
Build
ISO/IEC 42001 implementation
A working AI management system — inventory, risk and impact assessment, oversight, lifecycle controls and the evidence behind them — built to pass an accredited certification audit and to survive the year after it.
Duration
6–9 months to certification readiness
Built on
ISO/IEC 42001 · ISO/IEC 23894 · ISO/IEC 27001:2022 · EU AI Act
Indicative price
€25,000–65,000 per engagement
Who this is for
CISO or head of governance
Runs an ISMS and has been asked to extend it to AI.
Chief compliance officer
Needs the certificate because clients have started asking for it.
CEO
Is answering AI governance questions in tenders and wants a better answer than a slide.
Quality manager
Runs other management systems and wants this one integrated rather than parallel.
A management system is a habit, not a binder
Certification is awarded to a system that runs, not to a set of documents. Auditors sample. They take a decision your organisation made about an AI system and ask to see the record. They take a control and ask for evidence that it operated. A complete documentation set with no operating history fails, and it fails late — after the fee is paid and the date is in the diary.
The parts that take longest are the ones that have to accumulate evidence over time: risk and impact assessments actually performed, oversight actually exercised, an internal audit, a management review. That is why six to nine months is realistic, and why an implementation sold in eight weeks is selling a binder.
If you hold ISO/IEC 27001, much of the machinery is already yours — scope, leadership, competence, documented information, internal audit, management review. The work is to extend rather than duplicate. An organisation that ends up operating two parallel management systems has been served badly by somebody.
The genuinely new material is where the value sits, and one part deserves naming. Impact assessment considers effects on the people a system acts upon, not only risk to the organisation. That reversal of perspective does not exist in an ISMS, and it is the requirement most often delivered as a relabelled risk register. An auditor will see that immediately.
Human oversight is the other one. "A human reviews the output" appears in a great many designs and survives contact with almost no auditor. If the reviewer has three seconds, no context and no realistic route to disagree, the oversight is decorative. We design oversight that is operable, because operable is what gets tested.
How we do it
- 01
Scope and integration
2–3 weeks
What the AI management system covers, and how it relates to management systems you already run. Getting this right avoids duplicating an entire documentation set, and getting it wrong is expensive to unwind later.
- 02
AI inventory and classification
3–4 weeks
Everything you build, buy, embed and use, classified and owned. Where an EU AI Act engagement has run, this is the same inventory maintained rather than a second one.
- 03
Risk and impact assessment
4–6 weeks
Risk to the organisation, and impact on the people a system acts upon — two distinct assessments, documented separately, with the method written down so your own people can repeat it.
- 04
Controls and documentation
8–10 weeks
Annex A controls designed into how work actually happens: data and model lifecycle, oversight, transparency, supplier management. Written to be followed rather than to be filed.
- 05
Operate and accumulate evidence
8–12 weeks
The system runs. Decisions get recorded, assessments get performed, oversight leaves a trace. This phase cannot be compressed, and it is the one that decides the audit.
- 06
Internal audit, management review and certification support
4–6 weeks
Your clause 9.2 internal audit, the management review, corrective actions closed, and support through the accredited body's stage 1 and stage 2.
Named artefacts
What you receive
- AI management system scope and integration design
- AI policy and objectives, approved by leadership
- Maintained AI system inventory with owners
- Risk assessment method and populated register
- Impact assessment method and completed assessments, covering effects on affected people
- Annex A control set with a Statement of Applicability
- Data and model lifecycle procedures
- Human oversight design per system, assessed for operability
- Internal audit programme, records and management review minutes
- Certification readiness pack and support through stage 1 and stage 2
What we need from you
- A management representative with real hours. This is the single strongest predictor of whether the date holds.
- Leadership participation in the management review. An auditor asks about it and will know if it was a circulated document.
- Access to whoever knows what AI is actually in use, including outside IT.
- Product or engineering time where you build systems rather than only use them.
- Acceptance that evidence takes calendar time and cannot be manufactured at the end.
What changes
- 01A management system that operates, with evidence that accumulated rather than appeared.
- 02One inventory and one risk method serving certification and your EU AI Act position.
- 03Reuse of your ISO 27001 work made explicit instead of assumed.
- 04Impact on affected people assessed as the standard actually requires.
- 05Oversight that an auditor tests and finds real.
What it costs
€25,000–65,000 per engagement
All prices exclude VAT.
Questions
Can you certify us?
No, and nobody who implements can. Certification comes from an accredited certification body that must be independent of whoever built the system. We build it, we run your internal audit or bring in an independent auditor where we cannot, and we support you through stage 1 and stage 2.
We hold ISO 27001. How much carries over?
The management system machinery largely does. The AI-specific requirements do not: inventory, impact assessment on affected people, data and model lifecycle, human oversight. Clients with a mature ISMS find the effort materially lower, and the gap analysis quantifies it rather than promising it.
Does certification make us EU AI Act compliant?
No. The Act does not mention the standard and certification is not compliance. But a management system builds most of the structure the Act expects — inventory, risk process, oversight roles, evidence — so running one body of work mapped to both is cheaper than running two.
Can we go faster than six months?
Not honestly to a first certification. The constraint is evidence: an auditor samples records of things that happened, and records of things that have not happened yet do not exist. Where a deadline is fixed we tell you what is achievable by it, which is sometimes conformity without the certificate.
What does it cost?
€25,000–65,000 per engagement. The range reflects the number of AI systems in scope and how much of an existing management system can be reused. Certification body fees are separate and we give you an indication of those.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.