Comply · Certification

    ISO 42001 without the two-year detour

    An AI management system your certification body accepts: gap analysis, the controls that are actually missing, documentation that holds, and a rehearsed audit.

    Sound familiar?

    • A customer or tender now requires certification and the clock is running.
    • You have policies, but no management system that ties them to evidence.
    • The standard reads abstractly and nobody can say what it means for your AI systems.
    • Existing ISO 27001 work should count, and nobody has mapped it.

    What we do

    Gap analysis

    Clause by clause against your current reality, including what ISO 27001 already covers.

    AIMS build-out

    Scope, roles, risk process, objectives and controls — sized for your organisation, not a template.

    Documentation

    The records the auditor will ask for, produced as a by-product of how you work.

    Audit preparation

    Internal audit, management review, and a dry run of the certification interviews.

    Go deeper

    Questions we get

    Do we need EU AI Act compliance too?

    They are different things: the AI Act is law, ISO 42001 is a voluntary certifiable standard. The management system helps you demonstrate AI Act obligations, but it does not replace them.

    How long does certification take?

    For a focused scope, typically six to nine months from gap analysis to certification audit.

    Do you certify us?

    No — certification comes from an accredited body. We get you ready for them and stay with you through the audit.

    Tell us what's running in production.

    We'll tell you what we'd check first — and what we wouldn't bother with.

    Book a call
    Related
    More in Comply