The AIMS document set
Scope, AI policy, roles and authorities, and a risk method, register and treatment plan. Plus the Statement of Applicability (SoA): whether each of the 38 controls in the standard's Annex A applies and, if not, why.
ISO/IEC 42001 certification consultant
ISO/IEC 42001 is the standard for an AI management system (AIMS): the policies, roles and records behind your AI. We list your AI, build the AIMS around it and write the impact assessments auditors sample.
What you get
We write them; you sign the AI policy, the scope and the Statement of Applicability. Only an accredited certification body issues the certificate.
Scope, AI policy, roles and authorities, and a risk method, register and treatment plan. Plus the Statement of Applicability (SoA): whether each of the 38 controls in the standard's Annex A applies and, if not, why.
One for each system that makes, or materially shapes, a decision about a person, structured to ISO/IEC 42005:2025 (published 28 May 2025). Each covers affected individuals, groups and society, with evidence for each conclusion and a review date.
How your data is acquired, quality-checked, traced to its source (provenance) and prepared, with dataset documentation. If you hold Indian personal data, the provenance work overlaps almost entirely with the main duties of the Digital Personal Data Protection (DPDP) Act, due in its last commencement tranche.
What 42001 adds
If you know ISO 27001, most of ISO/IEC 42001's risk clauses will look familiar. One will not: the AI system impact assessment (clause 6.1.4) has no ISO 27001 equivalent.
It is a separate, documented analysis of what each AI system could do to individuals, groups of individuals and societies.
Clauses 6.1.1 (general), 6.1.2 (AI risk assessment) and 6.1.3 (risk treatment) are the familiar ones. Four A.5 controls back 6.1.4: the assessment process, its documentation, impact on individuals or groups, and societal impact.
Already hold ISO 27001?
Clauses 4, 5, 7, 9 and 10 share the harmonized structure of ISO 27001 and ISO 9001. If you run an information security management system (ISMS), they transfer almost intact and can halve your calendar.
| 42001 clause | ISMS already covers | Built new |
|---|---|---|
| 4 Context, 4.3 Scope | Context method, interested parties, scope writing | A scope that names AI systems, with a written reason for every exclusion |
| 5 Leadership, 5.2 AI policy | Governance forum, approval route, leadership commitment | A distinct AI policy (A.2.2), a dated review record (A.2.4) and a mapping to your security and privacy policies (A.2.3) |
| 6.1.2 AI risk assessment | Risk method, register, treatment plan | AI risk sources: training data, model behavior, autonomy, drift, third-party model changes |
| 6.1.4 AI system impact assessment | Nothing | A per-system assessment of consequences for people and society, restated at 8.4 and evidenced under A.5.2 to A.5.5 |
| 7 Support, 9 Performance, 10 Improvement | Competence, internal audit, management review, corrective action | AI competence criteria, and audits that reach the SoA and clause 6.1.4 |
| Annex A, Statement of Applicability | The SoA mechanism itself | 38 controls in nine groups, A.2 to A.10, selected from risk treatment, then checked against Annex A for omissions |
Annexes A and B are both normative, not optional reading. Annex B, pages 21 to 45 of roughly 51, is the largest block and carries the implementation expectation an auditor tests control by control. Annexes C and D are informative.
Under ISO/IEC 42006:2025, published 7 July 2025, the certification body must also meet auditor competence and audit-day requirements, on top of ISO/IEC 17021-1.
How we work
Most organizations can't list the AI they run, yet auditors ask for that list first. We start there, as in all our AI governance work. For a mid-sized company, expect six to twelve months to certificate, the first four to eight weeks on the list and scope.
Asking teams misses most of it, so we check the records that already know: which apps staff sign in to with company accounts (SSO and OAuth grants), expense lines, traffic to AI model services (APIs), browser extensions, and the admin console of every cloud tool you pay for. Many of those tools switched on an AI feature without asking.
Are you its provider, developer, deployer or a partner? That decides which controls apply: a team that only consumes a vendor API can justify excluding most of A.6.2 (development and validation), but never A.5 (impact assessment) or A.10 (third parties). A narrow scope is fine; one picked because nobody looked is a nonconformity (an audit finding) at Stage 2, the certification body's main audit.
Any system that makes, or materially shapes, a decision about a person needs a full 6.1.4 assessment. That count sets the project length.
