ISO 42001 Audit and Support

ISO/IEC 42001:2023 is the first international standard for establishing and managing an Artificial Intelligence Management System (AIMS)

Your board has probably already asked the question. Where exactly are we using AI, and who signed off on it? Most organisations struggle to answer. AI arrives sideways — a vendor adds a feature, a team trials a tool, a model gets embedded in a product nobody flagged as “AI” at procurement. By the time someone asks for an inventory, the answer is a shrug and three spreadsheets that disagree.

ISO 42001 audit

ISO/IEC 42001:2023 exists to fix that. Published in December 2023, it is the first international management system standard written specifically for artificial intelligence, and it gives you a defensible way to say who owns AI risk in your organisation and how you know the controls are working.

Vassallo Associates provides independent ISO 42001 auditing, gap analysis and certification-readiness assessments. We audit. We do not build your management system and then mark our own homework — and we will explain below why that distinction matters more than it sounds.

What ISO 42001 Actually Requires

ISO 42001 is a management system standard, not a technical specification. It says almost nothing about model architecture and a great deal about governance.

Structurally, it follows the Harmonised Structure shared by ISO 9001, ISO 14001 and ISO 27001 — clauses 4 to 10, covering context, leadership, planning, support, operation, performance evaluation and improvement. If you already run a certified management system, the skeleton will look familiar on day one.

What is new sits in the annexes:

• Annex A sets out the control objectives and controls for an AI Management System, spanning AI policy, internal organisation, resources, impact assessment, lifecycle management, data for AI systems, information for interested parties, responsible use, and third-party relationships
• Annex B provides implementation guidance for each control
• Annex C lists potential AI-related organisational objectives and risk sources
• Annex D covers applying the standard across sectors and domains

The standard applies whether you develop AI, resell it, or simply use somebody else’s. That last category catches far more organisations than expect it.

iso 9001 quality management
artificial intelligence implementation

Where Implementations Usually Go Wrong

Three failures come up repeatedly.

The inventory is incomplete. You cannot govern what you have not listed. Shadow AI — tools adopted by individual teams without procurement or IT involvement — is the single most common finding in a first gap assessment. Marketing has a copywriting tool. Finance has a forecasting plug-in. Neither appears on any register.

Impact assessment is treated as risk assessment with a new label. It is not. Clause 6 risk assessment asks what could go wrong for you. AI impact assessment asks what could go wrong for the people your system affects — candidates screened out, customers declined, patients triaged. Auditors notice when an organisation has simply copied its ISO 27001 risk register and changed the title.

Nobody owns it. An AI policy signed by the CEO and implemented by nobody is a non-conformity waiting to be written up. Clause 5 wants named accountability and evidence that the named person is actually doing something.

We would rather you heard this now than from a certification auditor.

Our ISO 42001 Artificial Intelligence Audit and Support services help organisations put robust AI governance in place, identify potential risks and prepare for ISO 42001 certification.

“Some people call this artificial intelligence, but the reality is that this technology will enhance us. So instead of artificial intelligence, I think we’ll augment our intelligence” – Ginni Rometty

Our ISO 42001 Audit Services

 

ISO 42001 Gap Analysis

The starting point for most clients, and usually the most useful single engagement.
We review your existing policies, processes, registers and controls against the full requirements of ISO/IEC 42001 — clauses 4 to 10 plus the Annex A controls relevant to your scope. You receive a written report showing what already conforms, what partially conforms, and what is missing, mapped clause by clause.

Where you already hold ISO 27001 or ISO 9001, we identify what carries across. In most cases a meaningful proportion of clause 4 to 10 evidence is reusable, which shortens the route considerably. That reuse is the main reason certified organisations reach ISO 42001 faster than those starting cold.
The report doubles as your implementation plan. Prioritised, with the high-effort items flagged so you can resource them properly.

 

ISO 42001 Internal Audits

Clause 9.2 requires internal audits. Certification bodies check that you have run them, that the auditors were competent and impartial, and that findings led somewhere.
We conduct structured internal audits against your documented AI Management System and report:
• Non-conformities, graded major and minor
• Observations and opportunities for improvement
• Gaps between documented process and actual practice
• Areas where evidence exists but is not retrievable — a surprisingly frequent problem
• Controls applied inconsistently across business units
Internal audits can run as a standalone programme or fold into your existing ISO audit schedule alongside ISO 9001, ISO 27001 and others.

 

ISO 42001 Pre-Certification Assessment

A rehearsal for the real thing, run to the same standard as a Stage 1 and Stage 2 audit.
We assess whether your documented information, risk and impact assessment processes, Statement of Applicability, operational controls and management review records will withstand scrutiny. We interview the people your certification auditor will interview. We ask for the evidence they will ask for.
Organisations going through certification for the first time frequently underestimate how much of the audit is conducted by asking staff questions rather than reading documents. If the answers do not match the policy, that gets written up. Better to discover it with us.

