ISO 42001 consulting: building your AI management system
You use AI or develop products with AI components, but responsibilities and risk assessments are not yet consistently defined? An AI management system specifies who assesses and approves AI applications and monitors their use. With our ISO 42001 consulting, we support you in building or further developing it.
ISO 42001: steering AI responsibly, with a management system that fits.
Your situation
You use AI or develop AI products and need to demonstrate that you handle them responsibly?
Employees use generative AI, products are given AI functions, business processes are automated. At the same time, clients, partners and supervisory authorities ask how you steer this use – and the EU AI Act brings new obligations.
Many organisations already have individual policies or security measures. What is missing is a framework that brings them together: which AI applications are used or developed? Who is responsible for them? Which risks need to be assessed and documented? How do you prepare for audits or certification?
ISO/IEC 42001, the first international standard for AI management systems (AIMS), provides this framework. The EU AI Act can be a reason to introduce an AI management system to ISO/IEC 42001. The EU AI Act does not require certification; however, many of its organisational requirements can be implemented and demonstrated in a structured way using the standard.
We start with how you actually use AI, not with document templates. If you already have an ISMS to ISO/IEC 27001, we integrate the AI management system into it instead of building a parallel structure.
Services & results
Six steps to an AI management system to ISO/IEC 42001
You get an AI management system to ISO/IEC 42001 that specifies who assesses and approves AI applications in your organisation and monitors their use. The path leads from scoping your use of AI and reviewing processes, policies and responsibilities to a maturity and gap analysis; an existing ISMS (information security management system) is taken into account.
You can start with the maturity and gap analysis or commission individual steps such as implementation support or audit preparation. The goal is not a documentation project but an AI management system that works in day-to-day operations.
01
Scoping and definition of objectives
Together, we analyse how AI is used or developed in your organisation and which objectives you pursue with the AI management system: internal steering, evidence for clients, preparation for certification, or the EU AI Act as a reason to regulate the use of AI in a structured way.
02
Current-state review
We review existing processes, policies, documentation and responsibilities as well as how AI is currently handled. It does not matter whether you already operate a management system or are just starting out.
03
Maturity and gap analysis
We assess maturity against the requirements of ISO/IEC 42001, identify specific deviations and derive the key areas for action. Among other things, we look at:
Governance structures
Roles and responsibilities
Risk management
Policies and rules for AI systems
Documentation and evidence
Monitoring and improvement processes
Strengths and gaps
A clear overview of existing strengths, identified gaps and necessary areas for action against ISO/IEC 42001.
04
Action planning
From the areas for action, we create a structured action plan. We prioritise the requirements of ISO/IEC 42001 and translate them into practicable measures.
Your action plan
Prioritised recommendations that show what needs to be done next.
05
Implementation support
On request, we support the implementation. We further develop processes and responsibilities with you, support the required documentation and evidence, and advise on technical, organisational and normative questions.
We use existing processes for information security, risk management, compliance or data protection as a basis.
06
Internal audits and certification preparation
We plan and carry out internal audits to ISO/IEC 42001 and include existing audit programmes, for example under ISO/IEC 27001 – this avoids duplicate work. Before a certification audit or an external assessment, we evaluate the audit readiness of your AI management system:
Document reviews
Interview preparation and audit simulations
Support during external audits
Support in addressing findings and nonconformities
Audit-ready
You know which documents and measures are still open before the external assessment – and your responsible staff know how an audit proceeds.
Our expertise
Information security management systems have been part of our work for decades – in IT-Grundschutz as well as under ISO/IEC 27001. We bring this experience with management systems, risk assessment and audits to ISO/IEC 42001 projects.
Because we also offer ISO 27001 consulting, internal audits and consulting on NIS2 and the Cyber Resilience Act (CRA), we look at these topics together. The AI management system is integrated into your existing structures.
On the technical side, we carry out AI pentests, for example for chatbots or systems for automated document processing. This way, organisational and technical evidence can be aligned with each other.
Getting started
Clarify objective, starting point and internal involvement
Discuss your use of AI and existing documents
Describe to us which AI applications you use or develop. Existing policies, risk assessments and assigned responsibilities are helpful. Also clarify with us whether an external assessment is planned. On this basis, we define the consulting or audit assignment.
Involving your responsible staff
Your responsible staff explain how AI is used and provide the existing documents. They decide on responsibilities, approvals and measures and put the agreed rules into practice. We provide expert support for the agreed tasks; responsibility for the use of AI remains with your organisation.
Capture AI applications, derive management needs clearly.
Consulting and the certification decision
Consulting and audit preparation do not replace a certification decision or an individual assessment of regulatory obligations.
Questions about ISO 42001 consulting
Can we start ISO 42001 consulting without an existing management system?
Yes. An existing ISMS or another management system is not a prerequisite for our consulting. We take into account what you have already put in place. Individual policies and defined responsibilities also help to plan the further build-up.
Do we already need to plan certification to ISO/IEC 42001?
No. You can first improve how AI is handled in your organisation without commissioning a certification audit. Whether you aim for external certification later is something we discuss based on your objectives. The consulting does not require this objective.
Can an AI management system be combined with our ISMS?
Yes. We check which risk assessment processes you can share and extend for AI applications. Internal AI audits can be aligned with your existing audit programme under ISO 27001. The AI-specific responsibilities, assessments and evidence are taken into account in addition.
Is a technical test of our AI applications part of ISO 42001 consulting?
No, it is a separate service. ISO 42001 consulting looks at how you organise the use of AI, responsibility and risk assessment. An AI pentest, by contrast, examines individual AI-based applications such as chatbots or systems for automated document processing for vulnerabilities. The two can be combined; an AI management system alone does not demonstrate the technical security of your applications.
Does the EU AI Act require certification to ISO/IEC 42001?
No. However, the standard offers an internationally recognised approach for implementing many organisational requirements of the EU AI Act in a structured way and demonstrating them to clients, partners and supervisory authorities. It does not replace an individual assessment of your obligations under the EU AI Act.