Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

ISO 42001 asks who is accountable when the model is wrong.

An ISO 42001 consultant in India is being asked, more and more, by organisations that put a model into production before anyone agreed who owned its output. ISO/IEC 42001:2023 is the first certifiable management system standard for artificial intelligence, and its central demand is unglamorous: name the accountable person, write down what the system is for, and assess what happens to the people affected when it gets something wrong.

It is built on the same Annex SL structure as ISO 27001, so if you already run an information security management system the clauses will look familiar and the two can share governance, internal audit and management review. What is genuinely new is Annex A: thirty-eight controls across nine objectives, covering AI policy, internal organisation, resources, impact assessment, the system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships.

Certification is not the only reason to do this. The EU AI Act, procurement questionnaires and enterprise customers are all converging on the same questions, and an AI management system answers most of them once. Where the underlying data also falls under ISO 27701 or the DPDP Act, the privacy and AI programmes should be designed together rather than sequentially.

Why you need it

01 / 06

Why an AI management system, and why now.

01

Someone is already using AI you have not assessed.

The first deliverable of almost every engagement is an inventory, and it is almost always longer than the organisation expected. Models embedded in SaaS products, a team’s own fine-tune, and a vendor feature switched on by default all count, and all carry obligations you have not yet accepted.

02

Impact assessment is the control that does the work.

The standard requires you to assess consequences for individuals and groups affected by an AI system, not only risk to the organisation. That inversion is the point of the standard, and it is the part that most existing risk processes do not cover at all.

03

It is the credible answer to a question customers now ask.

Enterprise procurement has started asking how AI is governed, and there has not been a good answer to give. A certified AIMS is currently the most recognised one available, and it maps usefully onto EU AI Act obligations for organisations in scope.

04

It bolts onto what you already run.

Shared Annex SL clauses mean scope, leadership, planning, support, operation, evaluation and improvement can be operated once across ISO 27001 and ISO 42001, with one internal audit programme and one management review rather than two.

Instrument

02 / 06

What an AI management system shares with the rest.

Where ISO 42001 overlaps the management system you may already be running, and where it genuinely asks for something new.

What we deliver

03 / 06

What we deliver.

01

AI inventory and scoping

Every AI system in use, built or embedded, with its purpose, its owner, the data it consumes and the decisions it influences. Then an honest scope statement for the management system, because certifying everything at once rarely survives contact with a budget.

02

Gap analysis against clauses and Annex A

Clauses 4 to 10 and all thirty-eight Annex A controls assessed as met, partially met or not met, with a Statement of Applicability that justifies every exclusion rather than quietly dropping it.

03

AI impact assessment method

A repeatable process for assessing consequences to individuals and groups, proportionate to the system, that your teams can actually run on the next model without calling us back.

04

Policy, roles and life-cycle controls

AI policy, accountable roles and authorities, and the life-cycle controls the standard expects: objectives for design, verification and validation, deployment, operation and monitoring, with the records each stage produces.

05

Data governance for AI systems

Provenance, quality, preparation and the acquisition controls in Annex A, including the uncomfortable questions about training data rights and about what your providers do with prompts and outputs.

06

Certification support

Internal audit, management review, and support through Stage 1 and Stage 2 with an accredited certification body. We do not issue the certificate; we make sure the auditor finds a working system.

How we run it

04 / 06

The engagement, step by step.

  1. 01

    Inventory and scope

    Find every AI system, including the embedded ones nobody classifies as AI, and agree what the management system covers.

    Weeks 1-3
  2. 02

    Gap analysis

    Assess against Clauses 4-10 and Annex A, and draft the Statement of Applicability with a justification for each decision.

    Weeks 3-6
  3. 03

    Build the management system

    Policy, roles, risk and impact assessment method, objectives, and the life-cycle and data controls. Written to be operated, not to be read once.

    Months 2-4
  4. 04

    Run it

    Operate the system long enough to generate real records: impact assessments completed, changes reviewed, incidents handled. An auditor needs evidence of operation, not of intent.

    Months 4-7
  5. 05

    Internal audit and management review

    Audit the system against the standard, correct what the audit finds, and hold a documented management review with the accountable leadership.

    Month 7-8
  6. 06

    Certification

    Stage 1 documentation review, then Stage 2 with the certification body, then the surveillance rhythm that keeps it alive.

    Month 8-10, then annually

Key benefits

05 / 06

What changes afterwards.

You know what AI you are running

The inventory alone changes decisions. It routinely surfaces systems making or shaping consequential decisions that nobody had assessed, and it gives each one a named owner for the first time.

A credible answer in procurement

Where AI governance questions currently produce an improvised response, a certified management system produces a certificate, a scope statement and a Statement of Applicability, which is what enterprise buyers are actually asking for.

One management system, not three

Shared clauses with ISO 27001 and ISO 27701 mean one internal audit programme, one management review and one improvement cycle, which is the difference between a system that is maintained and one that lapses.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Standards

  • ISO/IEC 42001:2023
  • ISO/IEC 23894:2023 AI risk management
  • ISO/IEC 22989 AI concepts and terminology

Assessment

  • AI system inventory and classification
  • AI impact assessment templates
  • Statement of Applicability

Adjacent obligations

  • EU AI Act obligation mapping
  • DPDP Act 2023
  • ISO/IEC 27701

Evidence

  • AphelioNYX Compliance Hub
  • Model and dataset registries

Mapping

  • ISO 42001 to ISO 27001 Annex SL alignment
  • AphelioNYX Frameworks Hub

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

Asked often enough to answer here.

We only use third-party AI, we do not build models. Does this apply?
Yes, and this is the most common misunderstanding about the standard. ISO 42001 distinguishes between roles (AI provider, AI producer, AI user) and an organisation that only uses other people’s AI still has obligations covering how systems are selected, what they are used for, what data is sent to them, how outputs are reviewed, and what is agreed with the supplier. Annex A has a whole objective on third-party relationships and another on use of AI systems. The scope is smaller than a model developer’s, but it is not empty.
How does this relate to the EU AI Act?
They are different instruments: the AI Act is law with defined risk categories and penalties, ISO 42001 is a voluntary certifiable management system. They are complementary rather than equivalent, and certification does not by itself demonstrate conformity with the Act. What an AIMS gives you is most of the governance machinery the Act expects: an inventory, risk and impact assessment, human oversight, documentation, and post-market monitoring. If you are in scope of the Act, building the management system first makes the legal work substantially cheaper.
Can ISO 42001 share an audit with our ISO 27001 certification?
Usually yes. Both are Annex SL management system standards, so Clauses 4 to 10 have the same structure and the scope, leadership, planning, support, evaluation and improvement machinery can be operated once. Many certification bodies will run integrated audits covering both, which reduces audit days and, more importantly, stops you maintaining two parallel systems that drift apart. The Annex A controls are entirely different between the two standards, so the control work does not merge, only the management system around it.
What is an AI impact assessment, and is it the same as a DPIA?
No, though they overlap and can share evidence. A data protection impact assessment looks at risk to personal data and to data subjects. An AI impact assessment under ISO 42001 looks at consequences for individuals and groups affected by the AI system’s behaviour, including fairness, error, contestability and the effect of automation on people who cannot opt out, whether or not personal data is involved. A model that allocates resources using no personal data at all can still need one.
How long to certification?
Eight to ten months is realistic for a first certification, and the constraint is rarely the documentation. Certification bodies need evidence that the system has operated, which means impact assessments actually completed, changes actually reviewed and a management review actually held, so there is an irreducible period of running the system before Stage 2. Organisations that already hold ISO 27001 move faster through the clause work, because the management system scaffolding is already there and audited.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.