Your customers want to know how you govern AI. Security questionnaires now come with an AI section. And since July 2026, Ireland has its own enforcement structure around the EU AI Act. We help you prepare for ISO 42001 certification in Ireland by building an ISO/IEC 42001 Artificial Intelligence Management System (AIMS) that stands up to all three: scoped around the AI you actually build, buy and use, run inside your real workflows, and backed by evidence an independent certification body can test.
A lot of Europe's technology, financial services and life-sciences work is run from Ireland. So Irish teams tend to feel two pressures before most: EU AI rules arriving in stages, and enterprise buyers who want something more concrete than a responsible AI statement on a website. ISO 42001 certification in Ireland has become one of the ways teams answer both.
| Date | What happened or applies |
|---|---|
| 1 Aug 2024 | EU AI Act (Regulation (EU) 2024/1689) enters into force |
| 2 Feb 2025 | Prohibited AI practices begin to apply |
| 4 Mar 2025 | Irish Government approves a distributed model of AI Act implementation |
| 2 Aug 2025 | Obligations for general-purpose AI model providers apply |
| 16 Sep 2025 | Ireland's list of national competent authorities reaches fifteen |
| 21 Jul 2026 | Regulation of Artificial Intelligence Act 2026 signed into law, establishing the AI Office of Ireland |
| 27 Jul 2026 | Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force |
| 2 Dec 2027 | High-risk obligations apply to Annex III systems (as amended) |
| 2 Aug 2028 | High-risk obligations apply to Annex I systems (as amended) |
Dates reflect the position at our last review, shown at the foot of this page. This is general information, not legal advice.
ISO/IEC 42001:2023 won't tell you which model to use or set a fairness threshold for you. What it asks is that you run AI the way a well-governed organisation runs anything that carries risk: decide what's in scope, give each AI system an owner, assess risk and impact, put controls in place, check they work, and fix what doesn't.
That's easier to see in practice. Here's the difference an AIMS makes to situations most teams will recognise:
| Situation | Without an AIMS | With an AIMS in place |
|---|---|---|
| A team connects a generative AI tool to the CRM | Found months later, usually during a customer audit | A defined approval route for new AI use, with a risk and data review before it goes live |
| A model is retrained and results shift | Nobody can say what changed, or when | Change and monitoring records linked to that system in the AI inventory |
| A customer asks which features use AI and who oversees them | A scramble across product, engineering and legal | An inventory with a named owner and human-oversight arrangements for each in-scope system |
| A supplier changes its AI terms or model | Noticed only if someone happens to read the email | Third-party AI reviewed on a defined cycle, with responsibilities agreed |
| The board asks how AI risk is being managed | Anecdotes and a slide | AI objectives, risk treatment status and audit results reported through management review |
Legally, no. As at our last review, no Irish or EU law requires ISO/IEC 42001 certification. It's a voluntary standard.
Commercially, it can be a different story. The requirement usually arrives through a contract clause, a tender scoring criterion, a customer's vendor due diligence, an investor's checklist, or a group policy set by a parent company. When that happens, a certificate from an accredited body is often the quickest credible answer.
Even then, a gap assessment is a sensible way to find out where you stand before someone else asks.
They get mentioned in the same breath so often that it's easy to treat them as one thing. They aren't. One is a certifiable management system standard. The other is law.
| ISO/IEC 42001 | EU AI Act | |
|---|---|---|
| What it is | A voluntary international standard for an AI management system | An EU regulation that applies directly in Ireland and every other Member State |
| Who it applies to | Any organisation that develops, provides or uses AI and chooses to adopt it | Providers, deployers, importers and distributors of AI systems in scope, with obligations depending on role and risk category |
| What gets looked at | Your organisation's management system: policies, processes, controls, records | Individual AI systems and general-purpose AI models |
| Outcome | A certificate from an accredited certification body, typically on a three-year cycle with surveillance audits | Legal compliance; for high-risk systems, conformity assessment before placing on the market |
| Who checks | An independent certification body | National competent authorities (in Ireland, coordinated by the AI Office of Ireland) and, for general-purpose AI models, the European AI Office |
A lot of AI Act preparation depends on things an AIMS makes you build anyway: an inventory of AI systems, a repeatable risk process, defined roles, documented human oversight, monitoring, supplier controls and records you can find again. Having that machinery running makes classification, documentation and oversight work far less painful.
ISO 42001 certification doesn't classify your AI systems under the Act, doesn't replace conformity assessment or CE marking for high-risk systems, and doesn't make you compliant by itself. It isn't a harmonised standard under the AI Act. Providers of high-risk systems also have specific quality management system obligations under Article 17, which CEN-CENELEC has been addressing through separate European standards such as EN 18286.
If your main question is what the AI Act requires of you specifically, start with our EU AI Act compliance services. Many teams run the two pieces of work side by side so the evidence is only gathered once.
