ISO 42001 may be relevant if your organisation develops AI, embeds it in a service, or relies on AI-enabled tools to support important work. The first step is understanding how AI is actually used across the business.
Look beyond tools labelled as AI
Start by talking with teams about the systems they use and the work those systems support. AI may be part of a product you build, a supplier platform, an internal assistant or a process that uses automated recommendations.
Record the intended purpose, users, data involved, supplier, owner and level of human oversight. This inventory helps you see where a consistent approach could be useful.
Consider impact and responsibility
The right controls depend on context. Consider what happens if an AI system is inaccurate, unavailable, biased or used in an unexpected way. Think about the people affected, the data involved and whether a person reviews important outputs.
Clear accountability matters. Decide who approves AI use, who checks changes, how concerns are raised and when a system should be reviewed or retired.
Choose a system that fits
ISO 42001 provides a management-system framework for setting direction, assessing risks and impacts, operating controls and improving over time. It is not a certification that every AI output is correct or risk-free.
A readiness assessment can help you decide whether certification supports your customer commitments, governance needs and business plans. It should also show the work involved before you commit to a timeline.
Key points
- Inventory real AI use, including supplier tools.
- Assess effects on people, data and business decisions.
- Use certification to support clear governance, not as a claim that AI is risk-free.
Need help applying this to your organisation? Talk to Cybervisory.
