Inventory
AI systems in use and under development. Own and third-party.
ISO 42001 is the AI management system. If you already run quality with ISO 9001 or security with ISO 27001, you reuse much of that structure here: the same continuous-improvement cycle, the same internal audit, the same level of control. Built for quality teams that aren't starting from zero.
ISO 42001 is the first international standard dedicated to the management of artificial intelligence systems. Published in 2023 and still without implementers with traction among Spanish SMEs, it opens a clear window of opportunity for those who want to get ahead of regulation.
The standard covers five areas: AI-specific policy and roles within the organisation, risk analysis for each AI system in use, model lifecycle (from training data to decommissioning), data and decision traceability, and internal audit of system performance.
In practice, ISO 42001 is the natural backbone for supporting compliance with the European AI Act: 2 August 2026 remains the general application date for the Regulation, while full high-risk obligations are deferred to 2 December 2027 for Annex III systems and to 2 August 2028 for Annex I systems, under Regulation (EU) 2026/1744 (the «Digital Omnibus on AI»), in force since 27 July 2026. That is why we implement in a cluster with Summum Consultoría, which handles legal AI Act compliance, and Summum IA, which handles the technical layer: three disciplines, a single implementation.
AI systems in use and under development. Own and third-party.
Policy, roles, procedures.
From data to model decommissioning, documented controls.
Internal and external with ENAC. Maintenance.
The operational detail: what we deliver as part of the engagement and what we keep active afterwards.
If you're already certified in ISO 9001 or ISO 27001: internal audit, the risk matrix and the continuous-improvement cycle work within the same framework. You extend the scope, you don't duplicate procedures.
AI-specific policy and roles
Committee, responsibilities, resources.
Risk analysis per system
AI-specific matrix.
Model lifecycle
From training data to decommissioning. Traceable.
Data and decision traceability
End-to-end auditable.
Internal AI audit
3 months before the external one.
Three-brand cluster
Standard, legal compliance and technical layer.
42001 is ISO. AI Act is regulation. They work together.
42001 alone does not cover the AI Act. AI Act without a management system is not sustainable. Pure Summum cluster.
Not legally. Strongly recommended as an AI Act pillar.
AENOR, BV, BSI, SGS. We coordinate the selection.
2–4 months if you already have 27001/9001. 4–6 months from scratch.
All three standards share the same high-level structure (Annex SL): the same continuous-improvement cycle, the same internal audit, the same management committee. You don't open a parallel system — you extend the scope of the one you already have.
The most common ones: incomplete traceability of training data, no designated AI risk owner, an impact assessment left unupdated after a model change, and bias controls without documented evidence.
It isn't a separate process: it's the same internal audit cycle with an AI-specific checklist (system inventory, per-system risks, model lifecycle) added to the usual points.
Usually the quality manager or whoever already owns the management system, supported by whoever runs the AI systems day to day: IT, the data team or the model vendor.
ISO 42001 is the technical implementation. Legal compliance and governance are handled by our sister divisions.
Does 42001 cover 100% of the AI Act? Read the controls mapping (ES) →