Verigo Global
//ISO 42001
AI Management SystemISO/IEC 42001:2023

ISO 42001, delivered end to end.

The first certifiable standard for responsible AI governance. Verigo takes you from first gap analysis to a certified AI Management System — and keeps you certified across the full three-year cycle, with senior practitioners on every engagement.

At a glance
Scope
Any AI system you build, buy, or operate
Standard
38 Annex A controls, 9 objectives
Cycle
3-year certificate + surveillance
Typical timeline
4–8 months to certified
2023Standard first published
38Annex A controls
9Control objectives (A.2–A.10)
3-yrCertification cycle
What ISO 42001 certifies

A living system, not a model card.

ISO/IEC 42001 certifies a complete AI Management System — a risk-based, continuously improving framework that governs how AI systems are designed, developed, deployed, and monitored across your whole organization.

The standard pairs management-system requirements (Clauses 4–10) with a catalog of 38 Annex A controls. Verigo’s Compliance by Design approach embeds those controls into how you already build and operate AI — so evidence is generated by the process, not assembled in a panic before each audit.

Risk-based — controls follow your actual AI use cases, not a checklist
The first certifiable standard purpose-built for responsible AI
A natural extension for organizations already certified to ISO 27001
Annex A — 2023 structure

38 controls, nine objectives.

8

Policy & Organization

AI policy, roles, resourcing, and the governance backbone of the AI management system.

3

Impact Assessment

Assessing effects of AI systems on individuals, groups, and society before deployment.

10

AI System Life Cycle

Requirements, design, verification, deployment, and monitoring across the AI lifecycle.

9

Data & Transparency

Data quality and provenance, plus disclosure to interested parties and third parties.

8

Use & Relationships

Responsible use objectives, supplier allocation of responsibility, and customer commitments.

How Verigo supports you

Four service lines, mapped
to the ISO 42001 lifecycle.

Engage any single stage or move through the whole journey with one accountable, senior-led team — and a peer-review quality gate on every deliverable.

01
Assess

ISO 42001 Readiness Assessment

Know exactly where you stand against ISO/IEC 42001:2023.

We benchmark your current state against Clauses 4–10 and all 38 Annex A controls, score your gaps by risk and effort, and hand you an independent remediation roadmap — the foundation for everything that follows.

What you receive
Clause 4–10 gap analysis
Annex A control-by-control review
Risk-scored remediation roadmap
Indicative certification timeline
02
Implement

AIMS Implementation Toolkit

We build the AI Management System with you — not for a shelf.

A practitioner-led program that stands up the full AIMS: AI risk assessment methodology, Statement of Applicability, the complete policy set, impact assessments, and the internal audit and management-review machinery that keeps it alive.

What you receive
AI risk assessment & treatment methodology
Statement of Applicability (SoA)
Full AIMS policy & procedure set
Internal audit & management review program
03
Prepare

Stage 1 & Stage 2 Pre-Audit Preparation

Walk into the certification audit knowing you will pass.

A mock Stage 1 documentation review and a full Stage 2 mock audit run by a lead auditor independent of your implementation team — surfacing nonconformities while there is still time to close them.

What you receive
Mock Stage 1 documentation review
Full Stage 2 mock audit
Nonconformity log & corrective actions
Auditor-readiness coaching for your team
04
Certify & Sustain

Certification & Surveillance Support

Get certified — and stay certified across the three-year cycle.

We support you through the certification body’s Stage 1 and Stage 2 audits, manage findings to closure, then keep the AIMS audit-ready through annual surveillance and three-year recertification.

What you receive
Certification body coordination
Findings management to closure
Annual surveillance audit support
Year-three recertification
The path to certification

From gap analysis to certified — and beyond.

Most clients reach certification in four to eight months. Here is the route, with indicative durations.

2–4 wks
Gap analysis
Readiness assessment against the 2023 standard.
3–6 mo
Build the AIMS
Risk method, SoA, policies, impact assessments, evidence.
~1 wk
Stage 1 audit
Certification body reviews AIMS documentation.
1–2 wks
Stage 2 audit
On-site assessment of operating effectiveness.
Certified
Three-year ISO/IEC 42001 certificate issued.
Yr 1 & 2
Surveillance
Annual checks, then recertify in year three.
Why certify with Verigo

Implementation and audit, under one roof.

Senior-led, always

Every engagement is run by practitioners with deep AI governance and ISO Lead Auditor credentials — never junior consultants with templates.

Audit-ready by design

Controls are embedded into how you build and operate AI, so evidence accumulates continuously instead of being reconstructed before each audit.

Independence preserved

Our pre-audit lead auditor is kept separate from your implementation team, protecting the integrity of the certification.

One certification, many doors

ISO 42001 builds on what you already have.

Our cross-framework control mapping lets your existing certifications accelerate ISO 42001 — and lets ISO 42001 evidence support the frameworks you already hold. Build it once, reuse it across:

ISO 42001 questions

Good to know before we start.

Questions on scope, timeline, or how this relates to ISO 27001? A senior practitioner will walk you through it.

ISO/IEC 42001:2023 is the first certifiable international standard for an Artificial Intelligence Management System (AIMS) — a structured framework for governing, developing, and deploying AI responsibly across its lifecycle, covering fairness, transparency, human oversight, and accountability.

Ready to begin?

Ready to certify to ISO 42001?

Tell us where you are — standing up your first AI governance program, or extending an existing ISO 27001 ISMS to cover AI. We'll come back with a scoped plan, fixed pricing, and the fastest path to a certified AIMS.