ISO/IEC 42001:2023 · AI Management Systems

Future-proof your operations.

Your business already uses AI. ISO/IEC 42001 is how you prove you are managing it responsibly: to your board, your customers, your insurers and, before long, your regulator. I take UK organisations from ungoverned AI to certification-ready, so you can scale AI models with confidence, without the jargon and without stopping the day job.

The standard
ISO/IEC 42001:2023, published December 2023. The world's first certifiable AI management system standard.
Certification
Awarded by an accredited third-party body. I get you ready for it and stand beside you through the audit.
Valid for
Three years, maintained by surveillance audits, then a full re-certification cycle.
Works with
ISO 9001, ISO/IEC 27001 and ISO/IEC 27701. Same clause structure, shared evidence, one audit programme.

Where UK businesses stand right now

AI adoption has run ahead of AI governance almost everywhere. The rules are arriving unevenly, and faster in some places than others. Organisations that put a management system in place now will meet those rules from a position of readiness rather than a scramble.

In force in the EU

The EU AI Act applies to UK firms too

If you place AI systems on the EU market, or your AI output is used in the EU, the Act reaches you regardless of where you are based. Its obligations are risk-tiered, and the highest tiers demand documented governance, risk management and human oversight; that is the same evidence an ISO/IEC 42001 management system produces.

Developing in the UK

The UK is regulating through existing regulators

Rather than one cross-cutting AI act, the UK has so far worked through the regulators you already answer to (the ICO, FCA, MHRA, HSE and others), applying existing powers to AI. That means the obligations arrive through your sector, not through a single commencement date, and they arrive sooner than most boards expect.

Commercial pressure

Procurement is moving faster than the law

The practical deadline is rarely legislative. It is the AI questionnaire in a tender pack, the insurer's renewal form, or the enterprise customer's supplier assurance review. Certification answers all three at once, with a certificate rather than a promise.

The short version: get ahead of the law rather than behind it. A management system takes months to build and days to evidence. That is the wrong way round if you start when the request arrives.

What is AI governance, and why does it matter to your business?

AI governance is simply the set of decisions, checks and records that make sure the AI your organisation uses does what you intend, keeps doing it, and can be explained when someone asks. It is not an ethics committee and it is not a document library. It is how the work actually gets controlled.

THE SCALE PROBLEM

A biased decision no longer affects one person

A biased human decision affects one applicant. A biased algorithm affects every applicant, simultaneously, at machine speed, and keeps doing it silently until somebody measures it.

THE BLACK BOX PROBLEM

If you cannot explain it, you cannot defend it

When a decision cannot be explained to the person it affects, accountability collapses. Regulators, tribunals and customers all ask the same question, and "the model decided" is not an answer.

THE EXPOSURE PROBLEM

New failure modes your existing controls miss

Adversarial inputs, model drift, inference attacks that re-identify anonymised data, safety failures in physical systems. Your ISO 27001 controls were not designed to catch any of these.

Why the informal approach always breaks down

01

It isn't systematised

Without defined processes, AI governance depends on one motivated individual rather than organisational capability. When that person leaves, the governance leaves with them.

02

It isn't auditable

Without documented evidence you cannot demonstrate anything to a regulator, a certification body or a customer. A policy nobody follows is worse than no policy; it is a written admission.

03

It doesn't scale

Two AI tools can be managed on goodwill. Twenty cannot. Informal checklists and occasional meetings become unmanageable exactly when the exposure becomes material.

Why ISO 42001?

Four reasons boards sign this off. They are not abstract; each one turns into evidence you can hand to somebody who is asking.

Benefit 01

Risk reduction

Proportionate controls for the risks AI actually creates (bias, privacy, security, safety), so failures become less frequent, less severe and far less expensive when they do happen.

Benefit 02

Shareholder trust

A certificate from an accredited body is a statement your board, investors and insurers can rely on. Governed AI reads as a lower risk profile, because it is one.

Benefit 03

Competitive advantage

In markets where trust in AI is fragile, certification differentiates. Customers, partners and procurement teams choose the governed option, and increasingly they are told to.

