Implementing ISO 42001 is a structured process that transforms how your organization governs AI. Done well, it results in not just a certificate — but a genuine AI Management System (AIMS) that reduces risk, builds stakeholder trust, and creates sustainable governance practices. This step-by-step guide walks you through the complete implementation journey for 2026.

Before You Begin: Understanding the Implementation Journey

ISO 42001 implementation is not a one-person project or a compliance checkbox exercise. It requires organizational commitment, cross-functional collaboration, and sustained effort over a period of several months. For most organizations, the journey from starting implementation to receiving a certificate takes 6-10 weeks with AICerty's online-first process, or 4-12 months with a more traditional approach.

The key success factors are executive sponsorship, a clear scope definition, and dedicated internal resources to build and document the AIMS. Organizations that treat implementation as a top-down mandate without internal ownership rarely succeed; those that build genuine cross-functional commitment move faster and produce more effective governance systems.

Step 1: Gap Analysis

The implementation journey begins with a gap analysis — an assessment of your current AI governance practices against ISO 42001 requirements. The gap analysis produces a clear picture of where you stand today and what needs to be built or improved to achieve certification.

A thorough gap analysis covers:

The output of the gap analysis is a prioritized remediation roadmap that guides the rest of the implementation. Organizations with existing ISO management system certifications typically have a much shorter gap list than those starting from scratch.

Step 2: Define the Scope of Your AIMS

Scope definition is one of the most strategically important decisions in ISO 42001 implementation. Your scope determines which AI systems, organizational units, processes, and locations are covered by the AIMS and subject to audit.

A well-defined scope is:

Many organizations start with a focused scope — covering their most significant AI system or a specific business unit — and expand it in subsequent certification cycles. This approach reduces initial cost and complexity while still delivering meaningful certification.

Step 3: Establish AI Governance Structures

Before building documentation, establish the organizational structures that will own and operate the AIMS. This includes:

These roles do not need to be full-time dedicated positions — in smaller organizations, a single person may cover multiple roles. What matters is that accountability is clear and that the people in these roles have the authority and resources to execute their responsibilities.

Step 4: Develop Your AI Policy

ISO 42001 requires top management to establish an AI policy — a high-level statement of the organization's commitment to responsible AI governance. The AI policy should:

The AI policy should be approved and signed by the CEO or equivalent executive. It does not need to be long — a well-crafted one-page policy is more effective than a lengthy document that no one reads.

Step 5: Conduct AI Risk Assessments

For each AI system within scope, conduct a structured risk assessment that identifies potential harms across key dimensions: bias and fairness, safety, privacy, security, transparency, and societal impact. Document the identified risks, assess their likelihood and severity, and determine appropriate risk treatment options.

ISO 42001 also requires an AI system impact assessment — a broader evaluation of the potential impact of AI systems on individuals, groups, and society. This goes beyond technical risk management to consider ethical and societal dimensions of AI deployment.

Step 6: Select and Implement Annex A Controls

Based on your risk assessments and organizational context, select the appropriate controls from ISO 42001's Annex A. Document your selection in a Statement of Applicability (SoA) — the key document that records which controls you have included, which you have excluded, and the justification for each decision.

Implement the selected controls across the relevant parts of your organization. Controls may address data governance practices, human oversight mechanisms, transparency and disclosure requirements, supplier management, and AI system monitoring.

Step 7: Build Required Documentation

ISO 42001 requires a documented AIMS, which includes at minimum:

Step 8: Conduct Internal Audit

Before the external certification audit, conduct an internal audit of your AIMS. The internal audit verifies that the AIMS is implemented as documented and that it meets ISO 42001 requirements. Internal auditors should be independent of the activities being audited.

The internal audit will identify nonconformities — areas where the AIMS does not meet requirements — that must be addressed before the external audit. Treat internal audit findings as valuable intelligence, not as failures.

Step 9: Management Review

Top management must conduct a formal review of the AIMS to assess its continuing suitability, adequacy, and effectiveness. The management review considers the results of internal audits, customer feedback, AI risk profile changes, and the organization's performance against AI objectives. It authorizes any necessary improvements to the AIMS.

Step 10: Certification Audit

The external certification audit consists of two stages:

With AICerty's online-first process, both stages are conducted remotely using structured digital workflows, making the process faster, more flexible, and significantly more cost-effective than traditional on-site audits.

Ready to Get Certified?

AICerty provides end-to-end ISO 42001, EU AI Act, and ISO 27001 certification services for AI companies worldwide. 100% online, 6-10 weeks, powered by BALTUM Bureau.

Visit aicerty.io
← Back to Blog