ISO/IEC 42001 is a management-system standard for organizations that develop, provide, or use AI. It tells an organization to establish responsibilities, understand context, assess risks and impacts, operate controls, monitor performance, and improve. It does not certify that an AI system is accurate, safe, lawful, or unbiased.

Small suppliers often meet the number in a client questionnaire before they meet the standard itself. The practical question is not “How do I pretend to be certified?” It is “Which management habits would make our limited AI use more controlled, and what can I say honestly?”

§1What the standard actually is

ISO/IEC 42001:2023 specifies requirements for an artificial intelligence management system. Like other management-system standards, it uses a repeatable cycle: leadership sets policy and objectives; the organization plans around risks and opportunities; it supports and operates controls; it evaluates performance; and it improves.

The standard can apply to organizations of different sizes and to developers, providers, or users of AI. The work still has to be tailored to context. Buying a standard does not choose your risk appetite or determine which laws apply.

§2Why enterprise clients mention it

A buyer wants a common vocabulary and evidence that suppliers govern AI consistently. ISO 42001 gives procurement teams a recognizable reference for ownership, risk, lifecycle controls, supplier management, records, and improvement.

Sometimes “Are you ISO 42001 compliant?” is copied into a questionnaire before the buyer has decided what evidence it expects. Ask whether certification is mandatory, whether alignment is acceptable, and which services are in scope.

§3Certification, conformity, and alignment

Certification is a formal assessment by a certification body. Self-declaring compliance or using a logo without the basis can mislead customers. Conformity means the requirements are met; proving it requires far more than borrowing a checklist.

Alignment is a narrower, useful statement when accurate. Say that your controls are informed by particular management-system practices, and name them. Do not turn “informed by” into “ISO compliant” in sales copy.

Sample languageWe are not ISO/IEC 42001 certified. Our AI governance practices are informed by its management-system approach, including accountable ownership, an AI use inventory, risk-based review, documented controls, training, incident handling, monitoring, and periodic improvement.

§4Why certification may be overkill under 50 people

Certification can require external fees, internal time, documentation, audits, corrective actions, and continued surveillance. If your AI use is limited to low-risk assistance and no customer requires a certificate, those resources may reduce more risk elsewhere.

That is not a rule that small companies should never certify. Certification can make sense when it is a contract requirement, a market differentiator backed by demand, or proportionate to the systems and decisions you control. Make a business case before starting.

§5Start with organizational context

Write down why you use AI, which customers and people may be affected, what contracts matter, which jurisdictions apply, and what could cause material harm. This sets the boundary of the management system.

A design agency using an approved image tool has a different context from a clinic using AI-supported notes or a software company embedding recommendations. Do not use one generic risk list for all three.

§6Assign ownership and policy

Name an accountable owner, define responsibilities for managers and users, and adopt a readable policy. Leadership should approve the scope and risk boundaries, not merely delegate the document.

For a small company, one owner and a quarterly cross-functional review may be enough. Record decisions and actions. The evidence of oversight matters more than a ceremonial committee name.

§7Maintain a useful AI inventory

Record systems, embedded features, providers, owners, purposes, data, affected parties, integrations, decisions supported, status, and review dates. Include experiments separately so the inventory does not become a graveyard of one-hour trials.

Connect each approved item to its vendor review and risk decision. The inventory should answer “What do we use, why, under what limits, and who is responsible?” without a meeting.

§8Assess risks and impacts proportionately

Assess likelihood and consequence across privacy, security, safety, fairness, explainability, intellectual property, reliability, people, and contractual duties. Consider benefits and foreseeable misuse as well as technical failure.

Use simple levels with clear escalation. A tool that reformats public marketing copy may receive a brief review. A system that ranks applicants needs deeper assessment, legal advice, testing, oversight, and possibly a decision not to proceed.

§9Operate controls across the lifecycle

Before use, approve the purpose, tool, data, owner, and review method. During use, apply access control, instructions, human review, monitoring, records, and incident reporting. At change or retirement, reassess material updates, remove access, export necessary records, and ensure deletion.

