Prove You Govern Your AI. Before Someone Asks You To.
ISO/IEC 42001 is the first certifiable standard for AI management systems — and right now it is the strongest evidence of responsible AI you can actually hand a buyer.
Every company now says its AI is safe, governed and human-overseen. Almost none can demonstrate it independently. As AI features move into regulated industries — finance, health, legal, public sector — buyers have started asking for proof, and a blog post about your principles is not proof.
ISO 42001 follows the same shape as other management system standards: clauses 4 to 10 define the system, and Annex A provides 38 controls across nine objectives covering AI policy, risk, lifecycle management, data governance, transparency and human oversight.
- An AI inventory you can defend
- Lifecycle governance, not sign-offs
- Real human oversight
- A head start on the EU AI Act
- Standard
- ISO/IEC 42001:2023
- Typical timeline
- 4–10 months
- Certificate valid
- 3 years
- Annex A controls
- 38 across 9 objectives
Annex A controls
Control objectives
Years a certificate lasts
EU AI Act high-risk deadline
ISO/IEC 42001:2023 — the standard, not the sales pitch
Everyone Claims Responsible AI. Almost Nobody Can Show It.
The gap between what companies say about their AI and what they can evidence has become a commercial liability.
An AI estate nobody has mapped
Models in production, vendor tools adopted by individual teams, features shipped before governance existed. The first honest inventory is usually a surprise to leadership.
Risk you cannot see or price
Oversight that exists on paper
A policy says a human reviews outputs. Nobody can name who, show when they last intervened, or produce the record. Auditors and buyers both test exactly this.
A claim that collapses under questioning
Regulation arriving on a timetable
The EU AI Act's principal high-risk obligations have been deferred to December 2027, not cancelled. Buyers in regulated sectors are already writing AI clauses into contracts today.
A deadline that only moves once
Building an AI Management System That Certifies
AI governance fails when it is a committee that meets quarterly. The standard requires it to be built into how systems are actually developed and run.
01 / 09
AI System Inventory & Scope
You cannot govern what nobody has written down.
We identify every AI and machine learning system in the business — including the ones procured by a team without telling anyone — classify them by risk and intended use, and set the certification scope around them.
What the Next Few Months Actually Look Like
Ranges, not a single number. Where you land inside them depends almost entirely on what already exists on day one.
- Phase 01
Week 0 · free
Gap analysis
We assess what you already do against the standard and hand back a prioritised plan with effort and dates against every gap. You keep it whether or not you continue with us.
We doAssess, document, price the work
You doA few hours of interviews
- Phase 02
Weeks 1–3
Scope, risk and the paper foundation
Certification scope agreed, risk methodology set, and the mandatory documents drafted — including the Statement of Applicability, the document auditors scrutinise hardest.
We doDraft everything, run the risk workshops
You doDecisions on scope and risk appetite
- Phase 03
Weeks 3–12
Implementing the controls
The longest phase and the one that varies most. Controls are built into your real systems rather than described in a document, with our engineers working alongside yours where the gaps are technical.
We doBuild, configure, evidence
You doAccess, and engineering time where unavoidable
- Phase 04
Concurrent
Training and awareness
Role-based training so the people an auditor interviews can answer confidently, plus a mock interview session so nobody meets these questions for the first time in the room.
We doDeliver training, run the dry run
You doGet your team in the room
- Phase 05
Min. 3 months in
Operate, internal audit, management review
The system must run long enough to produce real evidence — certification bodies generally expect around three months of operation before Stage 2. We run the mandatory internal audit and management review and close what they raise.
We doInternal audit, review, remediation
You doLeadership attendance at the review
- Phase 06
Then 30–60 days
Stage 1, Stage 2, certificate
Stage 1 reviews documentation and readiness. Stage 2, typically 30 to 60 days later, tests whether you genuinely operate the system. We prepare the evidence pack and attend both with you.
We doPrepare evidence, manage the auditor, handle findings
You doBe available for interviews
Where you land in the range depends on your starting point, your scope, and how much evidence already exists. Anyone quoting a fixed number of weeks before seeing your estate is guessing.
How We Run an ISO 42001 Programme
AI governance only works when it lives in the pipeline.
Inventory
Every AI system found, classified and scoped.
Impact & Risk
Effects on people and business, assessed and recorded.
Policy & SoA
All 38 controls judged, justified and documented.
Embed
Control points built into the ML lifecycle itself.
Operate & Audit
Evidence accumulates; internal audit finds gaps first.
Certify
Stage 1, Stage 2, certificate — then surveillance.
THEN BACK TO 01 — EVERY NEW MODEL RE-ENTERS HERE
Where AI Governance Is Already Being Asked About
Wherever an AI decision affects a customer, a patient, a claim or a citizen, someone is going to ask how that system is governed.
SaaS & Technology
Where enterprise security review is the single biggest drag on the sales cycle, and ISO 27001 is asked for by name.
Financial Services
Banking, payments and fintech, where supplier assurance is a regulatory expectation rather than a preference.
Health & Life Sciences
Patient and trial data carries obligations that buyers will not take on trust from an unaudited supplier.
Public Sector & Defence
Frameworks and tenders that list certification as a pass-or-fail eligibility criterion before scoring begins.
Retail & E-Commerce
Payment data, large supply chains, and sustainability criteria appearing in more and more supplier scorecards.
