PRIVINOTCH  /  Focus areas  /  ISO/IEC 42001 readiness

Become ready for ISO/IEC 42001 without the paperwork theatre

ISO/IEC 42001:2023 is the first international standard for an AI management system. We help you build one that works in practice, produce the evidence an auditor will look for and prepare you for independent certification.

Independent of certification bodies. We prepare you; we do not certify you.

Why it matters

A recognisable signal of governed AI

Buyers, boards and regulators increasingly want evidence that AI is managed, not just used.

Recognised

An international management system standard for organisations that develop, provide or use AI.

Certifiable

Independent accredited bodies audit against it, giving buyers an assurance they can rely on.

Reusable

Built on the familiar management system structure, so it sits alongside ISO/IEC 27001 and ISO 9001.

What we do

From scoping to audit-ready

We work with your people and existing systems and build only what you need.

01

Scope and context

Define which AI systems, teams and locations are in scope, and what interested parties expect of you.

02

Gap analysis

Assess your current practice against the standard’s requirements and produce a prioritised remediation plan.

03

AI policy, roles and accountability

Draft the AI policy, assign ownership and set up the governance forums and reporting lines.

04

Risk and impact assessment

Design a proportionate AI risk and impact assessment process, and run it on your priority systems.

05

Controls and evidence

Map controls to your AI lifecycle and third-party use, and set up the records that prove they operate.

06

Internal audit and management review

Prepare for the internal audit and management review cycles that certification bodies expect.

How it works

A clear path in four stages

Stage 1

Scope

Agree the boundaries of the AI management system and what success looks like.

Stage 2

Assess

Gap analysis against the standard and your obligations, with a plan.

Stage 3

Build

Policies, processes, risk methods and evidence, tested on real systems.

Stage 4

Prepare

Internal audit, management review and support through certification.

Good to know

What we will and will not do

What you get

  • A working AI management system, not a binder of templates
  • Evidence mapped to the standard and to your wider obligations
  • Support through certification readiness, with your chosen body
  • Integration with ISO/IEC 27001 or other systems you already run

What we do not do

  • Certify you, or promise a certification outcome
  • Reproduce the licensed text of the standard
  • Provide legal advice on regulatory compliance
  • Tie you to a particular tool or vendor
ISO/IEC 42001 certification does not by itself demonstrate compliance with the EU AI Act. We map the two so your effort supports both. You will need your own licensed copy of the standard.
Questions

Frequently asked

Do you certify us against ISO/IEC 42001?
No. Certification is carried out by independent, accredited certification bodies. We prepare you for it: we build the management system, evidence it and get you audit-ready, and we remain independent of whichever certification body you choose.
How long does it take to become ready?
It depends on scope, existing management systems and how many AI systems are in scope. Organisations that already run ISO/IEC 27001 or ISO 9001 can usually reuse a good deal of structure. We confirm a realistic timetable after a short scoping conversation rather than quoting a generic one.
Do we need ISO/IEC 42001 to comply with the EU AI Act?
No. ISO/IEC 42001 is a voluntary management system standard. It is a strong foundation for governance and evidence, but certification does not by itself demonstrate compliance with the EU AI Act, which sets its own legal requirements. We map the two so that your work supports both.
We already hold ISO/IEC 27001. What do we reuse?
The management system structure is shared, so governance, document control, internal audit, management review and corrective action processes can often be extended rather than rebuilt. What is new is the AI-specific layer: AI policy, impact and risk assessment, lifecycle controls and third-party AI oversight.
Do we need our own copy of the standard?
Yes. The standard is published by ISO and is licensed, so we work from your licensed copy and do not reproduce it. We interpret it for your context and explain what it means in practice.
Is it only for organisations that build AI?
No. It applies to organisations that develop, provide or use AI-based products or services. Many of the organisations we work with are primarily users of third-party AI, where supplier oversight and responsible use are the main challenge.
Talk to us

Tell us where you are with ISO/IEC 42001

A short note is enough. We will come back to you to arrange a scoping conversation.

  • Scoping conversation, no obligation
  • Practical view on effort and sequencing
  • Honest advice if it is not the right move yet

Prefer to talk it through? Book an intro call or email info@privinotch.co.uk.

We use your details to reply to you. See our Privacy Notice.