Skip to content
DevTrios — Engineering Partner
ISO/IEC 42001:2023

Prove You Govern Your AI. Before Someone Asks You To.

ISO/IEC 42001 is the first certifiable standard for AI management systems — and right now it is the strongest evidence of responsible AI you can actually hand a buyer.

Every company now says its AI is safe, governed and human-overseen. Almost none can demonstrate it independently. As AI features move into regulated industries — finance, health, legal, public sector — buyers have started asking for proof, and a blog post about your principles is not proof.

ISO 42001 follows the same shape as other management system standards: clauses 4 to 10 define the system, and Annex A provides 38 controls across nine objectives covering AI policy, risk, lifecycle management, data governance, transparency and human oversight.

  • An AI inventory you can defend
  • Lifecycle governance, not sign-offs
  • Real human oversight
  • A head start on the EU AI Act
Control pointDataControl pointTrainControl pointEvaluateControl pointDeployControl pointMonitorAIMS — 38 controls, 9 objectivesGOVERNANCE AT EVERY STAGE, NOT A SIGN-OFF AT THE END
Standard
ISO/IEC 42001:2023
Typical timeline
4–10 months
Certificate valid
3 years
Annex A controls
38 across 9 objectives
0

Annex A controls

0

Control objectives

0

Years a certificate lasts

0

EU AI Act high-risk deadline

ISO/IEC 42001:2023 — the standard, not the sales pitch

Why this lands on your desk

Everyone Claims Responsible AI. Almost Nobody Can Show It.

The gap between what companies say about their AI and what they can evidence has become a commercial liability.

An AI estate nobody has mapped

Models in production, vendor tools adopted by individual teams, features shipped before governance existed. The first honest inventory is usually a surprise to leadership.

Risk you cannot see or price

Oversight that exists on paper

A policy says a human reviews outputs. Nobody can name who, show when they last intervened, or produce the record. Auditors and buyers both test exactly this.

A claim that collapses under questioning

Regulation arriving on a timetable

The EU AI Act's principal high-risk obligations have been deferred to December 2027, not cancelled. Buyers in regulated sectors are already writing AI clauses into contracts today.

A deadline that only moves once

What ISO 42001 involves

Building an AI Management System That Certifies

AI governance fails when it is a committee that meets quarterly. The standard requires it to be built into how systems are actually developed and run.

IN SCOPEProduct platformCustomer dataEngineeringCloud estateOut ofscopeA NARROW SCOPE THAT PASSES BEATS A WIDE ONE THAT STALLS

01 / 09

AI System Inventory & Scope

You cannot govern what nobody has written down.

We identify every AI and machine learning system in the business — including the ones procured by a team without telling anyone — classify them by risk and intended use, and set the certification scope around them.

The roadmap

What the Next Few Months Actually Look Like

Ranges, not a single number. Where you land inside them depends almost entirely on what already exists on day one.

  1. Phase 01

    Week 0 · free

    Gap analysis

    We assess what you already do against the standard and hand back a prioritised plan with effort and dates against every gap. You keep it whether or not you continue with us.

    We doAssess, document, price the work

    You doA few hours of interviews

  2. Phase 02

    Weeks 1–3

    Scope, risk and the paper foundation

    Certification scope agreed, risk methodology set, and the mandatory documents drafted — including the Statement of Applicability, the document auditors scrutinise hardest.

    We doDraft everything, run the risk workshops

    You doDecisions on scope and risk appetite

  3. Phase 03

    Weeks 3–12

    Implementing the controls

    The longest phase and the one that varies most. Controls are built into your real systems rather than described in a document, with our engineers working alongside yours where the gaps are technical.

    We doBuild, configure, evidence

    You doAccess, and engineering time where unavoidable

  4. Phase 04

    Concurrent

    Training and awareness

    Role-based training so the people an auditor interviews can answer confidently, plus a mock interview session so nobody meets these questions for the first time in the room.

