Home / Trust Certifications / ISO 42001 (AI Governance)

Trust Certifications

ISO 42001 (AI Governance)

Govern how your organisation builds and uses AI, with a management system that customers and regulators can trust.

Product and compliance teams reviewing an AI system map
Image placeholder: Product and compliance teams reviewing an AI system map

Overview

What it is and who needs it

ISO/IEC 42001:2023 is the first international management system standard for artificial intelligence. It sets requirements for an AI management system (AIMS): how an organisation decides which AI systems to build or use, assesses their risks and impacts, and keeps them under control throughout their life.

It applies whether you develop AI products, build AI features into your software or use AI tools in your operations. If you already hold ISO 27001, much of the management system will be familiar and can be shared.

Who needs it

  • Companies building AI products or adding AI features to software
  • Organisations using third-party AI in decisions that affect customers or staff
  • SaaS vendors asked by enterprise buyers how their AI is governed
  • ISO 27001-certified organisations extending their management system to AI
Whiteboard showing an AI system life cycle
Image placeholder: Whiteboard showing an AI system life cycle

Scope

What is covered

AI system inventory

A register of the AI systems you build, buy and use, with purpose, owner and data sources.

AI risk and impact assessment

Assessment of risks to the organisation and of impacts on individuals and society.

AI policy and roles

An AI policy, objectives and clear accountability from leadership to product teams.

Responsible development and use

Controls for data quality, testing, transparency, human oversight and monitoring.

Supplier oversight

Due diligence and contract terms for AI models, platforms and data providers.

Fit with ISO 27001

One integrated management system, with shared audits, reviews and documentation.

Working with ISO 27001

How it fits alongside your ISO 27001 system

Both standards share the same management system structure, so an existing ISMS can be extended.

Shared with ISO 27001

  • Context, scope and leadership commitment
  • Risk-based planning and objectives
  • Competence, awareness and document control
  • Internal audit and management review
  • Corrective action and continual improvement

+

Added by ISO 42001

  • AI policy and AI-specific roles
  • AI system inventory and life-cycle controls
  • AI risk assessment and AI system impact assessment
  • Data quality and provenance for AI
  • Transparency and information for users
  • Oversight of AI suppliers and customers

Our approach

How we work, step by step

01

Discover

We identify every AI system in use or development and your role for each: provider, developer or user.

02

Gap assessment

Current governance is compared with the standard and with your ISO 27001 system if you have one.

03

Risk and impact assessment

We set the method and run the first assessments with system owners.

04

Design

AI policy, roles, objectives and the applicable controls are defined.

05

Implement and train

Controls are built into product and procurement processes, and teams are trained.

06

Audit and certify

Internal audit, management review and support during the certification audit.

Deliverables

What you receive

  • AI system inventory
  • AI risk assessment and AI system impact assessment reports
  • AI policy, objectives and role definitions
  • Statement of Applicability for the AI controls
  • Internal audit report and management review record
  • Support during the certification audit
AI system inventory and impact assessment documents
Image placeholder: AI system inventory and impact assessment documents

Why iSecurify

Three reasons customers choose us

01

Security and AI governance together

One team covers ISO 27001, ISO 42001 and privacy, so the systems are designed to work as one.

02

Practical for product teams

Controls are built into development and release, not added as paperwork.

03

Proportionate to your AI use

A company using a few AI tools needs a lighter system than one training its own models.

Questions

Frequently asked questions

Who is ISO 42001 for?

Any organisation that provides, develops or uses AI systems, regardless of size or sector.

Do we need ISO 27001 first?

No. ISO 42001 stands on its own. If you already run an ISO 27001 system, the two share the same structure, so you can extend what you have.

Does certification make us compliant with AI regulation?

No standard guarantees legal compliance. ISO 42001 gives you a documented, auditable way of managing AI risk, which supports the evidence that AI regulations expect.

We only use third-party AI tools. Does it apply?

Yes. The standard covers organisations that use AI as well as those that build it. The controls that apply to you will be fewer.

How long does implementation take?

Organisations with an ISO 27001 system in place typically need three to six months. Starting without one takes longer. [Typical duration to be confirmed]

Customer stories

What our customers say

  • Outsourcing our cybersecurity operations to iSecurify has been a strategic advantage. From real-time threat monitoring to compliance assistance, their managed services have brought us peace of mind and enabled our internal team to focus on business growth.

    Swapon Adhikary

    Director · The Hird

  • Following the launch of our website in both Dubai and India, we required immediate security validation to ensure platform integrity. iSecurify delivered a rapid yet comprehensive application security assessment, providing detailed and actionable findings. Their expert team collaborated directly with our developers to swiftly remediate vulnerabilities, enabling us to go live with confidence and security.

    Krutarth Pandya

  • We deployed iSecurify’s iSIEM-based monitoring with automated IP blocking, and the results were immediate. Malicious IPs targeting our systems were detected and blocked in real time. The integration was seamless, and the improvement in our threat response has been significant.

    Nandeep Mehta

Organisations we work with

Talk to us about ISO 42001 (AI Governance).

Share a few details and a consultant will come back with a scope and next steps.

info@isecurify.co