Deciding to pursue ISO/IEC 42001 certification is straightforward; knowing how to get there is not. An AI Management System (AIMS) touches leadership, data teams, risk functions, legal, and engineering — and without a clear roadmap, projects stall in ambiguity. This post lays out a practical, step-by-step implementation roadmap, from securing executive commitment through the two-stage certification audit, with realistic timelines and the artifacts you should produce at each stage.
Before You Start: Understand What an AIMS Is
ISO/IEC 42001:2023 is a management-system standard built on the Annex SL structure and the Plan-Do-Check-Act (PDCA) cycle. Rather than certifying a single AI model, it certifies your system for governing AI: the policies, roles, risk processes, controls, and continual-improvement mechanisms that keep AI development and use responsible over time. Implementation therefore is an organizational program, not a technical fix — which is why sequencing matters.
A quick note on timelines. A greenfield implementation (no existing management system) typically takes 8–14 months. Organizations that already hold ISO 27001 can often reach readiness in 4–6 months, because leadership structures, documentation practices, internal-audit capability, and risk methodology are already in place and simply need extending to AI.
The Roadmap at a Glance
- Secure leadership commitment and define scope
- Assign roles and stand up governance
- Inventory your AI systems
- Run a gap assessment
- Conduct AI risk and impact assessments
- Define your AI policy and objectives
- Select and implement Annex A controls
- Produce the Statement of Applicability
- Build documentation, registers, and records
- Train staff and raise awareness
- Operate the AIMS
- Run an internal audit
- Hold a management review
- Undergo the certification audit (Stage 1 and Stage 2)
Let’s work through each step.
Clause 5 makes top-management leadership a requirement, not a courtesy. Executives must commit resources, endorse the AI policy, and hold accountability for the AIMS. In parallel, define the scope (Clause 4): which parts of the organization, which AI systems, and which locations the AIMS covers. A tightly defined scope keeps the first certification achievable; you can expand later.
Artifacts: a scope statement, a leadership commitment/mandate, and an initial business case.
Establish an AI governance committee and name an AIMS owner (sometimes an AI governance lead or officer). Define roles and responsibilities — who approves high-risk deployments, who maintains the risk register, who reports to leadership. This maps to Annex A.3 (internal organization).
Artifacts: governance committee charter, RACI matrix, meeting cadence.
You cannot govern what you have not catalogued. Build an AI system inventory capturing each system’s purpose, owner, data sources, whether it is built in-house or third-party, its life-cycle stage, and a preliminary risk indication. Shadow AI — tools adopted by teams without central awareness — is a common blind spot, so cast a wide net.
Artifacts: AI system inventory / register.
Compare your current state against Clauses 4–10 and the Annex A controls to see what already exists and what is missing. The output is a gap register with severity ratings, owners, and remediation actions, plus a maturity rating per clause and control. This becomes the backbone of your implementation plan.
Artifacts: gap assessment report, gap register, prioritized remediation roadmap.
Following Clause 6, establish risk criteria, then identify, analyze, and evaluate AI risks, and treat them. Alongside this, perform AI system impact assessments examining consequences for individuals, groups, and society. The methodology aligns with ISO 31000 and ISO/IEC 23894.
Artifacts: risk criteria document, AI risk register, AI risk treatment plan, AI system impact assessments.
Draft and secure approval for an AI policy (Annex A.2) that expresses your principles for responsible AI, and set measurable AI objectives aligned with organizational strategy. These give the AIMS direction and provide criteria for later performance evaluation.
Artifacts: approved AI policy, documented AI objectives with metrics.
Based on your risk and impact assessments, select controls from Annex A (38 controls across nine objectives) and supplement with custom controls where needed. Implementation is the heaviest phase: writing data-governance procedures, building model-documentation practices, standing up human-oversight mechanisms, and tightening third-party management.
Artifacts: implemented controls plus their supporting procedures, model cards, oversight logs, data provenance records.
Compile the Statement of Applicability (SoA): for every Annex A control, state whether it applies, justify inclusion or exclusion, and record implementation status. The SoA ties your risk decisions to your control environment and is a primary audit document.
Artifacts: Statement of Applicability.
Clause 7 requires documented information. Assemble the full documentation set: policies, procedures, the risk and impact registers, the AI inventory, training records, and operational records. Establish version control and retention so evidence is auditable.