    We doDeliver training, run the dry run

    You doGet your team in the room

  5. Phase 05

    Min. 3 months in

    Operate, internal audit, management review

    The system must run long enough to produce real evidence — certification bodies generally expect around three months of operation before Stage 2. We run the mandatory internal audit and management review and close what they raise.

    We doInternal audit, review, remediation

    You doLeadership attendance at the review

  6. Phase 06

    Then 30–60 days

    Stage 1, Stage 2, certificate

    Stage 1 reviews documentation and readiness. Stage 2, typically 30 to 60 days later, tests whether you genuinely operate the system. We prepare the evidence pack and attend both with you.

    We doPrepare evidence, manage the auditor, handle findings

    You doBe available for interviews

Where you land in the range depends on your starting point, your scope, and how much evidence already exists. Anyone quoting a fixed number of weeks before seeing your estate is guessing.

How it runs

How We Run an ISO 42001 Programme

AI governance only works when it lives in the pipeline.

01

Inventory

Every AI system found, classified and scoped.

02

Impact & Risk

Effects on people and business, assessed and recorded.

03

Policy & SoA

All 38 controls judged, justified and documented.

04

Embed

Control points built into the ML lifecycle itself.

05

Operate & Audit

Evidence accumulates; internal audit finds gaps first.

06

Certify

Stage 1, Stage 2, certificate — then surveillance.

THEN BACK TO 01 — EVERY NEW MODEL RE-ENTERS HERE

Industries

Where AI Governance Is Already Being Asked About

Wherever an AI decision affects a customer, a patient, a claim or a citizen, someone is going to ask how that system is governed.

SaaS & Technology

Where enterprise security review is the single biggest drag on the sales cycle, and ISO 27001 is asked for by name.

Financial Services

Banking, payments and fintech, where supplier assurance is a regulatory expectation rather than a preference.

Health & Life Sciences

Patient and trial data carries obligations that buyers will not take on trust from an unaudited supplier.

Public Sector & Defence

Frameworks and tenders that list certification as a pass-or-fail eligibility criterion before scoring begins.

Retail & E-Commerce

Payment data, large supply chains, and sustainability criteria appearing in more and more supplier scorecards.

Professional & Legal

Client confidentiality, continuity obligations, and the quality assurance that panel appointments increasingly require.

Working across

United KingdomEuropean UnionUnited StatesUAE & GCCAustralia & NZRemote worldwide
Who it's for

ISO 42001 Matters If You Ship AI

Tick what applies.

00 OF 06

Worth getting ahead of — this question is coming.

How we engage

Fixed Scope. Fixed Fee. No Surprises.

Compliance consultancy has a reputation for open-ended day rates and a bill that grows with the project. We price the work after the gap analysis, when both of us know what it involves.

What you get

  • A free gap analysis before you commit to anything
  • A fixed implementation fee, quoted once the scope is known
  • Senior consultants doing the work, not supervising juniors
  • Documentation written for your business, never a template pack
  • We attend Stage 1 and Stage 2 with you
  • Support through the surveillance years, not just to the certificate

What we will not do

  • Sell you a certificate — an accredited body issues that, independently
  • Bill by the hour for work we should have scoped properly
  • Promise certification in a number of weeks the standard does not allow
  • Hand over a policy binder and disappear before the audit
  • Take commission for recommending a certification body
  • Claim an ISO certificate makes you compliant with a law it does not cover

What ISO 42001 does and does not get you

ISO/IEC 42001 is not currently a harmonised standard under the EU AI Act, so certification does not grant a presumption of conformity with it. We would rather tell you that up front than let you discover it later. What certification does give you is independently audited evidence of the governance the Act expects — which is both commercially useful today and a substantial head start on the technical documentation.

  • Certification is issued by an independent accredited certification body, not by us
  • It does not, by itself, make you EU AI Act compliant
  • The risk assessments and lifecycle records map directly onto AI Act technical documentation
  • The AI Act timeline has moved — the Digital Omnibus deferred principal high-risk obligations for standalone Annex III systems to December 2027 — so you have runway, not an excuse
Why Devtrios

We Build AI Systems, So We Govern Them Properly

We ship LLM and machine learning products ourselves. That is the difference between governance designed into a pipeline and governance bolted on as paperwork.

