ISO 42001 Consulting and AI Governance

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

Our ISO 42001 consulting helps organisations govern artificial intelligence with an AI management system (AIMS) that meets ISO/IEC 42001:2023 and is ready for certification. Security Solution Consultants (SSC) takes you from a first inventory of AI use to a working management system: AI policy, risk and impact assessments, controls across the AI life cycle, supplier oversight, internal audit and certification support.

AI governance committee around a conference table with a glowing network projected on the wall, representing ISO 42001 consulting
An AI management system turns good intentions about AI into accountable decisions.

Why ISO 42001 now

ISO/IEC 42001:2023 is the first certifiable management system standard for AI. Customers, regulators and procurement teams increasingly ask how AI is governed, and the EU AI Act applies to many organisations that offer AI systems in the European market. A certified AIMS gives one structured, auditable answer, and because it follows the same structure as ISO/IEC 27001, it integrates with the information security management system many organisations already run.

Our ISO 42001 consulting services

  • AI readiness and gap assessment against the clauses of ISO/IEC 42001 and its Annex A control objectives.
  • AI inventory and roles: every AI system you build, buy or use, with its owner, purpose, data and your role as provider, developer or user.
  • AI policy and objectives approved by leadership, with clear accountability.
  • AI risk assessment aligned with ISO/IEC 23894, integrated with your enterprise risk framework.
  • AI system impact assessment of effects on individuals, groups and society, in line with ISO/IEC 42005.
  • Controls and Statement of Applicability for data quality, transparency, human oversight, monitoring and third-party AI services.
  • Internal audit, management review and certification support through Stage 1 and Stage 2 audits with your chosen certification body.

From AI inventory to risk register

Monitor showing a grid of connected cards with a hand pointing at one, representing an AI system inventory and risk register
You cannot govern AI you have not found.

Most organisations find more AI than they expected: features inside SaaS tools, copilots, analytics models, chatbots and agents built by individual teams. We run a structured discovery, classify each system by risk, and link each one to the risks, controls and owners in a single register, so the AIMS covers what is really in use.

Impact assessments that hold up

Workshop group placing cards on a wall under a softly glowing face silhouette, representing AI system impact assessment
Impact assessment looks beyond the organisation to the people an AI system affects.

ISO/IEC 42001 asks you to assess the potential consequences of AI systems for individuals, groups and society. We facilitate those assessments with product, legal, privacy and risk teams, record decisions and residual risks, and set the triggers for reassessment when a model, its data or its use changes.

How we deliver

  1. Discover: inventory and gap assessment, two to four weeks depending on scale.
  2. Design: policy, roles, risk and impact methods, Statement of Applicability.
  3. Implement: controls, supplier requirements, monitoring and training.
  4. Assure: internal audit and management review.
  5. Certify: support through the certification audit and any corrective actions.

Why work with SSC

  • We build AI into our own GRC platform, so we understand AI risk from the inside.
  • SSC is certified to ISO/IEC 27001 and integrates ISO 42001 with your existing ISMS instead of creating a parallel system.
  • The GRCLens ISO 42001 module holds your AI inventory, risks, impact assessments and evidence.

Related: ISO 42001 training, our agentic AI risk assessment checklist, ISO 31000 vs ISO 23894 and certification and accreditation services.

Frequently asked questions

ISO/IEC 42001:2023 is the international standard for an artificial intelligence management system. It sets requirements for governing the development, provision and use of AI responsibly, and organisations can be certified against it.

It depends on how much AI you use and what governance already exists. A focused scope with an existing ISO 27001 ISMS can often be ready for certification in a few months; broader scopes take longer.

No, but organisations with ISO 27001 can reuse much of their management system, including risk management, internal audit, management review and document control.

Yes. The standard covers AI you provide, develop or use, including third-party AI services, and expects you to set requirements for and monitor those suppliers.

An independent, accredited certification body. SSC prepares you for certification and supports you through the audits, but does not issue the certificate.

Talk to us about ISO 42001 and AI governance

Tell us where you are today and what you need to achieve. We will come back with a clear scope, timeline and fixed quote.