AI governance

ISO/IEC 42001 AI management system implementation

Make AI governance repeatable across the full system lifecycle. We help organizations identify AI uses, assess impacts and risks, assign accountability, and build evidence for an AI management system.

Our implementation focus

Make the requirements operational.

  1. 01

    Inventory AI systems and use cases

  2. 02

    Define AIMS scope, policy, roles, and objectives

  3. 03

    Assess AI risks and impacts

  4. 04

    Establish lifecycle controls and records

  5. 05

    Create monitoring, review, and improvement practices

Independent assessment

ISO/IEC 42001 is a management system standard. It does not replace applicable AI law, and independent certification decisions are made by a certification body.

Questions we hear

Get the distinctions right.

Does ISO/IEC 42001 compliance satisfy the EU AI Act?

No. ISO/IEC 42001 provides a management system for AI, while the EU AI Act imposes legal duties that depend on the organization’s role and the system. They should be assessed separately.

Do organizations that only use AI need an AI management system?

ISO/IEC 42001 is designed for organizations that provide or use AI systems. The appropriate scope and depth depend on AI use, impacts, and the organization’s objectives.

Can ISO/IEC 27001 controls be reused?

Security governance, supplier oversight, and evidence workflows can provide a foundation. AI-specific risks, impacts, lifecycle decisions, and affected-party considerations still need explicit treatment.

Work with Normstone

Build a defensible path to readiness.

Tell us the outcome you need and the markets involved. We’ll help define the work.

Start a conversation