ISO/IEC 42001 for small and non-technical organisations: what it involves, who certifies, and when it is worth it
ISO/IEC 42001 has started to appear in places where a small Mauritian organisation cannot ignore it: a supplier questionnaire from a European client, a tender clause from a parastatal, a due diligence request from an investor, a group policy from a foreign parent. The question that follows is usually the same. Do we need to be certified, or is it enough to say we work in line with the standard?
This guide is written for the managing director or board member of an organisation with no technical team and no compliance function, who needs to make that call without first learning the standard.
Two things should be stated at the outset. ISO/IEC 42001 is a voluntary standard: no Mauritian law requires certification. And Consultaix advises on and implements AI management systems but does not certify them; certification is done by independent certification bodies, and the separation between the adviser and the certifier is deliberate.
What an AI management system is, in plain language
ISO/IEC 42001:2023 was published by ISO and IEC in December 2023. Its scope states that it “specifies the requirements and provides guidance for establishing, implementing, maintaining and continually improving an AI (artificial intelligence) management system within the context of an organization”, and that it is intended for organisations of any size that develop, provide or use AI-based products and services.
Strip away the vocabulary and an AI management system is the set of arrangements by which an organisation decides what AI it will use, who is responsible for it, what could go wrong, what it does about that, and how it checks that the arrangements are working. It is not software, and it is not a set of technical controls inside a model. It is the management layer around the use of AI, as a quality management system under ISO 9001 is the management layer around producing goods or services.
If you already hold ISO 9001 or ISO/IEC 27001, the shape will be familiar. ISO/IEC 42001 uses the same harmonised structure as those standards, with requirement clauses grouped under context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. The AI-specific content sits in the risk and impact assessment requirements, in the lifecycle controls for AI systems, and in a set of reference controls in an annex that an organisation selects from and justifies. This article does not reproduce clause text; the standard should be purchased and read by whoever leads the implementation.
For a non-technical organisation, the most important point is that the standard is about the use of AI, not only its development. A firm that uses a vendor’s chatbot for customer service, a recruitment tool with a screening feature, and a forecasting function inside its ERP is using AI systems in the standard’s sense, and can build a management system around those uses without writing a line of code.
Alignment versus certification
These two words are used loosely and it matters that they are not.
Alignment means that the organisation has built its AI governance in the shape of the standard and can show, if asked, how its arrangements correspond to the standard’s requirements. There is no external verification. The organisation can say “our AI governance is informed by, or aligned with, ISO/IEC 42001”, and if challenged it can produce a mapping and the underlying documents. Alignment is a claim the organisation makes about itself.
Certification means that an independent certification body has audited the organisation’s AI management system against the full requirements of the standard, found it to conform, and issued a certificate. The certificate carries a defined scope (which parts of the organisation and which AI systems it covers), has a validity period, and is maintained through surveillance audits. Certification is a claim a third party makes about the organisation, and that is the whole of its value.
The practical difference is in what each can be used for. Alignment answers most questionnaire and due diligence questions, satisfies a board that wants assurance that the organisation is not exposed, and is the basis of the framework described in the companion article on AI governance for a 20 to 200 person organisation. Certification is needed when somebody outside the organisation will only accept a third-party statement: a tender that scores certified bidders higher, a client contract that names the standard, a parent company policy, or a regulator that treats certification as evidence.
A third option sits between the two. An organisation can implement to the standard, have an independent party conduct a gap assessment or internal audit, and hold the report without seeking certification. This gives the board an independent view without the cost of the certification cycle, and makes certification a short step later if a client requires it.
Who certifies
Certification is issued by certification bodies, which are themselves assessed by accreditation bodies to confirm that they are competent to audit against a given standard. When a client or tender asks for “accredited certification”, it is asking that the certificate come from a body accredited for ISO/IEC 42001 specifically, not simply from a body accredited for other standards.
