Most founders who look up ISO/IEC 42001 stop reading after the phrase "management system."

It sounds like a framework built for a thousand-person compliance department, not a forty-person SaaS company still hiring its second engineer. That reading is wrong, and it's starting to cost companies deals.

Enterprise buyers are adding a new line to the security questionnaire: can you prove you're governing your AI systems responsibly, or are we taking your word for it? ISO 42001, published in December 2023, is the first certifiable standard built to answer that question, and unlike a lot of compliance frameworks, it was written to scale down as well as up.

38

reference controls in Annex A — and you only implement the ones your own risk assessment flags

9

control objectives they're grouped into, from policy and ownership to third-party accountability

2023

the year ISO/IEC 42001 published — the first certifiable standard for AI management systems

The requirements sit in two places. Clauses 4 through 10 are mandatory, covering organizational context, leadership commitment, risk planning, resourcing, operational controls, performance evaluation, and continual improvement. Annex A is the toolbox, and you select from it based on what your own risk assessment turns up.

That selection gets written down in a Statement of Applicability: which controls apply to your scope, and why the rest don't. It's the mechanism that keeps a five-person AI startup and a five-thousand-person enterprise certifying against the same standard without carrying the same workload.

None of this requires a platform purchase or a twelve-month runway. Most of it draws on the same discipline we bring to SOC 2 engagements: name an owner, write it down, prove it happened.

Stripped of certification language, the nine control objectives break down into work most companies can scope in a quarter, not a year:

This is the order we'd actually run it in, not the order the standard lists it:

  1. Name one accountable owner. Not a committee. One person whose job includes AI governance, even part-time, with a name a board or auditor can be given.
  2. Inventory every AI system touching the business. Internal tools, customer-facing features, vendor products already plugged into the stack. If nobody can produce this list today, that's the first finding.
  3. Write the AI policy and get it approved at the management level. A page and a half is enough to start. Vague and unsigned is not.
  4. Run a risk assessment on each system in the inventory, focused on who it affects and what happens if it's wrong.
  5. Document data provenance and quality checks for anything feeding a model, especially anything touching customer or employee data.
  6. Set up logging and monitoring so a decision an AI system makes can be traced back to what happened and when.
  7. Draft the Statement of Applicability. Decide which of the 38 controls apply to your scope, and write down why the rest don't.
  8. Run an internal audit before paying for an external one. Fix what it finds. External audit hours are expensive to spend finding things you already knew about.
  9. Book the certification audit. A document review stage, then a verification stage, once the internal review comes back clean.

If you can't say who owns AI governance at your company right now, that's not a paperwork problem. It's the finding your next enterprise buyer is going to surface for you.