: Gap assessment

    Compare your current policies, processes and records with each clause of the standard and the Annex A controls. List what is missing, most important first.

  3. Step 3: Risk and impact

    Assess the risks your AI systems create, and their possible impact on people, groups and society. Choose the treatment and the controls for each.

  4. Step 4: Build the AIMS

    Write the AI policy, set roles, and put controls and records in place across the AI life cycle, from design and data to use and retirement.

  5. Step 5: Check and improve

    Run an internal audit and a management review. Track corrective actions until they are closed, as the standard requires.

  6. Step 6: Certification audit

    Prepare for the two-stage audit by an accredited certification body. Support your team through it and help close any findings.

ISO/IEC 42001 services.

Alignment review

An independent view of how your current AI practice compares with ISO/IEC 42001, for organisations that want alignment before certification.

Readiness assessment

A gap assessment against every clause and control, with a ranked plan of the work needed before a certification audit.

AI risk and impact assessment

Methods and records for assessing AI risk and the impact of each AI system, built so you can repeat them as systems change.

Policy and control design

AI policy, roles, procedures and a Statement of Applicability that explains which controls apply and why.

Internal audit

An internal audit of your AIMS and support for the management review, before the certification body arrives.

Certification support

Help through the certification audit and the surveillance audits that follow.

What you have at the end.

  • A defined scope and an AI policy approved by leadership.

  • A repeatable way to assess AI risk and the impact of each AI system.

  • A Statement of Applicability that explains every control decision.

  • Records and evidence ready for a certification body to review.

  • An AI management system integrated with ISO/IEC 27001, not separate from it.

ISO/IEC 42001 questions.

Who is ISO/IEC 42001 for?

It is for any organisation that provides or uses products or services that rely on AI, regardless of size, type or sector. That includes developers of AI models, software providers adding AI features, and organisations using AI tools in daily operations.

Is certification required?

No. Certification is voluntary. Some organisations align with the standard to improve how they govern AI. Others certify to give customers, partners and regulators independent assurance.

Who issues the certificate?

An independent, accredited certification body audits your AI management system and issues the certificate. ISO/IEC 42006 sets the rules for bodies that audit and certify against ISO/IEC 42001. Vectra prepares you for that audit and supports you through it.

How does it relate to ISO/IEC 27001?

Both standards share the same management system structure, with the same core clauses. If you already hold ISO/IEC 27001, much of your governance, audit and review process can be reused. ISO/IEC 42001 adds the parts that are specific to AI, such as the AI system impact assessment.

Does ISO/IEC 42001 secure our AI tools?

It sets how you govern AI: policy, risk, roles and oversight. It does not stop an attack on its own. Technical controls, such as monitoring what AI agents do on your endpoints, sit alongside it. Our AI Security solution covers that side.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.