2-sec AI practice / ISO 42001

Build AI Governance You Can Operate and Certify

Build a clear path to ISO 42001 certification with governance that supports the security of your AI systems and data.

2-sec helps you turn AI policies into practical responsibilities, risk controls and audit evidence—so your organisation can move forward with confidence.

For organisations developing, deploying or using AI.

Business-firstScope shaped around your organisation’s AI use
Risk-basedPriorities connected to systems and data
Certification-focusedPreparation for independent assessment
OperationalGovernance that continues beyond the audit
From AI ambition to accountable action

Your AI policy needs a working system behind it.

When AI adoption spreads across teams, responsibility can become fragmented. Give people a consistent way to decide what is acceptable, manage the risks and show that oversight is working.

01 / VISIBILITY

Know what needs governing

Bring AI use cases, data flows and supplier dependencies into view, so important decisions start with a shared understanding.

02 / ACCOUNTABILITY

Make ownership explicit

Clarify who approves AI use, who manages risks and who steps in when a system or its purpose changes.

03 / ASSURANCE

Give stakeholders evidence

Build a record of decisions, reviews and corrective actions that supports scrutiny from leadership, customers and auditors.

What is ISO 42001?

ISO/IEC 42001 is the international standard for an AI management system. It sets requirements for governing how an organisation develops, provides or uses AI, including ongoing review and improvement.

Management System Scope

Defines which AI activities the management system covers, with policies, objectives and responsibilities suited to how the organisation develops, provides or uses AI.

AI Risk Management

Provides a structured way to assess AI risks and select appropriate controls, taking account of the systems, data, people and decisions involved.

Documented Evidence

Connects governance commitments to records of decisions, controls and reviews, helping demonstrate how the AI management system operates within its defined scope.

Continual Improvement

Uses monitoring, internal audits and management review to identify weaknesses, address findings and improve the management system as AI use and risks change.

How 2-sec can help

A practical path from governance gaps to audit readiness.

Start with your current position. Shape the engagement around your AI footprint, existing management systems and certification objectives.

SCOPE & BASELINE

AI discovery and gap assessment

Establish the intended management-system scope, map your AI use and assess the gaps between current practice and certification requirements.

RISK & IMPACT

Understand what is at stake

Assess risks and potential impacts on people and the organisation. Connect governance decisions with data handling, security and human oversight.

POLICY & OWNERSHIP

Build the governance structure

Define responsibilities, acceptable use, approval routes and escalation processes that teams can apply in their everyday work.

CONTROLS & EVIDENCE

Embed the operating practices

Translate agreed priorities into procedures for AI suppliers, system changes, monitoring and record keeping, with evidence of implementation.

REVIEW & READINESS

Prepare for independent assessment

Support internal audit preparation, management review and corrective actions so outstanding issues are visible before certification assessment.

CONTINUAL IMPROVEMENT

Keep governance current

Establish a review rhythm for changes in AI use, suppliers and risk, helping the management system remain useful as your organisation evolves.

Scope, deliverables and responsibilities are agreed for your engagement. Independent certification assessment is separate.

Your route to readiness

Build, implement and review your AI management system

Progress from an initial assessment to evidence of working governance, with a clear purpose for each stage.

1

Establish the starting point

Discuss your AI use, business priorities, existing governance and any customer or certification deadlines.

2

Agree a prioritised roadmap

Define scope, ownership and the work needed to close the gaps, with priorities matched to risk and capacity.

3

Implement and gather evidence

Put the agreed processes into use and capture the records that demonstrate how they operate.

4

Review and prepare

Check effectiveness, address findings and prepare for independent certification assessment.

Governance within the wider AI practice

Connect the policy to the system. And the data.

AI governance has practical consequences: which tools people can use, what information they can share, how suppliers are assessed and when human intervention is needed.

Position ISO 42001 within your wider security programme. Where a governance review identifies a need for technical assurance, agree the relevant testing or security work alongside the management-system engagement.

Explore AI Risk Assessment →Explore AI Policy Development →Explore AI Governance →Explore LLM and Prompt testing →

Part of 2-sec’s wider AI practice

  • AI governance: establish the responsibilities and decision processes around AI use.
  • Systems and data: connect oversight to access, information handling and supplier dependencies.
  • Assurance: identify where testing, review or further security work is needed.
Questions before you start

Make the next decision clearer.

Understand what certification covers and how an engagement can fit your organisation.

Does ISO 42001 certify that our AI tools are secure?

Certification concerns the AI management system within its defined scope. It does not certify every AI product as secure or remove the need for technical testing, monitoring and appropriate security controls.

Is this relevant if we use AI but do not build it?

Yes. The standard is relevant to organisations using AI as well as those developing or providing it. The starting point is the AI activity within your intended scope.

Can we build on an existing ISO 27001 programme?

Existing governance, risk and review processes can provide a useful starting point. The gap assessment establishes what can be reused and where AI-specific responsibilities and practices need to be added.

How long will readiness take, and what will it cost?

This depends on your scope, AI use, existing processes and internal capacity. An initial discussion helps define the work before a timetable and proposal are agreed.

Does 2-sec issue the ISO 42001 certificate?

This service focuses on governance implementation and certification readiness. An independent certification body makes the certification decision following its assessment.

Your next step

Find out what certification readiness looks like for you.

Whether you are building your first AI policy or preparing for an audit, start with a conversation about your current position and what you want to achieve.