ISO 42001 in Plain English: What an AI Management System Actually Requires
If you run a small or mid-sized business and you've started using AI somewhere — a chatbot, an AI-assisted hiring tool, maybe a model your one developer bolted onto the product last quarter — you've probably heard the term ISO 42001 by now. Usually from a customer's procurement team, an investor during due diligence, or a vendor trying to sound credible in a pitch deck.
What almost nobody does is explain what it actually requires. And when you don't have a compliance department, that gap is a bigger deal than it sounds. Large enterprises have people whose whole job is reading standards like this. You probably don't.
So here's the plain version: what this thing is, whether you actually need it, and what it would take to get there.
What it actually is
ISO/IEC 42001 was published in December 2023. It's the first international standard for what's called an AI management system, or AIMS. If you know ISO 27001, think of the relationship this way: 27001 certifies that you manage information security properly. 42001 does the same thing for AI — how you handle its risks, its effect on the people it touches, how it behaves once it's out in the world and not just in a demo.
It applies to any organisation that builds, provides, or uses AI systems. In practice that's most SMEs now, whether or not you think of yourself as "an AI company." Turned on an AI feature inside a SaaS tool you already pay for? Added an AI screening step to hiring? Have one engineer who's wired a model into your product? This standard is talking to you, even at five people, even at twenty.
It's not a replacement for actual law. It's a structure for meeting your obligations consistently — which starts to matter the moment you're fielding questions tied to Singapore's evolving AI guidance, or a customer's own regulatory requirements that have started flowing downhill onto you as their vendor.
Why an SME would bother with this at all
Honestly, it's usually one of three things that gets a small business to actually look into this.
A customer's procurement team asks for it. This is becoming common — larger companies pushing AI governance requirements down their supply chain the same way they did with ISO 27001 a decade ago. If you sell into enterprise or government, this is coming for you whether you're ready or not.
An investor asks during due diligence. AI governance has quietly become a real line item in diligence checklists, not a footnote anymore.
Or — and this is the one I'd actually recommend — you decide to get ahead of it. Building this in while you're still small is a fraction of the cost and pain of retrofitting it under deadline pressure because a deal now depends on it.
None of these require boiling the ocean. What they require is being able to show, credibly, that you know what AI you're running and that a specific person is accountable for it. That's genuinely most of the battle.
The structure, minus the jargon
ISO 42001 follows the same clause structure as other ISO management standards, with AI-specific bits layered in. Four parts do most of the actual work, and none of them need a big team.
Context of the organisation. Before you write a single policy, you need an honest inventory — what AI is the business actually using or building, and who's affected by it. For most SMEs this is closer to a half-day exercise than a months-long audit. The real problem is usually that nobody has written any of it down in one place, not that it's hard to figure out.
Leadership. Doesn't mean hiring a Chief AI Officer. At SME scale it usually just means the founder, or whoever runs ops, formally owning the AI policy and being able to speak to it in a room. Honestly this is often more credible at a small company than a large one — there's no confusion about who's accountable when it's obviously you.
Operational controls. Writing down how AI systems get used, and running a lightweight check before a new AI tool goes live — basically asking "what could go wrong here, and who gets hurt if it does" before you flip the switch, not after. Most SMEs have never done this on paper, even the founders who'd instinctively ask the right question out loud in a meeting.
Performance evaluation and continual improvement. A recurring check-in, not a full audit function, to make sure the inventory's still accurate and nothing new has quietly crept in. AI tools get adopted fast inside small teams — someone finds a useful tool on a Tuesday and it's part of the workflow by Friday. This is what stops that from turning into risk nobody's tracking.
What this actually looks like day to day
Strip out the ISO language and it comes down to four questions you should be able to answer at any moment, off the top of your head.
What AI are we actually running, and where? What could go wrong with each of these, and who gets hurt if it does? Who's on the hook for catching that before it happens? And can we actually show a customer or investor evidence of this — not just point at a policy document nobody's read?
You don't need to be certified to get real value out of this. Plenty of SMEs start by just aligning their day-to-day practices to what the standard expects, without pursuing formal accredited certification right away. Build the habit and the paper trail first. Certify later, when a deal or a regulator actually asks for it.
Where to actually start
Resist the urge to write a forty-page AI policy before you've done anything else — that's usually wasted effort at this stage. The first useful step is almost always the same, boring thing: a plain list of what AI is actually running in the business today, and an honest answer to what happens if each one fails, leaks something it shouldn't, or makes a bad call. That exercise alone tends to surface the real gaps, long before certification or accredited auditors or any serious budget enters the conversation.
For a small team with limited hours in the week, that's also just the smarter use of time — fix the two or three things that genuinely matter before worrying about the rest of the framework.
Belian Advisory helps SMEs build AI governance that actually fits their size — practical, aligned to ISO 42001, sized to what a small team can realistically keep up. If you want a straight answer on where your business actually stands, get in touch.