An ISO 42001 consultant in India is being asked, more and more, by organisations that put a model into production before anyone agreed who owned its output. ISO/IEC 42001:2023 is the first certifiable management system standard for artificial intelligence, and its central demand is unglamorous: name the accountable person, write down what the system is for, and assess what happens to the people affected when it gets something wrong.
It is built on the same Annex SL structure as ISO 27001, so if you already run an information security management system the clauses will look familiar and the two can share governance, internal audit and management review. What is genuinely new is Annex A: thirty-eight controls across nine objectives, covering AI policy, internal organisation, resources, impact assessment, the system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships.
Certification is not the only reason to do this. The EU AI Act, procurement questionnaires and enterprise customers are all converging on the same questions, and an AI management system answers most of them once. Where the underlying data also falls under ISO 27701 or the DPDP Act, the privacy and AI programmes should be designed together rather than sequentially.