For years, “responsible AI” has been a statement of values. ISO/IEC 42001 makes it a management system — one you can implement, measure, and prove.
Published in December 2023, ISO/IEC 42001 is the first international standard for an Artificial Intelligence Management System (AIMS). It does for AI what ISO 27001 did for information security: it defines the governance structure, the controls, and the evidence trail that let an organisation demonstrate — not merely assert — that its AI is well run.
It uses the same harmonised structure and Plan–Do–Check–Act cycle as ISO 27001, so it sits naturally alongside the management systems many firms already operate. Ten clauses in total; six of them carry the requirements an organisation must meet to certify.
What the standard actually requires
The management-system clauses (4 through 10) form the backbone: understand your organisational context and stakeholders; establish leadership and a written AI policy; plan around AI risks and formal system impact assessments; provide the resources, roles, and competence to deliver; operate the AI lifecycle under documented control; evaluate performance through internal audit and management review; and improve continually.
Annex A then supplies 38 reference controls across nine areas — governance and leadership, risk management, AI system impact assessment, data governance, transparency and documentation, human oversight and accountability, lifecycle development, deployment and monitoring, and third-party and supplier management.
Crucially, those controls are a reference set, not a checklist to adopt wholesale. You produce a Statement of Applicability that records which controls apply, which you have excluded, and why. That is what makes 42001 workable for a mid-market organisation rather than an enterprise-only undertaking — you scope it to the AI you actually run.
Why it matters now
Regulation is arriving with teeth. The EU AI Act’s obligations map closely onto 42001: risk-management systems for high-risk AI (Article 9), human-oversight measures (Article 14), and technical documentation and transparency (Articles 11 and 13) all correspond to the standard’s clauses and Annex A controls. Building an AIMS to 42001 gives you the evidence framework those obligations demand, rather than scrambling to assemble it later.
Procurement is asking, too. As buyers in financial services, healthcare, and the public sector formalise their AI vendor reviews, “are you aligned to ISO 42001?” is becoming a standard question. Being able to answer it — with evidence — is a commercial advantage, not just a compliance line item.
And trust compounds. A certified, or certification-ready, AI management system is a credible signal to clients, regulators, and partners that your AI is governed by design rather than by good intentions.
How Blue Avanti approaches it
We treat 42001 as a right-sized programme, not a bureaucracy. A typical engagement runs a gap assessment against the clauses and Annex A, a prioritised roadmap, the build-out of the AIMS artifacts — AI policy, a risk and impact-assessment method, the control implementations, and the Statement of Applicability — and, if you choose to certify, getting you ready for a two-stage audit with an accredited body.
And we practise what we advise. The systems we build for clients — including the assistant on this very site — are governed to these principles: a documented scope, enforced guardrails, human handoff, and a full audit trail of every interaction. The standard is not abstract to us; it is how we operate.
A 30-day ISO 42001 readiness sprint
For most organisations, the fastest route to a defensible posture is a focused sprint that produces the artifacts rather than trying to build them incrementally:
- Week 1: Inventory AI systems and uses across the organisation, including individual staff shadow use, and flag the highest-impact and highest-risk ones.
- Week 2: Gap-assess against 42001 clauses 4–10 and Annex A. Draft the written AI policy.
- Week 3: Stand up the risk and impact-assessment method. Draft the Statement of Applicability.
- Week 4: Implement the priority controls, assemble the evidence pack, and decide whether to pursue formal certification.
The output is a working AI management system and the documentation to prove it — the difference between “we are thinking about AI governance” and “here is our policy, our controls, and our audit trail.”