Blog

AI Governance: The Anchor

What ISO/IEC 42001 certification actually means for a small business.

When we announced the PECB partnership, we said we would come back with what it means in practice. Below you will find what ISO/IEC 42001 certification actually means for a small business.

Certification is voluntary. But the obligations under the EU AI Act are not, and the two overlap considerably. An organisation that builds a management system now is doing most of the work required for compliance anyway.

When a client, a tender, or an auditor asks for proof that you're using AI responsibly, you don't have time to figure out standards from scratch. You need a clear path to certification — and you need to get there without unnecessary detours.

Who's already doing this?

The list of certified organizations is still relatively small — around 350 worldwide as of spring 2026 — but it includes some notable pioneers:

  • KPMG Australia – among first organizations globally to certify, audited by BSI
  • Boston Consulting Group (BCG) – among the first 100 certified
  • AWS – major cloud provider to announce certification
  • IBM (Granite models) – major open-source AI developer to certify
  • CrowdStrike, Vanta, Meltwater, and Mimecast – all certified as of early 2026
  • Centerprise International – among first UK companies certified
  • NUWAVE – among US-based companies certified
  • Almawave – among the first European AI producers certified, by DNV
  • K&L Gates – among the first law firms globally to earn it
  • Hanwha Life – among insurance companies certified
  • AROBS Transilvania Software – among first Romanian companies certified
  • Iberdrola España – energy company in Spain certified
  • Siili Solutions – listed Finnish company certified
  • 3E – major product compliance software company certified
  • HCLTech – certified in July 2026

Being certified today puts you in the earliest cohort of adopters. As the certified population grows from hundreds to thousands, it will shift from differentiator to expectation — the same path ISO 27001 followed.

That's exactly why we became an Official PECB Partner. Through this partnership, we organize and deliver accredited ISO/IEC 42001 courses in Romania and the CEE region. But more importantly, it allows us to offer something that goes beyond a generic training session: a structured way for your team to understand, implement, and audit AI management systems — tailored to how your organization actually works.

Each course covers specific levels, and here are the targeted groups:

Foundation – 2 days

This is for people who need to understand the standard without having to implement it. Think of it as building the essential vocabulary and framework. After two days, your team will know what ISO/IEC 42001 requires, why it matters, and how it fits into your existing processes. It's the right starting point for decision-makers, project managers, or anyone who needs to speak the same language as auditors and compliance officers.

Lead Implementer – 5 days

This one is for the people who will actually build the system inside your organization. Over five days, we cover not just the theory, but the practical steps of designing, documenting, and rolling out a management system that meets the standard. By the end, your team will have the tools to turn requirements into processes — and processes into something that can be audited and certified.

If you need to be certified, this is the course that makes it happen.

Lead Auditor – 5 days

This is for those who will audit AI management systems — whether internally or as external auditors. It's a five-day deep dive into how to assess compliance, identify gaps, and conduct thorough audits. This course gives your team the ability to evaluate your own systems with the same rigor an external auditor would apply. That alone can save you time, money, and unpleasant surprises.

In-house sessions – tailored to your organization

We also deliver courses on-site, for a single organization, using examples from your actual work. This is the most practical option: instead of generic case studies, we work with your real processes, your real risks, and your real questions. It's not just training — it's building competence that stays in your company.

The GDPR parallel

The relationship between ISO/IEC 42001 and the EU AI Act is almost identical to the relationship between ISO 27001 and GDPR:

  • The AI Act is the law that contains legal obligations on providers and deployers of AI systems.
  • ISO/IEC 42001 is a certifiable management system — the first international standard specifically for AI management.
  • Being ISO 42001 certified does not automatically make you AI Act compliant. No regulator requires it as a legal obligation.

But here's the key: ISO/IEC 42001 is used as a foundation for AI Act compliance. Organizations that implement it are building the governance backbone the AI Act expects. When procurement teams started writing "AI-specific certification" into their RFPs in late 2024, nobody had one. Now, in regulated industries and European procurement, "are you 42001 certified or on the path" is becoming a standard question.

The anchor

AI is evolving faster than we can predict its medium- and long-term effects. Real control requires structure built from the start, because the cost of fixing a chaotic AI system after it's already embedded in your operations is exponential.

Think of ISO/IEC 42001 as an anchor that will not keep your ship from sailing, but from capsizing when the waves get high. It gives you protocols to inventory your models, assess impact, and integrate new capabilities safely. It turns an uncontrollable force into a manageable process.

The organizations that will navigate this smoothly are the ones that invest in understanding now to avoid panic later.

See the PECB courses we deliver →

← Back to Blog