Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 42001 Implementation — guide from Governance Docs

How to Implement ISO 42001: A Ten-Step Plan

ISO 42001 implementation is the newest of the management system projects and the
one with the least accumulated practice. ISO/IEC 42001:2023 is a first edition, and most
organisations approaching it have AI already in production and no governance around it. This is a
ten-step plan for that situation.

Before step one of ISO 42001 implementation: find the AI you already have

Every ISO 42001 implementation starts here, because every organisation has more AI in use than its inventory shows, because most of it arrived inside
SaaS products nobody classified as AI. Before scoping, sweep for it: models you built, models you
fine-tuned, third-party APIs, and AI features switched on inside tools you already licence. The
scope conversation is meaningless until you know what is in play.

The ten steps of ISO 42001 implementation

  1. AI inventory (3–5 weeks). The first move in any ISO 42001 implementation. Every AI system, its purpose, its data, its
    owner, and whether you are provider, developer or user of it — the standard treats those roles
    differently.
  2. Gap analysis (2–3 weeks). Against clauses 4–10 and the Annex A
    controls.
  3. Scope, context and interested parties (2–3 weeks). Interested parties
    here include people affected by AI decisions, not only customers.
  4. AI policy, roles and objectives (2–3 weeks). Clause 5.2 requires an AI
    policy; 5.3 assigns roles and authorities.
  5. AI risk assessment (4–8 weeks). Clause 8.2, using a defined and repeatable
    method.
  6. AI risk treatment (4–8 weeks). Clause 8.3, selecting Annex A controls and
    documenting what applies.
  7. AI system impact assessment (3–6 weeks). Clause 8.4, and
    the requirement with no equivalent in any other management system standard: assess the consequences
    for individuals and society, not just for the organisation. See our guide to
    responsible AI.
  8. Operational controls and lifecycle process (6–10 weeks). Data governance,
    model development, validation, deployment, monitoring and decommissioning. See
    ISO 42001 controls.
  9. Run the system (3–6 months). Monitoring, incidents, model drift reviews
    and change records need real history.
  10. Internal audit, management review, certification. Both prerequisites. See
    ISO 42001 certification.

A complete AI management system, ready to edit.

The ISO 42001 Toolkit covers the AI policy, inventory, risk assessment and treatment, the AI system impact assessment, Annex A control documentation and the audit set — editable and mapped to the clause each satisfies.

Explore the ISO 42001 Toolkit →

The three steps ISO 42001 implementation always underestimate

Step 7, the AI system impact assessment. Teams treat it as a second risk
assessment and duplicate step 5. It is a different question: clause 8.2 asks what could go wrong for
the organisation, clause 8.4 asks what the AI system does to the people subject to it. Fairness,
explainability, contestability and the availability of human review belong here.

Step 1, the inventory. Consistently understated because AI arrives through
procurement rather than engineering. The models nobody told you about are the ones creating the
exposure.

Step 8, monitoring. AI systems degrade. A control set that assumes a model
behaves in year two as it did at launch will not survive an audit, and drift monitoring has to be
designed in rather than added later.

ISO 42001 implementation now has a proper certification route

ISO/IEC 42006:2025
sets the requirements for bodies auditing and certifying AI management systems. That matters
practically: it is the piece that lets accredited certification operate consistently rather than
each body inventing its own approach. If you are choosing a certification body, ask how they are
accredited against it.

A realistic total for ISO 42001 implementation

Six to twelve months for an organisation with AI already in production and an
existing management system to build on. Where ISO 27001 exists, clauses 4, 5, 6, 7, 9 and 10
transfer almost entirely and the saving is real — budget it against clause 8, which is
AI-specific and has no equivalent elsewhere. See also
ISO 42001 vs the NIST AI RMF.

References

Implementation guides for the other standards

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.