AI consulting
ISO 42001 implementation
Certification of AI management systems
What is ISO 42001?
ISO/IEC 42001:2023 is the first international standard for AI management systems (AIMS). We help companies design and implement an AIMS and prepare for certification.
Why now: The EU AI Act requires demonstrable AI governance. ISO/IEC 42001 is an internationally recognised framework that covers these requirements and demonstrates a responsible approach to AI to clients and auditors alike.
Typical implementation timeline
Indicative schedule; the actual duration depends on the size and readiness of the company.
Months 1–2
Gap analysis and planning
Months 2–4
AIMS design and implementation
Months 4–5
Internal audit and remediation
Months 5–6
Certification audit
What we do in each phase
Gap analysis
Comparison of the current state against the requirements of the standard, identification of gaps and priority areas.
Scope and AIMS design
Defining the scope of the AI management system, roles and responsibilities, tailored to the size and sector of the company.
Statement of Applicability (SoA)
Selection and justification of the standard's Annex A controls: which apply, which do not, and why.
AI impact assessment
Impact assessment for individual AI systems, linked to the DPIA and the requirements of the AI Act.
AI policy and documentation
A clear AI policy, procedures and records. Staff training and integration into business processes.
Internal audit and certification
Internal audit, remediation of non-conformities and support during the certification audit by an accredited certification body.
Why Jaroslav Surman?
Certification without practice is not enough. We bring real experience.
ISO 42001 Lead Implementer
PECB certification, 2025. Plus ISO/IEC 27001 Lead Implementer (2026) for the link to information security.
Practice, not theory
We implement AI governance in practice: from policies and roles through documentation to internal audits.
Bridging law and technology
We combine the technical AIMS with legal documentation (AI Act, GDPR).
SME focus
We adapt the standard to the size of your company, without unnecessary bureaucracy.
Start with a gap analysis
Find out how far you are from certification. Initial consultation free of charge and without obligation.