ISO 42001
AI governance, properly in order
ISO 42001 shows that your organisation develops, deploys or provides AI responsibly, with clear roles and oversight.
Book an introductory call- AI governance
- Governance, risk & compliance
Why AI calls for oversight
Customers and partners are increasingly asking how an organisation manages the risks of AI.
Without a management system, AI use often stays fragmented, with no central overview of what’s deployed where.
AI applications are deployed without central oversight
A customer or partner asks about your AI governance
The EU AI Act calls for demonstrable governance around AI
The risk of AI without oversight
Without oversight, an AI application can fall under a high-risk category of the AI Act unnoticed, with the obligations that come with it.
Reputational damage from careless AI use can be just as serious as a data breach.
What the standard asks of your AI governance
ISO 42001 requires an AI policy, a risk assessment per AI application, and oversight across the whole lifecycle, from development to decommissioning.
An AI policy, approved by management
A risk assessment and impact assessment per AI application
Assigned roles and responsibilities for AI
Control over data, models and human oversight
Internal audits and management review
ISO 42001 and the AI Act together
ISO 42001 fits well alongside the EU AI Act: Vedeum helps set up both together, not as two separate projects.
Baseline assessment
We map which AI applications exist and what current governance looks like.
Implementation
We help set up policy, risk assessment and roles.
Internal audit
We carry out an internal audit and prepare you for the certification body.
Certification & maintenance
We guide certification and keep the system current as new AI applications appear.
Book a no-obligation introductory call
Tell us where your organisation stands. We will think through the first steps with you.
Book an introductory call