Several international certification bodies now offer ISO/IEC 42001 certification. SGS, for example, offers ISO/IEC 42001 certification through its Mauritius operation, and describes the standard as providing “a certifiable framework addressing the full AI lifecycle”. Other bodies with a presence in the region or operating remotely may also offer it, and the choice between them should rest on three questions: whether the body holds accreditation for ISO/IEC 42001 from a recognised accreditation body, whether its auditors have experience with organisations of your size and sector, and whether it can integrate the audit with any existing ISO 9001 or ISO/IEC 27001 certification you hold.
Two points on the separation of roles. The body that certifies you cannot also have designed your management system, because it would then be auditing its own work; Consultaix, like any adviser, stops at the point of readiness. And certification bodies typically conduct a two-stage initial audit, a documentation and readiness review followed by a test of whether the system is actually operating, with periodic surveillance audits and a recertification audit at the end of the cycle. The exact arrangements should be confirmed with the body chosen.
What implementation involves for a small organisation
The stages below are Consultaix’s recommended sequence for an organisation of roughly 20 to 200 people with no dedicated technical or compliance staff. They apply whether the goal is alignment or certification; certification adds the final two stages.
Stage 1: Scope and context
Decide what the management system covers. This is the most consequential decision in the exercise and the one most often rushed. A narrow scope (one business unit, three named AI systems) is faster to implement and audit, and can be extended later. A whole-organisation scope is cleaner but requires every AI use to be inventoried and governed. Alongside scope, the organisation lists the interested parties whose expectations bear on its AI use: customers, staff, regulators, the Data Protection Office, key suppliers.
Stage 2: Leadership and policy
Top management approves a short AI policy that states the organisation’s intent, its risk appetite, and the roles it assigns. An accountable executive is named. In a small organisation this is usually the managing director, with a delegate who runs the system day to day.
Stage 3: Inventory and classification
Every AI system in scope is recorded in a register with its purpose, owner, data, decision role and affected parties, and classified by risk. The register from the companion article serves this purpose. Nothing else in the management system can be evidenced without it.
Stage 4: Risk assessment and impact assessment
For each system, the organisation records what could go wrong, for whom, and what it does about it. The standard also expects an assessment of the impact of AI systems on individuals and society, which for most small organisations is proportionate to the risk tier and can be combined with a data protection impact assessment where the Data Protection Act 2017 requires one. ISO/IEC 42005:2025 provides guidance on AI system impact assessment and on how it fits into the management system; it is a guidance document, not a certifiable standard.
Stage 5: Controls and operation
The organisation selects the controls that apply to it from the standard’s reference set, justifies any it excludes, and writes down how each is implemented. For a non-technical user of vendor AI, many controls are satisfied by vendor terms, access management, acceptable use rules, human review steps and record-keeping rather than by technical measures. The output is a statement of which controls apply and where the evidence sits.
Stage 6: Competence and awareness
Staff who use AI systems in scope are trained to the level their role requires, and the training is recorded. Owners and reviewers receive more than general users.
Stage 7: Operate and gather evidence
The system runs for long enough to produce evidence: register updates, review records, incident logs, decisions, overrides. A certification body will not certify a system that exists only on paper.
Stage 8: Internal audit and management review
Someone independent of the day-to-day running of the system checks it against the standard and reports. Top management reviews the results, the incidents and the objectives, and records its decisions. In a very small organisation the internal audit may be outsourced, provided the auditor did not design the system.
Stage 9: Certification audit (if pursuing certification)
The certification body conducts its staged audit. Major findings must be closed before a certificate is issued.
Stage 10: Surveillance and improvement
The system continues to run, is audited periodically by the certification body, and improves in response to findings, incidents and changes in the organisation’s AI use.
What drives cost
Consultaix does not publish price figures for certification, because they depend on the certification body, the scope and the state of the organisation, and any number quoted in an article would be wrong for most readers. What can be described are the drivers.
Scope is the largest. The number of sites, AI systems, people and processes in scope determines audit days and implementation effort.
The starting point matters almost as much. An organisation that already holds ISO/IEC 27001 or ISO 9001 has a management system structure, an internal audit routine and a management review in place, and will spend most of its effort on the AI-specific content. An organisation starting from nothing must build the structure as well.
