AI Sentri
    ISO/IEC 42001

    ISO 42001 alignment, evidenced as you go.

    AI Sentri helps you implement the structures, controls, and oversight expected by ISO 42001 — without the operational complexity.

    What is ISO 42001?

    ISO/IEC 42001 is an international standard for managing artificial intelligence responsibly across an organisation. It provides a structured approach to governing AI systems, covering areas such as risk management, accountability, oversight, and continuous improvement.

    Why It Matters

    Brings structure to AI governance
    Helps manage risk and accountability
    Supports regulatory expectations (e.g. EU AI Act, data protection)
    Builds trust with customers and stakeholders

    How AI Sentri Aligns

    Mapping ISO 42001 principles to practical outcomes.

    PrincipleAI Inventory & Context
    What It MeansUnderstand what AI systems exist, their purpose, and organisational context
    AI SentriCentral AI Systems Inventory capturing purpose, use case, stakeholders, ownership, dependencies, and strategic alignment
    What This Means for YouFull visibility of your AI estate, with clear understanding of why each system exists and how it supports the business
    PrincipleGovernance & Accountability
    What It MeansEstablish clear ownership, oversight, and decision-making structures
    AI SentriNamed system owners and risk owners, governance committees, approval workflows, and escalation paths
    What This Means for YouClear accountability across every AI system, with defined decision-making and escalation when issues arise
    PrincipleRisk Management
    What It MeansIdentify, assess, and manage risks associated with AI systems
    AI SentriStructured risk capture including bias, privacy, misuse, and impact, with scoring, prioritisation, and linked mitigation actions
    What This Means for YouMove from ad hoc risk awareness to a consistent, proactive approach to managing AI risk
    PrincipleControls & Oversight
    What It MeansEnsure appropriate safeguards and controls are in place and working
    AI SentriStandard-driven governance (requirements), human oversight tracking, control status (met / not met), and effectiveness tracking
    What This Means for YouConsistent enforcement of governance standards across all systems, not just best-effort compliance
    PrincipleOperational Management
    What It MeansManage AI systems across their full lifecycle
    AI SentriCoverage of data usage, model lifecycle, testing, validation, deployment, performance, and dependencies within each system
    What This Means for YouConfidence that AI systems are managed consistently from creation through to ongoing use
    PrincipleMonitoring & Review
    What It MeansContinuously evaluate AI systems and governance effectiveness
    AI SentriPeriodic reviews, audit logs, performance monitoring, drift tracking, and review scheduling
    What This Means for YouOngoing visibility into system performance and governance health, not just point-in-time assessments
    PrincipleContinuous Improvement
    What It MeansIdentify issues, learn from them, and improve over time
    AI SentriIssue and incident logging, remediation tracking, dynamic action plans, and escalation where needed
    What This Means for YouA closed-loop governance model where issues are not just identified, but resolved and used to improve future performance

    Key Capabilities

    Centralised view of your AI estate
    Standardised governance across all systems
    Clear accountability and escalation
    Continuous monitoring and improvement
    Executive-ready insights and reporting

    Important Note

    AI Sentri supports alignment with ISO 42001 principles, but does not provide certification or legal advice. Organisations should seek appropriate professional guidance for formal compliance or certification requirements.

    AI Sentri helps you move from fragmented AI oversight to a structured, organisation-wide approach aligned with emerging global standards.

    AI Sentri is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.

    Before you start

    Questions about ISO 42001

    What does ISO 42001 certification involve?

    A two-stage external audit: Stage 1 reviews whether your documented management system meets the standard, Stage 2 tests whether you actually operate it, followed by periodic surveillance audits. Most of the effort sits in the year before — establishing the policies, roles, risk and impact assessments and records that Stage 2 looks for. Evidence collected continuously is far cheaper than evidence assembled for an audit.

    What is in Annex A of ISO 42001?

    A set of reference controls spanning AI policy, internal organisation and roles, resources for AI systems, impact assessment, the AI system lifecycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships. As with ISO 27001, you select the controls relevant to your context and justify anything you exclude.

    How long does ISO 42001 take to implement?

    Typically six to twelve months to certification for an organisation starting without an AI management system, and less where ISO 27001 is already in place, since the management-system structure carries across. The variable is rarely the documentation — it is how long it takes to establish an accurate picture of the AI systems in scope.

    What is ISO/IEC 42001?

    The international standard for an AI management system — the governance structure around AI, rather than a technical specification for models. It covers policy, roles and responsibilities, risk and impact assessment, lifecycle controls and continual improvement, and it is certifiable, which matters when a customer or insurer wants third-party assurance rather than your own word.

    How does it relate to the EU AI Act?

    They complement each other. The EU AI Act is law and sets obligations you must meet; ISO 42001 is a voluntary standard describing a management system that helps you meet them consistently. Organisations aiming at both usually find the ISO structure does most of the work of demonstrating the Act's process requirements.

    Do we need to be certified?

    Only if something requires it — a customer, a tender, an insurer. Many organisations align with the standard without certifying, and get most of the operational benefit. Aligning first is also the cheaper route to certification later, because the evidence is already being collected.

    How does AI Sentri help with ISO 42001?

    It scores each AI system against the expectations the standard sets around lifecycle controls, risk assessment and oversight, alongside your EU AI Act and GDPR position, and keeps the evidence attached to the systems themselves. The gap between where you are and what an auditor would look for is visible continuously rather than discovered during a readiness review.

    More in the full FAQ, or ask us directly.

    Your Privacy Matters

    We use cookies to provide essential functionality, analyse usage, and improve your experience. Under GDPR, you have the right to choose which cookies you allow. Strictly necessary cookies cannot be disabled. Privacy Policy