What ISO 42001 Actually Requires (Before You Assume It’s Out of Reach)
ISO/IEC 42001 is the international standard for AI management systems. If you’ve been treating it as something only large enterprises with dedicated GRC platforms need to worry about, that assumption is worth revisiting. The standard is explicitly designed to be scalable, and its core requirements map directly onto the kind of proportionate, practical governance that IT managers at mid-market companies are already trying to build — even if they’re doing it informally.

The standard establishes what’s called an AI Management System, or AIMS: a structured set of policies, processes, controls, and evidence practices around how your organization develops, deploys, or uses AI. That’s it. There’s no prescribed tool stack, no minimum headcount, and no requirement to hire a dedicated AI compliance officer before you can claim alignment. What it does require is that you’ve thought systematically about what AI you’re using, what risks those tools introduce, what controls you have in place, and whether you can demonstrate any of that when a customer, auditor, or regulator asks.
For a 50–500 employee organization running AI tools without formal oversight, that framing should land differently than “we need to implement a compliance framework.” It’s closer to: we need to stop winging it.
How to Build an AI Tool Inventory That Satisfies ISO 42001 Clause 4
The foundation of an ISO 42001 AI management system is understanding your AI context — what AI systems exist in your organization, who owns them, and what they’re being used for. Clause 4 of the standard covers this through requirements around understanding the organization and its context, and identifying interested parties and their expectations.
In practice, for a mid-market IT team, this translates to one concrete artifact: an AI tool inventory, sometimes called an AI tool register or AI risk registry. Before you can assess risk or implement controls, you need a record of what AI is actually running in your environment.
This is harder than it sounds. Shadow AI — employees using unapproved AI tools outside IT’s visibility — is a real gap. A mid-market company with 150 employees might have IT-sanctioned tools like Microsoft Copilot or a CRM with embedded AI, plus a long tail of individual accounts on ChatGPT, Grammarly Business, Notion AI, and AI-assisted coding tools that nobody ever registered. Your inventory has to capture both.
A working AI tool inventory for ISO 42001 alignment should capture, at minimum: the tool name and vendor, the business function it supports, who owns it internally, what data it touches (including whether personal data or sensitive business data flows into the model), and what category of AI risk the tool represents. You don’t need a sophisticated platform to start — a structured spreadsheet with those six fields is a legitimate first step. What matters is that the register is maintained, not just built once.
If you want a head start, download the free AI tool register template to use as your working inventory.
What AI Risk Assessment Looks Like Under ISO 42001 (Without an Enterprise GRC Platform)
ISO 42001 Clause 6 requires organizations to assess AI-related risks and opportunities, and to plan how to address them. This is where a lot of mid-market teams stall, because “risk assessment” sounds like it requires a formal methodology, a risk committee, and a scoring model someone else built for you.
It doesn’t have to be that complicated. What it does require is that your AI risk assessment is structured, documented, and proportionate to the actual stakes.
For mid-market AI compliance, a proportionate approach means you’re evaluating each tool in your inventory against a consistent set of risk dimensions. Think about four areas: (1) data risk — what data enters the AI system, and what are the consequences if it’s misused, retained, or exposed; (2) output risk — how much do humans rely on AI-generated outputs without verification, and what’s the blast radius of a bad output; (3) vendor risk — how transparent is the vendor about their model, training data, subprocessors, and data handling; and (4) regulatory risk — does the tool’s use case fall into any category that EU AI Act or sector-specific regulation would treat as high-risk.
You don’t need to score every tool the same way. A marketing team’s AI copywriting tool carries different risk than an AI-assisted HR screening tool. The point is to apply consistent criteria and record your reasoning. When a customer sends you an AI security addendum or an auditor asks about your AI risk controls, “we assessed it” is not enough — you need the record of how you assessed it.
AI vendor risk deserves specific attention here. ISO 42001 Annex A includes controls related to responsible AI use in supplier relationships. For most mid-market organizations, this means reviewing vendor documentation: does the vendor publish a system card, model card, or acceptable use policy? What are their data retention practices? Do they train on your inputs by default? These questions are answerable without a GRC platform. They just require someone to ask them and write down the answers.
Controls and Policies: The ISO 42001 AIMS Clause 8 Gap Most Teams Have
Clause 8 covers operational planning and control — the part of the standard that requires you to implement and manage the processes that address your identified risks. For a mid-market ISO 42001 AI management system, this is where the rubber meets the road.
Two controls matter most for organizations at this stage. First, an AI use policy: a written document that defines what AI tools employees are authorized to use, what data classifications are off-limits for AI input, how AI-assisted work should be disclosed internally, and how employees report concerns about AI outputs. Without a use policy, every governance conversation starts from scratch because there’s nothing to point to.
Second, an AI incident log: a mechanism for capturing when something goes wrong with an AI-assisted process. This doesn’t have to be elaborate. It’s a record of the event, what tool was involved, what the impact was, and what was done about it. ISO 42001 requires that you can demonstrate your management system responds to problems, not just that it exists on paper. An incident log is the primary evidence of that.
Both of these are documentation artifacts, not software dependencies. A well-structured Word document and a shared spreadsheet satisfy the control requirement. The gap isn’t technology — it’s whether anyone has actually written the policy down and whether the log is actually being used.
Evidence Practices: What “Prove It” Looks Like for a Mid-Market AI Audit
ISO 42001 is a management system standard, which means it cares about evidence of operation, not just evidence of intention. Clause 9 covers performance evaluation, including internal audit and management review requirements.
For a mid-market team without enterprise GRC, “evidence practices” means building documentation habits now that will hold up to scrutiny later. Three things matter here.
First, keep your AI tool inventory current. A register that was accurate six months ago and hasn’t been touched since isn’t evidence of an operating AIMS — it’s a historical artifact. Assign an owner, set a quarterly review cadence, and log when tools are added or retired.
Second, document your risk assessment decisions at the time you make them. If your team evaluates a new AI tool and decides it’s low-risk, write down why. A one-paragraph rationale attached to the inventory record is sufficient. What you’re creating is an audit trail that shows the assessment happened and how you reached your conclusion.
Third, keep records of policy reviews and updates. ISO 42001 expects that your AIMS evolves as your AI use evolves. If you update your AI use policy, version it and note what changed and why. That version history is evidence that your management system is active, not static.
None of this requires a GRC platform. What it requires is discipline — and a clear owner who knows the evidence needs to exist.
What to Do This Week: A Practical Starting Point for ISO 42001 Alignment
If your organization is using AI tools without formal governance, here’s a starting point that’s achievable in a week without pulling in outside resources.
Pull together your AI tool inventory. Survey your department heads, check your SaaS billing and SSO logs, and ask your team what AI tools they’re actually using — not just the ones IT provisioned. Build the register with the six fields described above: tool name, vendor, business function, internal owner, data sensitivity, and initial risk tier. Don’t aim for perfect. Aim for complete enough to show you know what’s running.
Once the inventory exists, you have the starting point for everything else: risk assessments, use policy scope decisions, vendor review prioritization, and the evidence record your AIMS needs to function.
If you want to understand where your current practices sit against the full ISO 42001 AI management system structure, take the free RAGP maturity assessment to see your gaps across inventory, risk, policy, and evidence practices. For organizations ready to operationalize governance rather than build it manually, see AI governance pricing to find the tier that fits your team size and compliance posture.
For the full framework breakdown, including how ISO 42001 maps to EU AI Act requirements for mid-market organizations, see our ISO 42001 framework guide.