ISO/IEC 42001 AI Management System Readiness
The world's first certifiable standard for governing artificial intelligence. We help you build an AI management system that holds up — designing it with your teams, testing the AI systems it governs the way an adversary would, and bringing you to audit-ready for a clean Stage 1 and Stage 2 certification audit.
Gap assessment to internal audit. CERT-In Empaneled. The accredited body issues the certificate — we make sure you earn it.
The first management standard built for AI
ISO/IEC 42001:2023 is the first international standard for an Artificial Intelligence Management System — an AIMS — and the first that an organization can be independently certified against.
It is not a checklist of model-safety techniques; it is a framework for governing AI as an ongoing organizational discipline. You define the scope of the AI systems you build, provide or use, assess the risks they create, assess their impact on the people and societies they touch, decide which controls treat those risks, operate them, and continually improve — under the oversight of leadership and the scrutiny of internal and external audit. Certification is independent, third-party proof that this system exists and works.
Published in December 2023 by ISO/IEC JTC 1/SC 42, the standard arrived as AI moved from experiment to infrastructure — and as regulators, boards and enterprise buyers started asking a harder question than "does it work?" They now ask "can you show it is governed responsibly?" ISO 42001 is built to answer that. It follows the same harmonized high-level structure as ISO/IEC 27001, so its management-system clauses, terms and core requirements line up — which means it integrates cleanly with an existing ISMS rather than duplicating it. Two requirements set it apart from a classic management standard: it mandates both an AI risk assessment and an AI system impact assessment — the second a deliberate reckoning with the consequences of your AI for individuals, groups and society, not just for the organization.
"Anyone can publish an AI policy. ISO 42001 asks you to prove the system behind it works — so we build the system to be true, and then we test the AI it governs."
Why organizations pursue ISO 42001
ISO 42001 applies to any organization that develops, provides or uses AI — regardless of size or sector. It is voluntary, but the pressure to adopt it is not.
| Criterion | Why it matters |
|---|---|
| You build or sell AI products | Enterprise buyers and procurement teams increasingly ask AI vendors to demonstrate governed, responsible development before they will sign — and a certificate answers the question once. |
| You use AI in decisions that affect people | Where AI informs hiring, lending, claims, pricing or safety, a certified AIMS shows regulators and the public that the impact was assessed, not assumed. |
| Regulation is arriving | The EU AI Act and a wave of national AI rules reward demonstrable governance. ISO 42001 gives you a recognized, auditable system to point to. |
| Your board wants assurance on AI | Independent certification gives leadership and audit committees objective evidence that AI risk is governed, not left to individual teams. |
| You already run ISO 27001 | Because 42001 shares the same high-level structure, you can extend an existing ISMS to AI governance — assess once, reuse the management system, certify both. |
| You want to lead on trust | As the first certifiable AI management standard, ISO 42001 is a credible, early signal that your organization takes responsible AI seriously. |
What the standard actually asks for
ISO/IEC 42001:2023 has two halves. The management-system clauses (4–10) define how the AIMS is run — context, leadership, planning, support, operation, performance evaluation and improvement — including the standard's two signature requirements, an AI risk assessment and an AI system impact assessment.
Annex A then provides the reference catalogue of AI management controls: 38 controls organized under 9 control objectives (A.2 through A.10), with implementation guidance for every one in the normative Annex B. Your Statement of Applicability records, control by control, which you apply and why — the single most scrutinized document in the audit.
A.2 Policies related to AI — Management direction and support: a documented AI policy, alignment with the organization's other policies, and periodic review to keep it fit for purpose.
A.3 Internal organization — Accountability that holds: defined AI roles and responsibilities, and a working process for people to report concerns about an AI system across its life cycle.
A.4 Resources for AI systems — Knowing what your AI is made of: documented data, tooling, compute, system and human resources behind each AI system, so risk can actually be understood.
A.5 Assessing impacts of AI systems — The standard's conscience: a process to assess the consequences of AI for individuals, groups and society, documented and retained.
A.6 AI system life cycle — Responsible by design: objectives and processes for development, plus requirements, design, verification and validation, deployment, operation, monitoring and event logging.
A.7 Data for AI systems — Trust starts with data: documented processes for data acquisition, quality, provenance and preparation across the data and system life cycle.
A.8 Information for interested parties — Telling people what they need to know: system documentation for users, external reporting channels, and incident communication.