Supplier controls matter because most small businesses buy rather than build AI. Review terms, security, training use, retention, subprocessors, change notice, and exit.

§10Evaluate and improve

Choose a few measures that reveal control: percentage of active tools with an owner and current review, overdue actions, reported incidents, completion of role-based training, and time to close unauthorized tools. Avoid vanity measures such as the number of policy pages.

Review incidents, near misses, client questions, vendor changes, and employee feedback. Record corrective actions and whether they worked. That is the useful core of continual improvement.

§11A credible alignment package

A small business can assemble a policy, scope statement, inventory, vendor checklist, risk template, approval records, training note, incident path, metrics, and quarterly review record. Together they show an operating system rather than a claim.

Use the shadow AI audit to build the inventory and the RFP guide to describe the result accurately. If certification later becomes commercially necessary, these habits reduce the gap—without pretending that readiness equals certification.

§12Run a quarterly management review

Set aside an hour each quarter. Bring the scope, inventory, open risk actions, incidents and near misses, vendor changes, employee feedback, client questions, training status, and the small set of measures you chose. The owner should prepare decisions, not a slide deck of activity.

Ask whether the policy is still suitable, whether controls are working, whether resources are adequate, and whether a material change needs a fresh assessment. A new integration, model change, customer sector, jurisdiction, or use involving people may alter risk even when the product name stays the same.

Write a short record: attendees, evidence reviewed, decisions, owners, deadlines, and the next meeting. Follow up old actions before opening new ones. This is the practical meaning of management review for a small organization: leadership sees the system, resolves trade-offs, and checks that promised improvements happened.

Once a year, step back further. Confirm the management-system boundary, interested parties, legal and contractual obligations, objectives, policy, risks, and internal review method. If you are moving toward certification, obtain the official standard and qualified support; a blog summary cannot establish conformity.

§13Know when to revisit certification

Revisit the business case when a valuable customer makes certification a condition, procurement repeatedly awards points for it, your own AI product becomes central to the service, or the consequences of failure materially increase. Estimate audit fees, preparation time, ongoing surveillance, remediation, and the internal owner’s capacity.

Also price the alternative: losing the opportunity, negotiating a scoped assurance package, or supplying evidence of alignment. Certification can reduce repeated customer review, but only if buyers recognize the certificate and its scope matches what they purchase.

If you proceed, define the scope carefully and avoid rushing directly to an audit. Run the management system long enough to produce records, complete internal review, address nonconformities, and hold management review. Certification should confirm an operating system, not become the event that creates one.

§14Use internal review before external assurance

Ask someone independent of the day-to-day owner to sample the inventory, approvals, assessments, training, incidents, measures, and review records. In a very small company, independence may mean a director from another function or qualified outside help. The reviewer should test whether practice matches the documented process, not merely confirm that documents exist.

Record findings in plain language, identify the cause, assign corrective action, and check whether the fix worked. A missing review date may point to unclear ownership; an unlisted tool may point to a procurement gap. Fix the system that produced the miss instead of polishing the sampled record.

This exercise is useful even when certification is not planned. It finds contradictions before a customer does and gives leadership a more reliable view than self-reporting by the policy owner alone.

§15Frequently asked questions

Is ISO 42001 mandatory?

ISO/IEC 42001 is a voluntary standard, though a customer contract may require certification or specified controls. Applicable law can impose separate AI duties.

Can a small business be ISO 42001 certified?

Yes. The standard can apply to organizations of different sizes. Whether certification is worth the cost and effort depends on risk, customer requirements, and commercial value.

What does alignment without certification mean?

It means adopting selected management practices and describing them precisely while clearly stating that the organization is not certified.

Does ISO 42001 prove an AI tool is safe?

No. It evaluates a management system, not a guarantee that every output or system is safe, accurate, lawful, or unbiased.

If you need the policy as well as the questions, the complete Clause Zero kit is $79.