Professional & Legal
Client confidentiality, continuity obligations, and the quality assurance that panel appointments increasingly require.
Working across
ISO 42001 Matters If You Ship AI
Tick what applies.
00 OF 06
Worth getting ahead of — this question is coming.
Fixed Scope. Fixed Fee. No Surprises.
Compliance consultancy has a reputation for open-ended day rates and a bill that grows with the project. We price the work after the gap analysis, when both of us know what it involves.
What you get
- A free gap analysis before you commit to anything
- A fixed implementation fee, quoted once the scope is known
- Senior consultants doing the work, not supervising juniors
- Documentation written for your business, never a template pack
- We attend Stage 1 and Stage 2 with you
- Support through the surveillance years, not just to the certificate
What we will not do
- Sell you a certificate — an accredited body issues that, independently
- Bill by the hour for work we should have scoped properly
- Promise certification in a number of weeks the standard does not allow
- Hand over a policy binder and disappear before the audit
- Take commission for recommending a certification body
- Claim an ISO certificate makes you compliant with a law it does not cover
What ISO 42001 does and does not get you
ISO/IEC 42001 is not currently a harmonised standard under the EU AI Act, so certification does not grant a presumption of conformity with it. We would rather tell you that up front than let you discover it later. What certification does give you is independently audited evidence of the governance the Act expects — which is both commercially useful today and a substantial head start on the technical documentation.
- Certification is issued by an independent accredited certification body, not by us
- It does not, by itself, make you EU AI Act compliant
- The risk assessments and lifecycle records map directly onto AI Act technical documentation
- The AI Act timeline has moved — the Digital Omnibus deferred principal high-risk obligations for standalone Annex III systems to December 2027 — so you have runway, not an excuse
We Build AI Systems, So We Govern Them Properly
We ship LLM and machine learning products ourselves. That is the difference between governance designed into a pipeline and governance bolted on as paperwork.
Controls inside your MLOps◆Honest model inventories◆Oversight that actually functions◆No AI governance theatre◆Straight talk on the AI Act
WE DO NOT WRITE YOU AN AI ETHICS POSTER
Trusted by startups, enterprises, and governments worldwide










































































































The stack behind the platforms we build.
We choose tools for the outcome they deliver, not for the trend they follow.
Frontend
8 tools“Knowledgeable, professional, and responsive — Devtrios added real value at every step of our project and delivered exactly what we needed.”
Where Our Clients Rate Us 5 Stars
Our clients don't just work with us, they recommend us — 4.9 on Google, 5.0 on Clutch and GoodFirms. Every badge below links straight to the profile it comes from. Independent reviews keep pointing to the same three things: strong technical expertise, clear communication, and delivery you can rely on.
Recognised on
Verified reviewsFrequently Asked Questions
Everything you might want to know before we talk. Still unsure? A quick call clears it up.
Ask us anythingISO/IEC 42001:2023 is the international standard for an AI management system — the first standard against which an organisation can actually be certified for how it governs artificial intelligence. Like ISO 27001, it has management system requirements in clauses 4 to 10, plus an Annex A of controls: 38 of them, grouped under nine objectives covering AI policy, internal organisation, resources, impact assessment, lifecycle management, data governance, information for interested parties, use of AI systems, and third-party relationships.
No. ISO/IEC 42001 has not been cited as a harmonised standard under the AI Act, so certifying against it does not confer a presumption of conformity. The honest framing is that it is the strongest head start available: the governance structures, risk and impact assessments, and lifecycle records that 42001 requires feed directly into the technical documentation the Act demands. Treat it as substantial preparation, not as a compliance certificate for the Act.
Yes. The Digital Omnibus on AI, published in the Official Journal in July 2026, deferred the principal high-risk obligations for standalone Annex III systems from August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products to August 2028. Separately, CEN-CENELEC published EN 18286 in 2026 covering the quality management system required of high-risk AI providers, though its reference has not yet been cited in the Official Journal. The direction of travel has not changed; the deadlines have moved.
Very possibly, yes. ISO 42001 explicitly covers the use of AI systems and third-party relationships, not just their development. If you deploy someone else's model into a decision that affects customers, you carry governance responsibility for that deployment. In practice, organisations that only consume AI often find certification faster to achieve, because the lifecycle controls sit at the procurement and monitoring layer rather than in training pipelines.
They share the same management system structure, so if you already hold ISO 27001 a large part of the foundation — context, leadership, competence, internal audit, management review, improvement — is already built and audited. Adding ISO 42001 on top is considerably cheaper than starting cold, and certification bodies can often run combined audits.
Typically four to ten months. Organisations with an existing ISO 27001 management system and a reasonably disciplined ML practice sit at the shorter end. The work that usually takes longest is not the paperwork — it is building an honest inventory of every AI system in use, including the ones individual teams adopted without telling anyone.
Get ahead of the AI governance question
Most companies do more AI governance than they can prove. The gap analysis shows you what is already defensible and what is not — at no cost.
Start Your Next Project with Devtrios
Tell us about your idea or business needs. Our team will review your requirements and get back to you within one business day with a clear plan, timeline, and a free consultation call.



