ISO 42001

ISO 42001 in Practice: 5 Steps to AI Compliance for SMEs

Anyone who uses AI without having a structured framework for it is acting – whether consciously or not – without governance. ISO 42001 closes this gap.

Marco Rossi
Marco Rossi
Compliance Operations Director
April 3, 2026
3 min read
5 Schritte zur KI-Compliance für KMU

ISO 42001 in Practice: 5 Steps to AI Compliance for SMEs

Artificial intelligence is no longer a future topic. Whether chatbots in customer service, automated accounting audits, or AI-supported production control –small and medium-sized enterprises use AI tools daily today, often without explicitly calling it "AI"What many overlook: Those who use AI also bear responsibility for it.

Exactly here is whereISO 42001The first international standard for management systems in the field of Artificial Intelligence was published in December 2023 and has since become the most important reference for responsible AI use – especially in the mid-market sector. In this article, we show how SMEs can take the path to ISO-42001 certification with a clear 5-step approach.

"Anyone who uses AI without having a structured framework for it is acting – whether consciously or not – without governance. ISO 42001 closes this gap."

What is ISO 42001 – and why is it relevant for SMEs?

ISO 42001 defines the requirements for an Artificial Intelligence Management System (AIMS)Similar to ISO 9001 for quality management or ISO 27001 for information security, the standard creates a structured framework for the use of AI in organizations – regardless of their size or industry.

What makes the standard particularly practical: It is intended both for companies that develop AI and for those that merely use AI. The latter applies to the majority of SMEs. So anyone who uses Office Copilot, ChatGPT or AI-supported analysis tools is fundamentally already addressed.

The relevance is growing significantly due to two external drivers: First, the EU AI Act requires companies that deploy or operate certain AI systems to provide demonstrable risk assessments and compliance documentation.ISO 42001 provides the appropriate framework for this. Secondly, major customers and public contractors are increasingly demanding evidence of responsible AI usage– and the ISO 42001 certification is precisely this proof.

Step 1: Inventory – How and where does your company use AI?

The first and often underestimated step is a complete inventory of all AI systems in the company. In practice, this means: Which tools, platforms or automated processes do you use – and can be classified as AI-supported?

This inventory includes not only products explicitly marketed as "AI". Algorithmic decision systems, chatbots, speech recognition, recommendation systems or automated quality checks also fall under the scope of ISO 42001.The goal is a complete AI landscape of the company – structured by areas of application, data sources and involved personnel groupsI don't see any German text to translate. Could you please provide the German content you'd like me to translate to English?

This inventory is not a one-time effort, but becomes a living document that is updated with every new AI implementation. With EUCERTA, this process is significantly accelerated through guided questionnaire workflows.

Step 2: Risk Analysis – What risks does your AI implementation bring with it?

Once the AI systems are inventoried, the risk analysis follows. ISO 42001 distinguishes between risks for the organization itself – such as data protection violations, erroneous decisions by AI or reputational damage – and risks for external stakeholders, particularly customers and affected third parties.

The standard does not require complete elimination of all risks, but rather a documented, proportionate approach to managing them. Specifically, this means: For each identified AI system, it is documented what risks exist, how severe they are, and what measures are being taken or have been taken to minimize risks.

A frequently underestimated risk in SMEs is the so-called "Shadow AI-Usage: Employees who use private AI accounts for business tasks without the company's knowledge. This is precisely where a significant data protection problem arises, which the risk analysis must make visible and the internal AI policy must address.

Tip: An internal AI usage policy is not an optional extra – it is a central element of ISO-42001 compliance and actively protects your company.

Step 3: Define AI Governance – Your Internal Guidelines

Based on the risk analysis, internal guidelines for AI deployment are developed. These form the core of the AI Management System and typically encompass three areas.

The first area is the AI usage policy: It defines which AI tools are permitted in the company, how sensitive data is handled, and which processes require human review.

The second area concerns transparency towards customers and partners: ISO 42001 promotes clear communication about when AI plays a role in processes or decisions. The third area is the assignment of responsibilities: The AIMS must clearly identify,who in the company is responsible for AI governance– even if in a 10-person company this is the same person who holds three other roles.

These guidelines do not need to be perfect – they need to exist, be documented and be lived. The standard evaluates structure and consistency, not perfection.

Step 4: Implementation and Documentation – Building the Management System

With clear guidelines, the actual implementation phase begins. The AI Management System is integrated into existing company structures and anchored in daily practice. This means specifically: Employees are trained, processes are adapted, and documentation is built up.

ISO 42001 is designed as a High Level Structure standard, which means it harmonizes strongly with other ISO management standards. Companies that are already certified to ISO 9001 or ISO 27001 can directly reuse many structures and documentation processes. The additional effort is considerably lower in these cases than a first-time implementation.

The documentation includes in addition to theguidelines as well as protocols of internal reviews, evidence of training measures and the results of regular management reviewsWith AI-supported platforms likeEUCERTAthis documentation effort can be dramatically reduced – many documents are automatically generated based on guided inputs.

Step 5: Certification – The Audit Process

Once the AIMS is implemented and documented, the external audit follows by an accredited certification body. The process is similar to other ISO audits: One or more external auditors review documentation, processes and the practical implementation in operations.

Typically, a Stage-1 audit takes place first, during which the documentation is reviewed, followed by a Stage-2 audit, in which the actual implementation is verified. Upon successful assessment, the certificate is issued – with a validity of three years and annual surveillance audits.

With EUCERTA, this process runs significantly faster: Through structured preparation on the platform, companies are typically audit-ready within 48 hours. The certificate that EUCERTA issues is tamper-proof, registered on a blockchain, and digitally verifiable by customers and partners at any time.

Conclusion: ISO 42001 is achievable – even for small companies

ISO 42001 may sound like a large enterprise topic at first glance. Upon closer examination, it becomes clear: The standard is designed to be practical, scales to any company size and addresses real risks that small businesses face daily – often without knowing it.

The five steps – inventory assessment, risk analysis, governance definition, implementation and certification – are clearly structured and can be implemented with the right tools in significantly less time than many assume. Those who start today will not only be compliant tomorrow – but will also have a real competitive advantage over competitors who continue to operate AI without a framework.

EUCERTA guides SMEs through all five steps – AI-supported, transparent and within 48 hours to certification. Start now at app.eucerta.com

Additional Resources

ISO 42001: The New Standard for AI Management Systems

EU AI Act 2025: What the Implementation Means for European SMEs

I don't see any German text to translate in your message. You've only provided an arrow symbol "→". Please provide the German text that you'd like me to translate to English, and I'll translate it while keeping technical terms, brand names, numbers, and formatting unchanged.Start free certification check: app.eucerta.com/onboarding

#
Share:

About the Author

Marco Rossi
Marco Rossi
Compliance Operations Director

Compliance Operations Director mit 18 Jahren Erfahrung in EU-Regulierungsstrategie.

Related Articles

ISO 42001

Two regulations are hitting SMEs at the same time – and many small and medium-sized businesses still don't know how to deal with them. On one side, the EU AI Act, which has been coming into force in stages since summer 2025 and requires companies that use or operate certain AI systems to conduct documented risk assessments and meet transparency obligations. On the other side, ISO 42001, the international standard for AI management systems, which establishes a structured governance framework for a company's entire use of AI. Those who treat these two requirements as separate projects are wasting resources. Those who approach them as a dual strategy stand to gain twice over.

May 28, 2026
ISO 42001

The world's first standard for responsible AI development and use. What companies need to know now.

Jan 5, 2024