Skip to main content
01 Readiness

ISO/IEC 42001 Readiness & Gap Assessment (with EU AI Act readiness overlay)

Best for organisations exploring certification, or needing a clear roadmap for both AI Act governance and ISO/IEC 42001.

What you get:

  • Discovery session and scope definition (org boundaries, AI use cases, objectives)
  • AI system inventory + ownership mapping
  • Provider/deployer role clarification + high-risk screening workshop
  • Initial documentation/evidence expectations for AI Act readiness (practical, non-legal)
  • Current-state review (governance, controls, documentation, risk processes)
  • Gap assessment mapped to ISO/IEC 42001 clauses/controls (tailored to your context)
  • Prioritised remediation roadmap (quick wins + foundational work)
  • Executive summary for leadership/procurement
Typical output: Gap report + implementation plan + recommended scope statement
02 Implementation

AIMS Design & Implementation

Best for organisations ready to build the management system and embed it—supporting both AI Act operationalisation and ISO/IEC 42001.

What you get:

  • AIMS policy and governance design (roles, accountability, oversight)
  • AI risk management approach (risk criteria, assessment workflow, register structure)
  • Documentation and evidence structure to support AI Act readiness (technical documentation pack templates)
  • Human oversight + transparency patterns (proportionate to use case)
  • Supplier/third-party model governance (incl. GPAI usage where relevant)
  • Core documentation set (proportionate to size/complexity)
  • Operational processes (change control, supplier/third-party considerations, monitoring)
  • Training / enablement for key stakeholders
  • Implementation support to make it "real" (not shelfware)
Typical output: AIMS documentation + operational workflows + evidence plan
03 Assurance

Internal Audit & Certification Readiness

Best for organisations approaching an external audit or needing internal assurance on AI Act and ISO/IEC 42001 readiness.

What you get:

  • Internal audit planning and execution support (aligned to ISO/IEC 42001 expectations)
  • Evidence readiness review for AI Act documentation and assurance requests
  • Support for procurement questionnaires / customer assurance packs
  • Evidence readiness review (what auditors will ask for, and where gaps remain)
  • Corrective action support (CAR plan, ownership, timelines)
  • Management review support pack
  • "Audit week" support (as agreed)

Important note: We do not issue certifications. Certification decisions are made by accredited certification bodies.

Add-ons

Common requests that complement our core services

AI use-case risk assessments (per system/model)
Supplier / third-party AI due diligence guidance
AI Act role & risk-tier classification workshop (provider/deployer, high-risk screening)
Technical documentation pack (templates + evidence mapping)
Board/leadership workshop: "ISO 42001 in plain English"
Ongoing advisory retainer (fractional AI governance lead)

Ready to get started?

Let's discuss which service fits your EU AI Act readiness and ISO/IEC 42001 implementation goals.