🤖 AI Governance🌐 ISO 42001🗺️ Implementation

Building an AIMS — ISO 42001 Implementation Roadmap Step by Step

An AI Management System touches leadership, data teams, risk functions, legal, and engineering. Here is the practical, step-by-step roadmap — from securing executive commitment to the two-stage certification audit — with realistic timelines and the artifacts each stage produces.

CM
Chandrika Mulage
🔐 Security Engineer·📖 10 min read
📅 June 18, 2026·🏢 SecComply
Building an AIMS — a step-by-step ISO 42001 implementation roadmap

From leadership commitment to the two-stage certification audit — the practical roadmap for building an AI Management System.

Deciding to pursue ISO/IEC 42001 certification is straightforward; knowing how to get there is not. An AI Management System (AIMS) touches leadership, data teams, risk functions, legal, and engineering — and without a clear roadmap, projects stall in ambiguity. This post lays out a practical, step-by-step implementation roadmap, from securing executive commitment through the two-stage certification audit, with realistic timelines and the artifacts you should produce at each stage.

14 Steps
From leadership commitment to the two-stage certification audit
8–14 mo
Typical timeline for a greenfield AIMS implementation
4–6 mo
Readiness timeline if you already hold ISO 27001
2 Stages
Certification audit: readiness review, then effectiveness testing

Before You Start: Understand What an AIMS Is

ISO/IEC 42001:2023 is a management-system standard built on the Annex SL structure and the Plan-Do-Check-Act (PDCA) cycle. Rather than certifying a single AI model, it certifies your system for governing AI: the policies, roles, risk processes, controls, and continual-improvement mechanisms that keep AI development and use responsible over time. Implementation therefore is an organizational program, not a technical fix — which is why sequencing matters.

A quick note on timelines. A greenfield implementation (no existing management system) typically takes 8–14 months. Organizations that already hold ISO 27001 can often reach readiness in 4–6 months, because leadership structures, documentation practices, internal-audit capability, and risk methodology are already in place and simply need extending to AI.

The Roadmap at a Glance

  • Secure leadership commitment and define scope
  • Assign roles and stand up governance
  • Inventory your AI systems
  • Run a gap assessment
  • Conduct AI risk and impact assessments
  • Define your AI policy and objectives
  • Select and implement Annex A controls
  • Produce the Statement of Applicability
  • Build documentation, registers, and records
  • Train staff and raise awareness
  • Operate the AIMS
  • Run an internal audit
  • Hold a management review
  • Undergo the certification audit (Stage 1 and Stage 2)

Let’s work through each step.

1
Secure Leadership Commitment and Define Scope

Clause 5 makes top-management leadership a requirement, not a courtesy. Executives must commit resources, endorse the AI policy, and hold accountability for the AIMS. In parallel, define the scope (Clause 4): which parts of the organization, which AI systems, and which locations the AIMS covers. A tightly defined scope keeps the first certification achievable; you can expand later.

Artifacts: a scope statement, a leadership commitment/mandate, and an initial business case.

2
Assign Roles and Stand Up Governance

Establish an AI governance committee and name an AIMS owner (sometimes an AI governance lead or officer). Define roles and responsibilities — who approves high-risk deployments, who maintains the risk register, who reports to leadership. This maps to Annex A.3 (internal organization).

Artifacts: governance committee charter, RACI matrix, meeting cadence.

3
Inventory Your AI Systems

You cannot govern what you have not catalogued. Build an AI system inventory capturing each system’s purpose, owner, data sources, whether it is built in-house or third-party, its life-cycle stage, and a preliminary risk indication. Shadow AI — tools adopted by teams without central awareness — is a common blind spot, so cast a wide net.

Artifacts: AI system inventory / register.

4
Run a Gap Assessment

Compare your current state against Clauses 4–10 and the Annex A controls to see what already exists and what is missing. The output is a gap register with severity ratings, owners, and remediation actions, plus a maturity rating per clause and control. This becomes the backbone of your implementation plan.

Artifacts: gap assessment report, gap register, prioritized remediation roadmap.

5
Conduct AI Risk and Impact Assessments

Following Clause 6, establish risk criteria, then identify, analyze, and evaluate AI risks, and treat them. Alongside this, perform AI system impact assessments examining consequences for individuals, groups, and society. The methodology aligns with ISO 31000 and ISO/IEC 23894.

Artifacts: risk criteria document, AI risk register, AI risk treatment plan, AI system impact assessments.

6
Define Your AI Policy and Objectives

Draft and secure approval for an AI policy (Annex A.2) that expresses your principles for responsible AI, and set measurable AI objectives aligned with organizational strategy. These give the AIMS direction and provide criteria for later performance evaluation.

Artifacts: approved AI policy, documented AI objectives with metrics.

7
Select and Implement Annex A Controls

Based on your risk and impact assessments, select controls from Annex A (38 controls across nine objectives) and supplement with custom controls where needed. Implementation is the heaviest phase: writing data-governance procedures, building model-documentation practices, standing up human-oversight mechanisms, and tightening third-party management.

Artifacts: implemented controls plus their supporting procedures, model cards, oversight logs, data provenance records.

