ISO/IEC 42001 · AI Governance

Get ISO 42001 certified and answer every question about your AI.

Customers, procurement teams and regulators have started asking how your Artificial Intelligence (AI) is governed, and "we are not sure" loses deals. ISO/IEC 42001 is the first international standard for Artificial Intelligence Management Systems (AIMS). Lexfield Digital Systems is an Irish consultancy that helps organisations that build, buy or operate AI implement the standard and get certified.

Already running ISO/IEC 27001? The two standards share the same structure, and we design your AI governance to sit inside the management system you already have. Looking for an auditor rather than a consultant? We will refer you to independent audit specialists.

Why ISO/IEC 42001

The questions about your AI are already coming

Customers, procurement teams and regulators are starting to ask the same question in different words: how do you govern your AI? ISO/IEC 42001 gives you a recognised, certifiable answer, before the question arrives as a lost deal or a compliance finding.

Answer procurement before it asks

AI governance questions are appearing in security questionnaires and tender requirements. A certified AI management system turns a difficult conversation into a one-line answer.

Prepare for the EU AI Act

The European Union's AI Act is phasing in obligations for organisations that provide or deploy AI systems. ISO/IEC 42001 does not replace legal compliance, but it builds the governance, documentation and risk practices those obligations rest on.

Use AI with confidence

An AI management system gives you an inventory of where AI is actually used in your organisation, who owns each system, and what could go wrong, so adoption speeds up instead of stalling in uncertainty.

Stand out early

The standard was published in December 2023 and certified organisations are still rare. Early adopters get a differentiator their competitors cannot copy quickly.

ISO/IEC 42001 is for you if
  • AI features ship inside your product
  • Models keep learning or change behaviour in production
  • AI makes or shapes decisions about people
  • You buy and deploy AI tools across the business
  • Customers ask how your AI is governed

Working out your route? The first call is free and carries no obligation: clear, practical advice either way.

Book a free introductory call

Services

What our ISO 42001 consultancy includes

We do one thing here: implementation consultancy, delivered by Lead Auditor trained practitioners. Advisory and audit stay in separate hands, which is what keeps your certificate fully credible. When you need an auditor, we connect you with independent specialists.

Consultancy

Implementation and certification support

For organisations building an AI management system, whether AI is your product or a tool your teams have started using.

  • Gap analysis against ISO/IEC 42001 with a prioritised roadmap
  • AI system inventory: every model, tool and AI-powered feature in scope, with a named owner
  • AI risk assessment covering fairness, transparency, safety, security and accountability
  • AI impact assessments for the systems that affect customers, employees or the public
  • Annex A control implementation across the AI lifecycle, from data and development to deployment and monitoring
  • Policies for responsible AI use, written for the people who actually use the tools
  • Integration with an existing ISO/IEC 27001 Information Security Management System (ISMS), so you run one management system, not two
  • EU AI Act applicability and role assessment: which risk tier and duties attach to you as provider, deployer, importer or distributor
  • Knowledge transfer throughout, so your team can run and improve the AIMS without ongoing consultancy
  • Certification audit preparation and liaison with your certification body

Two ways to work with us

Both are fixed-price. Pick the balance that suits your team, or move between them as the project runs.

Option 1 We build with you

We take the lead on drafting and building, and you review, decide and approve. The fastest route when your team is stretched.

Option 2 We coach, you build

Your team does the building while we guide, review and course-correct. More of the knowledge stays in-house, and the fee reflects the lighter touch.

Independence protects your certificate: certification bodies expect the people who build your management system and the people who audit it to be different, and that separation is what gives your certificate its value. We handle the building. When you need external audit services, including the internal audits the standard requires, we connect you with independent audit firms, so every part of your certification journey is covered and your certificate keeps its full credibility.

Process

From AI sprawl to a governed system

  1. Discover and scope

    We map where AI actually lives in your organisation: the products you ship, the tools your teams use, and the vendor systems working quietly in the background. Scope follows reality, not the org chart.

  2. Assess risk and impact

    Each AI system in scope gets a risk assessment and, where it affects people, an impact assessment. You end up knowing which systems deserve tight controls and which need only a light touch.

  3. Build the AI management system

    Policies, lifecycle controls, roles and records take shape around how your teams really work. If you already run ISO/IEC 27001, we extend that system rather than building a parallel one.

  4. Internal audit and management review

    Before certification, an independent auditor puts the system through the internal audit the standard requires. We help you engage one, support you through the audit, close out its findings, and guide your leadership through the management review.

  5. Certification

    We support you through the certification body's two-stage audit and stay with you through any findings, so the certificate lands and stays in place through surveillance audits.

Who you work with

We govern AI because we build with it

Lexfield's consultants have hands-on experience designing, building and operating digital systems, including systems that use AI in production. Our governance advice comes from shipping and running this technology, not from reading about it.

  • ISO/IEC 42001 Lead Auditor training Certified Lead Auditor training in ISO/IEC 42001, covering audit planning, execution and reporting against the AI management system standard.
  • ISO/IEC 27001 Lead Auditor training Lead Auditor training completed with SEQM in ISO/IEC 27001, the information security standard ISO/IEC 42001 is designed to integrate with.
  • Hands-on AI engineering experience Our consultants have hands-on experience building and operating AI-powered systems, so we know where the real risks live: in data pipelines, model behaviour, vendor dependencies and the gap between policy and practice.
  • Built for small and medium businesses Fixed-scope engagements, plain-English deliverables and governance sized to your actual AI footprint, not a framework built for a multinational.

