ISO/IEC 42001 is the first international standard built specifically for managing AI systems — not information security in general, not IT governance broadly, but the particular risks that come from deploying AI: opaque decisions, data that drifts, and systems that behave differently in production than they did in testing. If you're asking whether your business needs to care about it yet, the honest answer depends on how much an AI decision of yours could affect someone else if it went wrong.

What the standard actually asks for

Stripped of the certification-body language, ISO/IEC 42001 asks four things: document what your AI systems do and who's accountable for them, maintain a risk register that names specific use cases and their risk level, define where a human has to check or override the system before a decision takes effect, and run internal audits that verify all of this is actually happening, not just written down somewhere. It's the same discipline I already apply under ISO/IEC 27001 as a Lead Auditor — extended to the AI-specific risks the older standard was never written for.

Who needs to act on this first

Not everyone needs to act at the same speed. Organisations using AI in ways that materially affect people — healthcare decisions, financial assessments, hiring, anything with real consequences if it's wrong — need this now, because the regulatory and reputational exposure is already live, whether or not a formal audit has happened yet. Businesses using AI for lower-stakes internal efficiency (drafting, scheduling, summarising) have more runway, but "more runway" isn't "none" — the standard is moving from novel to expected faster than most people preparing budgets right now assume.

Two ways I work with this, and a third for teams who want to own it

As an ISO/IEC 27001 Lead Auditor and Lead Implementer, I offer both sides of this for AI governance specifically: an independent AI Governance Audit that tells you where the gaps are without a sales pitch attached to the findings, or hands-on AI Governance Implementation where I build the AI Management System — policies, risk register, controls — alongside your team.

For organisations that want to build this capability internally rather than commission an external review every time, I now also offer Internal AI Auditor Training — a structured programme that trains your own staff to run ISO/IEC 42001 internal audits between external reviews, built as an extension of my existing Company Training Day: from £1,250/day online, £1,600/day in person for a single-day foundation session, or £2,200 online / £2,800 in person for the fuller two-day programme that goes deeper into audit methodology and evidence-gathering.

Why train your own auditors rather than always bringing someone in

An external audit is a snapshot — accurate on the day, but the gap between reviews is where drift actually happens. A team that can run its own internal audits catches problems between the formal external checks, the same reason ISO/IEC 27001 has always required internal audits as part of the standard, not as an optional extra. This isn't a replacement for an independent audit; it's what happens in the months between them.