← Document packs ISO 42001:2023

ISO 42001 for SMEs: an AI governance guide

ISO 42001 is the first international standard that sets out requirements for an Artificial Intelligence Management System (AIMS). For small and medium businesses using or building AI, it is quickly becoming the benchmark clients ask about.

This guide covers what the standard requires, which documents an SME needs, and how it fits alongside ISO 27001 and other frameworks.

What ISO 42001 is

Published in December 2023, ISO 42001:2023 provides a certifiable management system for AI. It applies whether your organisation develops AI systems, deploys them, or simply uses AI tools in its operations.

The standard is built around the same plan-do-check-act cycle as ISO 27001, with specific requirements for AI context, risk assessment, lifecycle controls, and human oversight. It complements technical standards such as ISO/IEC 23894 (AI risk management guidance).

Why SMEs should care now

AI adoption among SMEs is growing quickly, and with it questions from customers and regulators about how AI is governed. Tenders increasingly reference AI governance, and organisations in the AI supply chain are being asked to demonstrate responsible practice.

For a small business, starting early is an advantage. Building a lightweight AI governance framework now is far cheaper than reconstructing it later when a client or auditor asks for evidence.

What you need to document

The documentation foundation for an AIMS is practical: an AI policy set covering governance, acceptable use, AI risk management, data governance for AI, and human oversight; an AI system impact assessment capturing which AI systems are in scope and their societal and individual impacts; and an implementation tracker based on the guidance in Annexure B of the standard.

Our ISO 42001 document packs provide ready-to-use templates for exactly this set, pre-structured with placeholder fields so you can tailor them to your business.

How ISO 42001 fits with ISO 27001

ISO 42001 and ISO 27001 use the same management system structure, so they combine naturally. An organisation certified for ISO 27001 already has the governance rhythm - policies, risk assessment, internal audit - that ISO 42001 builds on.

Many SMEs run them as a single integrated management system, sharing policies where the controls overlap and keeping one audit calendar.

A roadmap for a small business

Start by scoping which AI systems you have or plan to use. Build the documentation foundation, run an impact assessment on the systems that matter most, then implement the controls and review them through your existing management processes.

If certification is a goal, engage an accredited certification body early so their requirements inform your implementation from the start.

ISO 42001:2023 document packs

Ready-to-use ISO 42001:2023 templates, pre-structured with placeholder fields for your company details. Instant download after payment - no subscription.

ISO 42001:2023 FAQ

Is ISO 42001 certifiable?

Yes. Like ISO 27001, ISO 42001 can be certified by accredited certification bodies through an independent audit. It is the first certifiable international standard for AI management systems.

Do I need ISO 42001 if my team just uses ChatGPT?

Potentially. The standard applies to how AI is used, not just how it is built. Even simple internal AI use should be covered by AI use policies and basic risk and impact assessment, which our templates provide.

Is ISO 42001 related to the EU AI Act?

The EU AI Act is a law while ISO 42001 is a certifiable management standard, but they complement each other. A documented AI management system is a practical way to demonstrate responsible AI governance.

What documents do I need for an AIMS?

At a minimum, an AI policy set (governance, use, risk, data, and human oversight), an AI system impact assessment, and an implementation tracker. Our ISO 42001 packs cover all three.

Questions?

If you have questions about which kit is right for your business, or need a custom document set for a specific framework or industry, contact us at [email protected].