ISO/IEC 42001 is the international standard for AI management systems. It was published in late 2023 and has spent the last two years quietly becoming a procurement question. By 2026, "are you ISO 42001 aligned" sits in the same RFP slot that "are you ISO 27001 certified" did fifteen years ago.
The temptation is to treat the standard as a certification chase. Hire a consultant, build a binder, pass an audit, put the badge on the website. I have watched organisations do exactly this with 27001 and SOC 2 and end up with paperwork that has nothing to do with how the system actually runs.
42001 is the wrong place to make that mistake.
Why the binder approach fails here
ISO 27001 is about controls over information assets. The controls and the system can be loosely coupled — you can have a strong policy that is poorly implemented, and the system still mostly works.
42001 is about the management of AI systems whose behaviour drifts. The controls and the system are tightly coupled. A policy that is poorly implemented produces a system whose outputs you literally cannot trust month over month. Auditors who know what they are doing — and the next wave of them will — will spot the gap inside an hour.
The framing that works is to treat 42001 as a system-design guide that happens to be auditable, rather than as an audit framework that happens to be technical.
The controls, translated
Here is how I have come to think about the six 42001 control areas that come up most in delivery, and the artefact each one becomes when you build the management system into your program rather than around it.
AI policy and governance charter. The standard wants a policy. The artefact is a two-page document naming roles, accountabilities, escalation paths, and the criteria under which an AI system gets paused. Signed by the executive sponsor. Reviewed quarterly. Lives in the same repository as the operational workflows it governs, not on a SharePoint nobody can find.
AI impact and risk assessment. The standard wants risk assessment. The artefact is a per-use-case sheet that scores each AI workflow on harm potential, reversibility, regulatory sensitivity, and confidence in the eval harness. Not a per-organisation risk register — a per-use-case one. The retail transformation program had eleven workflows; we wrote eleven impact assessments. Each one took a few hours.
Data and model lifecycle controls. The standard wants provenance. The artefact is a model and dataset registry that names every model in use, where it came from, who owns it, what data it sees, when it was last evaluated, and what happens when it is retired. Two pages of metadata per model. Updated whenever a model changes.
Human oversight and intervention. The standard wants human control. The artefact is the human-gate map — a single diagram for each workflow showing where humans intervene, what they have the authority to do at each gate, and what triggers an escalation. The mistake is to treat human gates as ceremonial. They earn their place by what they can stop. A human-gate map is, in operational terms, the document that names which human is navigating which agent at which boundary. The agent drives the work between gates. The human navigates at every gate. Anything else is documentation theatre.
Evaluation and continual improvement. The standard wants ongoing measurement. The artefact is the eval harness itself — the test suite each agent runs against, the drift signals, the rotation cadence for adversarial cases, the quarterly review of which workflows still deserve to run. A workflow that has not been re-evaluated in six months should not be in production.
Audit trail and reporting. The standard wants traceability. The artefact is the single ledger that captures every workflow run — inputs, outputs, model used, gate decisions, human approver, cost — in a form that ops, risk, and external auditors all read from. One surface, three audiences. If you have built this, the audit is a read query.
How long this actually takes
For a program with eight to twelve AI workflows in active use, the artefacts above can be authored in roughly six weeks if a senior engineer and a governance lead work together with leadership air cover. They can be authored in twelve weeks if you treat them as a side project. They can be authored in twenty-six weeks if you let a consultancy build a binder.
The shape of the conversation in the room matters more than the headcount. If your AI architect, your delivery lead, and your governance lead are the same three people writing the artefacts together, the system is real. If they are separate people writing separate documents that get stapled together at the end, you have a binder.
A workflow that has not been re-evaluated in six months should not be in production.
The auditability question
42001 can be certified or not. As of 2026, certification bodies are still small in number and the audit market is forming. For many organisations the right answer for the next eighteen months is "aligned, not yet certified" — produce the artefacts, run the system, be ready to certify when the audit market matures and procurement starts asking for the badge specifically.
The argument against waiting is that procurement is already asking. The argument for waiting is that early audits are expensive and the assessors are still learning. I have advised both sides; the right choice depends on which RFPs you are losing.
Where to start
If you are running an AI workflow in production today, write the impact assessment for it this week. One page. Harm potential. Reversibility. Regulatory sensitivity. Eval confidence. Tomorrow’s you will be grateful.
If you have not started 42001 work and you have three or more AI workflows in production, the policy charter is the first artefact. It will surface every gap in roles and escalation that the rest of the system will need.
Treated this way, 42001 stops being a paper exercise and starts being what it was designed to be: a way of running AI that risk functions, leadership teams, and your future audit committee can stand behind. That is worth doing for its own sake. The certificate, if and when you go for it, is a downstream consequence.