ISO 42001 Certification Readiness Explained

ISO 42001 Certification Readiness Explained

A certification auditor cannot certify a policy library, a slide deck or a collection of disconnected spreadsheets. They certify an operating management system. ISO 42001 certification readiness means being able to show how your organisation governs AI in practice: what AI systems exist, who owns them, how risks are assessed, which controls apply, and how leadership reviews performance and acts on deficiencies.

For compliance teams, the difficult part is rarely writing an AI policy. It is turning governance intent into repeatable workflows and retaining evidence that stands up to independent scrutiny. That requires a defined Artificial Intelligence Management System (AIMS), not a one-off compliance project.

What ISO 42001 certification readiness actually means

ISO/IEC 42001 is the international standard for an AI management system. Like other management system standards, it asks an organisation to establish context, leadership commitment, planning, support, operational controls, performance evaluation and continual improvement. The standard is not limited to organisations building foundation models or developing AI products. It also applies to organisations procuring, deploying and overseeing AI-enabled systems.

Readiness is therefore not a binary question of whether every conceivable AI risk has been eliminated. It is whether the AIMS is appropriately scoped, implemented and demonstrably effective for the organisation’s AI role, risk profile and stated objectives.

A bank using AI for credit decisioning, a local authority deploying a chatbot, and a software provider embedding third-party machine learning services will require different controls and evidence. The standard expects proportionate governance. What it will not accept is an undefined inventory, unclear accountability or controls that exist only on paper.

Certification is also distinct from alignment. An organisation may say it is aligned with ISO 42001 because it has adopted selected good practices. A certification audit requires a recognised certification body to assess the full management system against the standard’s requirements and applicable control objectives.

Start with the AIMS scope, not the control checklist

The fastest way to create rework is to begin by ticking off Annex A controls before deciding what the management system covers. Certification scope determines the organisational boundaries, business units, locations, AI activities, suppliers and system types within the AIMS.

A credible scope statement should explain whether the organisation develops, provides, uses or procures AI systems, and identify the functions covered. It should also make clear any justified exclusions. For example, a UK business may initially certify its internal AI procurement and deployment processes while excluding a separately governed subsidiary. That decision needs rationale, governance ownership and consistent application.

Scope must reflect interested parties and their requirements. These commonly include customers, regulators, employees, affected individuals, insurers, shareholders and key suppliers. For European organisations, this analysis should connect to the EU AI Act where relevant, but the two frameworks should not be treated as interchangeable. ISO 42001 establishes a management system; the EU AI Act imposes legal obligations based on roles and risk classifications. A good AIMS creates the operational discipline needed to manage both, but certification does not itself prove EU AI Act compliance.

Build a complete, owned AI inventory

An auditor will expect the organisation to know where AI is being used and what decisions it influences. This is where many readiness programmes fail. Procurement records may identify suppliers, information security may hold a software register, and teams may maintain separate model documentation. None of these is necessarily an AI inventory.

Your inventory should establish a single record for each AI system or material use case. At minimum, it should capture the system purpose, business owner, technical owner, supplier or developer, deployment environment, data categories, affected groups, decision impact, lifecycle status and relevant legal or contractual requirements.

The inventory must be governed, not merely compiled. Define who can register a new use case, who validates its classification, how material changes are recorded and when systems are reviewed. An AI system that changes model provider, starts processing special category data or moves from assisting staff to making automated recommendations may require a new assessment. Without change control, yesterday’s inventory becomes audit evidence of weak governance.

For organisations subject to the EU AI Act, classification should sit alongside the inventory. The workflow should identify prohibited practices, potential high-risk systems, transparency obligations, general-purpose AI dependencies and any local legal requirements. This avoids the common mistake of running ISO 42001 and EU AI Act workstreams as competing spreadsheets.

Translate risks into controls and evidence

Risk assessment is central to ISO 42001 readiness, but generic AI risk statements are not enough. The organisation needs a defined methodology for identifying, analysing, evaluating and treating AI risks. It should account for risks to individuals, groups and society as well as risks to the organisation, including legal, security, performance, fairness, privacy and operational risks.

