Schollege

ISO/IEC 42001, from gap assessment to audit ready.

The international standard for managing AI, published in December 2023. We take you from where you are today to the point an auditor can be called in.

01 Standard

What the standard is

ISO/IEC 42001 sets out how an organisation governs the AI it builds and the AI it uses. It is a management system standard, in the same family as ISO 9001 and ISO/IEC 27001, which means it is about how decisions get made, recorded and reviewed, not about which model you chose.

It covers the risks an AI system creates, the controls that hold those risks down, the impact on the people affected by it, and the records that show any of it happened. Because it shares its structure with the other management system standards, it sits alongside what you already run rather than duplicating it.

It is new. Most organisations using AI today have no governance around it at all, which is why the gap is usually wider than people expect and why closing it is worth more than it will be in five years.

02 Package

What the package covers

One package, one price: assessment, implementation and the training your people need, taking you to audit ready.

Splitting it is possible and costs more, because the parts done separately take longer than the parts done together.

The package does not include the certification body's audit fee. That is paid by you, directly to them.

03 Process

How the work runs

Scope

We agree the boundary before anything else: which AI systems, which sites. This is stated by number, and it is what everything after it is measured against.

Assessment

Every clause and every applicable control, against what you actually do today. The output is a findings document that says what is met, what is partly met and what is missing, with the evidence each finding rests on.

Implementation

The policies, the AI risk assessments, the impact assessments, the statement of applicability and the records an auditor will ask to see. Written around how your business works, not lifted from a template pack.

Training

Competence and awareness are auditable requirements, so training is part of the work rather than an extra line. Your people have to know what the system asks of them, and you have to be able to show it.

Internal audit and management review

The standard requires you to check yourself before anyone else does. We run the first cycle with you.

Then you call the auditor.

04 Boundaries

What we do not do

We do not audit. No accredited body may certify a management system it helped build, and we do not want the conflict even where it is allowed.

You choose the certification body. We supply names, checked against two things: that 42001 sits in the accredited scope of that specific legal entity, and that its auditors are in your country, because Stage 2 needs someone on site. You can use your own instead.

You pay them directly. We never quote their fee and we do not take a margin on it.

05 Scope

Scope, stated plainly

The package is quoted before the assessment, so the boundary is fixed in writing first: the number of AI systems and the number of sites in scope.

If the assessment finds more AI in use than the boundary allowed for, which is common, we tell you and you decide whether to widen the scope or leave it where it is. Nothing gets quietly added.

06 Start

Find out where you stand.

A short conversation tells you what 42001 covers, whether it applies to you, and what closing the gap would involve. No obligation.

Send us the detail

Useful if you would rather write it down than talk it through.

Or message us now

Usually the faster route.

Open WhatsApp

Or email support@schollege.com.au