The standard explained

What is ISO 42001?

ISO/IEC 42001:2023 is the first international, certifiable standard for Artificial Intelligence Management Systems (AIMS), published in December 2023 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It applies to any organisation that develops, provides or uses AI, and it follows the same Clause 4 to 10 structure as ISO/IEC 27001, plus Annex A with 38 AI-specific controls. Certification means an accredited certification body has independently confirmed your AI governance meets the standard.

In practice, an AI management system under ISO/IEC 42001 must include the following:

  • An AI policy and clear roles Top management sets the organisation's position on AI, and every AI system in scope has a named owner who is accountable for it.
  • An AI system inventory A live register of every model, tool and AI-powered feature the organisation builds, buys or uses, including AI embedded in vendor products.
  • AI risk assessments Structured assessment of what could go wrong with each system: bias and fairness, safety, security, transparency and accountability.
  • AI impact assessments For systems that affect customers, employees or the public, a documented assessment of the impact on those people, not just on the organisation.
  • Lifecycle controls Controls across the whole AI lifecycle: data quality and provenance, development and testing, deployment, monitoring in production, and retirement.
  • Audit, review and improvement Internal audits, management reviews and corrective action, so the governance keeps pace as models, tools and regulations change.

Beyond the clauses: the annexes

The clauses say what an AIMS must do. The annexes are where ISO/IEC 42001 earns its keep for AI specifically:

Annex A38 reference controls

The AI-specific controls, from AI policy and impact assessment through data quality to lifecycle management.

Annex BImplementation guidance

Practical guidance for every Annex A control, so implementation never starts from a blank page.

Annex CObjectives and risk sources

A catalogue of AI-specific organisational objectives and risk sources to draw on when assessing your systems.

Annex DDomains and integration

Applying the AIMS across sectors and integrating it with other management systems such as ISO/IEC 27001.

Regulation

The EU AI Act raises the stakes

The EU Artificial Intelligence Act is now law and its obligations are phasing in. It classifies AI systems by the risk they pose to people and attaches different duties to each tier. Your obligations also depend on your role under the Act: provider, deployer, importer, distributor or authorised representative. Part of our work is establishing which tier and role apply to you, so you meet the duties you actually have.

  • Up to €35m or 7% of global annual turnover for prohibited AI practices
  • Up to €7.5m or 1% of global annual turnover for supplying incorrect or misleading information

ISO/IEC 42001 does not replace the Act, and it builds exactly the governance evidence the Act's duties rest on: an AI inventory, risk and impact assessments, documentation and human oversight. We map what remains for your specific tier and role.

FAQ

Questions we hear most often

What exactly is ISO/IEC 42001?

It is the first international, certifiable standard for managing AI responsibly, published in December 2023. It requires an Artificial Intelligence Management System (AIMS): a structured set of policies, risk assessments, controls and reviews covering how your organisation develops, buys and uses AI. It follows the same clause structure as ISO/IEC 27001, so the two work naturally together.

Do we need ISO/IEC 27001 before ISO/IEC 42001?

No. Each standard stands on its own. But because they share the same structure, organisations that already hold ISO/IEC 27001 can extend their existing management system to cover AI with far less effort, and organisations pursuing both can run a single integrated programme. We support either route.

How long does ISO 42001 certification take?

Comparable to ISO/IEC 27001: typically four to nine months for a small or medium organisation, and faster if you already run ISO/IEC 27001 and are extending an existing management system. The AI system inventory and impact assessments are usually the new work; the management system machinery may already exist.

How much does ISO 42001 certification cost?

Because the standard follows the same structure as ISO/IEC 27001, consultancy costs are broadly comparable, and materially lower if you are extending an existing certified management system rather than starting fresh. Certification body fees are separate and quoted by them. We work fixed-scope and fixed-price: one number after scoping, before you commit. If the scope changes mid-engagement, the price is re-agreed with you before any extra work happens, never discovered on an invoice.

Does ISO/IEC 42001 make us compliant with the EU AI Act?

Not by itself. The EU AI Act is law and has its own specific obligations depending on how your AI systems are classified. What the standard does is build the governance foundation those obligations rest on: an AI inventory, risk management, documentation and human oversight. We map the remaining gap for your specific situation.

We only use AI tools, we do not build them. Is this relevant to us?

Yes. The standard covers organisations that use AI, not only those that develop it. If your teams rely on AI tools for customer communication, decision-making or content, you carry AI risk and your customers may soon ask how you manage it. A right-sized AI management system answers that question.

Who issues the certificate?

An independent accredited certification body, after a two-stage audit. We never certify our own work. We prepare you for the certification audit, help you choose a certification body, and help you engage an independent auditor for the internal audits the standard requires.

Get started

Find out what governing your AI would actually take.

The first call is free and carries no obligation. We will tell you honestly whether ISO/IEC 42001 makes sense for your organisation now, later, or not at all.

Book a free introductory call