ISO 42001 certification: the artificial intelligence management system
ISO/IEC 42001 is the first certifiable international standard for managing artificial intelligence inside a company.
We help companies in Switzerland, Italy and international markets build and certify a solid AI management system — with the rare advantage of a consultant who writes software himself.
What ISO 42001 is
- Published in December 2023, it is the first international standard devoted to artificial intelligence management systems (AIMS), and currently the only one in the field you can certify against.
- It does not certify the individual algorithm, but the way the organisation governs AI: how it assesses risk, how it controls data and automated decisions, who answers for them, and what happens when something goes wrong.
- It covers the whole life cycle of AI systems, from design through to decommissioning, with attention to transparency, fairness, security and human oversight.
- It has the same underlying structure as the other ISO standards, so it integrates with an existing 9001, 27001 or 14001 system instead of duplicating it.
Why now: the European AI Act
- The AI Act (Regulation (EU) 2024/1689) is the first comprehensive piece of AI legislation, and it is coming into force in stages.
- From 2 August 2026, transparency duties apply to anyone using generative or conversational AI in contact with the public: the use of the algorithm has to be made apparent.
- The heavier obligations, for high-risk systems, apply from 2 December 2027.
- ISO 42001 is not imposed by the AI Act, but it is currently the most widely recognised way to show, in a structured manner, that AI governance is under control: risk management, traceable decisions, defined accountability.
The AI Act concerns the European Union, but it reaches Swiss companies too. Anyone placing AI systems on the EU market, or whose output is used within the EU, falls under the obligations — exactly as happened with the GDPR.
For a Ticino company selling or operating in Italy and in Europe, ISO 42001 is the way not to be caught unprepared. And it is the point at which a consultant working on both sides of the border is worth more than one who knows only the one.
Who needs it
- Companies that build AI solutions or embed them in their own products.
- Companies that use AI in processes affecting people: recruitment, credit, customer service, automated decisions.
- Suppliers whose clients, tenders or international supply chains are starting to ask for assurances about AI.
- Anyone who would rather get ahead of the AI Act than chase it.
How it fits with the other standards
If the company already runs a 9001 or 27001 system, 42001 does not start from scratch: it grafts onto the existing structure. The link with ISO 27001 is the most natural one, because AI governance and information security overlap heavily. Anyone who already holds 27001 starts ahead.
The path
The sequence is the one common to every standard: initial review with a free preliminary assessment → planning → building the system → training → internal audit → certification audit by an accredited third-party body → maintenance on a three-year cycle.
Under 42001 the AI risk analysis carries more weight than elsewhere: it is the heart of the standard, and the point where technical competence decides whether the system holds up or merely describes.
Why BS & Partners
- Real software expertise. We do not explain AI governance from a checklist: we build applications and we know what sits underneath a model. On a standard as technical as this, that is an advantage almost no ISO consultant around here can offer.
- Ten years in business, 117 projects, work in 9 countries.
- We operate on both sides of the border, which counts for more than usual on a standard tied to European law.
- The firm and the way we work: the BS & Partners profile.
Frequently asked questions
Is ISO 42001 mandatory?
No, it is voluntary. It is, however, the most widely recognised way to demonstrate structured compliance with the principles of the AI Act — which is mandatory.
What is the difference between ISO 42001 and the AI Act?
ISO 42001 is a voluntary, certifiable standard; the AI Act is a European law. The former helps you demonstrate compliance with the latter.
Is my Swiss company affected by the AI Act?
It may well be. The obligations apply to anyone placing AI systems on the European Union market, or whose output is used in the EU — the same dynamic already seen with the GDPR.
I already have ISO 27001 — do I have to start over?
No. ISO 42001 grafts onto the existing structure. The link with 27001 is particularly close, because AI governance and data security overlap.
How much does it cost, and how long does it take?
The cost has two components: our consulting fee and the fee of the certification body, which is an independent third party. It depends on how many AI systems are involved and on what the company already has in place: we discuss it at the first contact, on your specific case.
The firm in numbers
- 10 years in business
- 117 projects completed
- 9 countries we have worked in
Would you rather arrive prepared than play catch-up?
The preliminary assessment is free: we look at how you use or build AI today and what it takes to govern it demonstrably.
Request a free preliminary assessment
Or write to direzione@bs-partners.ch or call +41 76 731 16 99.