Benefit 04

Legal compliance

Already law in the EU under the AI Act, and developing in the UK through existing regulators. A management system aligns you now, so the rules land on a structure that is ready for them.

What is ISO 42001?

A risk-based approach to AI governance and, importantly, not a separate world. It follows the same High-Level Structure as the management systems you may already run, so it builds on what you have rather than starting again.

It builds on your existing registers

If you hold ISO 9001 or ISO/IEC 27001, you already have a risk register, a document control system, an internal audit programme and a management review. ISO/IEC 42001 extends them to AI rather than duplicating them: one policy tree, one management review, one combined audit cycle.

But it takes AI risk seriously on its own terms

It adds what no other standard covers: the AI System Impact Assessment, data quality and bias management, controls across the full model lifecycle, and explainability requirements. Current risks are structured; future ones are scanned for deliberately.

One structure, shared across the family

ISO 9001Quality management
ISO/IEC 27001Information security
ISO/IEC 27701Privacy information
ISO/IEC 42001AI management system
Shared High-Level Structure
Clauses 4–10
Unique risks The other three look inward, at how the organisation runs. ISO/IEC 42001 also looks outward, to identify and mitigate the risks that only AI brings:
  • Bias. A model that keeps updating can drift: if changes in its data go unmonitored, it becomes biased over time.
  • Safety. What happens to people and operations when an AI system is wrong.
  • Security. Attacks aimed at the model and its data, not only at the network around it.
  • Privacy. Models are built on large volumes of personal data, such as credit histories, which has to be anonymised.
  • Transparency and explainability. What the model was trained on and what it can do; and why it reached a decision, such as why you were declined.
  • Societal impact. The effect on people and communities beyond your own organisation.
Clause 6.1.2

Risk assessment

What could go wrong for the organisation (regulatory, reputational, operational, security, financial), and how likely and severe would it be?

Clause 6.1.4 · Annex B

AI System Impact Assessment

What is the real-world footprint on the people it affects: human rights, fairness, safety, privacy, environmental and societal effects? Both are required. Risk is the forecast; impact is the footprint.

Our services

Engage us for the whole journey or for the one part you are stuck on. Everything is delivered as documentation you own, in language your team can actually use.

01

AI Readiness Assessment

A short, structured diagnostic that answers the question before any other work starts: should you adopt or scale AI at all, and on what conditions? Evidence-based scoring across the dimensions that actually predict success, not a self-assessment questionnaire.

You receive a clear recommendation (proceed, proceed with conditions, pilot only, remediate and re-assess, or do not scale yet) and, where relevant, a costed plan for closing any gaps.

Discuss this

02

AI Strategy Workshop

A facilitated session, or short series, with your leadership team, turning “we should probably do something with AI” into a prioritised, realistic plan.

Which use cases are worth pursuing, which aren't yet, and what sequence makes sense given your data, your people and your risk appetite.

Discuss this

03

AI Implementation Support

Ongoing hands-on support as AI use cases move from pilot to business-as-usual. Advisory input, not systems integration.

Available as a day-rate retainer once you are past the initial assessment or strategy stage and need a steady hand through delivery.

Discuss this

04

Flagship programme

ISO/IEC 42001 AI Management System implementation

A structured 12- to 16-week programme that takes a process manufacturing client from wherever they currently stand to a working, audit-ready AI management system conformant with ISO/IEC 42001.

Two tracks, scoped by site count and the number of AI use cases in scope, not by company size alone.

See the two tracks

05

AI Estate Consolidation

For clients already running several disconnected AI or analytics systems, built independently, with no shared standards and no single view of what is in production.

The engagement reframes the ask from “merge everything into one system” to one platform, one management system, many governed use cases. It starts with its own short readiness assessment, then runs a phased programme, typically around 64 weeks across five phases, that delivers value early through a time-boxed, governed pilot, rather than making you wait months for governance to finish before anything visible happens.

