09 · AIMS · Governance · Lifecycle
ISO/IEC 42001 Readiness
The AI-management system regulators want to see.
End-to-end ISO/IEC 42001:2023 readiness — the first international standard for AI Management Systems (AIMS). Governance, risk, impact assessment, and lifecycle controls for AI, built to position you as trustworthy under EU AI Act and NIST AI RMF pressure. Mirrors ISO 27001's structure, so if you're running both, we integrate them.
Outcomes
- +AIMS scope statement + AI-system inventory
- +AI Impact Assessments (AIA) per ISO 42005 methodology
- +Full control set (Annex A + B) implementation guidance
- +Internal Audit + Management Review pack, certification-body-ready
01Scope
What we cover
In scope
- +Full 2023 Annex A control set + Annex B implementation guidance
- +Clauses 4–10: Context through Improvement (mirrors ISO 27001 structure)
- +AI-system inventory + role classification (provider / user / relevant party)
- +AI Impact Assessments (AIA) — the operational heart of ISO 42001
- +Data governance for AI — training, evaluation, deployment datasets
- +Third-party AI risk (foundation-model vendors, MLOps platforms)
Out of scope
- −EU AI Act certification directly (we support alignment; conformity assessment is a separate regime)
02Approach
How the engagement runs
AIMS scoping
Which AI systems? Which roles do you play — provider, user, distributor, importer? Which jurisdictions?
System inventory
Every model in production, staging, and shadow. Row per system: lifecycle stage, risk classification, owner.
Impact assessments
An AIA per system — intended use, unintended use, impacted parties, mitigation. ISO 42005 methodology.
Control implementation
Annex A controls implemented with your ML/AI teams. Governance that ships, not governance that prints.
Internal audit + review
Clause 9.2 internal audit executed, Management Review packet delivered.
03Deliverables
What you receive
Every artifact is defensible under external audit and actionable for engineering.
- 01AIMS Scope Statement + AI-System Inventory
- 02AI Impact Assessments (one per in-scope system)
- 03Statement of Applicability (Annex A)
- 04Data & Model Governance policies + records
- 05Internal Audit Report + Management Review packet
04Frameworks
Regulator-defensible mapping
05Timeline
Typical engagement pace
Gap analysis + scoping
3–4 weeks
AIMS design + AIA programme
6–8 weeks
Control implementation support
3–5 months
Internal audit + review
3 weeks
06FAQ
Common questions
Different question? Raise it on a scoping call — we'd rather flag surprises early.
Do we need ISO 27001 first?+
Not required, but strongly recommended. ISO 42001 mirrors 27001's structure — running them as one integrated management system is the efficient path.
How does this relate to the EU AI Act?+
ISO 42001 isn't the AI Act, but it's the recognized baseline regulators cite. A certified AIMS materially reduces your AI Act conformity-assessment burden for high-risk systems.
Can you run this alongside an AI Pen Test engagement?+
Yes. AI Penetration Testing produces evidence that plugs directly into ISO 42001 impact-assessment and data/resource controls.
Ship AI with governance regulators trust.
Scoping call, program plan within 2 weeks, first internal audit inside 6 months for focused scopes.
Book a scoping call