Get ISO 42001 Certified

Add certifiable AI governance to your ISO 27001 and ISO 27701 foundation with 3FACTOR's approach to ISO 42001

Human hand shaking a digital hand made of data

ISO/IEC 42001:2023 is the international standard for an Artificial Intelligence Management System (AIMS). It sets out how an organization governs the AI systems it develops, provides or uses.

Certification by an accredited body gives customers, regulators and investors independent evidence that AI risk is governed, with impact assessments and controls that operate day-to-day.

Customers or procurement teams are asking how you govern AI
You hold ISO 27001 and want AI governance without a second system
You develop, provide or use AI systems that affect customers or individuals
You want a certifiable structure that supports EU AI Act readiness
Consultant presenting AI governance reporting to leadership

While information security (ISO 27001) and privacy (ISO 27701) are essential foundations, ISO 42001 adds the AI governance layer that allows organizations of every size to turn fast-moving innovation into accountable decisions.

Marcus Atkins, Director of Compliance Services

Quick Nav

The 3FACTOR Approach

  • ISO 42001 does not need to become a second compliance program.
  • At 3FACTOR, we build your AI management system on the ISO 27001 and ISO 27701 foundation you already run, so AI governance adds a layer rather than a new system.
  • Take a look at our 7-stage certification process.

The 7-Stage Certification Process

Confirm which AI systems are in scope, how you develop, provide or use each one, and how much of your existing ISMS and PIMS can be reused.

  • Inventory AI systems, including third-party, vendor-embedded and internal tools
  • Confirm whether you develop, provide or use each AI system
  • Review your ISO 27001 ISMS and ISO 27701 PIMS for reuse
  • Define the AI Management System (AIMS) scope and boundary

The Integrated Model

ISO 42001, ISO 27001 and ISO 27701 share the same harmonized management system structure. Security and privacy form the foundation, and AI governance sits over the top.

AI Governance

ISO/IEC 42001ISO/IEC 42005

AI policy, AI system impact assessment, AI system life cycle, data for AI systems, transparency to interested parties and responsible use.

Privacy Foundation

ISO/IEC 27701

Personal data processing, privacy roles, data subject rights and privacy by design, extended to data used to train, test and operate AI systems.

Security Foundation

ISO/IEC 27001

Risk methodology, access control, logging, supplier security, secure development and incident management that every AI system relies on.

Built once, shared by all three

  • One risk methodology and risk register
  • One internal audit program
  • One management review
  • One document control and competence framework
  • Aligned Statements of Applicability
  • Integrated audits where your certification body offers them

Where ISO 42005 fits

ISO 42001 requires AI system impact assessments. ISO/IEC 42005:2025 gives guidance on how to perform them consistently, covering effects on individuals, groups and society. It is guidance, not a certifiable standard, and it is the method behind every impact assessment we deliver.

What We Deliver

The 3FACTOR delivery process is engineered to be as smooth as possible, specifically for highly time-constrained and challenging environments. Take a look at the key steps of our delivery process.

Understand exactly where you stand. We assess your AI governance, documentation and evidence against ISO 42001, credit what your ISO 27001 and ISO 27701 programs already provide, and deliver a prioritized roadmap.

  • AI system inventory and scope confirmation
  • Clause-by-clause gap assessment
  • Annex A review across all 38 controls
  • Reuse map from ISO 27001 and ISO 27701
  • Deliver a prioritized, actionable roadmap

Why organizations choose 3FACTOR

6–12 Months

Typical timeline to certification, shorter with an existing ISO 27001 ISMS

Senior-Led

Delivered by principals, not juniors. No bait-and-switch

Fixed-Price

Clear scope boundaries that protect your budget

Build Once

One management system across security, privacy and AI

How we help you avoid common ISO 42001 pitfalls

Our tried and tested approach keeps your certification journey on track.

Common failure modes

  • AI governance built as a second system

    Separate risk registers, audits and reviews duplicate the work already done for the ISMS.

  • Impact assessments completed once and filed

    No repeatable method, and results never reach risk treatment.

  • Nobody knows which AI is in scope

    Vendor-embedded AI and internal tools are missed until the auditor asks.

  • Privacy and AI handled by different teams

    Personal data in training sets and prompts falls between the two.

How we solve it

  • One integrated management system

    The AIMS layers onto ISO 27001 and ISO 27701, sharing risk, audit and review.

  • Repeatable impact assessments based on ISO 42005

    A documented method, triggered at design, significant change and retirement.

  • Complete AI inventory and scope

    Every AI system, including third-party and embedded AI, recorded and classified.

  • Privacy controls extended to AI data

    ISO 27701 controls cover personal data used to train, test and operate AI systems.

Two executives reviewing AI governance results on a tablet

Your ISO 42001 controls share one evidence base with your security and privacy programs, and support wider AI obligations.

ISO 27001ISO 27701ISO 42005EU AI ActNIST AI RMFSOC 2+ reuse controls across frameworks

Frequently Asked Questions (FAQs)

What Sets Us Apart

Operator Mindset

We've sat in the CISO seat. Our recommendations come from hands-on experience building security programs, not theoretical frameworks.

Certification as Revenue Enabler

We treat compliance as a business accelerator, not a cost center. Every engagement is scoped to unblock deals and open markets.

Regulatory Breadth

SOC 2, ISO 27001, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, ISO 42001: one team, full coverage, no handoffs.

Ready to start?

Schedule a 30-minute call to receive a tailored ISO 42001 plan and fixed-price proposal.