
10 Lessons from Our ISO/IEC 42001 AIMS Journey (And What You Can Learn from Us)
Key Takeaways
Starting an ISO/IEC 42001 journey early allows organisations to build AI governance, risk management, and responsible AI controls into systems before they become fully operational.
Successful ISO 42001 implementation requires organisation-wide involvement, strong documentation, internal audits, management support, vendor risk assessments, and clear evidence that AI controls are actually being implemented.
Organisations can integrate an AI Management System (AIMS) with existing frameworks such as ISO/IEC 27001, reducing duplicated processes while extending established risk management, auditing, documentation, and management review practices to cover AI-specific risks.
ISO/IEC 42001 certification should be viewed as an ongoing AI governance discipline rather than a one-time compliance achievement, with organisations continually assessing AI risks, improving controls, maintaining accountability, and building trust in how AI is developed and used.
When we started our ISO/IEC 42001:2023 journey, we knew there was a lot to figure out. AI Management Systems were still new territory for many organisations, and we had plenty of questions about what an effective AIMS would look like in practice.
For us at Youverify, the journey became much more than preparing documents for an audit. It challenged some of our assumptions, showed us where our existing processes could be stronger, and helped us build a more structured approach to governing AI across our organisation.
ISO/IEC 42001:2023 provides a framework for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System (AIMS). It helps organisations put a clear process around how they manage AI-related risks and opportunities.
We recently completed a successful ISO 42001 certification audit, and looking back, there are several things we wish we had known when we started.
Here Are The Lessons From Our ISO/IEC 42001 AIMS Journey You Can Apply
1. You Do Not Have to Wait for the AI System to Be Live
One of the first things we learned was that you do not have to wait until your AI system is fully operational before starting your AIMS journey. In fact, starting early can be an advantage.
At Youverify, we pursued our ISO/IEC 42001:2023 certification while the AI system was still in development. This meant the AIMS process could influence how we approached the system instead of becoming something we had to figure out later on.
As we worked through the requirements, we developed policies, procedures and controls while the system was still taking shape. This gave us the opportunity to think about governance, risk, security and responsible AI much earlier in the process.
The experience taught us something simple: it is easier to build governance into a project when you start thinking about it early.
What You Should Do
Do not wait until your AI system is completely built before you start thinking about governance. You can begin your AIMS journey while your AI system is still in ideation or development.
Starting early gives you more room to build governance requirements into the process instead of trying to fit them in later.
2. Integrate AIMS into Your Existing Management System
If you already run a management system like ISO/IEC 27001, don't treat ISO/IEC 42001:2023 as a completely separate project.
Both standards share a similar high-level structure, and much of the groundwork, including risk management, internal audits, document control, management reviews and corrective actions, may already exist.
You don't have to start from scratch to get AIMS in place. We already had an ISMS under ISO/IEC 27001, so instead of building a separate system for AI governance, we mapped the AIMS requirements onto what we already had.
We reused our existing risk methodology, internal audit program and management review process, and extended each one to cover AI-specific risks and controls.
That saved us from running two governance systems side by side. Less duplication, fewer conflicting processes, and one structure that actually holds together.
A Better Way You Can Approach It
Before you build AIMS as a standalone system, check what you already have in place. If you're already certified to ISO/IEC 27001 or something similar, integrating is almost always easier than duplicating.
That usually means aligning your risk framework, audit program and documentation structure instead of building new versions of each.
It's easier to maintain, and you end up with one governance framework instead of two that don't quite talk to each other.
3. Internal Audits Are One of Your Best Preparation Tools
If there is one part of the process that made a significant difference to our audit readiness, it was internal auditing.
An internal audit gives you the opportunity to test your organisation's preparedness before an external auditor does. It helps you identify gaps, challenge assumptions, and see whether people actually understand the controls they are expected to implement.
At Youverify, we conducted internal audits at departmental level using carefully prepared questions based on the AIMS requirements. This helped us identify what was working well, where more work was needed and what we might have overlooked, including whether people actually understood what the organisation had documented.
The result was valuable. We completed our Stage 1 audit with only minor areas of concern. Before Stage 2, we conducted another internal audit to make sure the issues identified had been addressed.
We then completed the overall external audit without major or minor non-conformities. The external auditor noted only a handful of observations and areas for improvement.
A Better Way to Prepare
Your first internal audit shouldn't happen right before the external assessment. Run it early enough that you actually have time to fix what it turns up.
And don't stop at whether a policy or control exists. Ask whether the people responsible for it understand it, whether they're actually following it, and whether they can prove that.
4. Responsible AI Is Not Just the Compliance Team's Job
One of the biggest lessons from our ISO 42001 journey: responsible AI isn't one department's job. The compliance team may coordinate the AIMS, but the actual work cuts across the whole organisation.
Product, engineering, legal, HR, operations and management all play a part in how AI gets developed, used and governed.
For us, departments worked alongside the compliance team throughout the certification process. They provided evidence, fixed the gaps we found, updated documents and answered questions during the audit. That made the whole process faster and less painful.
It also meant AI governance became everyone's job, not just something compliance handled alone.
What You Can Learn from This
Start communicating across departments early. Do not simply tell people that the organisation is pursuing ISO/IEC 42001:2023 certification. Help each department understand what AIMS means for them and where they fit into the process. Responsible AI works better when everyone understands their role.
5. Document What You Are Already Doing
One thing that surprised us: a lot of the AIMS requirements were already being met inside the organisation.
The problem was documentation. A process can exist in practice, but if it isn't clearly written down, consistently understood and backed by evidence, it's hard to demonstrate during an audit.
Most of the processes we needed already existed. The documentation was the weak point. Some processes hadn't been written down at all. Others existed but needed better labelling, or clearer explanations of how they applied to us.