Risk profile is the third driver. An organisation whose AI systems make or shape decisions about individuals will need deeper impact assessments, stronger controls and more evidence than one whose AI use is confined to internal productivity.
Then there are the recurring elements: surveillance audits over the certification cycle, the internal audit and management review each year, and the staff time to keep the register and records current. Certification is a cycle, not a project, and the ongoing cost should be weighed before the initial one. External help is a separate choice: an organisation with an experienced quality or compliance lead can implement with advice at the key points; one without will need more support. Neither changes what the certification body charges.
What drives the timeline
The calendar is driven less by the volume of documentation than by two things: the time it takes to make decisions, and the time the system must operate before it can be audited.
Decision time is about scope, roles and risk appetite. A managing director who settles these in the first month shortens everything that follows. An organisation that revisits scope repeatedly, or leaves the accountable executive unnamed, will stall regardless of how much documentation is produced.
Operating time is non-negotiable. The certification body needs to see records that the system has actually run: reviews conducted, incidents handled, a management review held. A small organisation with a narrow scope and an existing ISO management system can move through implementation in a matter of months; one starting from nothing, with a broad scope, should plan in terms of the better part of a year before a certification audit is realistic. Certification body scheduling adds its own lead time. The single biggest accelerator is an existing inventory of AI use: organisations that have already built the register and classification described in the companion article start at Stage 4.
When certification is worth it, and when alignment is enough
The decision turns on who needs the assurance and what they will accept.
| Situation | Consultaix recommendation |
|---|---|
| A client contract, framework agreement or tender names ISO/IEC 42001, or scores certified bidders higher | Certification, with scope drawn tightly around the services that client buys |
| A foreign parent or group policy requires certification of subsidiaries | Certification, coordinated with the group’s certification body and cycle where possible |
| The organisation is an exporter of services, including BPO, software or shared services, serving EU or UK clients whose own AI obligations are tightening | Certification is likely to become a commercial expectation; begin with alignment and an independent gap assessment, and be ready to certify when the first client requires it |
| The organisation is an FSC licensee or otherwise in a regulated sector where AI is used in decisions affecting customers | Alignment at minimum, with the FSC guidance as the overlay; certification if the board or the regulator’s expectations warrant third-party assurance |
| The organisation uses AI mainly for internal productivity, with human review of everything that leaves the building | Alignment is enough; certification would add cost without a corresponding audience |
| The board wants assurance that AI use is under control but no external party is asking | Alignment plus an independent gap assessment or internal audit, held on file |
| The organisation develops AI products for others | Certification is worth serious consideration, because buyers of AI products increasingly ask for it and the standard was written with providers in mind |
Consultaix recommendation: do not certify to impress. Certify because a named counterparty, present or reasonably foreseeable, will only accept third-party assurance. In every other case, build the management system to the standard, have it independently checked, and keep the option open.
If you already hold ISO/IEC 27001
Organisations with ISO/IEC 27001 certification have a head start, and should use it.
The two standards share the harmonised structure, so the context, leadership, support, performance evaluation and improvement arrangements can be extended rather than duplicated. One integrated policy set, one internal audit programme and one management review can cover both, and certification bodies commonly offer integrated audits.
The overlap is not total. ISO/IEC 27001 is concerned with the confidentiality, integrity and availability of information; ISO/IEC 42001 with the responsible development and use of AI, including fairness, transparency, human oversight, and impacts on individuals and society. An information security risk assessment does not ask whether an AI system’s outputs are accurate, biased or explainable. The AI-specific work in Stages 3 to 5 is therefore additional, even for a well-run ISMS.
The practical advice is to treat ISO/IEC 42001 as an extension of the existing management system, owned by the same people, with an AI system register that cross-references the information asset register and an AI risk register alongside the information security risk register. Where one certification body can audit both, the surveillance cycles can be aligned.
Evidence of alignment with the FAIR Guidelines and FSC guidance
Neither Mauritian document requires ISO/IEC 42001, and neither is binding in itself. But both describe governance expectations that the standard operationalises, which makes a management system built to the standard a convenient way of demonstrating alignment with them.
