The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
ISO/IEC 42001
ISO/IEC 42001 is the international standard for artificial intelligence management systems, published in December 2023 by ISO and IEC. It does not judge whether your model is good. It judges whether there is a defined way of deciding where AI goes, who approves it, what was considered before it reached production, and what happens when the output is wrong. It is the first AI standard that ends in a certificate issued by an independent body.
DM11 prepares your company for ISO/IEC 42001 and certifies no one. ISO itself states that it does not certify organisations: the certificate is issued by an independent certification body, which may be accredited by a national accreditation body. Whoever prepares cannot audit, and that separation is what makes the certificate worth anything.
Who runs the implementation
CGEIT, governance of enterprise IT, from ISACA
ISO/IEC 27001 Lead Auditor certified by BSI
CISA, information systems auditing
17 years of governance, risk and compliance
WHAT IT IS
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an artificial intelligence management system. Put plainly: it requires that there be a written, practised and verifiable way for the company to decide about AI, rather than a collection of decisions only the people who made them remember. It is published jointly by ISO and IEC, in its first edition, and comes from committee ISO/IEC JTC 1/SC 42, the artificial intelligence committee.
This is the difference that changes the commercial conversation. The NIST AI RMF is a voluntary framework with no certification body and no seal. The responsible AI principles large companies publish carry no third-party audit. ISO/IEC 42001 does: the company builds the management system, an independent certification body audits it, and the result is a certificate your customer can verify. ISO states plainly on the standard's own page that it does not certify organisations, and that the bodies which do may be accredited by national accreditation bodies.
Worth setting expectations early, because this is the most common confusion. The standard does not say whether your model is accurate, does not measure performance, does not approve an architecture and does not validate a specific algorithm. What it requires is everything around it: which AI uses exist in the company, who authorised each one, what was assessed before it went live, how performance is tracked afterwards, what happens when an output harms someone, and how all of that is evidenced. An excellent model in a company without those answers fails. A modest model in a company that can answer passes.
ISO describes the standard's audience as organisations of any size that provide or use AI-based products or services, across all industries, including public sector agencies and non-profits. That means the standard reaches the company training its own models, and it also reaches, with a very different scope, the company that bought an AI tool and put it in front of its customers. The second case is the overwhelming majority of the market today, and the one that usually arrives unprepared at a large customer's first question.
One is a voluntary technical standard that ends in a certificate. The other is European law, binding on those in its scope, with fixed deadlines and no certificate to buy. Holding 42001 does not make a company automatically compliant with the AI Act, and complying with the AI Act does not remove the standard if your customer demands the certificate. What does exist between them is real reuse: an inventory of AI systems, impact assessments, defined roles, human oversight and a record of what was decided serve both, which is why doing them together costs far less than doing them one at a time.
WHO USUALLY NEEDS IT
None of them starts with a company wanting a standard. All of them start with someone outside asking a question the company cannot answer in writing.
This is the most common route, and it arrives alongside a contract renewal. The buyer wants to know which AI systems touch their data, whether there is human oversight, what happens when the model is wrong and who answers for it. The company often does several of those things, and can prove none of them in the format requested. A certificate issued by a third party settles the discussion in one line, which is why it has started showing up in competitive bids.
The AI Act is law, and a 42001 certificate is not a free pass to it. But most of the work the law demands, inventory, impact assessment, roles, human oversight and record keeping, is the same work the standard requires. Companies that will need both usually discover too late that they did the same work twice, with two suppliers and two budgets.
Assistants bought on a department's credit card, an AI feature that appeared in an update to a system that already existed, personal use of a public tool with company information in it. Here the requirement has not arrived from outside yet, and it will. At this stage the value of the standard is less the certificate and more the inventory: it is the first time the board sees the full list.
