ISO 42001 & AI Governance

18 Key Steps for Implementing ISO 42001

18 Key Steps for Implementing ISO 42001
TL;DR
Quick summary

If you don’t know how to implement ISO 42001 standards, then this blog post is for you. In this post, I will explain how this standard actually works and how it helps you implement AI governance. I will show you all 18…

If you don’t know how to implement ISO 42001 standards, then this blog post is for you. In this post, I will explain how this standard actually works and how it helps you implement AI governance. I will show you all 18 key steps required to comply fully with this standard in an easy-to-understand manner. After reading this post, you will have a clear idea of the main milestones and objectives when setting up AI governance according to ISO 42001.

What is the connection between ISO 42001 and AI Governance?

Essentially, this standard explains how to manage and govern your AI systems so that they remain trustworthy and reliable. Once you follow these 18 steps, you will have a systematic AI governance framework in place.

The 18 Steps to ISO 42001 Compliance

  1. Gain Senior Management Commitment

    Securing commitment from leadership is crucial at the very beginning. Without sufficient resources—such as budget, personnel, and buy-in from senior and middle management—your implementation project is likely to fail.

  2. Set Up Project Management

    Define who is running the project, including the project manager and core team members (especially for mid-sized or large organizations). You should also assign an executive project sponsor from senior management who can step in to resolve roadblocks when the team gets stuck. Ensure you establish a project plan with clear milestones.

  3. Define Your Organization's Role

    Determine your company’s explicit role regarding AI systems—are you an AI provider, producer, or user? Your operational classification directly shapes how you carry out subsequent steps in the ISO 42001 lifecycle.

  4. Identify Stakeholders and Requirements

    Map out interested parties and their requirements:

    • Governments/Regulators: Compliance with AI laws and standards.

    • Customers: Reliable outputs, absence of hallucinations, and incident-free performance.

    • Employees: Understanding the impact of AI on their roles and future workplace.

  5. Define the Scope of the AIMS

    Define the boundary of your Artificial Intelligence Management System (AIMS). Smaller organizations typically apply the scope across the entire company, while larger enterprises may focus initially on specific AI systems or divisions.

  6. Establish a Top-Level AI Policy

    Draft an overarching AI policy outlining your organization’s strategic direction, purpose for governance, and major roles and responsibilities regarding AI management.

  7. Perform AI Risk Assessment and Treatment

    Identify potential risks posed by your AI systems and select safeguards to mitigate them. Annex A of ISO 42001 lists 38 specific controls you can leverage to treat these risks.

  8. Conduct AI System Impact Assessments

    Unlike risk assessments (which look at potential future events), impact assessments focus on the known, direct consequences of regular AI usage or potential misuse. Evaluate the practical impacts on individuals, groups, and society as a whole.

  9. Draft the Statement of Applicability (SoA)

    Create an SoA document reviewing all 38 controls from Annex A. Based on your risk assessments and stakeholder requirements, declare which controls are applicable or non-applicable, along with justification.

  10. Develop a Risk Treatment Plan

    Outline how you will implement the selected Annex A controls. Define responsibilities, allocate budgets and resources, and set target completion dates.

  11. Establish Support Processes

    Before implementing controls, establish underlying support mechanisms: allocate financial/human resources, design internal/external communication plans for AI updates, and set up document and record controls for formatting, security, and access.

  12. Implement Annex A Controls

    Begin executing the controls. Refer to Annex B for guidance: it mirrors the 38 controls of Annex A and provides actionable implementation advice for each.

  13. Conduct Training and Build Awareness

    Run this step in parallel with control implementation. Train employees on how to operate under new policies and build awareness so they understand why these AI controls are necessary.

  14. Operate the AIMS

    Put the AI processes into daily practice. Ensure continuous compliance across teams—AI governance is an ongoing operational commitment, not a one-time project.

  15. Monitor and Measure Performance

    Track AI system behavior, usage metrics, and security incidents on a daily operational basis. Compare these outcomes against your Key Performance Indicators (KPIs) to verify that target objectives are met.

  16. Conduct Internal Audits

    Perform internal audits regularly (at least annually for smaller entities, more frequently for larger enterprises). An independent internal auditor evaluates whether operations and AI systems comply with set policies, surfacing non-conformities before external audits.

  17. Perform Management Reviews

    Present audit findings, metrics, and risk reports to senior management. Leadership uses this review to evaluate effectiveness, adjust top-level goals, reallocate resources, or refine responsibilities.

  18. Execute Corrective Actions

    Systematically address non-conformities identified during internal audits or management reviews. Perform root-cause analysis to ensure problems are permanently resolved and prevented from recurring.

Once you complete these 18 steps, your organization will have a fully functioning AI Management System and will be prepared for formal ISO 42001 Certification.

If you have questions or want to discuss AI governance further, leave a comment below or connect with me on LinkedIn!

Kumail Mehdi

Kumail Mehdi

ISO 42001 Lead Auditor and AI strategist. 11 years in corporate leadership, 14 years running a digital agency. I help professionals, consultants and AI startups turn expertise into governed, AI-powered systems.