Module 6: Industry Standards and Frameworks

ISO 42001: AI Management System

Description

ISO/IEC 42001 (published December 2023) is the first certifiable international standard for AI Management Systems. It's the "ISO 27001 for AI": it structures your organization with formal processes for AI governance.

For startups, ISO 42001 is likely overkill on Day 1. But it's important to know because:

  • Enterprise clients will ask for it in RFPs
  • It's certifiable (a third-party audit validates your compliance)
  • It changes your company's value (a certified company = more trustworthy)

By the end you'll be able to:

  • Understand ISO 42001's structure
  • Identify when certification is valuable
  • Decide whether to implement pre-certification (best practices without an auditor)
  • Map your system to the ISO 42001 controls

What ISO 42001 is

ISO 42001 follows the typical structure of management system standards (similar to ISO 9001 for quality, ISO 27001 for security):

Clauses 4-10: management system requirements

  • Clause 4: Context (understanding your organization and stakeholders)
  • Clause 5: Leadership (management commitment)
  • Clause 6: Planning (objectives, addressing risks)
  • Clause 7: Support (resources, awareness, documentation)
  • Clause 8: Operation (operational planning, risk treatment)
  • Clause 9: Performance evaluation (monitoring, audit)
  • Clause 10: Improvement (corrective actions, continual improvement)

Annex A: AI controls

A specific list of controls for AI, organized into categories:

  • AI policies
  • AI risk assessment
  • Privacy and data protection
  • Information security
  • Reliability and resilience
  • Transparency and explainability
  • Fairness and non-discrimination
  • Human oversight
  • AI lifecycle management

Each control must be implemented, or excluded with a justification.


ISO 42001 vs the NIST AI RMF

AspectISO 42001NIST AI RMF
Certifiable✅ Yes❌ No (a voluntary framework)
Cost$$$$ (audits, fees)Free
AdoptionGrowing in enterpriseWider adoption in tech
DetailSpecific controls (Annex A)A functional framework
GeographicInternationalUS-origin, used globally
MaturityEarly stage (2024+)Established

They complement each other: ISO is the certifiable wrapper; NIST is the practical framework you use day-to-day.


When ISO 42001 is valuable

Definitely yes

  • An enterprise client (Fortune 500) requires it in an RFP
  • You're in a regulated sector (finance, healthcare) where customers expect certification
  • You compete against larger players who have it
  • M&A: certification raises your valuation

Probably not

  • An early startup pre-PMF
  • A 5-10 person team
  • A B2C consumer product
  • Customers don't ask for it

The middle approach: pre-certification

You implement the principles without officially certifying. If a client asks later, you can show:

  • "We follow ISO 42001 best practices"
  • Documentation aligned to the clauses
  • Internal audits but no external ones

It costs significantly less, and the value is real (preparedness for a future certification).


Implementation: mapping your system to ISO 42001

Clause 4: Context

## 4.1 Understanding the organization
[Brief description: a B2B SaaS AI assistant, 50 clients, 50K users]

## 4.2 Stakeholders
[Internal: the team, the board. External: clients, end users, regulators, providers]

## 4.3 Scope of the AI Management System
[Specifies: AI components, geographies, exclusions]

Clause 5: Leadership

## 5.1 Leadership commitment
[The CEO signs a commitment to AI ethics; allocates resources]

## 5.2 AI policy
[Link to the AI Use Policy from M6-02]

## 5.3 Roles, responsibilities, authority
[Link to the accountability matrix from M6-02]

Clause 6: Planning

## 6.1 Risks and opportunities
[The Risk Register from M6-05]

## 6.2 AI objectives
[Quantifiable: <5% hallucination rate, P95 latency <8s, 0 breaches]

Clause 7: Support

## 7.1 Resources [budget]
## 7.2 Competence [team training]
## 7.3 Awareness [policies communicated]
## 7.4 Communication [internal/external]
## 7.5 Documented information [this document + RoPA + DPIA + etc.]

