CA-07 · AI governance · cluster

ISO 42001 AI management

ISO 42001 is the AI management system. If you already run quality with ISO 9001 or security with ISO 27001, you reuse much of that structure here: the same continuous-improvement cycle, the same internal audit, the same level of control. Built for quality teams that aren't starting from zero.

StandardISO/IEC 42001:2023
Marketemerging
ClusterCal. + Cons. + AI

ISO 42001 is the first international standard dedicated to the management of artificial intelligence systems. Published in 2023 and still without implementers with traction among Spanish SMEs, it opens a clear window of opportunity for those who want to get ahead of regulation.

The standard covers five areas: AI-specific policy and roles within the organisation, risk analysis for each AI system in use, model lifecycle (from training data to decommissioning), data and decision traceability, and internal audit of system performance.

In practice, ISO 42001 is the natural backbone for supporting compliance with the European AI Act: 2 August 2026 remains the general application date for the Regulation, while full high-risk obligations are deferred to 2 December 2027 for Annex III systems and to 2 August 2028 for Annex I systems, under Regulation (EU) 2026/1744 (the «Digital Omnibus on AI»), in force since 27 July 2026. That is why we implement in a cluster with Summum Consultoría, which handles legal AI Act compliance, and Summum IA, which handles the technical layer: three disciplines, a single implementation.

The ISO 42001 AI management process.

The process · four stages
01

Inventory

AI systems in use and under development. Own and third-party.

02

Management system

Policy, roles, procedures.

03

Lifecycle

From data to model decommissioning, documented controls.

04

Certification

Internal and external with ENAC. Maintenance.

What is included

What ISO 42001 AI management includes.

The operational detail: what we deliver as part of the engagement and what we keep active afterwards.

If you're already certified in ISO 9001 or ISO 27001: internal audit, the risk matrix and the continuous-improvement cycle work within the same framework. You extend the scope, you don't duplicate procedures.

  • AI-specific policy and roles

    Committee, responsibilities, resources.

  • Risk analysis per system

    AI-specific matrix.

  • Model lifecycle

    From training data to decommissioning. Traceable.

  • Data and decision traceability

    End-to-end auditable.

  • Internal AI audit

    3 months before the external one.

  • Three-brand cluster

    Standard, legal compliance and technical layer.

Regulatory framework

The regulatory framework.

42001 is ISO. AI Act is regulation. They work together.

ISO/IEC 42001 Applicable to this service
EU AI Act Applicable to this service
AESIA guidelines Applicable to this service
ENS IA Applicable to this service
Summum cluster

How it intersects with related services.

42001 alone does not cover the AI Act. AI Act without a management system is not sustainable. Pure Summum cluster.

Frequently asked questions about ISO 42001 AI management.

Is it mandatory?

Not legally. Strongly recommended as an AI Act pillar.

Certification bodies?

AENOR, BV, BSI, SGS. We coordinate the selection.

How long does it take?

2–4 months if you already have 27001/9001. 4–6 months from scratch.

How does it integrate with the ISO 9001 or 27001 I already have?

All three standards share the same high-level structure (Annex SL): the same continuous-improvement cycle, the same internal audit, the same management committee. You don't open a parallel system — you extend the scope of the one you already have.

What's a typical ISO 42001 non-conformity?

The most common ones: incomplete traceability of training data, no designated AI risk owner, an impact assessment left unupdated after a model change, and bias controls without documented evidence.

Is the internal audit different from the one under ISO 9001?

It isn't a separate process: it's the same internal audit cycle with an AI-specific checklist (system inventory, per-system risks, model lifecycle) added to the usual points.

Who should lead the implementation in my company?

Usually the quality manager or whoever already owns the management system, supported by whoever runs the AI systems day to day: IT, the data team or the model vendor.