ISO 42001
Readiness
ISO 42001 certifies an AI management system - how you govern the AI you build, buy, or deploy. It is new enough that most organisations are assembling their approach from scratch, and buyers are starting to ask. We run readiness so your AI governance is real before a registrar tests it.
Who this is for
Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.
Companies shipping AI features whose enterprise buyers have started asking how the model is governed
Teams who already hold ISO 27001 and want the AI management system to sit alongside it
Organisations deploying third-party AI who need to show the risk was assessed rather than assumed
Anyone whose AI use falls in scope of emerging AI regulation and wants a defensible governance position
What the engagement does
Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.
- Define the AI management system scope and the systems it covers
- Establish AI policy, roles, and the governance the standard expects
- Run AI impact assessments on the systems in scope
- Assess the Annex A controls covering data, life cycle, transparency, and third-party relationships
- Document how AI systems are developed, evaluated, deployed and monitored
- Prepare for Stage 1 and Stage 2 with your registrar
What you walk away with
An AI management system a registrar can audit and a buyer can be shown: scope, policy, impact assessments, life cycle controls, and the evidence that each is operating. Where ISO 27001 already exists, the shared clauses are reused rather than duplicated.
How it runs
Four phases. You always know which one you are in and what is outstanding.
Scoping call
We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.
Assessment
We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.
Remediate and evidence
We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.
Hand off to your assessor
You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.
What the assessment covers
The control areas we walk for ISO 42001. Each breaks down into individual controls carrying status, owner and evidence in Talon.
Certification is issued by an accredited registrar. We build and prepare the management system and coordinate with the registrar you choose.
It runs in Talon, not in a spreadsheet
Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.
- Control-by-control status, kept current by the people doing the work
- Evidence filed against the control it satisfies, with expiry dates tracked
- The auditor request list, so nothing is chased over email
- A readiness view that shows what an assessor would see
Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.
Our partnersAsked on almost every ISO 42001 call
They answer different questions. 27001 covers information security; 42001 covers how AI systems are governed across their life cycle. They share the same management system clauses, so running 42001 on top of an existing ISMS is far cheaper than starting cold.
Yes. The standard covers AI you use as well as AI you build. If a vendor model touches customer data or makes decisions that affect people, the governance obligations are yours.
Increasingly, in procurement questionnaires for AI-enabled products and from buyers in regulated sectors. It is early, which is exactly why certification is currently a differentiator rather than a requirement.
A certified AI management system is not a regulatory approval, but the governance, impact assessment and documentation it requires substantially overlap what regulators ask for.
Rarely run alone
Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.
ISO 42001 readiness, on your timeline
A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.