5 signs your organisation is ready for ISO 42001
Five signals that ISO 42001 is worth starting now, and what a readiness check looks at before you commit to the AI management standard.
ISO 42001 is the management system standard for AI, published as ISO/IEC 42001:2023. It sets out how an organisation governs the AI it builds or uses, across the same operating clauses as standards like ISO 27001, plus a set of AI-specific controls. Deciding whether to pursue it is a judgement about timing as much as appetite. Here are five signs the timing is right.
1. A customer or your board has asked how you govern AI
The clearest signal is external. When a client questionnaire, a procurement process, or your own board asks for assurance that AI is under control, a recognised standard is the answer that carries weight. A promise that “we’re careful” does not survive due diligence. A management system you can evidence does.
2. You already run ISO 27001 or a similar system
If you hold ISO 27001, you already have the muscle ISO 42001 depends on: a defined scope, risk assessment, management review, internal audit, and the habit of writing decisions down. ISO 42001 follows the same Clause 4 to 10 shape, so much of what you built for information security carries over. Starting from an existing system is far less work than starting from nothing.
3. AI has moved from experiments into core operations
While AI is a few pilots run by curious teams, ad hoc decisions are survivable. Once it sits inside work that reaches customers, handles their data, or informs decisions about people, those calls need a system rather than individual judgement. If you could not currently list every AI system in use and who is accountable for each, that gap is the sign.
4. Someone can actually own it
A management system needs a named owner with the authority to make it stick, usually whoever already owns risk, security or operations, backed by leadership. If you have that person and they have the time, readiness work has somewhere to land. If nobody owns it, the standard becomes a document that describes an intention rather than a practice.
5. You keep tripping over the same gaps
Recurring problems are the honest signal. No inventory of the AI you run. No agreed rule for what a person must check before AI-assisted work goes out. No review date, so the policy drifts from reality. ISO 42001 exists to put structure around exactly these gaps, and if you recognise them, you are closer to needing it than you might think.
What readiness actually involves
Readiness is not certification. The useful first step is an honest look at where you stand against the standard’s clauses and controls, and which gaps to close first, before you commit time or budget to an audit. The free ISO 42001 readiness check gives you a per-clause view and a prioritised list, and the ISO 42001 overview explains what the standard asks and how certification-readiness typically works. We assess readiness and help close gaps; we are not a certification body, and nothing here is legal advice.