 

Ongoing Audit Support

Certification is a three-year cycle with surveillance audits, not a certificate you frame and forget.
We provide scheduled internal audits, corrective action verification, and pre-surveillance reviews across the certification cycle. For clients running several standards, we combine these into one integrated audit programme — one auditor, one visit, one report covering ISO 9001, ISO 27001 and ISO 42001 together.

 

ISO 42001 and ISO 27001: How They Fit

This comes up in almost every first conversation, so let us be precise.
ISO 27001 protects information. Confidentiality, integrity, availability. Its controls are built around protecting data as an asset.
ISO 42001 governs the behaviour and consequences of AI systems. Fairness, transparency, explainability, human oversight, the effects on people subject to automated decisions. Different questions entirely.
They overlap in useful places. Your risk management methodology, document control, competence records, internal audit programme, management review and corrective action process can serve both standards with minimal duplication. ISO explicitly positions the two as complementary.
Where they diverge, they diverge sharply. An ISO 27001 certificate says nothing about whether your recruitment model discriminates. Organisations that assume their ISMS “mostly covers it” are in for an uncomfortable gap analysis.
If you hold ISO 27001 already, you are in a strong position — but you are not most of the way there.

 

ISO 42001 and the EU AI Act

Clients ask whether certification delivers EU AI Act compliance. It does not, and you should treat anyone who says otherwise with caution.
The AI Act is law. ISO 42001 is a voluntary management system standard. Certification does not grant a presumption of conformity with the Act’s requirements.
What it does give you is the governance machinery the Act assumes you already have: an AI inventory, a risk management process, impact assessment, technical documentation, human oversight arrangements, post-market monitoring, and records that demonstrate all of it. Organisations with a functioning AIMS find AI Act readiness work considerably less painful than those starting from nothing.
Treat ISO 42001 as the foundation. Not the answer.

 

What ISO 42001 Certification Costs

There is no single figure, and any firm quoting one before understanding your scope is guessing.
Cost is driven by:
• Scope — how many AI systems, and whether you develop them or only use them
• Your role — developer, provider and deployer obligations differ substantially in effort
• Headcount and sites — certification body audit days are calculated largely from these
• Existing certifications — an established ISO 27001 or ISO 9001 system reduces both implementation effort and audit duration
• Internal capability — whether you have someone who can own the system, or need external support throughout

You will be paying for two separate things, and it helps to separate them mentally from the start. First, getting ready: gap analysis, implementation work, internal audits, pre-certification assessment. Second, the certificate itself: the accredited certification body’s Stage 1 and Stage 2 audit, plus annual surveillance across the three-year cycle.

We are independent of certification bodies, so our advice on the second is not affected by our interest in the first.

 

Who Certifies You

Not us. Not ISO either — ISO writes standards and does not certify organisations.
Certification comes from an accredited certification body, independently of any consultancy or audit work you have commissioned. This separation exists to protect the credibility of the certificate, and it is why we do not offer to implement your management system and then assess it.
Our role is to get you to the certification audit properly prepared, then stay involved through the surveillance cycle. Yours is to run the system. Your certification body’s is to issue the certificate.

 

Frequently Asked Questions

 

How long does ISO 42001 certification take?

For an organisation with an existing certified management system and a clearly bounded AI scope, several months is realistic. Starting with no management system, limited documentation and an unclear AI inventory, plan for considerably longer. The inventory and impact assessment work is usually the critical path — not the paperwork.

Is ISO 42001 mandatory?

No. It is voluntary. Procurement is another matter: AI governance questions are now routine in tender documentation and enterprise vendor assessments, and certification is an efficient answer to a long questionnaire.

We only use AI tools built by other people. Does it apply?

Yes. The standard covers organisations that use AI systems, not only those that build them. Your obligations differ from a developer’s, but you still need to know what you are running, what it affects, and who is accountable.

Can we integrate ISO 42001 with our existing certifications?

Yes, and you should. The shared clause structure means one policy framework, one internal audit programme and one management review can serve several standards. Integration is usually cheaper to run and easier to defend at audit than parallel systems.

Do we need ISO 27001 first?

No, but it helps. Existing certification gives you the management system infrastructure — document control, audit programme, corrective action — that ISO 42001 also requires.

What is the difference between a gap analysis and an internal audit?

A gap analysis measures you against the standard before your system exists, to tell you what to build. An internal audit tests the system you have built, to tell you whether it works. Most organisations need the first once and the second every year.

 

Talk to Our Audit Team

AI governance has moved from a technology question to a board question, and the organisations handling it well are treating it the way they treated information security a decade ago — as a management system with an owner, an audit programme and evidence.
We provide independent ISO 42001 gap analysis, internal audits and pre-certification assessments, scaled to your organisation’s size, sector and AI footprint. Whether you are scoping a first assessment or maintaining an established AIMS, we can tell you quickly where you stand.

We can help you today

Contact us now to discuss your ISO 42001 Artifical Intelligence Management requirements.

free meeting

   Address

53 Old Theatre Street Valletta VLT 1427 Malta Phone: (+356) 2540 7900 Email: malta@hvassallo.com75 King William Street London EC4N 7BE UK Phone: +44 (0) 203 7862 131 Email: london@hvassallo.com
 

Contact us