A gap assessment tells you, clause by clause, how far your current practice is from what ISO/IEC 42001 requires, and what it'll take to close the distance. It's where almost every engagement starts, and it's useful on its own even if certification is a year away.
Most of the work runs remotely through document review and short interviews with AI product owners, engineering, data, security, legal and your DPO.
A gap report is only useful if the gaps get closed in a way that survives an audit. Implementation is where most AIMS projects stall, usually because documents get written that nobody follows. We work the other way round: start with how your teams already build, buy and approve things, then put the ISO 42001 requirements into those routes.
You can have us draft most of the documentation with your input, or draft it yourselves and have us review it. Either way, the AIMS has to belong to you. The certification body will want to talk to your people, not ours.
Grouped the way ISO/IEC 42001 is structured, on the Plan-Do-Check-Act cycle. Under each item is the thing that should exist when we're done.
AIMS scope
A scope statement that names the AI systems, teams and boundaries in play.
AI system inventory
A maintained register of AI you develop, provide or use, with owners.
AI governance
An AI policy approved by top management and a clear governance structure.
AI risk management
A risk method, risk register and treatment plan specific to AI.
AI impact assessment
Assessments of effects on individuals, groups and society for in-scope systems.
Policies and procedures
The documented processes your teams actually follow.
Roles and accountability
Named owners, a RACI, and competence records.
Third-party AI governance
Supplier assessments, contract expectations and review cycles for AI you buy.
Documentation
A controlled document set, including the Statement of Applicability.
Monitoring
Defined measures for AI system performance, incidents and AIMS objectives.
Internal audit
A completed internal audit of the AIMS, with findings logged.
Management review
Minutes showing leadership has reviewed AIMS performance and made decisions.
Corrective actions
A nonconformity and corrective action log, with root causes and closures.
Continual improvement
Evidence that lessons from audits, incidents and reviews change how you work.
Seven steps with us, then a clear handover. We're open about where our role ends, because it matters: the certification audit has to be independent of the people who helped you prepare.
With VISTA Infosec
Discovery and scope
We confirm what's driving the project, which AI systems and entities are in play, and your role in relation to each.
Gap assessment
Clause and control-level review of current practice, with a prioritised plan.
AIMS design
Scope, policy, governance structure, risk and impact methods agreed with leadership.
Implementation
Procedures and controls built into your real workflows, with owners assigned.
Documentation and evidence
Statement of Applicability finalised; records building up as the AIMS operates.
Internal audit and management review
An independent internal audit, findings closed out, and a management review held.
Certification readiness
A readiness check against what the certification body will sample, and support preparing for Stage 1.
With your independent certification body
We can introduce you to an accredited partner certification body or work alongside the one you choose. We support you during the audits; we don't audit our own work, and we don't issue the certificate.
Stage 1 audit
Reviews your AIMS documentation and readiness, and confirms the audit plan.
Stage 2 audit
Tests whether the AIMS is implemented and working effectively, by sampling evidence and interviewing your people.
Certification decision
Made by the certification body. Nonconformities must be addressed first.
Surveillance audits
Usually annual, through the certificate's typical three-year cycle.
Recertification
A full reassessment before the certificate expires.
No one can honestly guarantee a certification outcome, and we won't. What we can do is make sure there are no surprises about what the auditor will ask for.
Good news, with a caveat. ISO/IEC 42001 uses the same harmonised management-system structure as ISO/IEC 27001, so a lot of your existing machinery carries straight over. But ISO 27001 certification doesn't satisfy ISO 42001, and an auditor won't accept information security controls as a stand-in for AI governance.
| Usually reusable from your ISMS | New work for the AIMS |
|---|---|
| Document control and records management | AI system inventory and AIMS scope |
| Internal audit programme and auditor pool | AI impact assessment for individuals, groups and society |
| Management review and corrective action process | AI-specific risk criteria and treatment (bias, transparency, misuse, model drift) |
| Risk methodology structure and risk register tooling | AI system lifecycle controls, from design through retirement |
| Supplier management process | Data for AI systems: quality, provenance, preparation |
| Competence, awareness and training records | Human oversight arrangements and AI-specific objectives |
Many certification bodies can run ISO 27001 and ISO 42001 audits together once both systems are mature, which can reduce duplicated effort. Worth raising with your certification body early.
We support teams across Ireland, including those based in Dublin, Cork, Galway, Limerick and Waterford, and we work just as well with a founder-led SaaS company in Limerick as with the Irish entity of a global group in Dublin. Where your people sit doesn't change the method. Building an AI management system in Ireland does mean thinking about a few local realities, though.
Workshops, interviews and evidence reviews run over video and a shared workspace. On-site sessions can be planned where the engagement needs them.
Our London team works in the same time zone as Ireland, so calls fit your working day.
If you need AIMS evidence to stay within the EU, we can process it on EU-region infrastructure.
We plan the AIMS with your sector supervisor in mind, whether that's the Central Bank of Ireland, the HPRA or the Data Protection Commission.
