ISO 42001 implementation is the newest of the management system projects and the
one with the least accumulated practice. ISO/IEC 42001:2023 is a first edition, and most
organisations approaching it have AI already in production and no governance around it. This is a
ten-step plan for that situation.
Before step one of ISO 42001 implementation: find the AI you already have
Every ISO 42001 implementation starts here, because every organisation has more AI in use than its inventory shows, because most of it arrived inside
SaaS products nobody classified as AI. Before scoping, sweep for it: models you built, models you
fine-tuned, third-party APIs, and AI features switched on inside tools you already licence. The
scope conversation is meaningless until you know what is in play.
The ten steps of ISO 42001 implementation
- AI inventory (3–5 weeks). The first move in any ISO 42001 implementation. Every AI system, its purpose, its data, its
owner, and whether you are provider, developer or user of it — the standard treats those roles
differently. - Gap analysis (2–3 weeks). Against clauses 4–10 and the Annex A
controls. - Scope, context and interested parties (2–3 weeks). Interested parties
here include people affected by AI decisions, not only customers. - AI policy, roles and objectives (2–3 weeks). Clause 5.2 requires an AI
policy; 5.3 assigns roles and authorities. - AI risk assessment (4–8 weeks). Clause 8.2, using a defined and repeatable
method. - AI risk treatment (4–8 weeks). Clause 8.3, selecting Annex A controls and
documenting what applies. - AI system impact assessment (3–6 weeks). Clause 8.4, and
the requirement with no equivalent in any other management system standard: assess the consequences
for individuals and society, not just for the organisation. See our guide to
responsible AI. - Operational controls and lifecycle process (6–10 weeks). Data governance,
model development, validation, deployment, monitoring and decommissioning. See
ISO 42001 controls. - Run the system (3–6 months). Monitoring, incidents, model drift reviews
and change records need real history. - Internal audit, management review, certification. Both prerequisites. See
ISO 42001 certification.
A complete AI management system, ready to edit.
The ISO 42001 Toolkit covers the AI policy, inventory, risk assessment and treatment, the AI system impact assessment, Annex A control documentation and the audit set — editable and mapped to the clause each satisfies.
The three steps ISO 42001 implementation always underestimate
Step 7, the AI system impact assessment. Teams treat it as a second risk
assessment and duplicate step 5. It is a different question: clause 8.2 asks what could go wrong for
the organisation, clause 8.4 asks what the AI system does to the people subject to it. Fairness,
explainability, contestability and the availability of human review belong here.
Step 1, the inventory. Consistently understated because AI arrives through
procurement rather than engineering. The models nobody told you about are the ones creating the
exposure.
Step 8, monitoring. AI systems degrade. A control set that assumes a model
behaves in year two as it did at launch will not survive an audit, and drift monitoring has to be
designed in rather than added later.
ISO 42001 implementation now has a proper certification route
ISO/IEC 42006:2025
sets the requirements for bodies auditing and certifying AI management systems. That matters
practically: it is the piece that lets accredited certification operate consistently rather than
each body inventing its own approach. If you are choosing a certification body, ask how they are
accredited against it.
A realistic total for ISO 42001 implementation
Six to twelve months for an organisation with AI already in production and an
existing management system to build on. Where ISO 27001 exists, clauses 4, 5, 6, 7, 9 and 10
transfer almost entirely and the saving is real — budget it against clause 8, which is
AI-specific and has no equivalent elsewhere. See also
ISO 42001 vs the NIST AI RMF.
References
- ISO/IEC 42001:2023 — the AI management system standard on iso.org.
- ISO/IEC 42006:2025 — requirements for bodies auditing and certifying AI management systems.
Implementation guides for the other standards
- ISO 27001 implementation
- ISO 9001 implementation
- ISO 13485 implementation
- ISO 14001 implementation
- ISO 45001 implementation
- ISO 22301 implementation
- GDPR implementation
- ISO 42001 implementation — you are here
- ISO 20000 implementation
- HIPAA implementation