Our expertise
Our services
Who we serve
Insights
About us
Insights Resource library Careers Let's talk

What is ISO 42001? The AI governance framework explained

If AI governance has landed on your desk, or you've got clients asking for evidence of how you manage AI responsibly, here's everything you need to know to get started, including if ISO 42001 is the right move.

JBHOGR&C
James Boughey, Head of Governance, Risk & Compliance
Forward Green

It didn’t take long for organisations of all types and sizes to embed AI into their critical operations and products (enter the cliché about efficiency). But, as with all new technology, there is a downside, in that it has surfaced a new problem to address: 

It’s often deployed without any formal review, clear ownership, or oversight of the data flowing through it. That means no one knows who's responsible when it makes a mistake, what sensitive data has been shared, or where it could leave you exposed.

Now that AI governance is becoming a standard requirement in client questionnaires, supplier onboarding and procurement processes, you’re probably being asked: “How do you govern AI?”, and many organisations don’t have an answer beyond “yep, we use it”. 

What is ISO 42001?

ISO/IEC 42001:2023 is the international standard for AI Management Systems (AIMS). It defines how organisations should govern AI responsibly, including practical controls, policies, risk management, oversight and accountability.

The catch that organisations are now discovering is that formal governance frameworks like ISO 42001 assume a mature compliance function is already in place and most aren’t there yet. 

So, what do those organisations do when there are still business risks to address?

What is AI Governance?

AI governance is the oversight, policies and controls that determine how AI is managed responsibly within an organisation. 

This includes accountability for AI outputs, how risks are identified and handled, what data AI can interact with and who owns it when something goes wrong.

Building AI Governance from the ground up

The first question to ask yourself is: What AI do we actually use? 

This can be a difficult question to answer – AI has likely been embedded into software and tools that you’ve already procured, perhaps without anyone even reviewing or signing it off.

You first need to identify every tool and use case for AI across the business, including anything that is an additional feature.

For each use case, document your answers to these questions:

  • What problems should it solve?
  • What decisions does it inform or make?
  • What actions can it perform autonomously?
  • Which business function(s) does it support?
  • Who depends on its output?
  • What happens if it makes a mistake?
  • What data is passed into the tool, and how sensitive is it?
  • Who owns it, and who is accountable for the outputs?

This record is what’s known as your AI Register, which is the essential foundation for building your governance position.

Establishing your governance position

Once you have visibility of your AI use, you can then establish how each use case should be governed. 

A simple model to follow is “Would I give this task or capability to a child?”. It sounds odd, but it’s a useful guideline for understanding how AI behaves. AI takes instructions literally, it can’t apply context when making judgements, it can be unpredictable and doesn’t recognise when it’s exceeded the goal or made a mistake unless a human catches it. 

So, with this in mind, this splits each of your use cases into three categories:

  • Autonomous: What tasks can your AI reliably and accurately do by itself?
  • Supervised: What tasks can your AI do with a human reviewing the output?
  • Off limits: What is too risky for your AI to be allowed to do? 

What does ISO 42001 certification require?

For those who are in a position to commit to the certification, the ISO 42001 framework requires the organisation to build and implement a formal AI Management System (AIMS). 

An AIMS consists of: 

  • Documented policies setting out responsible AI use
  • Risk management
  • AI system lifecycle
  • Operational controls to manage day-to-day use
  • Third-party AI governance
  • Clearly defined roles and responsibilities

Is ISO 42001 the right move for your organisation?

If the above sounded overwhelming or far beyond your current operational maturity, don’t worry, many are in the same position. 

ISO 42001 is a significant investment that requires dedicated time and resources. But it isn’t the only option available when it comes to AI governance, especially for smaller organisations.

AI Governance Foundations

Our AI Governance Foundations service has been developed for organisations who are at exactly this stage. You need to start building something tangible to show clients, but you’re not in a position to commit to ISO 42001.

Ultimately, you don't need a certificate to govern AI well. We build your governance on similar principles as ISO 42001, so you get the benefits of a matured compliance framework without the cost of a formal assessment. 

When you're ready to certify, you'll already be on the right path towards a mature AIMS.

What you'll gain: 

  • Evidence of a mature governance position that clients and regulators are looking for
  • Policies and controls embedded into your operations
  • An AI Register documenting all systems and use cases across your organisation
  • A prioritised roadmap supporting your ongoing governance journey as your AI use evolves
  • A team that understands their AI governance responsibilities
  • Matured governance practices supporting future alignment with ISO 42001

If you’re ready to commit to ISO 42001…

We support organisations with ISO 42001 implementation, including the build and embedding of a formal AIMS required to achieve certification. 

What you'll gain: 

  • A fully implemented AI Management System aligned to ISO 42001 requirements
  • Audit-ready policies and procedures that meet regulatory expectations
  • Controls embedded into day-to-day operations 
  • Demonstrate to clients and regulators that you govern AI to an internationally recognised standard
  • A team equipped to sustain and mature your AIMS as your AI landscape evolves.

Wherever you’re at on your AI governance journey, we can support you and help you achieve your goal. 

Get in touch with us to discuss what the right next step is.