A.9 Use of AI systems — Using AI as intended: defined processes and objectives for responsible use, and assurance that systems are used within their documented intended use.
A.10 Third-party & customer relationships — Accountability that doesn't leak: responsibilities allocated across partners, suppliers and customers wherever third parties touch the AI life cycle.
The management system itself — Context · Leadership · Planning · Support · Operation · Performance Evaluation · Improvement — runs on a continual Plan-Do-Check-Act cycle. Planning (Clause 6) is where the AI risk assessment, AI risk treatment and AI system impact assessment live, so governance keeps improving rather than decaying between audits.
From gap to certification-ready — and beyond
Certification is awarded by an accredited certification body after a two-stage audit. Our job is everything that earns it: building an AIMS that is genuinely sound, assessing the risk and impact of the AI it governs, validating that the controls work, and assembling the evidence so the audit confirms what is already true.
We take you from a first gap assessment to a confident Stage 2 — and stay with you through surveillance and recertification.
FIG. 02 — AIMS & certification lifecycle · 01–06 Intect-led · 07–08 accredited certification body · 09 the three-year cycle
The whole cycle is a Plan-Do-Check-Act loop — risk and impact assessment and implementation (Plan/Do), internal audit and management review (Check), remediation and continual improvement (Act). The AIMS is built to get better with every pass — which matters more for AI than for almost anything else, because the systems themselves don't stand still.
What an engagement includes
We scope to where you are — a first-time AIMS, an extension of an existing ISO 27001 ISMS to AI governance, or sustaining an existing certificate — and cover the work end to end.
Gap assessment against ISO/IEC 42001:2023
(management clauses 4–10 + all 38 Annex A controls)
AIMS scope definition
which AI systems, products, services, sites and third parties are in scope
AI risk assessment and risk treatment plan
AI system impact assessment
consequences for individuals, groups and society
Statement of Applicability
inclusion/exclusion decisions with justification, against Annex A
AI policy and procedure suite aligned to the standard
Control-implementation support across the AI life cycle, data, use and third-party relationships
Remediation of identified gaps, with a prioritized roadmap
Integration with an existing ISO 27001 ISMS where one exists, to avoid duplicated effort
Adversarial testing of the governed AI systems
prompt injection, model abuse, jailbreaks, data-poisoning exposure and related attacks — that proves controls actually work
Technical control validation and configuration review of the AI/ML stack and supporting infrastructure
Evidence collection and an audit-ready artifact pack
Remediation retest after fixes
Internal audit, conducted to the standard's requirements
by CISA-certified IS auditors
Management-review pack for leadership oversight
Pre-assessment / mock Stage 1 and Stage 2
Liaison and support through the certification body's Stage 1 and Stage 2 audits
Surveillance-audit support across the three-year cycle
Recertification readiness
Continuous-compliance guidance as your AI systems, risks and controls evolve
We govern AI — then we attack it
A paper audit confirms an AI control is written down. Because Intect is an offensive-security firm, we confirm the AI system it governs actually withstands attack.
Most AIMS work governs AI on paper
The conventional path to ISO 42001 documents policies, samples records and ticks the controls that have evidence behind them. That satisfies the letter of the standard — but a documented control for "responsible use" and a model that an attacker can jailbreak into unsafe behaviour are not the same thing. The risks that never surface in a document review — prompt injection, training-data poisoning, model extraction, unsafe tool use by an autonomous agent — are exactly the risks ISO 42001 exists to manage.
We test the AI the management system governs
Intect is CERT-In Empaneled with an offensive-security heritage, so our readiness work is technically validated against the actual AI systems in scope. Our researchers probe them safely, the way an adversary would — prompt injection and jailbreaks, model abuse and extraction, data-poisoning exposure, and the new attack surface of autonomous agents — and bring you pentest-backed evidence that your Annex A controls hold. This is the same capability behind our AI/ML Penetration Testing and AI-Assisted & Autonomous Penetration Testing services. You walk into Stage 2 with an AIMS whose controls have already withstood a real probe, and you leave governing AI that means it.
The certificate proves you govern AI. Our testing proves the AI you govern can take a hit.
AI ADVERSARIAL TESTING — PENTEST-BACKED EVIDENCEWhat you receive
Every engagement produces the artefacts your team needs to operate the AIMS — and the evidence pack an accredited certification body expects to review.
