PRIVINOTCH / Focus areas / ISO/IEC 42001 readiness
Become ready for ISO/IEC 42001 without the paperwork theatre
ISO/IEC 42001:2023 is the first international standard for an AI management system. We help you build one that works in practice, produce the evidence an auditor will look for and prepare you for independent certification.
Independent of certification bodies. We prepare you; we do not certify you.
A recognisable signal of governed AI
Buyers, boards and regulators increasingly want evidence that AI is managed, not just used.
An international management system standard for organisations that develop, provide or use AI.
Independent accredited bodies audit against it, giving buyers an assurance they can rely on.
Built on the familiar management system structure, so it sits alongside ISO/IEC 27001 and ISO 9001.
From scoping to audit-ready
We work with your people and existing systems and build only what you need.
Scope and context
Define which AI systems, teams and locations are in scope, and what interested parties expect of you.
Gap analysis
Assess your current practice against the standard’s requirements and produce a prioritised remediation plan.
AI policy, roles and accountability
Draft the AI policy, assign ownership and set up the governance forums and reporting lines.
Risk and impact assessment
Design a proportionate AI risk and impact assessment process, and run it on your priority systems.
Controls and evidence
Map controls to your AI lifecycle and third-party use, and set up the records that prove they operate.
Internal audit and management review
Prepare for the internal audit and management review cycles that certification bodies expect.
A clear path in four stages
Scope
Agree the boundaries of the AI management system and what success looks like.
Assess
Gap analysis against the standard and your obligations, with a plan.
Build
Policies, processes, risk methods and evidence, tested on real systems.
Prepare
Internal audit, management review and support through certification.
What we will and will not do
What you get
- A working AI management system, not a binder of templates
- Evidence mapped to the standard and to your wider obligations
- Support through certification readiness, with your chosen body
- Integration with ISO/IEC 27001 or other systems you already run
What we do not do
- Certify you, or promise a certification outcome
- Reproduce the licensed text of the standard
- Provide legal advice on regulatory compliance
- Tie you to a particular tool or vendor
Where this fits
Frequently asked
Do you certify us against ISO/IEC 42001?
How long does it take to become ready?
Do we need ISO/IEC 42001 to comply with the EU AI Act?
We already hold ISO/IEC 27001. What do we reuse?
Do we need our own copy of the standard?
Is it only for organisations that build AI?
Tell us where you are with ISO/IEC 42001
A short note is enough. We will come back to you to arrange a scoping conversation.
- Scoping conversation, no obligation
- Practical view on effort and sequencing
- Honest advice if it is not the right move yet
Prefer to talk it through? Book an intro call or email info@privinotch.co.uk.