ISO/IEC 42001:2023 sets requirements for an artificial intelligence management system. The standard covers how the organisation governs the development, procurement, use, management and decommissioning of AI systems. It is about accountability and control across the whole life cycle, not about assessing an individual model technically.
The need arrives quickly. AI is adopted in many parts of the organisation at once, often without anyone having an overview of which systems exist, what data they use, who owns them or what happens when they get things wrong. At the same time, customers, owners and authorities ask questions that require documented answers.
Berigo helps establish governance that makes the use of AI defensible and verifiable, and that can grow as adoption grows.
Who this is for
- Organisations developing their own AI systems or AI features within their products.
- Organisations procuring and using AI from suppliers, including features that arrive inside existing systems.
- Organisations where AI agents have been given access to business systems and data.
- Organisations meeting responsible AI requirements in tenders, customer agreements or owner dialogue.
- Organisations preparing for the EU AI Act that need structure for the work.
What Berigo can deliver
- A governance model for AI, with roles, responsibilities and decision-making authority.
- An inventory of AI systems and use cases, with an owner and purpose for each.
- An AI policy and objectives for responsible use, anchored with leadership.
- Risk assessments of AI systems, and assessment of impact on people and the organisation.
- Requirements for data and data quality across the life cycle.
- Transparency towards users and affected parties, and documentation of system purpose and limitations.
- Human oversight, with clear points for intervention and override.
- Competence building for developers, system owners and decision-makers.
- Supplier management for AI services, including contractual requirements.
- Life cycle management from idea to decommissioning, with monitoring in operation.
- Handling of AI-related incidents and nonconformities.
- Measurement, reporting, internal audit and management review.
- Preparation for the certification audit, and support through it.
The relationship to the EU AI Act
A management system under ISO/IEC 42001 provides structure that supports the organisation's work on responsible AI, and much of what it takes to govern AI properly is shared with the regulation's expectations around governance, documentation and risk management. Certification to ISO/IEC 42001 does not, however, automatically document full compliance with the AI Act. The regulation has its own requirements that depend on role, risk classification and use case, and those must be assessed separately.
What you gain
- An overview of which AI systems the organisation actually has, and who owns them.
- Decisions about AI taken with known risk rather than blindly.
- Documentation that answers questions from customers, owners and authorities.
- A management system that can expand as the use of AI grows.
- A shared language between technical teams, security, legal and leadership.
TrustAlign in the work
TrustAlign is Berigo's own portal for governance, risk, compliance and audit support. It is used as the working surface through implementation and onwards into operation, so that requirements, work and evidence sit together instead of being scattered across spreadsheets and shared folders.
- Frameworks and requirements, with compliance status per framework.
- Risk register with risk assessment and follow-up of treatment.
- Control register with status, owners and deadlines.
- Statement of Applicability, with justification per control.
- Policies and governance documents.
- Audit programme, audit plans and the running of audits.
- Findings classified as nonconformity, observation or opportunity for improvement, with root cause, corrective action and verified closure.
- Incidents, vulnerabilities, assets and suppliers.
- Evidence and documentation attached to what it belongs to.
- Management review built on the audit programme.
- Reports and exports of risks, controls, findings, incidents, policies, suppliers and vulnerabilities.
- Norwegian and English interface, a separate organisation per client, roles for administrator, manager and viewer, two-factor sign-in and an audit log.
TrustAlign additionally has a dedicated area for AI systems, and framework support for both ISO/IEC 42001 and the EU AI Act.
TrustAlign can be used as a standalone portal, and can by agreement and technical clarification be connected to relevant document and data sources. The portal by itself provides neither certification nor regulatory compliance. It structures the work that has to be done, and makes it verifiable.
Who does what
Berigo is an adviser and implementation partner. The certification audit is carried out by an independent certification body that you choose yourselves. We issue no certificates, we do not influence the auditor's judgement, and we do not guarantee a particular outcome. We prepare the organisation as well as we can, and support you through the audit and the work that follows.