39 / 63ISO 42001 AI Management System

ISO 42001 certification, scoped to the AI you actually run

ISO 42001 for Canadian organisations, from an AI system inventory to a certificate an accredited body signs.

  • CCIE Security-led team
  • Readiness only, never your certifier
  • Canadian data residency
THE WORK

ISO 42001, three pillars, one operator.

One Canadian team inventories the AI, builds the AI management system, and prepares both audit stages.

  1. 1

    Scope the system

    Annex A carries 38 controls. A Statement of Applicability decides which of them bind you, and every control you leave out has to be justified in writing.

  2. 2

    Build the AIMS

    Policy, roles, impact assessment, lifecycle records, data provenance and supplier terms, written so an auditor can follow the AIMS end to end rather than take your word for it.

  3. 3

    Prepare both stages

    Stage 1 reads your documents. Stage 2 tests whether what you documented actually runs, and the gap between the two can't exceed six months or stage 1 is repeated in full.

THE PROOF

Built to last. Evidence over promises.

ISO 42001 certification isn't theoretical any more. Over 350 organisations worldwide held the certificate by April 2026, and Canada has exactly one accreditation body offering it.

IN PRODUCTION

The Canadian AIMS that passed stage 2.

A European tender asked for ISO 42001 and we had eleven weeks. Two consultancies quoted us a year and a policy library. SMEnode started by listing what we actually run, which turned out to be four systems, not the fourteen we'd assumed. Smaller scope, real evidence, certificate in hand before the deadline.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

ISO 42001 in Canada, made real.

No Canadian law requires this. A customer, a tender, or a board asks for it, and that turns out to be a firmer deadline.

Good work starts with a list, not a policy.

Before anything else we write down every AI system you run, who owns it, what it decides, whose data feeds it, and which of them a supplier operates on your behalf. That list is usually shorter than the internal assumption and it always contains one surprise: a model somebody bought on a credit card, or a vendor feature switched on by default. Scope comes from that list. Annex A's 38 controls then get filtered through a Statement of Applicability, and you justify every one you leave out. Then comes the unglamorous part. An impact assessment saying what happens to a person when the system is wrong. Lifecycle records showing what changed and who approved it. Data provenance you can show. Supplier terms that survive the question of who trained this. Most gaps we find aren't missing controls, they're controls with nothing written down, and stage 1 reads documents before stage 2 tests anything.

What the standard is, and what it isn't.

ISO/IEC 42001:2023 is the first international AI standard written for the management system around your models rather than for the models themselves. Buyers often ask for it as responsible AI certification, which is close enough as shorthand but not what the certificate says. The next question is always ISO 42001 vs ISO 27001. The answer is subject, not structure: both are management system standards with the same clause layout, so holding one makes the second materially cheaper. ISO 27001 governs information security, who can reach data and how it's protected. ISO 42001 governs AI systems, what a model decides, whose data trained it, and what happens when it's wrong. Same auditors, same shape, different risk.

The regulatory case changed in July.

Canada still has no AI statute in force, so nothing here is legally compulsory. AIDA halted in January 2025 and no successor has been tabled, which leaves PIPEDA, Quebec Law 25 and the voluntary code as what actually applies. The EU AI Act's high-risk deadline, the one most of the market sells against, moved from 2026-08-02 to 2027-12-02 when the Digital Omnibus on AI, Regulation (EU) 2026/1744, took effect on 2026-07-27. Article 50 transparency duties were excluded from that deferral and landed on time. So the honest reason to certify is commercial. Somebody won't buy without it, and that's a better deadline than a regulatory one because it doesn't move.

Control checklist
THE METHOD

How an ISO 42001 readiness engagement runs.

Four steps, and step 01 is counting things. Nobody wants to start with an inventory and it decides the cost of everything after it. A team that thinks it runs fourteen AI systems often runs four that matter, plus ten features inside software it already pays for. Certifying the four is months of work. Certifying fourteen is a year you needn't spend. We won't quote the rest until this is done.

  1. Step 01

    Inventory and scope

    Every system, owner, decision, data source and supplier written down, then a defensible boundary drawn around the ones that belong inside the management system. The surprise in that list is why we do it first.

  2. Step 02

    Statement of Applicability

    The 38 Annex A controls filtered against your risk and impact assessments, each exclusion justified in writing, because stage 1 will ask about the exclusions and not the inclusions.

  3. Step 03

    Build and evidence it

    Policy, roles, lifecycle records, data provenance and supplier terms. Our engineers do the technical work rather than handing you a folder of templates to fill in yourselves.

  4. Step 04

    Both stages, then hand off

    We prepare you for stage 1, fix what it raises, and stand behind you through stage 2. The certificate comes from an accredited body, never from us, and we'll help you pick one whose accreditation is real.

QUESTIONS

ISO 42001 questions, answered straight.

Answers first, including whether this standard is mature enough to bother with and why the EU deadline moved. An architect takes the call, not a salesperson.

Fair question, and the loudest voices online say too early. It's real. More than 350 organisations held the certificate by April 2026, and BSI picked up UKAS accreditation early in 2026 and ANAB accreditation in March. There's no free route: free courses teach the standard, they don't certify you, and the certificate has to come from an accredited body after a two-stage audit.

Subject, not structure. Both are management system standards with the same shape, so if you hold one the second is materially cheaper. ISO 27001 governs information security: who can reach data and how it's protected. ISO 42001 governs AI systems: what a model decides, whose data trained it, and what happens when it's wrong. Same auditors, same clause layout, different risk.

No, and be wary of anyone who says otherwise. The certificate comes from a certification body holding accreditation for this standard, and in Canada the Standards Council of Canada is the only accreditation body offering it. We do the inventory, the Statement of Applicability, the build and the evidence, then help you choose a body and get through both stages.

Less urgently than you were told a month ago. The high-risk obligations for standalone systems moved from 2026-08-02 to 2027-12-02 under the Digital Omnibus, which took effect 2026-07-27. Article 50 transparency duties were not deferred. This was never the same thing as EU compliance anyway: it's a management system certificate that makes an EU conversation easier, not a substitute for one.

When nobody has asked, because a certificate nobody requested is an expensive way to signal seriousness. When you don't know what AI you run, since the inventory is cheap and does most of the useful work on its own. And when the real question is security, because that standard is more mature, more recognised, and a better first certificate.

Scope sets both, and scope comes from the inventory. Kickoff to a signed Statement of Applicability runs about five weeks once the system list settles, and the build after it depends on how much evidence already exists. Stage 1 to stage 2 can't run past six months or stage 1 repeats in full, so we plan backwards from your audit date.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.