ISO/IEC 42001:2023 is the certifiable management system standard for AI. It asks for an AI policy, AI risk assessment, AI system impact assessment and 38 Annex A controls. Teddy's agents build each part from your AI systems and reuse an existing ISMS where you have one, and a compliance engineer takes you through the certification audit.

ISO/IEC 42001:2023 is a voluntary, certifiable standard for an AI management system. It uses the same clause structure as ISO 27001, so both can run as one integrated management system. Here is what it asks for and where it lives in Teddy.
Determine your role for AI, for example developer, provider or user, the AI systems in scope and the interested parties that matter.
Top management sets an AI policy that fits the organization's purpose and links to other policies, such as information security and privacy.
Assess risks related to AI systems, select controls and record them in a Statement of Applicability against Annex A.
Assess the potential consequences of AI systems for individuals, groups and society, and document the results.
From AI roles and resources to data, the AI system life cycle, information for interested parties, responsible use and third-party relationships.
Internal audits, management reviews and corrective action, which can be combined with those of your ISMS.
The standard asks for an AI policy, clear roles, risk and impact assessments and controls that work in practice. Most teams start without knowing who owns which part.
Teddy sets up policy, roles and reviews for the AI systems in scope.
Each AI system gets an owner and someone who approves changes.
Teddy drafts the impact assessment for each system. The system owner reviews it.
The ISMS lives in one folder, the new AI policy in another, and a consultant offers a fresh ISO 42001 project. ChatGPT can write an AI policy, but it does not know your models, your data or your existing controls. Teddy extends the ISMS you already run and adds only what ISO 42001 asks for on top.
Pia · ComplianceDo we need a separate risk register for AI?
Arne · MLWho approves it when we retrain the model?
Lisa · LegalTwo customers ask for ISO 42001 in their RFP.
ConsultantNew ISO 42001 project: 30 days, starting with a scope workshop.
Vera · CEOCan our ISO 27001 auditor do this in one go?
Teddy's agents reuse what you have and build only what is new. You decide, and a compliance engineer is there when the auditor arrives.
Teddy sets your role for AI and the AI systems in scope, and aligns the scope with your existing ISMS so both run as one system.
Clauses 4 to 10 and many controls carry over. The gap audit shows what ISO 42001 adds, control by control.
The Policy Agent drafts the AI policy and the AI roles, linked to the policies you already have instead of repeating them.
For each system, Teddy drafts who can be affected, how, and which measures limit the impact. The system owner reviews and approves.
The Evidence Agent collects change history, model documentation and data sources from connected tools, so the auditor sees the life cycle in practice.
Ask in plain language what ISO 42001 adds or how to assess an AI system. Teddy answers from your live management system. For the certification audit, our compliance engineers are at your side.
Ask TeddyWhat is new compared to ISO 27001? How do we assess impact? Teddy knows the standard and your systems.
Agents do the workScope, AI policy, impact assessments, SoA and evidence, each with its source.
Our team backs you upCompliance engineers help you choose a certification body and join you through Stage 1 and Stage 2.
No. ISO/IEC 42001 is voluntary and the EU AI Act is law. The standard supports much of the governance the Act expects, and Teddy maps both onto one control set, but it does not replace the Act's legal duties.
No, ISO 42001 can stand on its own. If you already run an ISMS, the shared clause structure means much of the management system is already in place.
A documented assessment of how an AI system can affect individuals, groups and society, for example through bias or wrong decisions. ISO 42001 requires it in clause 6.1.4.
An accredited certification body. ISO/IEC 42006 sets additional requirements for bodies that audit AI management systems. We help you find one, and a compliance engineer goes through the audit with you.
Start with a gap audit against ISO/IEC 42001 on your existing ISMS.
Reviewed by Sven Moritz, former CISO · October 2026
From gap assessment to certificate, for an organization without a mature management system.
Ready for Stage 1. AI policy, AI risk and impact assessments and the Statement of Applicability built on your existing ISMS. Only the AI-specific gaps show up as new work.
Auditors rarely find no assessment at all. They find one that still describes last year's model and last year's use case. Make updates part of every model release.
Gaps in the AI system inventory are among the most frequent findings. Leaving difficult systems out of scope does not lower the risk, it moves it into the audit.
An AI policy alone is not enough. Auditors look for AI-specific evidence such as data quality, model lifecycle, fairness and transparency, not only security controls.