Controls inside your MLOpsHonest model inventoriesOversight that actually functionsNo AI governance theatreStraight talk on the AI Act

WE DO NOT WRITE YOU AN AI ETHICS POSTER

InventoryGovernCertify

Trusted by startups, enterprises, and governments worldwide

Technology Stack

The stack behind the platforms we build.

We choose tools for the outcome they deliver, not for the trend they follow.

Frontend

8 tools
React
Next.js
TypeScript
Tailwind CSS
Vue.js
Angular
Sass
Vite
Based on 0+ verified client reviews
4.9/ 5.0
4.9 on Google, 5.0 on Clutch and GoodFirms
0%
Client Satisfaction
0+
Verified Reviews
0%
Client Retention

“Knowledgeable, professional, and responsive — Devtrios added real value at every step of our project and delivered exactly what we needed.”

C
Connie Woo
Founder, Fintech Startup
Ratings & Reviews

Where Our Clients Rate Us 5 Stars

Our clients don't just work with us, they recommend us — 4.9 on Google, 5.0 on Clutch and GoodFirms. Every badge below links straight to the profile it comes from. Independent reviews keep pointing to the same three things: strong technical expertise, clear communication, and delivery you can rely on.

Recognised on

Verified reviews
Our Services
FAQ

Frequently Asked Questions

Everything you might want to know before we talk. Still unsure? A quick call clears it up.

Ask us anything

ISO/IEC 42001:2023 is the international standard for an AI management system — the first standard against which an organisation can actually be certified for how it governs artificial intelligence. Like ISO 27001, it has management system requirements in clauses 4 to 10, plus an Annex A of controls: 38 of them, grouped under nine objectives covering AI policy, internal organisation, resources, impact assessment, lifecycle management, data governance, information for interested parties, use of AI systems, and third-party relationships.

No. ISO/IEC 42001 has not been cited as a harmonised standard under the AI Act, so certifying against it does not confer a presumption of conformity. The honest framing is that it is the strongest head start available: the governance structures, risk and impact assessments, and lifecycle records that 42001 requires feed directly into the technical documentation the Act demands. Treat it as substantial preparation, not as a compliance certificate for the Act.

Yes. The Digital Omnibus on AI, published in the Official Journal in July 2026, deferred the principal high-risk obligations for standalone Annex III systems from August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products to August 2028. Separately, CEN-CENELEC published EN 18286 in 2026 covering the quality management system required of high-risk AI providers, though its reference has not yet been cited in the Official Journal. The direction of travel has not changed; the deadlines have moved.

Very possibly, yes. ISO 42001 explicitly covers the use of AI systems and third-party relationships, not just their development. If you deploy someone else's model into a decision that affects customers, you carry governance responsibility for that deployment. In practice, organisations that only consume AI often find certification faster to achieve, because the lifecycle controls sit at the procurement and monitoring layer rather than in training pipelines.

They share the same management system structure, so if you already hold ISO 27001 a large part of the foundation — context, leadership, competence, internal audit, management review, improvement — is already built and audited. Adding ISO 42001 on top is considerably cheaper than starting cold, and certification bodies can often run combined audits.

Typically four to ten months. Organisations with an existing ISO 27001 management system and a reasonably disciplined ML practice sit at the shorter end. The work that usually takes longest is not the paperwork — it is building an honest inventory of every AI system in use, including the ones individual teams adopted without telling anyone.

Free gap analysis

Get ahead of the AI governance question

Most companies do more AI governance than they can prove. The gap analysis shows you what is already defensible and what is not — at no cost.

Contact

Start Your Next Project with Devtrios

Tell us about your idea or business needs. Our team will review your requirements and get back to you within one business day with a clear plan, timeline, and a free consultation call.

Contact Information
info@devtrios.com+44 7470 801776
Avenue Road, SE25 4DX, London, United Kingdom
Connect With Us

Let's Discuss Your Project