Prove your AI is governed, not just impressive
You have models in production and no written answer to who approved them, what data trained them, or who is accountable when one is wrong.
What you get
- An inventory of every AI system in use, including the ones bought inside other software
- A gap analysis against ISO/IEC 42001, with the findings ranked by exposure rather than by effort
- Impact assessments, human-oversight points and an incident path that names people, not departments
- The documented management system an auditor or an enterprise client will actually ask to see
AI stopped being a capability and became a compliance question
Whether you are consuming third-party models through an API, embedding a vendor's AI feature inside a product you sell, or training on your own customer data, the question you now get asked is the same: show us how this is governed. It arrives from enterprise procurement teams, from insurers, and increasingly from regulators — the UAE's PDPL and Saudi Arabia's NDMO both reach data your models touch.
ISO/IEC 42001 is the first certifiable standard for an AI Management System (AIMS). It exists because the honest answer to that question is a management system, not a slide about your ethics principles.
Who this is for
AI-powered B2B software companies whose deals stall in security review, and who need to prove the data pipeline is governed before procurement will sign.
Regulated enterprises — finance, healthcare, government — using AI to process personal data, automate decisions or triage customers.
Any company training or fine-tuning on customer data, where the questions are provenance, bias and the right to an explanation.
Three ways to start
Scoping workshop. Defining the boundary of the management system is the step most often got wrong. Too broad and you burn engineering time governing systems nobody asked about; too narrow and the certificate answers no question a buyer has. We run this with the people who can actually decide, and we come out with a defensible scope and your role in the AI value chain named — provider, producer or user.
Gap analysis and vendor risk assessment. Most of your exposure is not in code you wrote. We assess you against the Annex A controls and audit what your AI suppliers, and their suppliers, are contractually and technically obliged to do. You get findings ranked by exposure and a remediation order.
Full implementation to audit-ready. Policies, AI impact assessments, risk treatment, human-oversight points, incident handling and an internal audit — built into the development lifecycle you already run and mapped onto your ISO 27001 controls where they overlap, which is often. ISO/IEC 42001 shares the Annex SL structure, so integration is the point rather than a second parallel system.
Why most AI compliance projects fail their audit
They produce documentation that describes a company that does not exist. The policy says models are reviewed before release; the release process has no review step. An auditor finds that gap in an afternoon, and so does a serious enterprise client.
We write the management system against how your engineering and operations actually work, then change what genuinely has to change. That is slower to start and it is the only version that survives contact with an auditor.
What determines the cost, and what we cannot sell you
Scope decides both the price and the duration, and the scope is the first deliverable rather than an assumption. What moves it: how many AI systems fall inside the boundary, whether you are a provider of them or a user of somebody else's, whether ISO 27001 already exists — in which case a large part of the management system is there and needs extending rather than writing — and how much of your current practice is evidenced rather than merely done well.
The scoping workshop is a small, fixed piece of work with a written output, and it comes before any implementation commitment. What you have at the end of it is a defensible boundary, your role in the AI value chain named, and a scope you could take to another advisory firm or straight to a certification body.
We are not a certification body and cannot be one. Certification is issued by an accredited body after its own audit, and the same firm cannot both build a management system and certify it. Anyone offering you a certificate is describing something that does not exist. What we can do is build the system an auditor will accept, and tell you plainly when you are not ready to be audited.
If nobody has asked you for this, your AI use amounts to a vendor feature inside software you bought, and no personal data passes through it, ISO/IEC 42001 is probably not your next spend. A short scoping conversation establishes that, and we will say so rather than start a programme.
How the engagement runs
- 01
Diagnose
Two weeks inside your operation. We map how the work is actually done, where two systems disagree, and what each gap costs you in a month.
- 02
Architect
A target design tied to operating decisions: which system holds which truth, who owns it, and what has to be true before go-live.
- 03
Implement
Delivery in phases you can stop after. We train your team to run it, because a system that only we can operate is a system you do not own.
- 04
Govern
The part everyone skips. Ownership, review cadence and metrics, so the system does not quietly decay back into chaos.
Questions
What people ask before they start this work
How is an ISO/IEC 42001 engagement priced?
In stages, each with a fixed scope. The scoping workshop is small and priced on its own, because the boundary of the management system has to be settled before anything else can be estimated honestly. Gap analysis and implementation are quoted after it. What moves the number is how many AI systems are in scope, your role in the value chain, and whether ISO 27001 already exists to build on.
How long until we are audit-ready?
It depends on how much of the management system already exists. An organisation with ISO 27001, a documented development lifecycle and a real risk process is extending something. An organisation starting from an ethics statement and a set of models in production is building one. The binding constraint is usually how fast engineering and operations can absorb the changes, not how fast documents can be written.
Can Faceela certify us?
No, and no consultancy can. Certification is issued by an accredited certification body after its own independent audit, and the firm that builds a management system is barred from certifying it. We prepare you, run an internal audit, and tell you honestly whether you are ready before you pay for a certification audit. Anyone promising a certificate as part of an advisory engagement is selling something that does not exist.
We already have ISO 27001. Do we need a second management system?
No, and building one is a common mistake. ISO/IEC 42001 shares the Annex SL structure with ISO 27001, so the policy framework, risk process, internal audit and management review are extended rather than duplicated. What is genuinely new is the AI-specific material: system inventory, impact assessments, data and model provenance, human oversight points and the incident path when a model is wrong.
We only use ChatGPT and one AI feature inside a product we bought. Do we need this?
Probably not yet. If nobody in procurement is asking, no personal or regulated data passes through those tools, and no automated decision affects a customer, a full management system is not your next spend. An acceptable-use policy and a record of which tools are in use may be all that is proportionate. We will tell you that in a scoping conversation rather than start a programme you do not need.
Who owns and maintains the management system after handover?
You do. The policies, the AI system inventory, the impact assessments and the internal audit programme are yours, written against how your teams actually work so they can be maintained by named people inside the organisation. A management system that needs a consultant present to keep breathing fails its first surveillance audit, which is exactly when nobody is watching it any more.
Does this cover UAE PDPL, Saudi NDMO or the EU AI Act?
It gives you the structure those obligations are assessed against, but a standard is not a legal opinion and we do not present it as one. The inventory, impact assessments, data provenance records and oversight points are what a regulator or an enterprise client asks to see. Where a specific legal question arises, that belongs to your counsel, and the management system is what supplies them with evidence.
AI Governance (ISO/IEC 42001)
Start with a diagnosis
Tell us the symptom in one line. We will come back with what we would look at first and what it would take.
Monday to Friday, 9:00 AM – 6:00 PM (GST)
Prefer we call you?
Leave your WhatsApp number and we will reach out.
