Put Effective Governance Around the AI Your Organisation Uses
Many organisations already use AI through productivity platforms, third-party services, customer-facing products and automated processes, and governance has not always kept pace. Secure Chain helps you establish an Artificial Intelligence Management System aligned with ISO/IEC 42001:2023, turning AI governance into defined responsibilities, risk-based decisions, operational controls and evidence that management and, where required, an independent certification body can review.
- Microsoft CopilotUserApproved
- Customer Service AIProviderIn review
- Third Party LLMUser · ProviderApproved
- Internal AutomationDeveloperApproved
- Open Risks6
- Accepted Risks3
- Treatment Plans9
- Internal AuditComplete
- Controls Implemented31 / 38
- Evidence AvailableLinked
Illustrative view · figures for example only
AI Adoption Often Moves Faster Than Governance
Most organisations we speak to are not short of controls. They have information security policies, a procurement process, a data protection function and some form of supplier management. What they usually lack is a consistent way of applying those arrangements to AI.
The pattern is familiar. Copilot is switched on for a pilot group, a CRM supplier enables an AI summarisation feature by default, a product team integrates a language model API, and a department starts using a browser-based tool to draft client material. Each decision may be reasonable on its own. Nobody, however, can produce a single list of what is in use, who approved it, what it is used for and what the organisation's position would be if it produced a harmful or wrong result.
That gap tends to surface when a customer due-diligence questionnaire asks how AI is governed, or when a board member asks the same question after reading about an incident elsewhere. The honest answer is often that it depends who you ask.
Not every use of AI carries the same level of risk, and an AIMS should not treat it as though it does. An internal tool that helps staff summarise meeting notes needs lighter treatment than a system that influences decisions about customers, patients or employees. The point of ISO 42001 is to make those judgements deliberately, record them and revisit them, so they become repeatable and accountable rather than dependent on individuals.
- Identifying which AI systems are actually in use, including features embedded in existing platforms
- Determining the organisation's role in relation to each system
- Assigning an accountable owner
- Evaluating intended use and assessing possible impacts on people
- Approving new use cases against agreed criteria
- Managing third-party AI services through supplier oversight
- Recording risk decisions and the reasons for them
- Monitoring whether systems continue to perform as expected
- Giving interested parties meaningful information about how AI is used
A Managed Route from Initial Scope to Certification Readiness
We run ISO 42001 implementation as a consultancy engagement with defined phases, but the content of each phase is adjusted to the organisation. A twenty-person professional services firm using third-party tools does not need the same documentation set as a software provider shipping AI features to customers, and we do not push both through an identical package.
Phase 1, discovery and scoping. We establish the organisational boundaries of the AIMS, the AI systems that are relevant, internal and external issues, interested parties and their requirements, legal and contractual considerations, and the organisation's role in relation to each system. The scope statement that comes out of this is the decision everything else depends on, so we spend time on it.
Phase 2, readiness and gap assessment. We review existing governance, information security, privacy, procurement, risk management, development and supplier-management practice against the applicable requirements of the standard and Annex A. The output is a gap report that separates what can be extended from what has to be built.
Phase 3, AIMS design. We define governance responsibilities, policy direction, AI objectives, assessment methods, the criteria used to approve or reject AI uses, documentation requirements and the control framework, including the justification for including or excluding each Annex A control.
Phase 4, risk and impact work. We establish practical methods for AI risk assessment, risk treatment and AI system impact assessment, then apply them with the system owners to the systems within scope. This is where the method gets tested; if owners cannot complete an assessment without us in the room, the method is too complicated and we simplify it.
Phase 5, implementation and evidence. We help process owners put the agreed controls into operation and set up records that show approvals, assessments, decisions, monitoring and review actually happening. Evidence is designed to come out of normal work, not to be assembled the week before an audit.
Phase 6, assurance and readiness. We support the internal audit, corrective actions and management review, then complete a certification-readiness assessment and help you prepare for independent Stage 1 and Stage 2 audits.
Typical AI Governance Issues We Encounter
Most organisations already have AI in use before they have governance arrangements around it.
No AI inventory
Nobody can produce a single list of the AI systems in use, including features switched on inside existing SaaS platforms.
No named owner
Tools are approved by whoever bought them. When an output is wrong or harmful, accountability is unclear.
Embedded AI nobody approved
Suppliers enable summarisation, drafting or scoring features by default, outside procurement and risk review.