These became areas of focus during Stage 1. Once we reviewed and updated the documentation, we were in a much stronger position for Stage 2. Having a process is one thing. Being able to prove it is another.
Start With What You Have
Before creating a large number of new documents, look at what your organisation is already doing.
You may find that many of the required processes already exist. They may simply need to be documented, structured and aligned more clearly with the AIMS requirements.
Good documentation also has value beyond certification. It helps employees and collaborators understand how things are supposed to work.
6. Management Needs to Be More Than a Sponsor
Management involvement made a real difference to our AIMS journey, and it wasn't just about approving the certification budget.
Management made the call to pursue ISO/IEC 42001:2023 certification in the first place. They funded the process, backed staff training, sat in on internal audits and management reviews, and made sure the team had what it needed during the Stage 2 audit.
That involvement cleared away the kind of practical barriers that slow these processes down.
What Leadership Should Do
Management support should go beyond saying yes to the project. Leadership should be prepared to provide resources, participate where necessary, respond to issues and help remove obstacles during implementation and the audit process.
When management is engaged, the rest of the organisation is more likely to take the process seriously.
7. Start Messy, and Improve as You Go
We didn't start our AIMS journey with perfect documentation, perfectly designed controls or complete knowledge of what the certification process would look like.
It was our first time doing this. Some of our documents were still drafts. Some controls were still being built. Other requirements only made sense once we'd researched them and worked through the process.
That didn't stop us from starting. We improved as we went. We leaned on research, internal reviews, AI tools and whatever else helped us understand the work better and improve it.
Each audit, review and gap we found gave us another chance to make the system better.
Do Not Wait for Perfect
Do not let the fear of getting everything wrong stop you from starting. Begin with what you have. Build the first version, identify what is missing, ask questions, do your research, use the resources available to you and improve it.
Your first draft does not have to be your final draft.
8. Take Risk and Vendor Assessments Seriously
As organisations lean more on external technology and AI services, understanding your own systems isn't enough. You also need to understand the risks introduced by the third parties you rely on.
We ran a risk assessment on the AI system we were developing, to catch potential risks early.
Then we assessed our third-party and AI vendors: how they handled our data, what security controls they had, and whether they met our legal, security and business requirements.
For AI vendors specifically, there were extra questions to ask: how data is handled, whether customer data is used for model training, and how AI-related risks are managed.
These assessments pushed us past the basic question of whether a vendor could provide a service. We also had to ask whether we were comfortable with how that service was being provided.
Look Beyond the Vendor
Do not treat vendor assessments as paperwork that needs to be completed and filed away. Understand how the organisations you rely on protect your data and what measures they have in place.
When AI is involved, go further. Ask the questions that matter for your use case, including how data is handled, how long it is retained and how AI-related risks such as bias and fairness are addressed.
9. Evidence Is Your Strongest Asset
One lesson that became especially clear during the audit process was the importance of evidence. Saying a control exists isn't enough. You need to be able to show that it exists and that it's actually being implemented.
We made a point of keeping an evidence trail for every AIMS requirement. That meant documented procedures, records of implementation, and, where it made sense, live demonstrations of controls actually running.
For example, where a third-party platform supported a particular control, we could pull up the relevant dashboard or configuration rather than just describing what the platform was supposed to do.
Build Evidence Into Your Work
Do not start collecting everything a few days before the audit. Build evidence into your normal operations. Keep records, maintain relevant logs, document reviews, retain supporting information and track the implementation of important controls.
When the auditor asks for evidence, you should be able to find it without scrambling to create it.
10. The Real Value Is What Happens After the Certificate
Perhaps the biggest lesson from our AIMS journey is that the certificate isn't the end of the process.
It's one outcome of the process. The real value is what you're able to do differently because of what you learned getting there.
The work we put into ISO/IEC 42001:2023 also sharpened how we run our wider information security management system. Getting ready for the AIMS assessment changed how we think about governance and documentation, and that thinking carried well beyond AI.
A management system is only as good as what it changes. It should shift how the organisation works day to day, not just how it looks during an audit.
Look Beyond the Certificate
Do not measure the success of your AIMS only by whether you received the certificate. Ask what has improved because of the process.
- Can your organisation identify AI risks earlier?
- Can it make better decisions about AI?
- Do employees understand how they should use AI?
- Can the organisation demonstrate accountability for how AI is used?
- Can customers and other stakeholders have greater confidence in how AI is governed?
Those are the questions that matter after certification.
On a Final Note
Looking back at our AIMS journey, one of the biggest things we learned is that responsible AI is an ongoing organisational discipline.
ISO/IEC 42001:2023 gives organisations a framework, but that framework only becomes meaningful when people actually use it in their day-to-day work.
We also learned that you do not need to start with everything figured out. Start by understanding your AI landscape. Identify your risks, define accountability, document what you are already doing, build practical controls, involve your people, get management involved, create evidence and keep improving.
The process is about more than achieving ISO 42001 certification. It is about building an organisation that can use AI responsibly and confidently as the technology continues to evolve.
You can learn more about how we approach responsible AI in our Responsible AI Policy.
If your organisation is looking to strengthen how it manages AI, or wants to understand how Youverify approaches AI governance in practice, explore Youverify or speak with our team.
About the Authors:
This article was a collaborative effort by members of Youverify’s Legal, Compliance and IT teams, who worked together throughout the company’s ISO/IEC 42001:2023 certification journey. Contributors: Betty Omotola, Abidat Akinleye, Bolaji Mustapha and Victor Dominic. |
Frequently Asked Questions

Youverify Announces Dimitri Kanellopoulos As its New Country Managing Director For South Africa Region

Youverify 2023 Rundown: Here’s what we Served you this Year
