Most founders who look up ISO/IEC 42001 stop reading after the phrase "management system."
It sounds like a framework built for a thousand-person compliance department, not a forty-person SaaS company still hiring its second engineer. That reading is wrong, and it's starting to cost companies deals.
Enterprise buyers are adding a new line to the security questionnaire: can you prove you're governing your AI systems responsibly, or are we taking your word for it? ISO 42001, published in December 2023, is the first certifiable standard built to answer that question, and unlike a lot of compliance frameworks, it was written to scale down as well as up.
reference controls in Annex A — and you only implement the ones your own risk assessment flags
control objectives they're grouped into, from policy and ownership to third-party accountability
the year ISO/IEC 42001 published — the first certifiable standard for AI management systems
The requirements sit in two places. Clauses 4 through 10 are mandatory, covering organizational context, leadership commitment, risk planning, resourcing, operational controls, performance evaluation, and continual improvement. Annex A is the toolbox, and you select from it based on what your own risk assessment turns up.
That selection gets written down in a Statement of Applicability: which controls apply to your scope, and why the rest don't. It's the mechanism that keeps a five-person AI startup and a five-thousand-person enterprise certifying against the same standard without carrying the same workload.
Stripped of certification language, the nine control objectives break down into work most companies can scope in a quarter, not a year:
- Policy and ownership. A written AI policy, approved at a real management level, not a paragraph buried in the employee handbook. One named owner accountable for AI governance decisions, and a channel for employees to flag concerns without it disappearing into Slack.
- Resources and data. An inventory of every AI system in use or development, the data feeding it, where that data came from, and the infrastructure running it. Most companies have never written this down in one place.
- Impact and risk assessment. A documented process for evaluating how an AI system affects the people it touches, customers, employees, or applicants, with the results kept on file, not just discussed once in a meeting.
- System lifecycle and logging. Controls that run from development through deployment through retirement: technical documentation, monitoring, and event logs that let you reconstruct what a system did and why.
- Data quality and provenance. Verification that training and input data is accurate, sourced legitimately, and prepared in a way you can explain if asked.
- Stakeholder communication and third parties. Clear documentation for users, a plan for communicating incidents, and defined accountability with every vendor whose AI touches your stack. If you're building on someone else's model, this is where that relationship gets formalized in writing.
This is the order we'd actually run it in, not the order the standard lists it:
- Name one accountable owner. Not a committee. One person whose job includes AI governance, even part-time, with a name a board or auditor can be given.
- Inventory every AI system touching the business. Internal tools, customer-facing features, vendor products already plugged into the stack. If nobody can produce this list today, that's the first finding.
- Write the AI policy and get it approved at the management level. A page and a half is enough to start. Vague and unsigned is not.
- Run a risk assessment on each system in the inventory, focused on who it affects and what happens if it's wrong.
- Document data provenance and quality checks for anything feeding a model, especially anything touching customer or employee data.
- Set up logging and monitoring so a decision an AI system makes can be traced back to what happened and when.
- Draft the Statement of Applicability. Decide which of the 38 controls apply to your scope, and write down why the rest don't.
- Run an internal audit before paying for an external one. Fix what it finds. External audit hours are expensive to spend finding things you already knew about.
- Book the certification audit. A document review stage, then a verification stage, once the internal review comes back clean.
If you can't say who owns AI governance at your company right now, that's not a paperwork problem. It's the finding your next enterprise buyer is going to surface for you.