ISO/IEC 42001:2023 — AI Management Systems

AI Management System Certification

ISO 42001
Consultant

ISO 42001 consulting for companies that build or use AI and now have to show a customer, an auditor or a regulator how that AI is governed, with particular depth in regulated industries. Fixed-fee gap assessment, implementation support and certification audit preparation.

"Keep it Simple. Keep it Real."

100%
Pass Rate
200+
Happy Clients
A to Z
Full Service
Jared Clark, ISO 42001 Consultant

Who This Is For

Three reasons companies come to us about ISO 42001

ISO/IEC 42001 is the certifiable standard for an artificial intelligence management system. The companies asking about it tend to fall into two groups: those that build AI into what they sell and are being asked to prove it is governed, and those that use AI inside work a regulator or auditor already watches. We work with both, and we do our best work where the two meet.

A regulator or auditor is asking

In April 2026 FDA issued its first warning letter citing inappropriate use of artificial intelligence under 21 CFR 211.22(c): specifications, procedures and master records written by AI and released without qualified review. ISO 9001 and ISO 13485 auditors are asking the same question in their own words. If AI touches your records, someone will ask who approved them. See ISO 42001 for GMP manufacturers.

You sell AI or software and customers are asking

Enterprise buyers started writing ISO 42001 into vendor security reviews and questionnaires in 2026. Sometimes they want a certificate; more often they want documented alignment with the standard's controls. If your product includes AI, the answer has to exist before the questionnaire arrives, and your team has to be able to defend it on a call. See ISO 42001 for AI and software companies.

You already hold ISO 9001, 13485 or 27001

ISO 42001 is built on the same Annex SL structure as the standards you already certify to. Most of clauses 4 through 10 exist in your system today. What is missing is the AI-specific content, and adding it is a much smaller project than starting a management system from nothing. See ISO 42001 for ISO 9001 certified companies.

What The Standard Is

ISO 42001 in plain terms

ISO/IEC 42001:2023 was published in December 2023. It describes an AI management system: the policies, roles, risk assessments, records and reviews an organization uses to keep the AI it develops or uses under control. Clauses 4 through 10 follow the same pattern as ISO 9001, ISO 27001 and ISO 13485, which is why companies holding those certificates have a head start. Annex A adds the AI-specific controls, grouped into nine areas that cover policy, roles, resources, impact assessment, the AI system lifecycle, data, information for interested parties, use of AI systems and third-party relationships.

Certification is issued by an accredited certification body after a Stage 1 and Stage 2 audit, exactly as with ISO 9001. Fewer than a hundred organizations held a certificate in January 2026 and roughly 350 did by spring, so the auditors are still few and the queues are real. The standard is not required by any US law. It also does not, on its own, satisfy the EU AI Act: the European version was adopted in March 2026 but has not been cited in the Official Journal, and the standard being written to carry the AI Act's quality-management requirements is prEN 18286. We explain that in ISO 42001 and the EU AI Act.

In our view the useful way to think about ISO 42001 is not as an AI project at all. It is a quality-system question applied to a new kind of tool: what does it do, who owns it, what could go wrong, how do we know, and what is the record. Companies that already answer those questions for their equipment and suppliers can answer them for AI. That is the whole of our approach. Read What is ISO 42001? for the longer version.

How We Work

Fixed fees, stated up front

Two fixed-fee starting points and one scoped engagement. You know the price before we begin, and you own everything we produce.

Fixed fee

ISO 42001 Gap Assessment

$9,750

A two-to-three-week review of your AI systems against every clause and every Annex A control, ending in a written report, a prioritized plan and an honest estimate of the time and cost to certification.

What the gap assessment covers

Fixed fee

AI in the Quality System Review

$5,000

For GMP, ISO 9001 and ISO 13485 sites. We find where AI is already writing, checking or deciding inside your quality system and tell you whether those records would survive an inspection.

What the review covers

Scoped after the assessment

Implementation and Audit Preparation

Quoted

Policies, the AI system inventory, impact assessments, the Statement of Applicability, training, internal audit and a mock certification audit. Priced from the gap report, so you pay for the gaps you actually have.

How implementation runs

The Process

8 Steps to ISO 42001 Certification

The same eight-step method we use for every management system, with the AI-specific work in the places the standard puts it.

1

Gap Assessment

Inventory every AI system in use, including the ones nobody told IT about, and measure your current practice against each clause and control.

2

AI Policy & Documentation

An AI policy with an owner, the objectives behind it, and the documented information clause 7.5 expects, built inside your existing document control.

3

Risk & Impact Assessment

AI risk assessment and AI impact assessments for the systems that affect people, products or decisions, using the risk method your system already has.

4

Implementation

The Statement of Applicability, the Annex A controls that apply to you, supplier AI terms, and approval workflows for AI-assisted work.

