Skip to content
Jess Jeetley
← All writing

2 July 2026 · 6 min read

What ISO 42001 actually asks of you

Most people meet ISO 42001 as a spreadsheet of controls handed to them by a customer's procurement team. That is the worst possible introduction to it.

Stripped of the annexes, the standard asks one question in nine different ways: can you show me how this decision was made? Which system, which data, which trade-off, which human, which date.

That is why it is achievable for a twenty-person company and painful for a two-thousand-person one. Small teams still remember their decisions. Large ones have to go and find them.

The parts that consistently take longer than teams expect: the AI system inventory, because nobody owns it; the impact assessment, because it forces you to name the people who could be harmed; and the supplier clauses, because your model provider's terms probably do not say what you assumed they said.

The parts that take less time than expected: the management system scaffolding. If you already hold ISO 27001, you have most of it.

My advice to founders chasing enterprise contracts: get certified against the scope that unblocks revenue, not against everything you might one day build. Scope discipline is the difference between a four-month programme and a fourteen-month one.

Jess Jeetley advises founders, scaleups and enterprise boards on AI strategy and AI governance. Book a session or take the ISO 42001 course.

The Governance Note

One short note, most weeks

What I am seeing in board rooms on AI strategy, assurance and ISO 42001. New subscribers get The 12 Questions Your Board Should Ask About AI — a one-page agenda you can take into your next meeting.

No spam. Unsubscribe in one click.

Keep reading