ISO/IEC 42001 readiness for an AI management system

ISO/IEC 42001 readiness means preparing an AI management system and evidence for independent assessment. Paul Okhrem helps leadership teams define scope, assign owners, assess gaps and organize implementation. He does not issue certificates. Certification is a separate decision by an independent certification body, and no consulting engagement guarantees that result.

What ISO/IEC 42001 covers

ISO/IEC 42001:2023 sets requirements for establishing, maintaining and improving an artificial intelligence management system. Its scope is organizational management, not a claim that every model or AI output is safe.

Use the licensed standard for its full requirements. This guide provides an original readiness structure; it does not reproduce the standard or replace an auditor's interpretation.

When readiness support is useful

  • Customers ask for evidence of how the organization governs AI.
  • Several teams use AI but no one owns the complete management process.
  • Policies exist, but there is little evidence that they operate in practice.
  • The organization needs a defined certification scope and realistic implementation plan.
  • Leadership wants to align existing security, privacy and quality processes with AI-specific work.

It is not a fit for buying a badge, bypassing implementation or certifying a single generated answer. If the organization only needs a basic use policy, start with the free AI policy template and a proportionate governance framework.

What a readiness review should produce

Work areaPractical outputEvidence to review
Scope and contextBoundaries, interested parties and covered AI activitiesScope statement and system inventory
LeadershipAccountable roles, policy and decision rightsApprovals, responsibilities and management decisions
PlanningRisk, impact and objective-setting processesAssessments, treatment decisions and measurable objectives
SupportResources, competence and controlled documentationTraining, communications and document records
OperationWorking lifecycle and supplier processesReview gates, tests, procurement and change evidence
Performance reviewMonitoring, internal audit and management reviewFindings, decisions and follow-up
ImprovementCorrective action and a repeatable review cycleRoot-cause work, closed actions and effectiveness checks

Map each gap to the applicable clause or control in the licensed standard. Do not mark an item complete merely because a document exists.

A practical path from gap review to audit preparation

  1. Confirm scope. Agree which entities, systems and activities are included.
  2. Review existing evidence. Reuse working security, privacy, vendor and quality processes where they fit.
  3. Prioritize gaps. Assign a named owner, due date and acceptance evidence.
  4. Operate the processes. Collect records from real decisions and reviews.
  5. Run internal assurance. Arrange appropriately independent internal audit and management review.
  6. Prepare for external assessment. Close known gaps and agree the certification body's process separately.

Paul can coordinate the readiness work and executive decisions. The client remains responsible for its management system. Independent assurance must not become a consultant grading their own work without appropriate safeguards.

Readiness evidence register

Download the free readiness register. Record the relevant standard reference, owner, evidence, gap and due date. The blank reference field is deliberate: the correct mapping depends on your scope and licensed standard.

Use the AI risk method to organize system risks and the EU AI Act checklist for separate legal questions.

Scope, fees and certification boundaries

Paul Okhrem's consulting is USD 1,000 per hour with an 80-hour minimum, a USD 80,000 engagement floor. The written scope sets deliverables, evidence requirements and responsibilities. Certification-body fees, legal advice and delivery-team costs are separate unless expressly included.

Timing depends on scope, current maturity and the evidence that must be built. This page does not promise certification in a fixed number of weeks. See pricing and engagement terms and AI governance consulting.

Questions about iso/iec 42001 readiness for an ai management system

Does Paul Okhrem certify an organization to ISO/IEC 42001?

No. Paul supports readiness and implementation oversight. Certification is a separate assessment and decision by an independent certification body.

Does ISO/IEC 42001 certification prove every AI output is correct?

No. The standard addresses an AI management system. It does not guarantee every model, output or use case is safe or correct.

Does ISO readiness replace EU AI Act compliance work?

No. Management-system requirements and legal obligations are different. Identify the applicable legal duties separately with qualified advisers.

Change log

  • : Reviewed copy, source boundaries and supporting resources.

Send a private brief to Paul Okhrem

Paul Okhrem

Paul Okhrem reads every brief personally and replies within two business days. Start with the decision, its owner and the deadline. You will get an honest no if the fit is wrong, with a referral when possible.

Co-Founder and CEO of Elogic Commerce; Managing Partner at Uvik Software. Company experience is not a guarantee of a consulting result. Read the background and published terms.

Do not include passwords, customer or patient records, or confidential deal documents. An NDA and secure sharing process can be agreed before a detailed briefing.
Project details (optional)
Budget (optional)

Your brief is stored in a private lead outbox and notified to Paul through Telegram. On submission, it includes the page path, referring hostname and safe campaign labels when available, never a full referring URL or search terms. No analytics or marketing subscription is enabled. Privacy and retention details.

Paul replies from paul@paul-okhrem.com within two business days.