ISO basic certificate: Your roadmap to certification
Valid until 5. September 2026 13:14

1. The company
Entering the basic company data on your certification platform is a key step on the way to ISO certification. This includes analysing the company environment. Previously, this was complex and meant weeks of work. That's a thing of the past! Our AI assistant has already created the necessary basics for you.
|
Our AI Policy | Documentation created |
|
These topics (internal and external) are relevant to our AI management system | Documentation created |
|
These individuals and groups are affected by our AI management system | Documentation created |
|
Statement of applicability for ISO 42001 | Documentation created |
|
Management principles for the use of AI | Documentation created |
|
The scope of our AI management system | Documentation created |

2. Goals
Entering and editing your goals is an important step in setting your direction and documenting your progress. This is also very simple, as the goals you have given us in the questionnaire have already been created.
|
Our goal: To ensure a high level of transparency in our AI use cases | Documentation created |
|
Our goal: To understand and mitigate risks in our AI use cases | Documentation created |
|
Our goal: To build our customers' and partners' confidence in the use of AI | Documentation created |
|
Our goal: to develop AI systems that can be used in a transparent and accountable manner | Documentation created |

3. Processes
While you were filling out the questionnaire, we already created your process landscape. The processes and procedures are assigned to the different areas of your company. Now it's just a matter of putting the finishing touches to them: Further elaborate your processes and customise them to suit your company.
|
Our purchasing and procurement process | Documentation created |
|
How We Handle Concerns Related to the Use of AI | Documentation created |
|
Our approach to assessing the impact of AI implementation | Documentation created |
|
Our Process for the Responsible Development of AI Systems | Documentation created |
|
Data Management Process for the Development of AI Systems | Documentation created |

4. Documents
Work instructions and guidelines are a central component of your management system. We have already created the most important documents for you based on your specifications. Now it's time to adapt them to your specific requirements with the help of our AI.
|
Guideline for changes in our management system | Documentation created |
|
AI use case: Use of AI systems for text creation and documentation (emails, reports, proposals, minutes) | Documentation created |
|
AI use case: Use of AI systems for text creation and documentation (emails, reports, proposals, minutes) | Documentation created |
|
AI use case: Using AI systems to build an AI management system | Documentation created |
|
AI use case: Use of AI systems in our knowledge management | Documentation created |
|
AI use case: Use of AI systems for data analysis and reporting | Documentation created |
|
AI use case: Use of AI systems to support marketing and sales | Documentation created |
|
AI use case: Use of AI systems for information research | Documentation created |
|
AI use case: Use of AI systems to automate business processes | Documentation created |
|
AI use case: Development of proprietary AI models and systems | Documentation created |
|
Job Description: AI System Manager (Development of In-House AI Systems) | Documentation created |
|
Job Description: AI Coordinator | Documentation created |
|
The Role of Department Heads in Relation to AI | Documentation created |
|
Disclosure requirements regarding adverse effects and incidents, as well as toward stakeholders | Documentation created |
|
Documentation requirement: Source of data for my our systems | Documentation created |

5. Risks and opportunities
We have already created a list of risks in your certification tool. These are based on the information you provided in the questionnaire and the information on your activities. You can now edit and customise these risks and opportunities.
|
Incorrect or flawed decisions made by AI | Documentation created |
|
Data Protection and Information Security Risks | Documentation created |
|
Loss of control due to a lack of transparency in the use of AI | Documentation created |

6. Valuations
The ISO standards require an initial audit and an initial management review to be carried out as the basis for certification. We have already prepared and created both documents for you so that you are already optimally prepared for certification.

