What is ISO 42001 (AI Management System / AIMS) and what do companies underestimate about it?

ISO/IEC 42001 is the first international standard for AI management systems (AIMS). It works like ISO 27001, but for artificial intelligence: a certifiable, risk-based management system that lets you govern the responsible use of AI in a demonstrable way. For companies in scope of the EU AI Act, ISO 42001 is not mandatory, but it provides a structured framework that aligns closely with the Act's quality and risk management duties and serves as strong evidence of conformity.

What ISO 42001 requires

  • An AI policy and clear roles and responsibilities for AI governance
  • Risk assessment and impact assessment for each AI system
  • Data governance across the full data lifecycle
  • Documentation of AI systems, their limitations, and their intended use
  • Transparency toward users and continuous improvement (the PDCA cycle)

What companies underestimate

In the experience of Kertos's certified experts, two areas are where teams start too late:

  • Documentation. AI governance is, at its core, product regulation. A large part of both frameworks consists of documenting the product and showing the limitations of the AI system to users. Smaller teams and startups rarely have established documentation practices, and that is usually the first thing to trip a project up.
  • Data governance. You have to show where your data comes from, how it is processed and enriched, and what usage rights apply, not only for personal data. Anything that flows into training, RAG, or a verification layer has to be traceable. Often this has to be done retroactively, because teams did not record what originally went into the training data.

How Kertos helps

Kertos helps you build an AIMS for ISO 42001 and the EU AI Act without starting a separate programme. Through the agentic platform KAIA you create an AI inventory, assess systems by risk and role, and manage the required documentation in one place, alongside your existing frameworks such as ISO 27001, GDPR, and NIS2. What makes the difference is the combination of software and people: certified Kertos experts translate the deliberately broad wording of the standard into concrete steps tailored to your company, and stay with you through the audit. The aim is effective over performative, meaning lean, living processes rather than documents that exist only for the audit.

The result is continuous compliance as an outcome, not another tool: a 100% audit pass rate, around 80% less manual effort, 98% customer satisfaction, and 4.9 stars on G2 and OMR Reviews. Kertos is made in Germany, EU co-financed, and hosted on European infrastructure.

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check