Events such as a new model version, training data, use case or vendor, or a wider user population.
Once the AIMS has produced records, including at least one internal audit and one management review (both needed before Stage 2), we dry-run the audit against the clauses and your SoA. This Stage 1 readiness report is our own check, not a requirement, so the certification body's paid days aren't spent on the same gaps.
Limits, stated plainly
See also EU AI Act compliance and NIST AI RMF gap assessments.
Who is accountable. Top management owns the AIMS under clause 5.1 and approves the AI policy. We can draft every word but can't be your accountable owner, and the auditor will ask who is. Internal audit reports and management review minutes too: we prepare, your people decide.
What SecWiz is not. We are a consultancy, not a certification or accreditation body, and ISO itself certifies nobody. If the firm that built your AIMS also audited it, the audit would be invalid. SecWiz is not itself ISO 27001 certified and doesn't claim to be.
Only staff using a public chatbot? Then skip this. An acceptable-use policy and a vendor review is the proportionate answer, not a nine-month project.
No. It adds to them, and assumes your information security baseline lives elsewhere. 42001 governs how AI systems are chosen, built, deployed, monitored and retired, and what they do to the people they affect. It says almost nothing about patching, access control or cryptography. If you already hold 27001, clauses 4, 5, 7, 9 and 10 carry over and your calendar shortens. If you hold nothing, you build the management system and the AI governance together.
Six to twelve months from kick-off to certificate for a mid-sized company. We quote nine when we know nothing else about you. Roughly four to eight weeks on inventory and scope, then eight to sixteen weeks writing and starting to operate the AIMS, then a stretch where it simply runs and produces records. You need at least one internal audit and one management review before Stage 2, because you cannot certify a management system that has never operated.
Yes. The standard covers organizations that only deploy AI, not just those that build it. Your Statement of Applicability looks different: most of A.6.2, the development, verification and validation controls, can be excluded with written justification. A.5 impact assessment and A.10 third-party and customer relationships cannot. In practice the harder part is the inventory: nobody has written down the vendor APIs and the AI features switched on inside existing SaaS.
No, and no consultancy can. We implement, you operate, and an independent certification body accredited for ISO/IEC 42001 audits and issues. Ask any prospective body to show 42001 explicitly on its accreditation scope, since 27001 accreditation does not extend to it, and verify on the accreditation body's public register or IAF CertSearch. Book that body early, alongside implementation, not after it. Accredited auditor supply is the external bottleneck on this standard and Stage 2 slots have run months out.
No. 42001 is a voluntary international management system standard. The AI Act is binding law with its own conformity assessment route. CEN-CENELEC adopted the identical text as EN ISO/IEC 42001:2026 on 18 March 2026, but presumption of conformity under Article 40 requires a reference published in the Official Journal, and there isn't one. EN 18286:2026, the quality management system standard written for Article 17 (approved 12 July 2026, available from 22 July 2026), isn't cited there either. A provider of a high-risk system keeps the full evidentiary burden. What the certificate does buy you is a credible governance record to build the Article 17 work on.
No. A certificate from a body accredited by any IAF MLA signatory is recognized internationally, which is what your buyer's third-party risk team is checking. What it does affect is cost, auditor scheduling and lead time, so confirm current scheme status with the accreditation body before you commit. SecWiz is India-based and delivers remotely, so working across time zones with your chosen body is normal for us.
Who the system decides about or affects, what could go wrong for them, how likely and how severe, what evidence supports each conclusion, what you changed as a result, and when you will look again. Groups matter as much as individuals, and societal effects are a named control, A.5.5. We structure ours to ISO/IEC 42005:2025. The test an auditor applies is simple: does this document analyze consequences for people, or has it slipped back into risk to the business?
Three things. A Statement of Applicability with all 38 controls marked applicable, which turns every control you cannot evidence into a finding. Policies that restate the clause text with no operating records behind them, when auditors sample event logs under A.6.2.8, incident records under A.8.4 and closed corrective actions with effectiveness verification. And a merged risk and impact assessment. The fourth, arriving a year later at surveillance, is a risk register nobody refreshed because no re-assessment triggers were ever defined.
Let's talk
Tell us roughly what AI you run and who it makes decisions about. You get a scope, a realistic month count and the number of impact assessments, which sets your budget. We reply within one working day.