Policy without process
An acceptable-use policy exists, but there is no approval route, assessment method or record of decisions.
Impact on people not assessed
Data protection impact assessments are done, but the wider effects on customers, staff or the public are not considered.
Supplier assurance stops at security
Third-party AI services are reviewed for information security but not for model behaviour, data use or change notification.
Outputs relied on without review
Staff use AI-drafted material in client work or decisions without a defined level of human checking.
No monitoring after go-live
Systems are assessed once at approval and never revisited, even as the model, data or use case changes.
Everything in the engagement, set out up front.
The management system that has to sit behind an AI policy. These elements depend on each other; a policy without the rest is a statement of intent, not an AIMS.
Scope and leadership
A defined AIMS scope that reflects your actual role and systems, with top management accountable for the AI policy, objectives and resources rather than delegating the whole thing to IT.
AI system inventory and ownership
A maintained inventory of relevant AI systems, each with an owner, intended use, supplier and applicable assessments. Without it, scope and risk work have nothing reliable to stand on.
Risk and impact assessment
Methods for AI risk assessment and AI system impact assessment, with criteria for evaluating and approving uses, so similar requests receive similar decisions.
Selected and justified controls
Annex A controls chosen against assessed risk and recorded in a statement of applicability, with reasons for inclusion or exclusion that will stand up to an auditor's questions.
Operating evidence
Records showing that approvals, assessments, monitoring and supplier reviews take place. This is usually where implementations fall short, because documents were written but processes never started.
Measurement, audit and improvement
Objectives with measures, internal audit, management review and corrective action that close the loop and keep the system current as AI use changes.
What you receive.
- AIMS scope statement
- Context and interested-parties analysis
- AI governance structure, roles and responsibilities
- AI policy
- AI system inventory
- AI risk assessment methodology, risk register and treatment plan
- AI system impact assessment method and completed records
- Statement of applicability
- AI objectives and measures
- Third-party AI assessment arrangements
- Acceptable-use and operational procedures
- Competence and awareness records
- Monitoring and reporting arrangements
- Internal audit programme and report
- Management review inputs and records
- Corrective-action tracking
- Certification-readiness findings
Built for organisations that need the work done properly.
Organisations using Microsoft Copilot internally
You are a user of AI. The work centres on acceptable use, data access and permissions, supplier assurance, staff awareness and monitoring how outputs are relied on.
Software providers incorporating a third-party language model
You are both a user of the model and a provider of the resulting product. Scope has to cover how you select and monitor the model, and what information you give your customers.
Businesses deploying AI-assisted customer support
Impact assessment matters more here because outputs reach the public. Escalation to people, transparency and monitoring of quality become central controls.
Professional services firms using AI to analyse or draft
Client confidentiality, review of outputs before they are relied on, and clear rules on which tools may handle which information tend to dominate the control set.
Organisations developing their own models or AI products
The full AI system life cycle applies: data quality and provenance, design and verification, release criteria, ongoing performance monitoring and retirement.
What changes once the work is done.
What a well-implemented AIMS should give you. These outcomes depend on the system being operated, not just documented, and certification remains a decision for the certification body.
Clearer accountability
Named owners for AI systems and AI-related decisions, and an agreed view of which systems sit within scope.
Repeatable assessment
A consistent way of assessing AI risk and impact, so new use cases are approved or declined on recorded criteria.
Oversight of third-party and internal systems
Better visibility of systems you build and those you buy, with traceable approval and risk-treatment decisions.
Evidence for assurance and certification
Management reporting based on defined objectives, evidence for customer and procurement questions, and a structured basis for independent certification.
Build on Governance That Already Works
An AI policy may be one documented component of an AIMS, but it does not constitute one. Certification readiness is not achieved by producing a library of documents. The organisation must be able to demonstrate that its governance processes are understood, used and reviewed.
If you already operate ISO 27001, ISO 9001 or another management system, much of the machinery exists. We extend what works rather than running a parallel system that doubles the audit and review burden.
Equally, ISO 27001 certification does not automatically establish conformity with ISO 42001. AI-specific risks, impacts, roles, objectives and controls still need to be addressed, and an information security risk register rarely captures the effects of an AI system on the people it is used about.