Best practice: the FAIR Guidelines for the Development and Use of Artificial Intelligence, published by the Ministry of Information Technology, Communication and Innovation, are non-binding. They state that they “do not create legal obligations and do not replace existing laws or regulatory powers”, and that they are intended to inform future procurement standards, contractual requirements and, where justified, legislation. They set out a risk-based governance model with indicative low, medium and high risk tiers, expect clear assignment of responsibility for every AI system, and call for record-keeping, auditability, monitoring and periodic review. Each corresponds to something an ISO/IEC 42001 management system produces as a matter of course: a register, an accountable owner per system, risk and impact assessments, records, internal audit and management review. An organisation that can show its ISO/IEC 42001 mapping can show its FAIR alignment in the same document.
Best practice: the FSC’s Fintech Series Guidance Notes No. 4, Principles for the Responsible Use of Artificial Intelligence in Financial Services (September 2025), applies to FSC licensees in insurance, wealth management and non-banking financial institutions, and sets out nine principles the document describes as “non-binding”: fairness and bias mitigation, transparency, accountability, privacy, security, environmental sustainability, human-centricity, continuous monitoring and evaluation, and compliance and ethics. The guidance also expects licensees to define “responsibility for the AI system across its entire life cycle” and to maintain effective human oversight. A licensee with an ISO/IEC 42001 management system can map each principle to the relevant part of its system and present that mapping to its board and, if asked, to the FSC.
Legal requirement: none of the above displaces the Data Protection Act 2017. Where an AI system processes personal data, the controller’s duties under the Act apply, including section 22 (policies and measures to demonstrate compliance), section 34 (data protection impact assessment where processing is likely to result in a high risk) and section 38 (automated individual decision making). An ISO/IEC 42001 management system should incorporate the Act’s requirements rather than sit beside them, and the data protection officer designated under section 22(2)(e) should have a defined role in it.
The FAIR Guidelines note that elements of the framework may be translated into “procurement standards and contractual clauses”. Organisations that have built to ISO/IEC 42001 will already hold the evidence in a recognised form when that happens.
Where Consultaix fits
Consultaix’s AI Governance Advisory service designs and implements AI management systems informed by ISO/IEC 42001, the FAIR Guidelines and the Data Protection Act 2017, and prepares organisations for certification audit by an independent body; Consultaix does not certify. The founder, Faaleh M. Sookye, is a Certified ISO/IEC 42001:2023 Implementer. Organisations unsure whether their AI use warrants this level of structure can begin with the AI Readiness Assessment, which scores governance alongside the other four dimensions of the Consultaix AI Adoption Ladder.
Sources
- ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, ISO/IEC, 2023: https://www.iso.org/standard/42001
- ISO/IEC 42001:2023 publication record, IEC Webstore, 2023: https://webstore.iec.ch/en/publication/90574
- ISO/IEC 42005:2025, Information technology, Artificial intelligence, AI system impact assessment, ISO/IEC, 2025: https://www.iso.org/standard/44545.html
- ISO/IEC 42001 Certification, Artificial Intelligence (AI) Management System, SGS Mauritius: https://www.sgs.com/en-mu/services/iso-iec-42001-certification-artificial-intelligence-ai-management-system
- FAIR Guidelines for the Development and Use of Artificial Intelligence, Ministry of Information Technology, Communication and Innovation, Mauritius, 2026: https://aim.govmu.org/aim/wp-content/uploads/2026/04/fairguidelines.pdf
- Fintech Series Guidance Notes No. 4, Principles for the Responsible Use of Artificial Intelligence in Financial Services, Financial Services Commission, Mauritius, September 2025: https://www.fscmauritius.org/media/206401/guidelines-on-responsible-use-of-ai.pdf
- The Data Protection Act 2017 (Act No. 20 of 2017), Republic of Mauritius, 2017: https://www.fscmauritius.org/media/105843/the-data-protection-act-2017.pdf
- AI Risk Management Framework (AI RMF 1.0), National Institute of Standards and Technology, 2023: https://www.nist.gov/itl/ai-risk-management-framework