Discuss this

The flagship programme

Two tracks to an audit-ready AI management system

Scoped by how many sites and how many AI use cases are in scope, rather than by headcount. Both end in the same place: a working AIMS you own, ready for an independent audit.

Foundational AIMS

12 weeks

A single site with a small number of AI use cases in scope.

Full Scope AIMS

16 weeks

Multi-site clients, or a broader AI system inventory.

Certification Support

Optional add-on

Prepares you for the independent certification body audit. The audit fees themselves are a direct cost of yours, paid to the certification body, and sit outside anything quoted for either track.

Both tracks are quoted individually once the scope is clear. Ask for a figure at the introductory briefing and you will get one in writing.

A note on certification. Certification is awarded by an independent third-party certification body. It cannot be issued by the person who helped you implement, and you should be wary of anyone who offers both. My job is to get you to the point where that audit is a formality, and to be in the room while it happens.

Your roadmap to certification

Seven steps, from measuring the distance to holding a certificate and keeping it. The first three are delivered with me as part of the flagship AIMS programme. The last four belong to an independent certification body; I prepare you for them and sit in the room. Scroll through to see what happens at each step and what you end up holding.

Seven steps, gap analysis to re-certification
  1. Wright Frameworks Opening weeks of the AIMS implementation

    1. Gap analysis

    Know the distance before you start

    Every clause of ISO/IEC 42001 assessed against what you already do, including AI systems in scope that nobody had counted. This sets the real scope and effort for everything that follows, before either of us commits to a plan.

    Output

    • Clause-by-clause gap map with owners and dates
    • AI use case register: purpose, primary risk, owner
    • Reuse map against any ISO 9001 or 27001 you already hold
  2. Wright Frameworks The core of the AIMS implementation

    2. Implementation

    Building the system

    Scope, AI policy, risk assessment, AI System Impact Assessments and Annex A controls, built and evidenced until the management system is something your team actually runs, not a folder nobody opens.

    Output

    • Defensible AIMS scope statement and AI policy
    • Risk register and completed AI System Impact Assessments
    • Statement of Applicability with justified controls
    • Documented information under proper control
  3. Wright Frameworks Closing weeks of the AIMS implementation

    3. Internal audit & review

    Test it yourself before anyone else does

    An internal audit against the standard and a management review with genuine AI content, so gaps get found and closed on your own terms first. This is what turns Stage 1 from a gamble into a formality.

    Output

    • Internal audit programme, reports and findings
    • Management review minutes with AI agenda items
    • Corrective actions raised and closed
    • Indexed evidence pack ready for the audit
  4. External Certification body

    4. Stage 1 audit

    Prove the documentation holds up

    The certification body's first formal audit, checking that your management system is documented and conforms to the standard, before it looks at whether it actually works. I prepare you for it and I am in the room when it happens.

    We work with you to ensure your readiness for this audit.

    Output

    • Stage 1 findings reviewed and closed
    • Certification Support add-on available for this step
    • A clear picture of what Stage 2 will test
  5. External Certification body · certified for 3 years

    5. Stage 2 audit

    Prove the system actually works

    The certification body's second audit, on site, testing whether the management system is genuinely operating day to day. It covers record sampling, process walkthroughs and interviews. Pass it, and you are certified to ISO/IEC 42001 for three years.

    We work with you to ensure your readiness for this audit.

    Output

    • Stage 2 findings and nonconformities handled
    • Certificate issued by the accredited body, valid three years
    • Surveillance and re-certification plan agreed
  6. External Certification body · years 1 and 2

    6. Surveillance audits

    Keep it alive, not just certified

    Two follow-up audits during the three-year cycle, confirming the management system is being maintained rather than left to lapse once the certificate is framed.

    Output

    • Evidence and risk register kept current year-round
    • AI System Impact Assessments refreshed as models change
    • Audit-ready position maintained ahead of each visit
  7. External Certification body · year 3

    7. Re-certification

    Show it has improved, not just survived

    A full Stage 1 and Stage 2 audit repeats at the end of the three-year cycle, this time expecting evidence of real improvement, not just that the original system is still standing.

