AI governance
ISO/IEC 42001 AI management system implementation
Make AI governance repeatable across the full system lifecycle. We help organizations identify AI uses, assess impacts and risks, assign accountability, and build evidence for an AI management system.
Our implementation focus
Make the requirements operational.
- 01
Inventory AI systems and use cases
- 02
Define AIMS scope, policy, roles, and objectives
- 03
Assess AI risks and impacts
- 04
Establish lifecycle controls and records
- 05
Create monitoring, review, and improvement practices
ISO/IEC 42001 is a management system standard. It does not replace applicable AI law, and independent certification decisions are made by a certification body.
Questions we hear
Get the distinctions right.
Does ISO/IEC 42001 compliance satisfy the EU AI Act?
No. ISO/IEC 42001 provides a management system for AI, while the EU AI Act imposes legal duties that depend on the organization’s role and the system. They should be assessed separately.
Do organizations that only use AI need an AI management system?
ISO/IEC 42001 is designed for organizations that provide or use AI systems. The appropriate scope and depth depend on AI use, impacts, and the organization’s objectives.
Can ISO/IEC 27001 controls be reused?
Security governance, supplier oversight, and evidence workflows can provide a foundation. AI-specific risks, impacts, lifecycle decisions, and affected-party considerations still need explicit treatment.
Market context
The same standard, different buyer questions.
Work with Normstone
Build a defensible path to readiness.
Tell us the outcome you need and the markets involved. We’ll help define the work.