On certification, you choose the body. Several certification bodies offer ISO/IEC 42001 certification in Ireland, including the National Standards Authority of Ireland (NSAI). Whichever you pick, check it's accredited for ISO/IEC 42001, and we'll support you through its audits.
ISO 42001 certification services in Ireland aren't only for AI labs. These are the kinds of organisations we set up to support, and what usually starts the conversation.
Auditors sample evidence. They'll want to see that the AIMS has been operating for long enough to produce records, not just that the documents exist. Your certification body will confirm what it expects; this is the evidence set we work towards.
Want the fuller version? Our ISO 42001 readiness checklist walks through the questions to ask before you book the audit.
We're an audit-led compliance firm with more than 21 years behind us. That background shapes how we prepare you: we think about your AIMS the way an auditor will read it.
We don't publish a price list, because two ISO 42001 projects rarely look alike. What we can do is explain where the money goes, so you can budget sensibly and compare quotes fairly.
There are usually two separate costs. The first is readiness and implementation support, which is what we provide. The second is the certification audit itself, charged by your certification body for Stage 1, Stage 2 and the surveillance audits that follow. Then there's your own team's time, which is easy to forget and often the largest of the three.
| Cost factor | Why it matters |
|---|---|
| Number and type of AI systems in scope | More systems means more risk and impact assessments, and more evidence to sample |
| Your role: developer, provider or user of AI | Building and selling AI brings lifecycle and data controls that pure users may not need |
| Entities, sites and headcount in scope | Drives how many audit days a certification body calculates |
| Existing ISO 27001 or similar system | Reusable processes can shorten implementation noticeably |
| Documentation maturity | Starting from scratch takes longer than refining what exists |
| How much drafting you want us to do | Full drafting and review-only support are priced differently |
| Sector and regulatory exposure | Financial services and health technology often need deeper risk and oversight evidence |
You'll get a fixed quote after a short scoping call. If you're comparing providers, check whether each quote includes the internal audit and management review support; those are often where cheaper quotes cut corners.
ISO/IEC 42001:2023 is the international standard for an Artificial Intelligence Management System (AIMS). Published by ISO and IEC in December 2023, it sets requirements for establishing, implementing, maintaining and continually improving how an organisation governs the AI it develops, provides or uses. It's certifiable, which means an accredited certification body can audit you against it.
No. As at our last review, no Irish or EU law makes ISO/IEC 42001 certification mandatory. It can become a requirement through contracts, tenders, customer due diligence or group policy, and it can support your wider AI governance, but it's a voluntary standard.
Nobody needs it by law. It tends to make most sense for SaaS and AI product companies selling to enterprise customers, financial services and health technology firms using AI in regulated activities, and organisations whose customers or parent companies ask for independent assurance on AI governance.
It depends on scope, the number of AI systems, and whether you already run ISO 27001. A focused scope building on an existing ISMS often reaches certification readiness in roughly four to six months; a standing start or a broad multi-entity scope takes longer. The AIMS also needs to run long enough to produce records before the audit. We give you a written timeline after the gap assessment.
There are two parts: readiness and implementation support, and the certification body's audit fees. Both depend mainly on the number of AI systems in scope, your role as developer or user, headcount and sites, and how much existing management-system work you can reuse. We provide a fixed quote after scoping.
No. ISO/IEC 42001 certification doesn't by itself make you compliant with the EU AI Act, and it isn't a harmonised standard under the Act. It can give you governance structures that support AI Act work, such as an AI inventory, risk processes, human oversight and records. Your AI Act obligations depend on your role and the risk category of each system and have to be assessed separately.
Yes. Both follow the same harmonised management-system structure, so document control, internal audit, management review, corrective action and supplier processes can usually be shared. The AI-specific parts, including impact assessment, AI lifecycle controls, data for AI systems and human oversight, still have to be built. Some certification bodies can audit both together.
We agree the likely scope, review your existing documents, and hold short interviews with the people who own, build, buy and oversee AI. We then assess your practice against each clause and the relevant Annex A controls. You receive a rated gap report, a prioritised remediation plan, a draft scope statement, a first-pass AI inventory and a timeline to readiness.
An independent, accredited certification body issues it after Stage 1 and Stage 2 audits. VISTA Infosec doesn't issue ISO 42001 certificates. We prepare you and support you through the audit, and can introduce you to an accredited partner certification body. It's worth checking that any body you use is accredited for ISO/IEC 42001, whether through INAB in Ireland or another IAF member accreditation body.
Yes. Our delivery is remote-first, so we can support teams anywhere in Ireland, including Dublin, Cork, Galway, Limerick and Waterford. On-site sessions can be arranged where an engagement needs them, and our London team works in the same time zone.
VISTA InfoSec LLC,347 Fifth Ave,
Suite 1402-526, New York, NY 10016
© Copyright 2026. VISTA InfoSec. All Rights Reserved. | Disclosure Policy | Privacy Policy | Sitemap
Enquire Now
WhatsApp us