ISO 42001 certificationFor organizations that use AI

Govern the AI you use with ISO 42001.

An AI management system gives you shared rules for purchased AI services, ownership, risks, competence, and follow-up. AmpliFlow brings the work together for certification and daily use afterwards.

Free, with no preparation needed. After the call, you receive a quote with the proposed setup, support, and price.

A management system for responsible AI use

An AI management system makes AI use a management responsibility

The management system connects the register, AI policy, and follow-up in an organization-wide approach. It defines how AI may be used, who is responsible, and how risks, results, and improvements are followed up.

ISO 42001 follows the same logic as other management system standards: management sets the direction, the business applies it, and the organization checks that the approach works.

  1. Decide

    Define the scope, policy, objectives, responsibilities, and rules for approved AI use.

  2. Implement

    Assess risks and impacts, review suppliers, ensure competence, and put relevant controls in place.

  3. Follow up and improve

    Monitor use, handle nonconformities, complete internal audits, and have management review the results.

The EU AI Act also covers user organizations

The EU AI Act covers organizations that use AI

The AI Act is being applied in stages and also covers organizations that use AI systems under their authority. The obligations depend on the organization's role, the AI system's risk class, and its use. Requirements may concern AI literacy, human oversight, monitoring, and transparency. Data protection rules, sector requirements, contracts, and procurement may place additional requirements on AI use.

ISO 42001 does not replace a legal assessment, and certification does not automatically prove compliance. The standard does provide a structure for mapping requirements, assigning responsibility, documenting decisions, and following up the work.

Read more about the EU AI Act →
Start with the AI you already use

Keep one register of the AI services you use, buy, and develop

You do not need to develop AI to benefit from ISO 42001. Start with a configurable register of the AI services and systems already in use or being purchased. Decide which details the register should contain and appoint who approves use, assesses risks, and follows up approved controls.

Use

Set boundaries for AI services employees already use

Document approved tools and use cases, permitted data, and competence requirements. Follow up nonconformities and actions.

Buy

Set requirements before purchase and follow up the supplier

Document the supplier, intended use, permitted data, and responsibility before purchase. Decide how the AI system will be monitored and reviewed.

Develop

Govern in-house AI systems from idea to retirement

Document purpose, ownership, data, risks, impacts, and controls from idea and development through operation, change, and retirement.

The platform

Link AI systems, risks, controls, and governed documents in AmpliFlow

Link controls to processes, risks, pages where you publish policies and procedures, and legislation. Competence owners record requirements, supplier owners follow up suppliers, and nonconformity owners assign actions in AmpliFlow.

  • Configure an AI system registerAdd the information needed to govern each AI system, such as purpose, owner, supplier, data categories, data sources, operating status, and planned retirement.
  • Link each control to the relevant process, risk, policy, and ownerLink the control to the risk assessment, process, and approved procedure so that its implementation and owner are clear.
  • Follow up nonconformities, actions, and objectives in separate registersManagers record competence requirements, procurement staff review suppliers, and designated managers assign actions. Before management review, the internal project lead compiles progress against objectives, measurement results, and open nonconformities.

Screenshots of project reports, risk assessments, governed content, and competence requirements

See how AmpliFlow handles registers, competence requirements, and follow-up

The images show project reports, risk assessments, published policies and procedures, and competence requirements in AmpliFlow.

Controls for AI governance

Assess all 38 controls and follow up those that apply to you

The AmpliFlow control register contains every control in Annex A and is used to assess applicability, record responsibility, and follow up implementation. Add custom controls where your AI management system needs them. This supports the work described in ISO/IEC 42001:2023, clause 6.1.3 and Annex A.

Set a status and appoint a user, team, or role as owner of each control. Create tasks, attach files, and link the control to relevant processes, risks, pages with policies and procedures, legislation, or equipment. You can export the control register as a PDF and use it as input to your Statement of Applicability (SoA). See the control-register product description.

Optional AI assistance can produce an editable control-description draft. See who should review the text and how legal questions are kept separate.

Book a free call about AI controls →

Annex A contains

38

controls already configured in a register where you assess applicability and follow up status, responsibilities, tasks, and supporting material.

  • AI policy
  • Roles
  • Applicability and status
  • Owners and tasks
  • Custom controls
  • Export the control register as PDF input to the Statement of Applicability
ISO 42001 controls workspace in AmpliFlow showing control status, applicability, and follow-up
The ISO 42001 control view keeps applicability, status, ownership, and follow-up in one workspace.
Responsibility and decisions for each AI system

See the owner, risks, and next action for each AI system

The organization appoints who records the AI system and intended use, assesses risks and impacts, decides whether the risk can be accepted, and follows up control status, review material, and outstanding actions. Controls can link to processes, risks, pages with approved policies and procedures, legislation, and equipment.

AI system and use case

Record the purpose, data, supplier, affected process, and system owner

You can configure the AI system register with fields for purpose, intended use, permitted data, owner, and affected process, and record the supplier and planned follow-up in the supplier register.

Risk and control

Assess risks and impacts, select controls, and assign tasks

Use the risk module and a custom list to set up impact-assessment steps, owners, and decisions. Document applicability, status, ownership, and supporting material in the control register.

Nonconformity and follow-up

Owners record nonconformities, assign actions, and compile results

An appointed reporter records the nonconformity, the nonconformity owner assigns the action, and the action owner documents the result. Open nonconformities, action status, objectives, and measurements are compiled for management review.