5

Training

Awareness for everyone who touches AI and competence for the people who own it, recorded in the training system you already run.

6

Workflows & Controls

Human oversight where it matters, change control for AI systems and prompts, monitoring, and a record trail an auditor can follow.

7

Internal Audit

A full internal audit against the standard and a mock Stage 2 so the certification audit holds no surprises.

8

Management Review & Metrics

The measures clause 9 asks for, a management review that actually reviews AI, and the improvement loop that keeps the certificate.

Why Us

A quality-systems consultant for an AI standard

Most firms offering ISO 42001 come from information security. They know ISO 27001 and they know software companies. Our practice comes from the other side: quality systems and regulatory affairs for FDA-regulated manufacturers, where the questions ISO 42001 asks about AI are questions we have been answering about equipment, software and suppliers for years. For AI and software companies that means working alongside the security team and the ISO 27001 or SOC 2 program you already have, and adding the management-system discipline those programs do not fully cover.

Jared Clark, our principal consultant, holds a JD and an MBA, is a Certified Manager of Quality/Organizational Excellence, Certified Quality Auditor and Certified Pharmaceutical GMP Professional through ASQ, holds the Regulatory Affairs Certification from RAPS and the PMP, and is certified in Computer System Validation, Computer Software Assurance and Pharmaceutical Validation Management. That last group matters here. Deciding whether an AI tool is fit for use inside a regulated process is a validation question before it is a governance question, and the answer has to satisfy 21 CFR Part 11 and GAMP 5 as well as ISO 42001.

Credentials and verification links are on the About page.

What that background changes in practice

  • We build the AI management system inside the quality system you have, not beside it. One document control, one CAPA, one management review.
  • We treat AI-generated records the way an FDA investigator will: who reviewed them, what qualified that person, and where the approval lives.
  • We know what a certification auditor can and cannot ask for, because we have prepared clients for hundreds of management-system audits under the same Annex SL structure.
  • We will tell you when certification is not worth it yet. Documented alignment answers most procurement questionnaires; a certificate is a bigger commitment.

Guides

Read before you decide

The questions every buyer asks, answered in enough detail to plan a budget and a timeline.

Included At No Additional Cost

LeanISO software

Every ISO 42001 engagement includes access to our LeanISO platform for the AI system inventory, impact assessments and risk register, document control, internal audit scheduling and corrective actions. You keep it after certification.

Included

with every engagement

Frequently asked questions

Is ISO 42001 certification required by law?

No. ISO 42001 is a voluntary international standard. Demand for it comes from customers and procurement teams asking vendors for it, from insurers, and from regulators asking how AI inside a regulated process is controlled. It does not by itself satisfy the EU AI Act; the standard being written for that purpose is prEN 18286.

How long does ISO 42001 certification take?

Four to twelve months from gap assessment to certificate is typical. Organizations with a working ISO 9001, ISO 13485 or ISO 27001 system are usually at the short end because the management-system clauses already exist. Certification bodies have reported auditor backlogs, so booking the audit early matters.

How much does ISO 42001 consulting cost?

Our gap assessment is a fixed $9,750 and our AI-in-the-quality-system review is a fixed $5,000. Implementation support is scoped after the gap assessment. Certification body fees are separate and depend on the body and the size of the audit.

We already have ISO 9001. How much of it counts toward ISO 42001?

A great deal. ISO 42001 uses the same Annex SL structure, so context, leadership, planning, support, operation, performance evaluation and improvement already exist in your system. What is new is the AI-specific content: an inventory of AI systems, AI impact assessments, Annex A controls and evidence of human oversight.

Does ISO 42001 apply if we only use AI tools rather than build them?

Yes. The standard covers organizations that develop, provide or use AI systems. A manufacturer using a vendor's AI in quality, planning or documentation is within scope, and the controls on supplier AI and on reviewing AI-generated records are the ones that matter most for that company.

We already have SOC 2 or ISO 27001. How big is an ISO 42001 project?

Smaller than starting from nothing, and the overlap differs. ISO 27001 already gives you the management-system clauses, a risk process and a Statement of Applicability, so ISO 42001 mostly adds AI-specific content. SOC 2 gives you control evidence and audit habits but not the management-system clauses, so there is more to build. Either way the new work is the AI system inventory, AI impact assessments, the Annex A controls that apply, and records of how models and prompts are changed and overseen.

Why does FDA matter for an ISO standard?

In April 2026 FDA issued a warning letter citing inappropriate use of artificial intelligence under 21 CFR 211.22(c): AI-written specifications, procedures and master records released without qualified review. For a GMP manufacturer, governing AI is now an inspection question, and ISO 42001 is the management-system way to answer it.

Find out where you stand on ISO 42001

Schedule a free 30-minute consultation. We will ask what AI you use, what systems you already certify to, and who is asking you for ISO 42001, then tell you plainly what certification would take.

Or email us at [email protected]