    Output

    • Three years of evidence and improvement demonstrated
    • Stage 1 and Stage 2 re-audit supported end to end
    • A new three-year certification cycle begins

Sectors

My background sits inside one industry family, process manufacturing, but from two different vantage points. Chemical engineering gives me a general, systems-level understanding of the whole family; two industries within it, petrochemicals and brewing, are where my delivery experience actually runs deep. The labels below tell you which is which.

General

Manufacturing & process industries

A chemical engineering foundation underpins this, not one single sector. Process manufacturing runs on the same underlying logic wherever the product changes: engineered systems, safety cases, quality control, continuous improvement. That grounding means I can follow an AI governance conversation in most process manufacturing environments without needing the fundamentals explained first.

Speciality

Petrochemicals and chemicals

Fourteen years inside petrochemical operations, where process safety management is already how the plant runs, not a document on a shelf. ISO/IEC 42001 slots into that same discipline: same audit programme, same evidence, extending what you already run rather than duplicating it.

Speciality

Brewing, food and beverage

Twelve years in brewing and FMCG, including managing a $20m capacity upgrade, in an environment where quality and food-safety systems are already mature and well understood. Forecasting, yield optimisation and automated inspection are usually where AI appears first on the production side, and governance needs to sit alongside those existing checks, not be added as an afterthought.

Why Wright Frameworks?

Most AI governance advice comes from people who have never had to make a management system survive contact with a real operation. I have spent twenty-six years inside heavy industry, where a control that only works when someone is watching is not a control; it is a hazard.

I bring the discipline of process and project engineering to AI governance: define the system, evidence it, audit it, improve it. No theatre, no 200-page policy nobody reads.

Our vision

A process manufacturing industry where AI governance is as fundamental as process safety; plants can scale their AI as confidently as they scale any other management system, without increasing the risk.

Our mission

We guide process manufacturing plants on the journey to AI governance readiness and ISO/IEC 42001 certification, combining AI standards mastery with 26 years' hands-on engineering experience across the manufacturing value chain and structured change management.

Background & credentials

Certified ISO/IEC 42001 Lead Implementer

Global AI Certification Council (GAICC), accredited in the UK through the CPD Standards Office. Verify this accreditation

AI for Leaders, Harvard Business School Online

Executive certification in leading AI adoption and its organisational implications. Verify this certificate

26 years in manufacturing

Brewing and petrochemicals: operations that run continuously, where management systems are load-bearing rather than decorative.

Chemical Engineer

A risk-based, systems-first way of thinking that maps directly onto how ISO/IEC 42001 asks you to govern AI.

Project Management Professional

Formal project discipline: scope, stages, evidence and closure, applied to implementation programmes.

PMP certification held from 2010 to 2013.

Process, projects, operations & reliability

Process engineering, project engineering, operations management, and maintenance and reliability technical advisory.

Wayne Wright Wayne Wright Founder, Wright Frameworks Ltd · London, United Kingdom

Enquire

Start with a free 30-minute introductory briefing. No slides and no pitch. We walk through where AI already sits in your operation, what ISO/IEC 42001 would actually require of you, and whether it is worth your time. You will get a straight answer either way.

  • A 30-minute briefing, at no cost and with no obligation
  • An honest view on whether certification is right for you yet
  • A written outline of scope, effort and indicative cost if it is
  • Response within one working day

Fields marked * are required.

Only needed if you would rather I called.

0 of 4000 characters used. Please do not include sensitive information in your message.

We use your name, organisation, contact details and message to respond to your enquiry and to keep a record of it. Read the privacy notice (PN-001 v1.2) for how long we keep it and your rights.

Your data is handled securely. Enquiries are sent over an encrypted connection, stored in the United Kingdom, used only to respond to you, and kept for no longer than the privacy notice says.

The enquiry form needs JavaScript

It is switched off in this browser, so the form cannot send. Nothing is lost — email enquiries@wrightframeworks.co.uk with your name, organisation and a sentence about your AI systems, and you will have a reply within one working day.

The same address works if the form fails for any other reason.