ISO/IEC 42001 readiness for an AI management system
ISO/IEC 42001 readiness means preparing an AI management system and evidence for independent assessment. Paul Okhrem helps leadership teams define scope, assign owners, assess gaps and organize implementation. He does not issue certificates. Certification is a separate decision by an independent certification body, and no consulting engagement guarantees that result.
What ISO/IEC 42001 covers
ISO/IEC 42001:2023 sets requirements for establishing, maintaining and improving an artificial intelligence management system. Its scope is organizational management, not a claim that every model or AI output is safe.
Use the licensed standard for its full requirements. This guide provides an original readiness structure; it does not reproduce the standard or replace an auditor's interpretation.
When readiness support is useful
- Customers ask for evidence of how the organization governs AI.
- Several teams use AI but no one owns the complete management process.
- Policies exist, but there is little evidence that they operate in practice.
- The organization needs a defined certification scope and realistic implementation plan.
- Leadership wants to align existing security, privacy and quality processes with AI-specific work.
It is not a fit for buying a badge, bypassing implementation or certifying a single generated answer. If the organization only needs a basic use policy, start with the free AI policy template and a proportionate governance framework.
What a readiness review should produce
| Work area | Practical output | Evidence to review |
|---|---|---|
| Scope and context | Boundaries, interested parties and covered AI activities | Scope statement and system inventory |
| Leadership | Accountable roles, policy and decision rights | Approvals, responsibilities and management decisions |
| Planning | Risk, impact and objective-setting processes | Assessments, treatment decisions and measurable objectives |
| Support | Resources, competence and controlled documentation | Training, communications and document records |
| Operation | Working lifecycle and supplier processes | Review gates, tests, procurement and change evidence |
| Performance review | Monitoring, internal audit and management review | Findings, decisions and follow-up |
| Improvement | Corrective action and a repeatable review cycle | Root-cause work, closed actions and effectiveness checks |
Map each gap to the applicable clause or control in the licensed standard. Do not mark an item complete merely because a document exists.
A practical path from gap review to audit preparation
- Confirm scope. Agree which entities, systems and activities are included.
- Review existing evidence. Reuse working security, privacy, vendor and quality processes where they fit.
- Prioritize gaps. Assign a named owner, due date and acceptance evidence.
- Operate the processes. Collect records from real decisions and reviews.
- Run internal assurance. Arrange appropriately independent internal audit and management review.
- Prepare for external assessment. Close known gaps and agree the certification body's process separately.
Paul can coordinate the readiness work and executive decisions. The client remains responsible for its management system. Independent assurance must not become a consultant grading their own work without appropriate safeguards.
Readiness evidence register
Download the free readiness register. Record the relevant standard reference, owner, evidence, gap and due date. The blank reference field is deliberate: the correct mapping depends on your scope and licensed standard.
Use the AI risk method to organize system risks and the EU AI Act checklist for separate legal questions.
Scope, fees and certification boundaries
Paul Okhrem's consulting is USD 1,000 per hour with an 80-hour minimum, a USD 80,000 engagement floor. The written scope sets deliverables, evidence requirements and responsibilities. Certification-body fees, legal advice and delivery-team costs are separate unless expressly included.
Timing depends on scope, current maturity and the evidence that must be built. This page does not promise certification in a fixed number of weeks. See pricing and engagement terms and AI governance consulting.
Questions about iso/iec 42001 readiness for an ai management system
Does Paul Okhrem certify an organization to ISO/IEC 42001?
No. Paul supports readiness and implementation oversight. Certification is a separate assessment and decision by an independent certification body.
Does ISO/IEC 42001 certification prove every AI output is correct?
No. The standard addresses an AI management system. It does not guarantee every model, output or use case is safe or correct.
Does ISO readiness replace EU AI Act compliance work?
No. Management-system requirements and legal obligations are different. Identify the applicable legal duties separately with qualified advisers.
Change log
- : Reviewed copy, source boundaries and supporting resources.
Send a private brief to Paul Okhrem

Paul Okhrem reads every brief personally and replies within two business days. Start with the decision, its owner and the deadline. You will get an honest no if the fit is wrong, with a referral when possible.
Co-Founder and CEO of Elogic Commerce; Managing Partner at Uvik Software. Company experience is not a guarantee of a consulting result. Read the background and published terms.