Valuations / Internal audit
As part of the implementation of our AI Management System, we conducted a system audit to verify conformity with the requirements of ISO 42001. To do so, we systematically reviewed each requirement of the standard and compared it with its implementation within our organization. The audit was based on the methods described below.
- Documentation Reviewed: We verified that the required AI Management System documentation was complete and that relevant AI use cases, risks, objectives, and controls had been adequately documented.
- Comprehensive Analysis: We carried out a thorough evaluation of the documented policies, processes, and measures for the responsible use of AI, as well as their practical implementation within our organization.
- Interviews Conducted: We interviewed relevant individuals to gain insight into the actual use of AI systems, the awareness of associated risks, and the effectiveness of the established controls and requirements.
- Effectiveness Review: We assessed whether the defined measures for governing and monitoring AI applications had been effectively implemented and whether the intended objectives were being achieved.
The results of this comprehensive review are documented in this audit report, which identifies both the strengths and the opportunities for improvement within our AI Management System.
|
Chapter 4.1: Internal and external issues affecting the AI management system have been identified | Documentation created |
|
Chapter 4.2: Relevant interested parties and their requirements have been identified and taken into account | Documentation created |
|
Clause 4.3: The scope of the AI management system has been defined and documented | Documentation created |
|
Chapter 4.4: The AI management system has been established and documented | Documentation created |
|
Chapter 5.1: Top management actively supports the AI management system | Documentation created |
|
Chapter 5.2: Principles for the responsible use of AI have been defined | Documentation created |
|
Chapter 5.3: AI roles, responsibilities and authorities have been defined | Documentation created |
|
Chapter 6.1: AI-related risks and opportunities have been identified and assessed | Documentation created |
|
Chapter 6.2: AI objectives have been established and plans to achieve them have been defined | Documentation created |
|
Chapter 6.3: Changes to the AI management system are planned and controlled | Documentation created |
|
Chapter 7.1: Required resources for the AI management system have been provided | Documentation created |
|
Chapter 7.2: Required competencies for the use of AI are ensured | Documentation created |
|
Chapter 7.3: Awareness of the AI management system requirements is ensured | Documentation created |
|
Chapter 7.4: Internal and external communication related to the AI management system has been defined | Documentation created |
|
Chapter 7.5: Required documented information for the AI management system is available and controlled | Documentation created |
|
Chapter 8.1: Processes for the operation and control of AI applications have been defined and implemented | Documentation created |
|
Chapter 8.2: AI risk assessments are performed at planned intervals | Documentation created |
|
Chapter 8.3: AI risk treatment measures are implemented and monitored | Documentation created |
|
Chapter 8.4: AI system impact assessments are performed and documented | Documentation created |
|
Chapter 9.1: Monitoring, measurement, analysis and evaluation are established | Documentation created |
|
Chapter 9.2: Internal audits are planned and conducted | Documentation created |
|
Chapter 9.3: The AI management system is regularly reviewed by management | Documentation created |
|
Chapter 10.1: The AI management system is continually improved | Documentation created |
|
Chapter 10.2: Nonconformities are analysed and corrective actions are implemented | Documentation created |
|
Annex A.2: Principles for the responsible use of AI have been established | Documentation created |
|
Annex A.3: AI roles, responsibilities and authorities have been defined | Documentation created |
|
Annex A.4: Resources for the responsible use of AI have been provided | Documentation created |
|
Annex A.5: Impacts of AI applications are systematically assessed | Documentation created |
|
Annex A.6: AI applications are governed and monitored throughout their life cycle | Documentation created |
|
Annex A.7: Quality, origin and use of AI data are ensured | Documentation created |
|
Annex A.8: Information about the use of AI is provided transparently | Documentation created |
|
Annex A.9: AI applications are used and monitored responsibly | Documentation created |
|
Annex A.10: Requirements for AI-related supplier and customer relationships have been defined | Documentation created |

Valuations / Management report
We have conducted an initial management review. In doing so, we reviewed the requirements of Chapter 9.3 of ISO 42001 step by step and assessed each of the specified review inputs. This initial management review provides an overview of the current implementation status of our AI Management System and identifies areas where improvement is needed. The categorization explains how the conclusions were reached.
- Comprehensive Analysis: We carried out a detailed evaluation of the implementation of our AI Management System, with particular focus on identified AI-related risks, impact assessments, achievement of our AI objectives, and the effectiveness of the measures that have been established.
- Effectiveness Review: We assessed whether the actions introduced to improve the responsible use of AI have been implemented effectively and whether they have achieved the intended results.
The results of this management review document both the strengths and the identified improvement opportunities within our AI Management System. They serve as a basis for future decisions and actions aimed at the continual improvement of the safe, transparent, and responsible use of Artificial Intelligence.
|
1. Status of measures from previous management reviews | Documentation created |
|
2. Changes to internal and external aspects of the AI management system | Documentation created |
|
3. Stakeholders relevant to the AI management system | Documentation created |
|
4. Performance of our AI management system | Documentation created |
|
5. Improving our AI management system | Documentation created |

7. Declaration of principle
The ISO standards require that you, as a self-employed person or company management, commit to the principles of your management system. This also includes your employees. If you wish, you can also invite network partners or freelancers to also commit to the principles.