8
Produce the Statement of Applicability

Compile the Statement of Applicability (SoA): for every Annex A control, state whether it applies, justify inclusion or exclusion, and record implementation status. The SoA ties your risk decisions to your control environment and is a primary audit document.

Artifacts: Statement of Applicability.

9
Build Documentation, Registers, and Records

Clause 7 requires documented information. Assemble the full documentation set: policies, procedures, the risk and impact registers, the AI inventory, training records, and operational records. Establish version control and retention so evidence is auditable.

Artifacts: policy/procedure library, registers, records, document-control system.

10
Train Staff and Raise Awareness

Clause 7 also requires competence and awareness. Train developers, reviewers, and business users on the AI policy, their responsibilities, human-oversight duties, and how to report concerns. Awareness reduces the automation-bias and misuse risks that controls alone cannot eliminate.

Artifacts: training materials, attendance records, competency assessments.

11
Operate the AIMS

Run the system in production (Clause 8): execute risk treatments, perform impact assessments on new or changed systems, monitor models, and maintain records. Auditors want to see the AIMS operating, not just documented — Stage 2 assessment hinges on operational effectiveness, so allow enough operating time to generate real evidence.

Artifacts: monitoring records, operational logs, updated registers.

12
Run an Internal Audit

Clause 9 requires internal audits to verify the AIMS conforms to the standard and works in practice. Use independent auditors (internal or external) to test controls and surface nonconformities before the certification body does.

Artifacts: internal audit plan, audit report, nonconformity and corrective-action records.

13
Hold a Management Review

Leadership reviews AIMS performance: audit results, risk status, incidents, progress against objectives, and improvement opportunities (Clauses 9 and 10). This closes the PDCA loop and demonstrates ongoing top-management engagement.

Artifacts: management review minutes and decisions.

14
Undergo the Certification Audit

Certification is performed by an accredited certification body in two stages:

  • Stage 1 — Readiness / documentation review. The auditor examines your documentation, scope, SoA, and readiness, identifying gaps to resolve before Stage 2.
  • Stage 2 — Operational effectiveness. The auditor tests whether the AIMS is genuinely implemented and effective, sampling evidence and interviewing staff.

Certificates are valid for three years, with annual surveillance audits to confirm continued conformity, and recertification at the end of the cycle. Recognized certification bodies include Schellman, BSI, DNV, A-LIGN, and SGS.

Artifacts: Stage 1 findings closure, Stage 2 evidence, certificate.

A Realistic Timeline

ScenarioTypical DurationWhy
Greenfield (no existing MS)8–14 monthsBuilding governance, documentation, and audit capability from scratch.
Existing ISO 270014–6 monthsReuse leadership structures, risk methodology, document control, and internal-audit function.

The biggest schedule risk is under-resourcing the implementation phase (Step 7) and not leaving enough operating time (Step 11) before Stage 2.

Regulatory Context: Timing Your Program

The push toward certified AI governance is reinforced by regulation. The EU AI Act imposes high-risk obligations on an evolving timeline — originally 2 August 2026, with the November 2025 Digital Omnibus proposing deferral toward 2 December 2027 and the Council signalling support around late June 2026 — backed by penalties up to €35 million or 7% of turnover. ISO/IEC 42001 helps operationalize these duties, and aligns with the NIST AI Risk Management Framework and standards such as ISO/IEC 23894 and ISO/IEC 24028. Given multi-month implementation times, organizations expecting to fall under high-risk obligations are well advised to begin their AIMS program now rather than waiting for final deadlines.

Key Takeaways

🗺️
KEY TAKEAWAYS
  • An AIMS is an organizational program built on PDCA — sequence the work; don’t treat it as a technical project.
  • The roadmap runs from leadership commitment and scope through risk/impact assessment, control implementation, the SoA, operation, internal audit, and a two-stage certification audit.
  • Expect 8–14 months greenfield, or 4–6 months with existing ISO 27001.
  • Each step produces specific artifacts — inventory, gap register, risk register, impact assessments, SoA, model cards, oversight logs.
  • Leave enough operating time before Stage 2, which tests effectiveness, not just documentation.
  • Certificates last three years with annual surveillance; recognized CBs include Schellman, BSI, DNV, A-LIGN, and SGS.

Ready to Build Your AIMS?

SecComply’s compliance team guides organizations through the full ISO 42001 implementation roadmap — from AI system inventory and risk assessments to the Statement of Applicability and the certification audit.

Frequently Asked Questions

How long does ISO 42001 implementation take?

Roughly 8–14 months for a greenfield program, or 4–6 months for organizations that already hold ISO 27001 and can reuse existing management-system infrastructure.

Do we need a dedicated AI governance team?

You need clear ownership — typically an AIMS owner and an AI governance committee — but the effort draws on existing risk, legal, data, and engineering functions rather than requiring a large new team.

What happens in the two-stage certification audit?

Stage 1 reviews documentation and readiness; Stage 2 tests operational effectiveness through evidence sampling and interviews. Passing both leads to a three-year certificate with annual surveillance.

Can we start with a limited scope?

Yes, and it is often wise. Define a focused scope for your first certification — a specific business unit or set of AI systems — and expand in later cycles.

This article provides general information about ISO/IEC 42001 and does not constitute legal advice.