The key test is traceability. An auditor should be able to follow a line from an identified risk to a treatment decision, a control owner, documented implementation and evidence of operation. If a recruitment screening tool presents a discrimination risk, for example, evidence may include supplier due diligence, intended-use restrictions, human oversight procedures, performance testing, reviewer training, incident escalation and periodic review records. The exact package depends on the use case. The connection between risk and treatment should not be ambiguous.

Annex A provides reference control objectives and controls, but it is not a mandatory tick-box catalogue. Organisations should determine applicability, justify exclusions and document their control position in a Statement of Applicability. A thin document that simply marks controls as applicable without showing implementation will not establish readiness.

Useful evidence normally includes:

  • approved policies and AI governance procedures;
  • system-level impact, risk and supplier assessments;
  • records of approvals, monitoring, change decisions and incidents;
  • training and competence records for people with AIMS responsibilities;
  • internal audit reports, corrective actions and management review minutes.

Evidence should be current, attributable and retrievable. A control with no owner is difficult to operate. A control with an owner but no retained record is difficult to audit.

Test whether governance works under pressure

ISO 42001 certification readiness depends on operational performance, not document volume. Clause 9 requires monitoring, measurement, analysis and evaluation, together with internal audit and management review. Clause 10 requires nonconformities and continual improvement to be managed systematically.

This is often where organisations that have completed an initial gap assessment find they are not yet ready for certification. They may have established policies and completed several assessments, but have not allowed enough operating time to demonstrate recurring review, exception handling and corrective action.

Internal audit should test the AIMS against the standard and against the organisation’s own procedures. It should sample real systems, not just central documentation. Can the auditor locate the relevant inventory record? Is its risk classification supported? Were control actions completed by the assigned owner? Was a supplier reassessed following a material change? Are overdue actions escalated?

Management review is not a ceremonial meeting. Senior management should receive evidence on AIMS performance, audit findings, incidents, changes in internal and external issues, resource needs, risks and opportunities, and improvement actions. The output must include decisions and follow-up. Board reporting that describes AI risk in broad terms but cannot show ownership, open actions and trends is unlikely to support a mature certification case.

Prepare for the certification audit in two stages

Certification bodies commonly conduct a Stage 1 and Stage 2 audit. Stage 1 assesses whether the management system is sufficiently designed and documented for the organisation to proceed. It focuses on scope, context, documented information, internal audit, management review and preparedness for the main assessment.

Stage 2 tests implementation and effectiveness through interviews, evidence sampling and process observation. Auditors will follow the trail across teams. Legal may explain the compliance basis, procurement may evidence supplier controls, product or operations teams may demonstrate system oversight, and leadership may show how performance is reviewed.

Before engaging a certification body, run a realistic pre-assessment. Treat it as an evidence retrieval exercise rather than a policy review. Select a sample of AI systems across different risk profiles and ask whether every required record can be produced quickly, consistently and with a clear owner. Resolve systemic gaps before the external audit, particularly those involving scope, risk treatment, internal audit, management review and corrective action.

Avoid an evidence architecture built on spreadsheets

Spreadsheets can support an early discovery exercise, but they become fragile when the programme must manage approvals, changes, evidence, control testing and auditor access across multiple systems. Version confusion, missing ownership and manual reporting are governance risks in their own right.

A dedicated system of record gives compliance teams a more defensible position: one AI inventory, mapped obligations, assigned actions, time-stamped evidence and reporting that reflects current status. Endaxi AIG is designed for this practical layer of work, combining ISO/IEC 42001 workflows with EU AI Act classification and audit-ready documentation without turning implementation into a major enterprise platform project.

The most useful readiness question is simple: if an auditor asked tomorrow how one specific AI system is governed, could the organisation demonstrate the answer from registration through to review? Build the AIMS until that answer is consistently yes.