AI Sentri helps you implement the structures, controls, and oversight expected by ISO 42001 — without the operational complexity.
ISO/IEC 42001 is an international standard for managing artificial intelligence responsibly across an organisation. It provides a structured approach to governing AI systems, covering areas such as risk management, accountability, oversight, and continuous improvement.
Mapping ISO 42001 principles to practical outcomes.
AI Sentri supports alignment with ISO 42001 principles, but does not provide certification or legal advice. Organisations should seek appropriate professional guidance for formal compliance or certification requirements.
AI Sentri helps you move from fragmented AI oversight to a structured, organisation-wide approach aligned with emerging global standards.
AI Sentri is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.
Before you start
A two-stage external audit: Stage 1 reviews whether your documented management system meets the standard, Stage 2 tests whether you actually operate it, followed by periodic surveillance audits. Most of the effort sits in the year before — establishing the policies, roles, risk and impact assessments and records that Stage 2 looks for. Evidence collected continuously is far cheaper than evidence assembled for an audit.
A set of reference controls spanning AI policy, internal organisation and roles, resources for AI systems, impact assessment, the AI system lifecycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships. As with ISO 27001, you select the controls relevant to your context and justify anything you exclude.
Typically six to twelve months to certification for an organisation starting without an AI management system, and less where ISO 27001 is already in place, since the management-system structure carries across. The variable is rarely the documentation — it is how long it takes to establish an accurate picture of the AI systems in scope.
The international standard for an AI management system — the governance structure around AI, rather than a technical specification for models. It covers policy, roles and responsibilities, risk and impact assessment, lifecycle controls and continual improvement, and it is certifiable, which matters when a customer or insurer wants third-party assurance rather than your own word.
They complement each other. The EU AI Act is law and sets obligations you must meet; ISO 42001 is a voluntary standard describing a management system that helps you meet them consistently. Organisations aiming at both usually find the ISO structure does most of the work of demonstrating the Act's process requirements.
Only if something requires it — a customer, a tender, an insurer. Many organisations align with the standard without certifying, and get most of the operational benefit. Aligning first is also the cheaper route to certification later, because the evidence is already being collected.
It scores each AI system against the expectations the standard sets around lifecycle controls, risk assessment and oversight, alongside your EU AI Act and GDPR position, and keeps the evidence attached to the systems themselves. The gap between where you are and what an auditor would look for is visible continuously rather than discovered during a readiness review.
More in the full FAQ, or ask us directly.