TRANSLATING THE ASK
The sentence the customer writes rarely describes the work. These are the four that come up most, with what each one means in practice and what changes the size of the project.
| What they asked for | What that actually means | What changes the size |
|---|---|---|
| Are you certified to ISO 42001? | The buyer wants a document issued by a third party, not a statement from you. The route is to build the management system and engage an independent certification body to audit it. | How many AI uses fall in scope, whether the company builds models or only consumes them, and how much management system already exists because of ISO 27001. |
| We need to comply with the EU AI Act | It is law, not a standard, and there is no certificate to buy. The work is to classify each AI system, meet what that classification requires, and keep the evidence. | The company's role in each system, whether any use falls into the higher-obligation categories, and whether the service is offered in the European market. |
| We want an AI usage policy | Usually the first step, and on its own it does not survive an audit. A policy without an inventory describes a world nobody verified, and it is the document that turns into dead letter fastest. | Whether an inventory of AI uses exists, how many departments will be interviewed, and whether the policy must also bind suppliers. |
| We need to assess the risk of our AI uses | That is the impact assessment, and it is the heart of both routes. Done once, in the right format, it answers the standard, the law and the customer's questionnaire. | How many systems will be assessed, whether any of them decides something about a person, and whether personal data or automated decisions are involved. |
None of this requires buying the standard to begin. The scoping conversation happens first, and the first useful deliverable is almost always the inventory, because it is what reveals the real size of everything else.
STORIES
We change our customers' names with the same confidentiality that will protect your company later. The names change, the pattern of the problems repeats. Where a customer authorises it, we share named references in a conversation.
Software as a service
A large contract renewal arrived with a new annex asking which AI systems touched the customer's data, who supervised them, and what happened when the model got it wrong. Product answered one way, support answered another, and legal held the reply because neither answer could be backed by a document.
We built the inventory before writing any policy, because the disagreement between departments was a symptom of there being no single list. Each use got an owner and a stated purpose, including the ones that had arrived embedded in products bought earlier. We then assessed by impact rather than by technology, and human oversight was defined wherever the output went straight to the customer.
The questionnaire came to have one written answer, with the record behind each statement. And the internal conversation changed subject: instead of arguing over who replies to the customer, the team started arguing over which AI uses were worth the oversight they required.
Financial services
The board asked for a map of AI use expecting a single page. What existed was an assistant bought on a department's card, an AI feature switched on in an update to an old system nobody had read, and use of a public tool with internal documents in it. None of those had gone through approval, and none was against the rules, because there were no rules.
We ran the mapping without a witch hunt, which is the only way it comes out complete: nobody who declared a use faced a sanction, and the list was treated as a snapshot rather than an accusation. We then wrote the policy on top of what actually existed, with what is free, what needs approval and what is prohibited, and defined who approves a new use and who can block one already decided.
The final list was several times longer than the estimate of whoever asked for it, and that was the most valuable deliverable of the project. Two uses were discontinued by the departments themselves once the purpose was written down, and the rest entered the approval route on record.
Export manufacturing
The company had a project engaged to meet the European AI regulation and a certification requirement arriving from a customer, handled by different teams with different suppliers. Nobody had compared the two scopes, and both were about to ask the same people for the same inventory and the same impact assessment.
We paused both for a week and cross-checked what each required. Inventory, impact assessment, roles, human oversight and a record of decisions serve the standard and the regulation when they are done once, in the format that fits both. What was genuinely specific to each side was kept separate and explicit, so nobody would confuse them later.
The common work was done once, with one team and one schedule. The company gained a written answer to which part of the effort answers the law, which answers the standard, and which answers both, which was the information the board needed to decide the order.
SELF-ASSESSMENT
Twenty-one questions, about four minutes. The result appears in full on screen, with a score per area and a picture of your AI usage profile. We do not ask for an email to show the result, and no band promises certification.
WHO DOES WHAT
This separation is not a commercial choice of ours, it is how certification works, and ISO states it on the standard's own page. Whoever prepares cannot audit, because an auditor assessing their own work produces no assurance at all. Worth knowing all four roles before hiring any of them.
HOW WE RUN IT
Order matters more here than in any other standard, because the temptation is to start with the policy, which is the easy part to write and the part that least survives an audit without the rest underneath it.
It starts here and not with the policy, because a policy written about a world nobody verified describes a different company. We map the AI systems in use, the ones embedded in software that already existed, the ones bought by departments outside IT, and the use of public tools with company data. Each item gets an owner, a purpose, and a note of what it decides or suggests.
