ISO 42001 Consulting · AI Management System (AIMS) | SIXE
Compliance ISO/IEC 42001
AI · MANAGEMENT SYSTEM (AIMS)

ISO/IEC 42001 consulting and implementation

The first international certifiable standard for governing AI in your organisation. We take you from readiness assessment to certification — no boilerplate, no fluff.

Our team is a certified ISO/IEC 42001 lead auditor. We prepare your certification with the same criteria the certification body will use to audit you.

01 · What it is

What is ISO/IEC 42001.

ISO/IEC 42001 is the first international standard that defines an Artificial Intelligence Management System (AIMS). It doesn't regulate a specific algorithm: it establishes how your organisation governs, controls and improves the use of AI throughout its lifecycle.

It applies to any organisation that develops, provides or uses AI systems — from those training their own models to those integrating third-party AI into their processes. Being certified shows clients, tenders and regulators that AI in your house is governed, not improvised.

02 · Why certify

Why adopt it now.

  • Weighs in tenders and due diligence: hardly anyone is certified yet; getting ahead is a commercial edge.
  • Aligns with the EU AI Act: much of the governance the Regulation requires is delivered through an AIMS.
  • Builds on ISO 27001: if you already have an ISMS, a good part of the road is done.
  • Genuinely reduces risk: bias, traceability, human oversight and AI incident management, embedded in the process.

03 · How we work

From where you are to ready to certify.

No generic templates: the management system is built on your real processes and the AI systems you actually use.

1
Assessment

Where you stand

We measure your maturity against ISO 42001 and scope the real perimeter of the management system.

2
Gap Analysis

What's missing

Every requirement and Annex A control you're missing, prioritised by risk with an executable roadmap.

3
Implementation

We build the AIMS

Policies, AI impact assessment, controls and evidence — on your processes, not on a template.

4
Pre-audit

Full dress rehearsal

A lead auditor walks through the system exactly as the certification body will. Non-conformities surface now, not in the real audit.

SIXE prepares and supports; does not certify. The certification audit is issued by an independent accredited body — for impartiality, whoever helps you implement cannot be the one who certifies you. Because we are certified lead auditors, we prepare the process with the same criteria the auditor will use.

04 · Requirements

What ISO 42001 will ask of you.

The standard follows ISO's high-level structure (clauses 4 to 10) and adds an annex of AI-specific controls. In practice, it covers six fronts.

01 · Context

Context and scope

Which AI systems are in scope, which stakeholders are affected and what objectives the management system pursues.

02 · Leadership

Policy and responsibilities

An AI policy backed by top management, with clear roles and responsibilities across the organisation.

03 · Planning

Risks and impacts

Documented AI risk assessment and AI system impact assessment.

04 · Operation

AI lifecycle

Controls over design, data, development, deployment and monitoring of every AI system.

05 · Data

Data and transparency

AI data management and clear information for users and third parties on how AI is used.

06 · Improvement

Evaluation and improvement

Internal audits, AI incident management and continual improvement of the management system.

05 · It doesn't stand alone

ISO 42001, the EU AI Act and ISO 27001.

The EU AI Act is mandatory law; ISO 42001 is a voluntary certifiable standard that helps you demonstrate much of that governance. And if you already work with ISO 27001, the AI management system builds on your information security system instead of duplicating it.

That's why they're usually addressed together. Go back to the compliance map to see them side by side.

06 · Frequently asked questions

ISO 42001, in plain English.

What exactly is ISO/IEC 42001?
It is the first international certifiable standard for an artificial intelligence management system. It defines how an organisation governs the use of AI — risks, transparency, oversight, improvement — in an auditable way, not how a specific model works.
Who does it apply to?
Any organisation that develops, provides or uses AI systems, regardless of size. The system is scaled to your organisation and the AI systems you actually use.
How long does certification take?
It depends on scope and starting point; if you already have an ISMS (ISO 27001), quite a bit less. After the initial assessment we give you a realistic timeline.
Can an SME be certified?
Yes. The standard does not require a large department: it requires control proportional to risk. An SME with AI in production can be certified with a system sized to its scale.
How does it relate to the EU AI Act?
They are not the same thing. The EU AI Act is mandatory law; ISO 42001 is voluntary and certifiable, and helps you demonstrate much of the governance the Regulation expects. They complement, but do not replace, each other.
Does SIXE certify ISO 42001?
No, and no serious firm should. Certification is issued by an independent accredited body; whoever implements cannot certify — it is incompatible on impartiality grounds. We are certified lead auditors: we prepare the process with the same criteria the certification body will use.

AI in production without a management system?

Tell us which AI systems you use. We come back with an initial assessment against ISO 42001 and a proposal with the phases broken down: assessment, gap analysis, implementation and pre-audit. Price per phase, no closed packages that don't fit.

+34 91 198 02 43 (EU)  ·  +1 628 900 3024 (US)  ·  Mon–Fri 8:30–16:30 (GMT+1)