Artifacts: policy/procedure library, registers, records, document-control system.
Clause 7 also requires competence and awareness. Train developers, reviewers, and business users on the AI policy, their responsibilities, human-oversight duties, and how to report concerns. Awareness reduces the automation-bias and misuse risks that controls alone cannot eliminate.
Artifacts: training materials, attendance records, competency assessments.
Run the system in production (Clause 8): execute risk treatments, perform impact assessments on new or changed systems, monitor models, and maintain records. Auditors want to see the AIMS operating, not just documented — Stage 2 assessment hinges on operational effectiveness, so allow enough operating time to generate real evidence.
Artifacts: monitoring records, operational logs, updated registers.
Clause 9 requires internal audits to verify the AIMS conforms to the standard and works in practice. Use independent auditors (internal or external) to test controls and surface nonconformities before the certification body does.
Artifacts: internal audit plan, audit report, nonconformity and corrective-action records.
Leadership reviews AIMS performance: audit results, risk status, incidents, progress against objectives, and improvement opportunities (Clauses 9 and 10). This closes the PDCA loop and demonstrates ongoing top-management engagement.
Artifacts: management review minutes and decisions.
Certification is performed by an accredited certification body in two stages:
- Stage 1 — Readiness / documentation review. The auditor examines your documentation, scope, SoA, and readiness, identifying gaps to resolve before Stage 2.
- Stage 2 — Operational effectiveness. The auditor tests whether the AIMS is genuinely implemented and effective, sampling evidence and interviewing staff.
Certificates are valid for three years, with annual surveillance audits to confirm continued conformity, and recertification at the end of the cycle. Recognized certification bodies include Schellman, BSI, DNV, A-LIGN, and SGS.
Artifacts: Stage 1 findings closure, Stage 2 evidence, certificate.
A Realistic Timeline
| Scenario | Typical Duration | Why |
|---|---|---|
| Greenfield (no existing MS) | 8–14 months | Building governance, documentation, and audit capability from scratch. |
| Existing ISO 27001 | 4–6 months | Reuse leadership structures, risk methodology, document control, and internal-audit function. |
The biggest schedule risk is under-resourcing the implementation phase (Step 7) and not leaving enough operating time (Step 11) before Stage 2.
Regulatory Context: Timing Your Program
The push toward certified AI governance is reinforced by regulation. The EU AI Act imposes high-risk obligations on an evolving timeline — originally 2 August 2026, with the November 2025 Digital Omnibus proposing deferral toward 2 December 2027 and the Council signalling support around late June 2026 — backed by penalties up to €35 million or 7% of turnover. ISO/IEC 42001 helps operationalize these duties, and aligns with the NIST AI Risk Management Framework and standards such as ISO/IEC 23894 and ISO/IEC 24028. Given multi-month implementation times, organizations expecting to fall under high-risk obligations are well advised to begin their AIMS program now rather than waiting for final deadlines.
Key Takeaways
- An AIMS is an organizational program built on PDCA — sequence the work; don’t treat it as a technical project.
- The roadmap runs from leadership commitment and scope through risk/impact assessment, control implementation, the SoA, operation, internal audit, and a two-stage certification audit.
- Expect 8–14 months greenfield, or 4–6 months with existing ISO 27001.
- Each step produces specific artifacts — inventory, gap register, risk register, impact assessments, SoA, model cards, oversight logs.
- Leave enough operating time before Stage 2, which tests effectiveness, not just documentation.
- Certificates last three years with annual surveillance; recognized CBs include Schellman, BSI, DNV, A-LIGN, and SGS.
Frequently Asked Questions
Roughly 8–14 months for a greenfield program, or 4–6 months for organizations that already hold ISO 27001 and can reuse existing management-system infrastructure.
You need clear ownership — typically an AIMS owner and an AI governance committee — but the effort draws on existing risk, legal, data, and engineering functions rather than requiring a large new team.
Stage 1 reviews documentation and readiness; Stage 2 tests operational effectiveness through evidence sampling and interviews. Passing both leads to a three-year certificate with annual surveillance.
Yes, and it is often wise. Define a focused scope for your first certification — a specific business unit or set of AI systems — and expand in later cycles.
This article provides general information about ISO/IEC 42001 and does not constitute legal advice.