A list of AI uses, each with an owner and a stated purpose
What each system decides, suggests or generates, and about whom
Where each one came from: built, bought, or embedded in another product
The uses that turned up outside IT's view, listed without a witch hunt
Delivery milestoneThe board sees the full list for the first time, and it is usually longer than whoever asked for it estimated.
With the list in hand, each use is assessed by what it can cause, not by the technology behind it. A simple classifier that decides about a person weighs more than a sophisticated model that summarises internal documents. The assessment is done once, in a format that serves the standard, the AI Act and the customer questionnaire at the same time.
An impact assessment per system, recording what was considered and by whom
Classification of each use under the EU AI Act, where it applies
Security, privacy, discrimination and reputational risks, kept separate
A recorded decision per use: proceed, proceed with conditions, or do not proceed
Delivery milestoneEvery AI use has a written decision, with the name of whoever made it and what was taken into account.
Now the policy makes sense, because it describes a world that exists. We define who approves a new use, what must happen before a system reaches production, where human oversight is mandatory, and what happens when someone challenges an output. Where the company already holds ISO 27001, much of the structure is reused rather than duplicated.
An AI usage policy stating what is allowed, what needs approval and what is prohibited
Roles and responsibilities, including who is allowed to say no
An approval route for a new use case, with what must be ready beforehand
A challenge and correction route, and what to do when an output harms someone
Delivery milestoneA new use case goes through the route end to end, and the record of it becomes the system's first piece of evidence.
An audit does not assess intent, it assesses evidence. We organise the proof in the format the auditor expects, with a trail of who decided what and when, and we run a rehearsal audit with your team. The point of the rehearsal is that the real day holds no surprises, and that the surprises appear while they are still cheap.
Evidence organised by requirement, each with an owner
Defined monitoring: what is tracked after a system reaches production
A rehearsal audit with the team, with gaps listed and prioritised
A remediation plan with owners and dates, before the body is engaged
Delivery milestoneThe gaps show up in the rehearsal rather than in the certification audit, which is where they get expensive.
HOW LONG IT TAKES
We do not publish a standard timeline, because a published timeline becomes a promise and scope varies far more here than in other standards. These are the factors that move the clock most, and the first conversation already shows which one your company is in.
A company that only consumes supplier AI has a much smaller scope: the assessment falls on the selection, the contract, the oversight and the monitoring, not on training data and model lifecycle. A company that trains or fine-tunes its own models carries all of that as well. Both can certify, and the work is not the same size.
A company certified to ISO 27001 already has the structure 42001 reuses: an approved policy, management review, nonconformity handling, internal audit and document control. In that case the project is an addition rather than a build. A company starting from zero builds both layers at once, and it is honest to say that takes longer.
The most underestimated of the three. The inventory is quick when AI sits in product and engineering. When it has appeared in marketing, support, legal and HR, each with its own supplier, the mapping becomes the main work of the first phase, and it is what sizes everything that follows.
WHY THE PREPARER CANNOT AUDIT
Every certification market works this way, and it is worth knowing the rule before hiring anyone. If the same firm that wrote the policy also signed off the audit of it, the certificate would tell the recipient nothing: it would be someone's opinion about their own work. That is why DM11 prepares and does not certify, and why the certification body is engaged directly by you.
DM11 assesses, implements alongside your team and organises the evidence
The certification body audits and issues the certificate, engaged by you
The accreditation body recognises the certification body
Be wary of anyone offering preparation and certification in the same contract
The rehearsal audit we run is not an audit, and does not count as one
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered without hedging.
It is, and that is the characteristic that sets it apart from almost everything else in AI governance. The company builds the management system, an independent certification body audits it, and the result is a certificate your customer can verify. ISO states plainly that it does not certify organisations: the bodies that do are independent, and they may be accredited by national accreditation bodies. DM11 prepares and does not certify, and anyone offering both in the same contract is offering a certificate that is worth less.
Since July 2025 that question has a written answer, and it is recent enough to be missing from most material on the market. ISO/IEC 42006 sets out the requirements a body must meet in order to audit and certify AI management systems, on top of the base that already applied to any management system certification, ISO/IEC 17021-1. In practical terms: it is what makes your certificate mean the same thing as another company's certificate, issued by another body, in another country. When choosing, ask in writing whether the body operates to ISO/IEC 42006 and which accreditation body recognises it. Anyone who will not answer those two will answer everything else.