AI assistance and the law

Have control owners review AI drafts and lawyers assess legal obligations

AI assistance can draft a description of how a control will be implemented and followed up. Have the control owner review the draft against the approved policy and risk assessment before approving the text. Have a lawyer assess the organization's obligations under the EU AI Act separately.

See how AmpliFlow uses AI and processes data →

From scope to audit material

Organize the ISO 42001 work into four project phases

Map your AI systems, assign responsibility, assess risks, and gather the material needed for the certification audit.

04

Gather material for the certification audit

Close the remaining gaps, complete an internal audit, and gather results, objectives, and measurements. AmpliFlow helps you prepare the material. A certification body conducts the external certification audit.

Mini, Midi, or Maxi

Choose how much of the implementation you want to lead yourselves

Every package includes AmpliFlow, system setup, file migration, templates, and an introduction to the software and templates. The difference is how much support you get with project leadership, internal audit, training, and adaptation. Every level requires management involvement and an internal owner.

Mini

You lead and carry out the work yourselves

For teams with an internal project lead that want to build the management system themselves on a ready-made foundation in AmpliFlow.

Included

  • AmpliFlow software
  • System setup
  • File migration
  • Templates
  • Introduction to the software and templates

Midi

You share project leadership with AmpliFlow

For teams that want to combine their own work with project leadership, internal audit, training, and help adapting the setup.

Included

  • AmpliFlow software
  • System setup
  • File migration
  • Templates
  • Introduction to the software and templates
  • Internal audit
  • Project leadership together with AmpliFlow
  • Midi training package
  • Adaptation for a simpler way of working

Maxi

AmpliFlow leads the implementation

For teams that want us to lead the implementation and adapt the system for an efficient way of working.

Included

  • AmpliFlow software
  • System setup
  • File migration
  • Templates
  • Introduction to the software and templates
  • Internal audit
  • Project leadership led by AmpliFlow
  • Adaptation for a simpler way of working
  • Maxi training package
  • Adaptation for a more efficient way of working

Not sure which package fits? We recommend a level based on your current position, available time, and internal capacity.

Book a call
FAQ

Common questions before choosing ISO 42001 certification

Is file migration included?
Yes. File migration is included at no extra charge, for example from SharePoint, file servers, or older systems. Together, we decide which files should move.
How does AmpliFlow handle AI systems we build, buy, or use?
Build the register with AmpliFlow's configurable lists and choose fields for details such as purpose, owner, supplier, data categories, data sources, personal data, operating status, and planned retirement. You appoint the people responsible for the work. One possible assignment is for system owners to register systems, risk owners to assess risks, control owners to follow up applicable controls, and nonconformity owners to assign actions. Competence requirements and objectives are managed in the modules included in the selected setup.
How are AmpliFlow's own AI features used?
The optional AI assistance can draft descriptions of how controls will be implemented and followed up. Have the control owner fact-check, adapt, and approve the text before using it as a governed document or audit evidence. Read how AmpliFlow uses AI and processes data.
How does AmpliFlow help us become ISO 42001 certified?
AmpliFlow holds the AI-system register, control register, tasks, and audit material. You define the scope, AI policy, and roles, assess risks, select controls, and complete an internal audit. In Mini, you lead the work; in Midi, you share project leadership with AmpliFlow; and in Maxi, AmpliFlow leads the agreed working sessions and training.
Do we need ISO 42001 if we do not develop our own AI?
ISO 42001 applies to organizations that provide or use products or services that utilize AI systems. You do not need to develop your own AI to use the standard. Then assess whether customer requirements, procurement terms, risk level, or other business requirements justify third-party certification. If you mainly need internal rules, you can start with a policy, register, and follow-up before deciding on certification.
What is an AI management system?
An AI management system is the organization-wide way you govern AI. Management defines the scope, policy, objectives, and responsibilities. The business assesses risks and impacts, sets supplier requirements, ensures competence, and follows up use. Internal audits, management reviews, nonconformities, and improvements then show whether the approach works.
How does the EU AI Act affect companies that use purchased AI services?
The EU AI Act also covers organizations that use AI systems under their authority. The obligations depend on factors such as the organization's role, the AI system's risk class, and its use. Requirements may concern AI literacy, human oversight, monitoring, and transparency. Have a lawyer assess which requirements apply to each use case.
Does ISO 42001 certification mean that we comply with legal requirements?
No. ISO 42001 is a management system standard and does not replace legal advice or guarantee compliance with the EU AI Act. It gives you a structure for mapping requirements, assessing risks, assigning responsibility, documenting decisions, and following up the work.
Can we coordinate ISO 42001 with other management system standards?
Yes. Decide which processes and roles to share across management systems and which objectives, nonconformities, and results to follow up together. In AmpliFlow, appointed people record processes, competence requirements, suppliers, nonconformities, and objectives in separate registers. Controls can link directly to processes, risks, pages with policies and procedures, legislation, and equipment.
Free call, followed by a scoped proposal and price

Book a free call about scope and support

You do not need to prepare anything. We start with the AI systems in scope, the time your internal lead can set aside, and the support you need. Based on that, we propose Mini, Midi, or Maxi. After the call, you receive a quote with the proposed setup and price.