// Research / Trust, PII & Safety
ISO 42001 implementation that survives the surveillance audit.
ISO/IEC 42001:2023 is the AI management system standard buyers are asking for. We run the gap assessment, implement controls, and wire evidence collection into your pipeline so the AIMS survives year-two surveillance.
// What we see
Year one passes. Year two surveillance is where the AIMS breaks.
01
The policies live in SharePoint, the system lives in CI/CD
The audit passes because the documents exist. Six months later engineering has shipped 40 model versions the AIMS never tracked - the surveillance audit files the nonconformity and the program restarts.
02
Annex A controls written for an ISMS, not an AI system
Most consultants port ISO 27001 control language across and call it AIMS. The auditor opens a model card, asks where the impact assessment was triggered, and the evidence doesn't connect.
03
Evidence is collected the night before the auditor arrives
Risk decisions, model cards, eval results - manually compiled, retroactively dated. It survives a casual review. It doesn't survive a competent auditor pulling on a thread for ten minutes.
// Case Study
We trained EasyDocs' invoice extraction model
EasyDocs is the platform provider - they ship document management software to their own customers. We trained the fine-tuned NLP model that runs inside it, auto-extracting VAT numbers, totals, and addresses from invoices and learning from every user correction. Deployed on their servers, no external dependencies.
98%
field-level extraction accuracy
<300ms
inference time per invoice
On-prem
deployment with no external dependencies

// What we do
Three things that decide whether the AIMS holds up.
Most ISO 42001 work fails at year-two surveillance, not year-one audit. We build for the system that operates after we leave - controls in the pipeline, evidence collected automatically, management review tied to engineering reality.
Annex A controls in the pipeline
Controls live where the work happens, wired into the engineering loop.
- A.6.2 impact assessments triggered by deploy events
- A.7 data quality checks in ingestion
- A.8 lifecycle controls in CI/CD, A.9 reporting wired in
Evidence automation, not folders
The auditor walks in, you click through dashboards mapped to Annex A control IDs.
- Model cards and datasheets generated at training time
- Eval results linked to versions and deploy gates
- Hash-chained audit logs of risk decisions
Crosswalk to AI Act and ISO 27001
Mapped once so you don't pay twice - one evidence layer feeds all three audits.
- Covers ~70% of EU AI Act technical documentation
- Inherits most ISO 27001 information-security controls
- One management review for all three cycles
// Method fit
ISO 42001 isn't the right framework for every AI program.
skip it if
Your AI portfolio is two prompts and a vector store
One customer-facing chatbot and a RAG over your docs? A documented risk policy plus your existing ISO 27001 controls covers the surface.
Your driver is the EU AI Act, not a buyer requirement
If procurement isn't asking yet and only the AI Act is load-bearing, run that program directly - ISO 42001 is a longer path.
EU AI Act & GDPR ComplianceYou need the certificate this quarter
Realistic timeline to Stage-2 audit is 6-12 months. If a buyer wants it in 90 days, scope narrowly and document current state.
use it if
ISO 42001 fits when your AI portfolio justifies a management system, buyers or regulators are asking, you have ISO 27001 or run it in parallel, and surveillance audits matter.
// How we work
Gap assessment first. Build in the open. Hand off the evidence dashboards.
Every ISO 42001 engagement starts with a gap assessment that names which controls are real and which are theatre. From there we build inside your engineering systems - not in a parallel SharePoint tree.
01
Gap assessment and scope (week one)
Current state mapped against clauses 4-10 and Annex A: a defensible scope statement, a gap matrix with effort estimates, and a roadmap your CISO signs off.
02
Implement controls in your systems
Annex A controls go into your model registry, CI/CD, and eval pipeline. Evidence dashboards pull from sources your engineers already use. Policies are drafted to match what the systems do.
03
Hand off the management review cadence
Evidence dashboards, management review pack, internal audit program, and the AI Act / ISO 27001 crosswalk - plus Stage-1 and Stage-2 mock audit rehearsals. Slack for 30 days.
// Expert insight
“Most ISO 42001 work is consulting theatre - a SharePoint folder of policies that the engineering team has never read. The AIMS that survives surveillance year two is the one where Annex A controls are wired into the deploy pipeline, and evidence is generated as the work happens. We build the second one.”
Michał Pogoda-Rosikoń
Co-founder @ bards.ai
// Why bards.ai
1B+ tokens/day in production - we know what audit evidence looks like.
Most ISO 42001 consulting is run by lawyers and auditors without engineering depth. The AIMS that holds up needs engineers to implement the controls. We do both sides.
AI engineering credibility, not pure compliance
We've shipped 1B+ tokens/day in production and 16+ open-source models. Annex A controls land in model registries, deploy gates, and eval pipelines.
Crosswalk built in
ISO 42001 covers ~70% of EU AI Act technical documentation - we map to the AI Act and ISO 27001 in one engagement.
Evidence produced from real pipelines
Everyone on your engagement has shipped AI to production and wired evidence collection into CI/CD - model cards, deploy gates, control IDs.
// FAQ
Common questions about ISO 42001 implementation
No. Certificates are issued by accredited certification bodies (BSI, DNV, TÜV, DEKRA, Bureau Veritas, and others). We're not a certification body and we don't audit. We do the implementation work that gets you ready, and we stand by you through the audit. We can recommend CBs we've worked with and rate their AI-domain familiarity.
From gap assessment to Stage-2 audit readiness typically runs 6-12 months end-to-end, with our engineering work concentrated in 8-12 weeks of structured delivery. The variability is mostly your scope and current maturity. Lean engagements with one product land closer to 6 months. Multi-product enterprise scopes with legacy systems take 9-12.
ISO 42001 isn't a substitute for AI Act conformity, but it covers most of the management-system and technical-documentation requirements that high-risk systems need. We build the AIMS so it produces the artifacts the AI Act expects (risk management documentation, post-market monitoring, transparency information) without duplication. Crosswalk matrix included.
Not strictly required, but ISO 27001 covers the information security baseline that ISO 42001 builds on. If you're already certified, we plug the AIMS into the existing ISMS. If not, we either run them in parallel or scope ISO 42001 narrowly enough that the security overlap is handled in-context.
// Related services
Adjacent problems we solve
- Learn more
Trust, PII & Safety
PII Redaction & LLM Data Privacy
Neural PII detection in 20+ languages with reversible tokenization and audit logs - the LLM never sees what it doesn't need.
- Learn more
Trust, PII & Safety
LLM Guardrails & Safety
We measure where Llama Guard drops on your fine-tune, train custom classifier heads that answer in under 10ms, and red-team both chat and agent surfaces.
- Learn more
Trust, PII & Safety
On-Prem & Air-Gapped LLM Deployment
Signed install bundles, an offline model registry, and FIPS-validated crypto - deployment finishes the same day the network is sealed.
// Let's ship it
A defensible scope statement, then the roadmap.
Send your AI scope, ISO posture, and which buyers are asking - you'll get a defensible scope statement and a roadmap to audit readiness within a business day.
- Engagements from
- $40K
- Typical range
- $40K-$120K
- Duration
- 4-8 weeks
Fixed-fee proposal after the first scoping call. Scope drivers: scope, current maturity, greenfield evidence layer. CB audit fees are separate..
Michał Pogoda-Rosikoń
Co-founder @ bards.ai