Secure Chain approaches this as an operational change programme rather than a template exercise. We bring governance, risk and compliance experience, practical ISO management system implementation and information security assurance capability. Implementation is proportionate to your size and risk, documentation is written around how you actually operate, and we work directly with management and process owners so the evidence and processes are sustainable after we step back. Support is delivered by our UK-based consultancy team.
- Document control and records management
- Competence and awareness
- Internal audit and management review
- Corrective action and continual improvement
- Risk governance
- Supplier oversight
Questions we are asked most often.
What is ISO/IEC 42001:2023?
ISO/IEC 42001:2023 is the international standard that sets out requirements for an Artificial Intelligence Management System (AIMS). It follows the same high-level structure as ISO 27001 and ISO 9001: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A adds AI-specific controls covering areas such as impact assessment, data for AI systems, the AI system life cycle, information for interested parties and third-party relationships. It is a management system standard, so it describes how an organisation governs AI over time rather than how any single model should be built.
Is ISO 42001 only for companies that develop AI?
No. The standard applies to organisations that develop, provide or use AI systems. A firm that only uses Microsoft Copilot and a handful of third-party AI services can operate an AIMS. Its scope and controls will look different from those of a software provider training its own models, because the organisation's role, the systems involved and the possible effects on people are different. Part of the scoping work is establishing that role for each system in scope.
Can ISO 42001 be integrated with ISO 27001?
Yes, and for organisations that already hold ISO 27001 this is usually the sensible route. Document control, competence records, internal audit, management review, corrective action and supplier oversight can often be extended rather than rebuilt. ISO 27001 certification does not, however, establish conformity with ISO 42001. AI-specific risks, impact assessments, roles, objectives and Annex A controls still need to be defined, operated and evidenced.
Do we need an inventory of AI systems?
In practice, yes. You cannot set a defensible scope, assess risk or assign ownership for systems you have not identified. The inventory does not need to be elaborate, but it should record each relevant system, its intended use, the organisation's role in relation to it, the owner, the supplier where applicable and the assessments that apply. Most organisations find more AI in use than they expected once embedded features in existing SaaS platforms are included.
What is an AI system impact assessment?
It is a documented assessment of the potential consequences of an AI system for individuals, groups of individuals and society, considering its intended use and foreseeable misuse. It is related to, but separate from, the organisational AI risk assessment. The depth should be proportionate: an internal drafting assistant will not need the same treatment as a system that influences decisions about customers or employees. Where a data protection impact assessment already exists, the two can be coordinated, but one does not replace the other.
Does ISO 42001 guarantee compliance with AI legislation?
No. The standard gives you a structured way to identify obligations, assess risk, apply controls and keep evidence, which supports compliance activity under legislation such as UK GDPR or the EU AI Act where it applies to you. It does not replace those legal or regulatory obligations, and conformity with ISO 42001 should not be presented as proof of legal compliance. Legal interpretation of specific obligations should be taken from appropriately qualified advisers.
Can Secure Chain certify our organisation?
No. Secure Chain provides implementation and readiness support. Formal certification must be performed independently by an appropriately accredited certification body. We can help you prepare for the Stage 1 and Stage 2 audits and respond to any findings, but we do not audit our own implementation work for certification purposes.
How do we know whether we are ready for certification?
Readiness means the AIMS has been operating long enough to produce evidence: assessments completed for in-scope systems, risk treatment decisions recorded, objectives being measured, at least one internal audit completed across the scope, a management review held and nonconformities being tracked to closure. We carry out a certification-readiness assessment against those points before you book Stage 1. How long implementation takes depends on scope, the number of AI systems involved, existing management system maturity and the availability of process owners, so we agree a timeline after discovery rather than quoting a fixed duration.
ISO 42001 Readiness Assessment
Many organisations are not ready for a full implementation project. They first need to understand:
- What AI they are actually using
- What governance already exists
- Which systems should be within scope
- What gaps exist against ISO 42001
- What level of effort certification would require
ISO 42001 Readiness Assessment
Fixed scope- AI usage discovery workshop
- AI inventory review
- Governance review
- Gap assessment against ISO 42001
- Risk and impact assessment review
- Executive summary report
- Prioritised roadmap
- Current State Assessment
- Gap Report
- Recommended Scope
- Priority Actions
- Management Briefing
Discuss your ISO 42001 project.
Tell us how AI is used in your organisation and what is prompting the question, whether that is a customer requirement, a board request or a plan to certify. We will suggest a proportionate starting point, which is often an initial readiness review.
Request a Readiness Assessment