ISO/IEC 42001

ISO/IEC 42001 implementation and readiness, without improvisation

We structure the AI management system your organisation needs to demonstrate control over how AI is built, bought and used — and to face an external audit with evidence.

What is ISO/IEC 42001?

ISO/IEC 42001 is the international standard for an AI management system (AIMS). It specifies requirements for establishing, implementing, maintaining and continually improving the governance of artificial intelligence within an organisation, covering context, leadership, planning, support, operation, performance evaluation and improvement, with a set of controls in Annex A addressing AI policy, roles, impact assessment, data, lifecycle and third parties.

Engagement options

Gap analysis

Structured comparison of your current state against every clause and Annex A control, with a prioritised remediation plan.

Implementation

Full AIMS build: scope, policy, inventory, impact assessment, risk treatment, controls, documentation and indicators.

Internal audit

Internal audit conducted against ISO/IEC 42001 by a Lead Auditor, with findings, evidence and corrective action plan.

Certification readiness

Pre-audit review, document pack, interview preparation and remediation before the accredited body's stage 1 and stage 2.

Typical deliverables

  • AIMS scope statement and AI policy approved by leadership
  • AI system and vendor inventory with owners and risk tiers
  • AI impact assessment methodology and completed assessments for priority use cases
  • Risk treatment plan and Statement of Applicability for Annex A controls
  • Human oversight, data quality and lifecycle documentation
  • Internal audit programme, indicators and management review records

Frequently asked questions

What is the difference between Lead Implementer and Lead Auditor work?

Lead Implementer work builds the management system: scope, policies, controls, documentation and evidence. Lead Auditor work evaluates it: internal audit, readiness assessment and gap analysis against the standard. VGrid provides both, kept separate so the review of a system is never a review of our own implementation without disclosure.

Can VGrid certify our organisation to ISO/IEC 42001?

No. Certification is issued exclusively by accredited independent certification bodies. VGrid prepares the organisation, runs internal audit and readiness, and supports the certification process — but does not issue the certificate.

How does ISO/IEC 42001 relate to ISO/IEC 27001 and 27701?

They share the same management-system structure, so controls, risk processes and audit routines can be integrated. Organisations already certified to ISO/IEC 27001 or 27701 typically reuse a significant part of their governance, documentation and audit machinery when implementing ISO/IEC 42001.

Assess your ISO/IEC 42001 readiness

Start with a gap analysis against every clause and Annex A control, with a prioritised remediation roadmap.