Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

Warden · AI Governance

ISO/IEC 42001 certifies a management system, not a model

An alignment engagement that builds the AI management system ISO/IEC 42001:2023 describes — scope, policy, risk and impact assessment, controls, internal audit and management review — and gets you ready for a certification body's audit.

The standard rewards organizations that already run one

42001 follows the harmonized management-system structure, so if you hold ISO 27001 the shape is familiar and much of the evidence machinery can be reused. What is new is the AI-specific impact assessment and the Annex A controls around data, lifecycle and third parties.

  1. Scope decides the workloadAn over-broad scope statement is the most common reason a 42001 program takes twice as long as planned.
  2. Impact assessment is not risk assessmentThe standard asks about consequences for individuals and society, which most existing risk processes do not capture.
  3. Certification is a third party's decisionWe prepare the management system and the evidence; an accredited certification body issues the certificate.

How the engagement runs

1

Scope and context

Define the boundary of the AI management system, interested parties and objectives.

2

Gap analysis

Clauses 4 to 10 and the Annex A controls against what you already operate, reusing ISO 27001 evidence where it applies.

3

Build

Policy, roles, AI risk and impact assessment process, Statement of Applicability and the control set.

4

Operate and audit

Run the system long enough to produce records, then internal audit and management review ahead of the certification audit.

What you hold at the end

  • A defensible scope statement and AI management system policy
  • AI risk and impact assessment methodology, applied to your real systems
  • A Statement of Applicability with justification per Annex A control
  • Internal audit program, findings and management review records
  • A certification-readiness assessment ahead of the external audit

The instrument itself

ISO/IEC 42001:2023
The AI management system standard, certifiable by an accredited body, with Annex A controls specific to AI.
ISO/IEC 27001
Where you already hold it, the management-system machinery, internal audit and evidence practice carry over.
EU AI Act interaction
A 42001 management system is useful supporting evidence for AI Act governance obligations, but it is not a substitute for conformity assessment.

What carries the evidence

A management system that runs, not a binder

Certification audits fail on missing records far more often than on missing policy. We build for the records.