No. ISO/IEC 42001 is a management system standard in its own right, and a company can pursue it without holding 27001. That said, a company that already holds 27001 arrives with a concrete and not-small advantage: an approved policy, management review, internal audit, nonconformity handling and document control are structures 42001 reuses rather than demanding again. In that case the project is an addition. For a company starting from zero, both layers are built at once, and it is honest to say that takes longer.
Not automatically, and be wary of anyone who says it does. One is a voluntary technical standard that ends in a certificate; the other is European law, binding on those in its scope, with fixed deadlines and no certificate to buy. What does exist between them is real reuse of work: an inventory of AI systems, impact assessments, defined roles, human oversight and a record of decisions serve both. Doing them together costs considerably less than doing them one at a time, and that is the conversation worth having before starting.
The regulation entered into force on 1 August 2024 and applies in stages. Prohibited practices and AI literacy rules have applied since February 2025; the rules for general-purpose AI models since August 2025; general application of the regulation began on 2 August 2026. Obligations for the high-risk systems listed in Annex III apply from 2 December 2027, and those for AI embedded in regulated Annex I products from 2 August 2028. Those last two deadlines were set by Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026. If the material you are working from shows different high-risk dates, it predates that amendment.
The difference that decides the choice is what each one produces at the end. The NIST AI RMF is a voluntary framework, published in January 2023, with no certification body and no seal: it is excellent for organising thinking about AI risk and it produces no document to show a customer. ISO/IEC 42001 ends in a certificate issued by an independent third party. A company that needs to prove something to a buyer goes the ISO route. A company structuring itself internally, with no external requirement, finds a free starting point in the NIST framework. The two coexist, and work done for one covers much of the other.
It applies, with a much smaller scope, and that is the situation most companies are in today. ISO describes the standard's audience as organisations that provide or use AI-based products and services, and the word use is there deliberately. What changes is the content of the work: the assessment falls on supplier selection, the contract, who supervises the use and what is done with the output, not on training data and model lifecycle. The typical mistake in this profile is assuming responsibility sits with the supplier. Whoever puts the output in front of the customer answers for it.
We do not publish a timeline, and the reason is not commercial reticence: a published timeline becomes a promise, and three things move that number more than company size. Whether the company builds its own models or only consumes third-party AI, how much management system already exists in the building because of another standard, and how many departments use AI without going through IT, which is the most underestimated of the three. The first conversation already shows which of those you are in, and the first-phase inventory is what sizes the rest with numbers rather than estimates.
With the inventory, not the policy. It is counter-intuitive, because the policy is the easy part to write and the part that seems to produce a quick result, but a policy written about a world nobody verified describes a different company and does not survive the first audit. Mapping the AI uses fits in a few weeks, does not require buying the standard, and is usually the first time the board sees the full list, including what arrived embedded in older systems and what was bought outside IT. After that, the scoping conversation is about numbers.
A short conversation already shows whether your case is about certification, regulatory compliance, or organising the use that already exists. If you would rather start on your own, the self-assessment above gives you the picture on screen, with no mandatory registration.
ISO/IEC · ISO/IEC 42001:2023, edição 1, publicada em dezembro de 2023 · accessed on
ISO/IEC · ISO/IEC 42006:2025, edição 1, publicada em julho de 2025 · accessed on
Parlamento Europeu e Conselho da União Europeia · Jornal Oficial de 12/07/2024, em vigor desde 01/08/2024 · accessed on
Parlamento Europeu e Conselho da União Europeia · Digital Omnibus on AI, em vigor desde 27/07/2026 · accessed on
NIST, instituto nacional de padrões e tecnologia dos Estados Unidos · NIST AI 100-1, publicado em 26/01/2023, de uso voluntário · accessed on
ISO/IEC · ISO/IEC 27001:2022, edição 3, com a emenda 1:2024 · accessed on
This page is informational and describes how DM11 reads and applies the sources above. It does not reproduce the text of any standard, does not replace reading the official document, and does not replace an audit, a certification, an independent assessment or legal advice. Where a standard requires formal assessment, it is carried out by an accredited body, auditor or assessor, always separate from whoever did the preparation.