Getting started with ISO 42001
By Sam Rivera, Founder, SentinelPanda · June 20, 2026 · 1 min read · ISO 42001
Start where the risk is: inventory your AI, assess it, and build the management system around the systems that actually matter.
Inventory first
Like any AI governance effort, ISO 42001 starts with knowing what AI you actually operate — built, fine-tuned, and third-party. The AI system inventory is the foundation the whole management system acts on, so build it before anything else.
Assess and scope
Run an AI risk assessment over those systems, and decide the AIMS scope — which AI systems and processes it covers. A focused scope around the AI that matters keeps the effort proportionate and the certificate meaningful.
Policy and controls
Draft the AI policy (leadership's statement of responsible-AI intent), then select the Annex A controls relevant to your risk and document them in an applicability statement. You implement the controls that fit, not the whole annex blindly.
Reuse what you have
If you hold ISO 27001, the management-system machinery is shared — reuse it and add the AI-specific parts. SentinelPanda anchors the AIMS to your AI inventory and runs the risk, controls, and evidence.