The complete AI management system, written to ISO/IEC 42001, published in the UK as BS EN ISO/IEC 42001:2026. 151 pages across eleven editable files plus a nineteen-sheet Excel workbook, including the clause 8.4 impact assessment pack that separates a real AI management system from a security system with the word AI pasted over it.
ISO 42001 is where AI governance stops being a slide deck and becomes a system: who decides, on what evidence, with what oversight, and what happens when it goes wrong. The established toolkit vendors have not touched it. This one covers it in full, including the requirement they would handle worst if they tried.
The clause 5.2 AI policy, then one policy per Annex A control objective: roles and concerns, resources and inventory, impact assessment, life cycle, data, transparency, responsible use, suppliers and customers, plus human oversight and AI incidents. Each opens with what the market gets wrong about the claim it covers.
Clauses 4 to 10, including the section that matters most: why clause 8.4, the AI system impact assessment, is a main-body requirement no other ISO management system standard has, and how it differs from the risk assessment at 8.2. Cites the current UK designation, BS EN ISO/IEC 42001:2026, which superseded the 2023 designation in March 2026.
Context, the AI system inventory built to catch shadow AI, risk assessment and treatment, the impact assessment procedure, life cycle from specification to withdrawal, data and provenance, transparency, human oversight written against automation bias, AI incidents, suppliers, Statement of Applicability, change triggers, competence, documents, audit and improvement.
The heart of the standard. The method, a proportionality triage so small systems get small assessments, the full template covering individuals, groups and society, redress, reassessment triggers, and a complete worked example: an ordinary CV screening tool taken all the way through to five concrete actions. Nobody else in this market has a worked example.
The honest document. ISO 42001 is not a harmonised standard and confers no presumption of conformity, whatever a salesperson implies. An article-by-article map of what the standard gives you, what it does not, the current deadlines as amended in 2026, and the transparency obligation that is already in force and not limited to high-risk systems.
Deployment authorisation, the gate nothing goes live without. Verification and validation with performance-by-group. Dataset quality and bias. Human oversight definition and test. AI incident report with the mandatory impact-assessment-revisited field. Supplier assessment. Change record. Audit and review set.
AI system inventory, impact assessment register, risk register, the 38-slot Statement of Applicability, data and provenance, human oversight with override-rate formulas, incidents, suppliers, changes, competence, documents, findings, audit programme and management review, plus a dashboard counting the findings assessors raise most.
Every clause and objective with the question and the evidence, the ten findings we would expect against a new AI management system, and why spending most of your time on clause 8.4 is the right call.
The ninety-day order of work, what to reuse if you already hold another ISO certification, and the plain English dictionary including the pairs everyone confuses: risk versus impact, transparency versus explainability, normative versus informative.
Not a summary. The actual questions an assessor puts about that document, and what to put in front of them. You will not find this in a template bundle, because template bundles are not written by people who have sat in the assessor’s chair.
Certification does not make you legally compliant, and the two are routinely confused. The statutory duties are mapped next to the clauses so neither is being satisfied by accident.
Every document carries a phase number in its header, from appoint through to learn. If you are lost, look at the header of whatever is in front of you and you know where you are.
Where a document must be produced by a competent specialist, such as a fire risk assessment, asbestos survey, legionella or health surveillance, the toolkit says so, explains how to commission one, and tells you how to judge whether what you were handed is any good. Selling you a template for those would be worse than selling you nothing.
Organisations that develop, provide or simply use AI and need to show governance: software companies embedding models, professional services firms adopting AI tools, and anyone whose customers or board have started asking who is accountable for the AI. UK accredited certification became possible in January 2026, so early certifiers are genuinely early.
Drafted for the United Kingdom with notes for Scotland and Northern Ireland, and structured so that the management system requirements carry across unchanged to any jurisdiction. Outside the UK you would replace the legal register entries with your own obligations; everything else holds.
Fully editable Microsoft Word and Excel in one zip. Every placeholder is in [SQUARE BRACKETS] so you can see at a glance what needs your input. Every guidance box is shaded so you know what to delete before you issue the document.
You may use, edit, adapt and rebrand everything within your own organisation, on as many sites and for as many people as you employ, and give completed copies to your certification body, assessor, clients, insurer or regulator.
You may not resell, share or distribute the blank toolkit outside your organisation, or repackage it as your own product.