ISO/IEC 42001 / AI MANAGEMENT SYSTEMS

ISO 42001 consultant for the age of agents.

I help organizations that build and use AI on Azure and Microsoft 365 put an AI management system in place: clear ownership, risk assessment, controls and evidence aligned with ISO/IEC 42001.

01 / THE STANDARD

What ISO 42001 asks for.

ISO/IEC 42001:2023 is the international standard for an AI management system (AIMS). It sets requirements for establishing, implementing, maintaining and continually improving how an organization governs the AI it develops, provides or uses.

It follows the same management-system structure as ISO 27001, so it can be integrated with an existing information security program. It is voluntary, and organizations can be certified against it. Only an accredited certification body can certify; advisory work, including mine, does not grant certification.

Core areas

  • Context, scope and interested parties
  • Leadership, AI policy and accountability
  • AI risk and impact assessment
  • Lifecycle controls for data, development, deployment and suppliers
  • Monitoring, internal audit and management review
  • Corrective action and continual improvement

02 / HOW I HELP

From gap to evidence.

I work directly with you to turn the standard into practical decisions your teams can follow, without building a paper system nobody uses.

Typical work

  • AI system inventory and scoping
  • Gap assessment against the standard's clauses and Annex A controls
  • AI risk and impact assessment method
  • Policies, roles and approval workflows
  • Control design on Azure and Microsoft 365
  • Evidence collection and audit preparation

If you decide to pursue certification, I help you prepare. The audit itself is performed by an accredited certification body.

Read the gap assessment checklist

03 / ON THE MICROSOFT STACK

Controls you can evidence.

Many ISO 42001 controls can be supported by tools you may already run. Microsoft's own certifications and documentation help, but they do not cover how your organization configures and uses its services. That responsibility stays with you.

Where evidence often comes from

  • Access to AI systems and data: Microsoft Entra ID, Conditional Access, least privilege
  • Data governance: Microsoft Purview sensitivity labels, DLP and retention
  • Monitoring and detection: Microsoft Defender and Microsoft Sentinel
  • Testing and monitoring of agents: Microsoft Foundry evaluations and tracing
  • Records: policies, risk registers and management review minutes
See my AI security work

04 / COMMON QUESTIONS

ISO 42001,
answered.

Is ISO 42001 mandatory?

No. It is a voluntary standard. Customers, regulators or procurement teams may ask for it, and it can be a useful structure even if you never certify.

Can you certify us?

No. Certification is granted by accredited certification bodies after an independent audit. I help you assess gaps and prepare, and alignment is not the same as certification.

How is it different from ISO 27001?

ISO 27001 covers information security management. ISO 42001 covers the management of AI systems, including AI-specific risk, impact on people, transparency and responsible use. They share a structure, so they can be run together.

Does Microsoft's certification cover our AI use?

No. A platform provider's certifications cover its own services and processes. How you configure, govern and use them is your responsibility and needs your own evidence.

START WITH A GAP ASSESSMENT

Know where you stand
before the audit.

Book a free session