Clause 8: Operation

## 8.1 Operational planning
[Sprint planning, change management]

## 8.2 AI risk assessment
[The process from the NIST Map function]

## 8.3 AI risk treatment
[The process from the NIST Manage function + the risk register]

Clause 9: Performance Evaluation

## 9.1 Monitoring
[From the NIST Measure function]

## 9.2 Internal audit
[Annual schedule; the ethics audit (M8) plays this role]

## 9.3 Management review
[The quarterly governance review]

Clause 10: Improvement

## 10.1 Continual improvement
[Post-incident reviews, a lessons-learned database]

## 10.2 Nonconformity and corrective action
[The incident response process + remediation tracking]

Annex A controls

For each control, you document:

  • Status: Implemented / Partially / Not Applicable / Planned
  • Evidence: a link to where it's shown
  • Owner

The certification process

If you go for certification:

Phase 1: Gap analysis (1-3 months)
  - An internal review of the current state vs. the ISO requirements
  - Identify the gaps
  - Plan remediation

Phase 2: Implementation (3-12 months)
  - Address the gaps
  - Document policies and procedures
  - Train the team
  - Operate the system for 3-6 months

Phase 3: Internal audit (1 month)
  - Conduct the internal audit
  - Address the findings
  - Prepare for the external one

Phase 4: Stage 1 audit (external)
  - The auditor reviews the documentation
  - Identifies major gaps
  - You plan to address them

Phase 5: Stage 2 audit (external)
  - The auditor is on-site (or remote), verifying
  - The certificate is issued if you pass

Phase 6: Surveillance audits (annual)
  - The auditor returns annually
  - A 3-year recertification cycle

Cost: $20K-$100K+ depending on company size and auditor. Time: 6-18 months from start to certificate.


The value of pre-certification (the alternative)

Without paying for certification:

  1. Document everything per the ISO 42001 structure
  2. Run internal audits annually
  3. Train the team
  4. When a client asks: "We follow ISO 42001 best practices; we can provide the documentation"

Cost: time only. Benefit: real governance + preparedness if you need certification later.


Common traps

Trap 1 — Certifying too early. You spend $50K on certification, then pivot the product. Wasted. Wait for traction + revenue + client demand.

Trap 2 — Certification as a panacea. Certification ≠ ethical AI. Certification ≠ legal compliance. Certification is evidence of process, not perfection.

Trap 3 — Documenting for certification, not for use. Beautiful documents nobody reads. Documentation should serve operations first, certification second.

Trap 4 — Skipping pre-certification. You want to certify but skip the documentation discipline. The certification audit fails — the auditor sees a mess.


Exercise

For your Capstone:

  1. Is ISO 42001 certification relevant now? Justify yes/no
  2. Map your existing path deliverables to the ISO 42001 clauses (which clauses are auto-covered?)
  3. Identify 3-5 typical gaps for a pre-certification startup
  4. Decision: do you implement pre-certification now or wait?
See the solution
  1. Relevance: typically NOT now if you're a pre-PMF startup. YES if:

    • You have ≥10 enterprise clients
    • Your industry is finance, healthcare, or government
    • Client RFPs are starting to ask
  2. Auto-covered by the path deliverables:

    • Clause 5.2 (AI policy): ✅ via the M6-02 governance
    • Clause 6.1 (risks): ✅ via the M6 NIST mapping
    • Clause 8.2 (risk assessment): ✅ via M6
    • Clause 9.1 (monitoring): ✅ via M6 Measure
    • Annex A bias: ✅ via the M2 bias toolkit
    • Annex A privacy: ✅ via M3 + M5 GDPR
    • Annex A transparency: ✅ via citations + explainability
  3. Typical gaps:

    • Clause 5.1 formal leadership commitment (often informal)
    • Clause 7.2 systematic competence training
    • Clause 9.2 a formal internal audit cycle
    • Clause 10.2 a formal corrective action process
    • Annex A: human oversight controls
  4. The decision tree:

    • Do you have enterprise demand? → Plan certification on a 6-12 month timeline
    • No specific demand, but you anticipate it? → Implement pre-certification (3-6 months of documentation work)
    • Bootstrapped, no demand? → Skip for now, revisit yearly

Summary

You learned:

  • ✅ The ISO 42001 structure: Clauses 4-10 + Annex A
  • ✅ The comparison with the NIST AI RMF
  • ✅ When certification is valuable
  • ✅ The pre-certification approach (best practices without an auditor)
  • ✅ Implementation: mapping to the clauses
  • ✅ The cost and timeline of certification

Checkpoint: if you know when ISO 42001 certification would be valuable and how to map your system, that's enough.


Next capsule

08 — Project: Standards Mapping. You apply the NIST AI RMF (mainly) and ISO 42001 (a conceptual mapping) to your concrete system.


Resources

  1. ISO/IEC 42001 official.
  2. BSI Group — ISO 42001 guide — implementation help.
  3. AI Verify Foundation — Singapore-origin AI testing.
  4. Comparison: NIST vs ISO.