ISO/IEC 42001 · Artificial Intelligence Management

Move faster with AI — without losing control.

ISO/IEC 42001 establishes an AI management system that brings governance, risk-based thinking and oversight to how organisations develop, provide and use AI. We help you build it proportionately — for AI developers, providers and users.

What it is

A brief introduction to ISO/IEC 42001

ISO/IEC 42001 defines requirements for an AI management system, including AI policy, roles, risk and impact assessment, data and information management, transparency, human oversight, supplier governance and continual improvement.

CroftSpurr summaries are written in our own words. We do not reproduce copyrighted clauses from ISO standards.

Why organisations pursue it

Common business drivers.

You build, embed or deploy AI in products or operations.

Customers, investors or regulators are asking AI governance questions.

Internal use of AI has outpaced your policies and oversight.

You want a defensible position on responsible AI.

You plan to align with the EU AI Act and other emerging regulation.

Business benefits

Outcomes a well-built system can support.

01

Visibility of where AI is used, by whom and for what

02

Clear AI accountability across leadership, product and operations

03

Risk and impact assessment in advance — not after incidents

04

Confident answers to customer and investor scrutiny

05

Supplier AI governance, not blind trust

06

A foundation for emerging AI regulation

Common triggers

What usually prompts a project.

  • A flagship customer asks how AI is governed.
  • An investor or board member raises AI risk concerns.
  • An incident involving an AI tool has surfaced weak controls.
  • An AI feature is being launched without an approval route.
  • Internal use of generative AI is uncontrolled.

What implementation involves

The core building blocks.

  1. 01

    AI policy, objectives and organisational roles.

  2. 02

    AI system inventory, use cases and risk assessment.

  3. 03

    AI system impact assessment.

  4. 04

    Data and information management for AI.

  5. 05

    Transparency, communication and human oversight.

  6. 06

    Supplier AI governance and incident handling.

How CroftSpurr helps

A focused, hands-on approach.

Separate pathways for AI developers, AI providers and organisations using third-party AI.
Practical use-case inventory and risk assessment.
Impact assessment workshops aligned with ISO/IEC 42005.
Integration with information security (ISO/IEC 27001) and privacy.
Leadership briefings on responsible AI commitments.

Relationship with other standards

How it fits the wider picture.

  • ISO/IEC 23894 - Artificial Intelligence — Guidance on Risk ManagementGuidance on AI risk management — feeds 42001 risk processes.
  • ISO/IEC 42005Guidance on AI system impact assessment.
  • ISO/IEC 38507Governance implications of AI for the governing body.
  • ISO/IEC 27001Information security underpins AI management.

Typical project journey

What a project usually looks like.

  1. 01AI landscape workshop
  2. 02Use case inventory
  3. 03AI risk and impact assessment
  4. 04Policy and control design
  5. 05Implementation and oversight
  6. 06Internal audit and certification readiness

Certification

Consultancy and certification are different.

CroftSpurr helps you understand requirements, implement your management system and prepare for the certification audit. Independent certification is carried out by a separate certification body. We do not sell or issue ISO certificates.

FAQs

Common questions.

Is ISO/IEC 42001 only for AI developers?+

No. It applies to organisations that develop, provide or use AI. Many of our engagements involve organisations using third-party AI extensively.

How does ISO/IEC 42001 relate to the EU AI Act?+

They are not the same, but an ISO/IEC 42001-aligned management system gives you a strong foundation to meet AI Act and other regulatory obligations.

Can we combine ISO/IEC 42001 with ISO/IEC 27001?+

Yes — and we encourage it. The structures align and many controls overlap.

Fact check or approval required — verify implementation timeframes against client-specific scope

Make ISO/IEC 42001 useful to the business.

Start with a focused conversation.

Talk to CroftSpurr