ISO 42001 in Practice: 5 Steps to AI Compliance for SMEs
Artificial intelligence is no longer a topic of the future. Whether chatbots in customer service, automated accounting checks or AI-supported production control – small and medium-sized enterprises use AI tools every day, often without explicitly calling it "AI". What many overlook: whoever uses AI also bears responsibility for it.
This is exactly where ISO 42001 comes in. The first international standard for management systems in the field of artificial intelligence was published in December 2023 and has since become the most important reference for responsible AI use – especially among SMEs. In this article, we show how SMEs can achieve ISO 42001 certification with a clear 5-step approach.
"Whoever uses AI without having a structured framework for it acts – whether consciously or not – without governance. ISO 42001 closes this gap."
What is ISO 42001 – and why is it relevant for SMEs?
ISO 42001 defines the requirements for an Artificial Intelligence Management System (AIMS). Similar to ISO 9001 for quality management or ISO 27001 for information security, the standard creates a structured framework for the use of AI in organizations – regardless of their size or industry.
What makes the standard particularly practical is that it is intended both for companies that develop AI and for those that merely use AI. The majority of SMEs fall into the latter category. So anyone using Office Copilot, ChatGPT or AI-supported analysis tools is fundamentally already addressed.
Relevance is growing significantly due to two external drivers: First, the EU AI Act requires companies that use or operate certain AI systems to provide verifiable risk assessments and compliance documentation. ISO 42001 offers the appropriate framework for this. Second, major customers and public contracting authorities increasingly demand proof of responsible AI use – and certification according to ISO 42001 is exactly this proof.
Step 1: Inventory – How and where does your company use AI?
The first and often underestimated step is a complete inventory of all AI systems in the company. In practice, this means: which tools, platforms or automated processes do you use – and can they be classified as AI-supported?
This inventory does not only include products explicitly marketed as "AI". Algorithmic decision-making systems, chatbots, speech recognition, recommendation systems or automated quality checks also fall within the scope of ISO 42001. The goal is a complete AI map of the company – organized by areas of use, data sources and involved groups of people.
This inventory is not a one-time effort, but becomes a living document that is updated with every new AI implementation. With EUCERTA, this process is significantly accelerated through guided questionnaire workflows.
Step 2: Risk analysis – What risks does your AI use entail?
Once the AI systems have been inventoried, the risk analysis follows. ISO 42001 distinguishes between risks for the organization itself – such as data protection violations, erroneous decisions made by AI or reputational damage – and risks for external stakeholders, particularly customers and affected third parties.
The standard does not require the complete elimination of all risks, but a documented, proportionate handling of them. Specifically, this means: for each identified AI system, it is recorded which risks exist, how severe they are, and which measures for risk minimization are being or have been taken.
A frequently underestimated risk in SMEs is the so-called "Shadow AI" use: employees who use private AI accounts for business tasks without the company knowing about it. This is exactly where a significant data protection problem arises, which the risk analysis must make visible and the internal AI policy must address.
Tip: An internal AI usage policy is not an optional extra – it is a central element of ISO 42001 compliance and actively protects your company.
Step 3: Define AI governance – your internal policies
Based on the risk analysis, internal policies for AI use are developed. These form the heart of the AI Management System and typically encompass three areas.
The first area is the AI usage policy: it defines which AI tools are permitted within the company, how sensitive data is handled, and which processes require human review.
The second area concerns transparency toward customers and partners: ISO 42001 promotes clear communication when AI plays a role in processes or decisions. The third area is the assignment of responsibilities: the AIMS must clearly designate who in the company is responsible for AI governance – even if that is the same person who holds three other roles in a 10-person company.
These policies don't need to be perfect – they need to exist, be documented, and be lived. The standard evaluates structure and consistency, not perfection.
Step 4: Implementation and Documentation – Building the Management System
With clear policies in place, the actual implementation phase begins. The AI Management System is integrated into the existing company structures and anchored in daily practice. Concretely, this means: employees are trained, processes are adapted, and documentation is built up.
ISO 42001 is designed as a High-Level-Structure standard, meaning it harmonizes strongly with other ISO management standards. Companies already certified according to ISO 9001 or ISO 27001 can directly reuse many structures and documentation processes. The additional effort is significantly lower in these cases than an initial implementation.
In addition to the policies, the documentation also includes records of internal reviews, evidence of training measures, and the results of regular management reviews. With AI-powered platforms like EUCERTA, this documentation effort can be dramatically reduced – many documents are automatically generated based on guided input.
Step 5: Certification – The Audit Process
Once the AIMS is implemented and documented, the external audit by an accredited certification body follows. The process resembles other ISO audits: one or more external auditors examine documentation, processes, and the practical implementation within the company.
Typically, a Stage 1 audit takes place first, during which the documentation is reviewed, followed by a Stage 2 audit, in which the actual implementation is examined. Upon successful evaluation, the certificate is issued – valid for three years, with annual surveillance audits.
With EUCERTA, this process runs considerably faster: through structured preparation on the platform, companies are typically audit-ready within 48 hours. The certificate issued by EUCERTA is tamper-proof, registered on a blockchain, and digitally verifiable by customers and partners at any time.
Conclusion: ISO 42001 is achievable – even for small companies
At first glance, ISO 42001 sounds like a topic for large corporations. On closer inspection, however, it becomes clear: the standard is designed to be practical, scales to any company size, and addresses real risks that small businesses take on daily – often without knowing it.
The five steps – inventory, risk analysis, governance definition, implementation, and certification – are clearly structured and, with the right tools, achievable in significantly less time than many assume. Those who start today will not only be compliant tomorrow – but will also have a real competitive advantage over competitors who continue to operate AI without a framework.
EUCERTA guides SMEs through all five steps – AI-powered, transparent, and to certification within 48 hours. Start now at app.eucerta.com
Further Resources
→ ISO 42001: The New Standard for AI Management Systems
→ EU AI Act 2025: What Implementation Means for European SMEs
→ Start the free certification check: app.eucerta.com/onboarding

