Add certifiable AI governance to your ISO 27001 and ISO 27701 foundation with 3FACTOR's approach to ISO 42001

ISO/IEC 42001:2023 is the international standard for an Artificial Intelligence Management System (AIMS). It sets out how an organization governs the AI systems it develops, provides or uses.
Certification by an accredited body gives customers, regulators and investors independent evidence that AI risk is governed, with impact assessments and controls that operate day-to-day.

While information security (ISO 27001) and privacy (ISO 27701) are essential foundations, ISO 42001 adds the AI governance layer that allows organizations of every size to turn fast-moving innovation into accountable decisions.
Marcus Atkins, Director of Compliance Services
Confirm which AI systems are in scope, how you develop, provide or use each one, and how much of your existing ISMS and PIMS can be reused.
Confirm which AI systems are in scope, how you develop, provide or use each one, and how much of your existing ISMS and PIMS can be reused.
ISO 42001, ISO 27001 and ISO 27701 share the same harmonized management system structure. Security and privacy form the foundation, and AI governance sits over the top.
AI policy, AI system impact assessment, AI system life cycle, data for AI systems, transparency to interested parties and responsible use.
Personal data processing, privacy roles, data subject rights and privacy by design, extended to data used to train, test and operate AI systems.
Risk methodology, access control, logging, supplier security, secure development and incident management that every AI system relies on.
ISO 42001 requires AI system impact assessments. ISO/IEC 42005:2025 gives guidance on how to perform them consistently, covering effects on individuals, groups and society. It is guidance, not a certifiable standard, and it is the method behind every impact assessment we deliver.
The 3FACTOR delivery process is engineered to be as smooth as possible, specifically for highly time-constrained and challenging environments. Take a look at the key steps of our delivery process.
Understand exactly where you stand. We assess your AI governance, documentation and evidence against ISO 42001, credit what your ISO 27001 and ISO 27701 programs already provide, and deliver a prioritized roadmap.
Understand exactly where you stand. We assess your AI governance, documentation and evidence against ISO 42001, credit what your ISO 27001 and ISO 27701 programs already provide, and deliver a prioritized roadmap.
6–12 Months
Typical timeline to certification, shorter with an existing ISO 27001 ISMS
Senior-Led
Delivered by principals, not juniors. No bait-and-switch
Fixed-Price
Clear scope boundaries that protect your budget
Build Once
One management system across security, privacy and AI
Our tried and tested approach keeps your certification journey on track.
AI governance built as a second system
Separate risk registers, audits and reviews duplicate the work already done for the ISMS.
Impact assessments completed once and filed
No repeatable method, and results never reach risk treatment.
Nobody knows which AI is in scope
Vendor-embedded AI and internal tools are missed until the auditor asks.
Privacy and AI handled by different teams
Personal data in training sets and prompts falls between the two.
One integrated management system
The AIMS layers onto ISO 27001 and ISO 27701, sharing risk, audit and review.
Repeatable impact assessments based on ISO 42005
A documented method, triggered at design, significant change and retirement.
Complete AI inventory and scope
Every AI system, including third-party and embedded AI, recorded and classified.
Privacy controls extended to AI data
ISO 27701 controls cover personal data used to train, test and operate AI systems.

Your ISO 42001 controls share one evidence base with your security and privacy programs, and support wider AI obligations.
We've sat in the CISO seat. Our recommendations come from hands-on experience building security programs, not theoretical frameworks.
We treat compliance as a business accelerator, not a cost center. Every engagement is scoped to unblock deals and open markets.
SOC 2, ISO 27001, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, ISO 42001: one team, full coverage, no handoffs.
Schedule a 30-minute call to receive a tailored ISO 42001 plan and fixed-price proposal.