Gap assessment report
Your current AI governance mapped against ISO/IEC 42001:2023, with a prioritized roadmap to certification-ready.
AI risk assessment & treatment plan
A defensible methodology, AI risk register and treatment decisions the auditor can follow.
AI system impact assessment
A documented assessment of your AI's consequences for individuals, groups and society, retained per the standard.
Statement of Applicability
Each of the 38 Annex A controls, included or excluded, with documented justification.
AI policy & procedure suite
The AIMS documentation set, written to the standard and tailored to how you actually develop and use AI.
Internal audit report
Independent verification, by CISA-certified IS auditors, that controls are operating, not just documented.
Management review pack
The oversight evidence leadership needs for Clause 9.
Pre-assessment / mock audit report
A dry run of Stage 1 and Stage 2, with findings to close before the real thing.
AI adversarial testing & technical control validation report
Pentest-backed evidence that key controls and the governed AI systems genuinely withstand attack, with remediation guidance and retest.
Audit-ready evidence pack
Collected, organized artefacts that map cleanly to the controls and clauses.
Why teams choose Intect for ISO 42001
CERT-In Empaneled — An assessor accredited under India's national cybersecurity authority, with CISA-certified IS auditors in-house — credibility the audit room recognizes.
We govern and we break — Most consultancies only write AI policy. We implement the AIMS and then attack the AI it governs, so your evidence is proven, not asserted.
Genuine AI-security depth — We run dedicated AI/ML and autonomous-agent penetration testing. The threats ISO 42001 asks you to manage are threats we test for a living.
One partner, the full cycle — From first gap assessment through Stage 2 support, surveillance and recertification — and integration with your existing ISMS — continuity instead of handoffs.
Frequently asked questions
Does Intect issue the ISO 42001 certificate?
No — and no consultancy can. The certificate is issued by an independent, accredited certification body after it conducts the Stage 1 and Stage 2 audits. Intect makes you certification-ready: we build and validate the AIMS, run the AI risk and impact assessments, conduct the internal audit and mock audit, and support you through the certification body's audits. Keeping readiness and certification separate is exactly what preserves the audit's independence — and its value.
How is ISO 42001 different from the EU AI Act?
The EU AI Act is law; ISO 42001 is a voluntary, certifiable management standard. They are complementary — a certified AIMS is a recognized, auditable way to demonstrate the responsible-governance practices regulations increasingly expect. ISO 42001 won't make you automatically compliant with any specific regulation, but it gives you the management system most of them assume you already have. We scope your AIMS with your regulatory obligations in view.
We already have ISO 27001 — do we start from scratch?
No. ISO 42001 uses the same harmonized high-level structure as ISO 27001, so your context, leadership, planning, support and improvement machinery largely carries over. We extend your existing ISMS to AI governance — reusing what works and adding only what is genuinely AI-specific, like the AI impact assessment and the Annex A controls.
What is an AI system impact assessment, and how is it different from a risk assessment?
ISO 42001 requires both. The AI risk assessment looks at risk to the organization and its objectives. The AI system impact assessment looks outward — at the consequences of your AI for the individuals, groups and societies it affects. Both are mandatory clause requirements, and both are documents the auditor will examine. We help you produce each properly.
How many controls are in ISO 42001?
Annex A lists 38 controls organized under 9 control objectives (A.2 to A.10), covering AI policy, internal organization, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI, and third-party relationships. Implementing every control is not mandatory — but your Statement of Applicability must justify each inclusion and exclusion. Annex B gives implementation guidance for all of them.
How long does certification take?
It depends on the size and complexity of your AI estate and how mature your current governance is — which is exactly what the gap assessment establishes first. We give you a realistic, evidence-based timeline up front rather than a generic promise, and we sequence the work so nothing blocks the certification audit.
What happens after we're certified?
Certification runs on a three-year cycle. The accredited body conducts annual surveillance audits to confirm the AIMS is still operating, and a full recertification audit at the end of the cycle. This matters especially for AI, because the systems keep learning and changing — we support you across the whole cycle so the certificate stays live and the governance keeps pace.
Govern it once, prove it everywhere
A well-built AIMS is stronger when the AI it governs has actually been tested — and when it sits on a mature security and privacy foundation.
Build an AI management system that's ready to be certified.
Tell us where you are — first AIMS, an extension of an existing ISO 27001 ISMS, or maintaining an existing certificate — and we'll scope a readiness assessment that fits, or connect you with an assessor.