- AI Governance & Control
- ISO/IEC 42001
ISO/IEC 42001 Consulting Services
Crescent AI builds the AI inventory, risk assessment, lifecycle controls, and audit evidence structured toward ISO/IEC 42001's certification requirements — the way a certifying body's audit actually checks for them, not a policy mapped to a checklist. Certification itself is issued by an accredited certifying body; we build the readiness and evidence behind it.
Evidence Structured the Way an Auditor Actually Checks
A policy mapped to ISO/IEC 42001's clauses isn't the same as evidence an auditor can verify. We build the inventory, risk assessment, and lifecycle controls the standard requires, then collect the evidence in the form a certification audit actually checks against.
What is ISO/IEC 42001?
ISO/IEC 42001 is the certifiable international standard for an AI management system (AIMS): policy, risk assessment, lifecycle controls, and audit evidence, structured the way a certification body's audit actually checks for them, not just a policy mapped to a checklist.
A standard-specific slice of a broader control system.
ISO/IEC 42001 work is the standard-specific slice: building the inventory, risk classification, and evidence structured for that certification's exact control set. AI Governance & Control is the broader technical control system this standard-specific work draws on, the same inventory, risk scoring, and approval workflows, also mapped to frameworks like NIST AI RMF, not rebuilt from scratch for each standard.
Recognize the symptoms
When You Need ISO/IEC 42001 Work
If two or more of these are already true, a gap assessment is the right next step.
- An enterprise customer's procurement team is asking for ISO 42001 evidence you don't have
- You don't know whether you're a quarter away from certification or a year away
- There's no current AI inventory, so a gap assessment can't even start
- Risk assessment exists as a document, not evidence an auditor can actually verify
What We Build Toward Certification
Five parts, engineered as one system, mapped to what an audit against ISO/IEC 42001 actually checks.
AI Inventory & System Registration
One place that tracks every AI system, agent, and model in scope, who owns it, and how risky it is, structured the way the standard's AIMS scope requires.
Risk Assessment Methodology
A repeatable way to score risk across the systems in scope, documented as a method, not a one-off spreadsheet a single person understands.
Lifecycle Controls
One consistent process for changing any in-scope AI system, propose, test, roll out, review, roll back, tracked the same way every time.
Audit Evidence Collection
Tamper-proof logs and records tied to each control, so an auditor can trace a claim back to the evidence behind it, not just a policy statement.
Gap Assessment & Readiness Scoring
An honest read on what's already in place against the standard's control set, and a realistic estimate of how far out certification actually is.
ISO 42001 Work We've Delivered
Organized around the real engagement shape, not a generic compliance checklist.
Pre-Audit Gap Assessments
A structured review of what's already documented and enforced against ISO/IEC 42001's control set, before a certifying body ever looks at it.
AI Inventory & Risk Register Build-Outs
Turning an incomplete or informal list of AI systems into a live, scoped inventory with a risk score attached to each one.
Lifecycle Control Documentation
Writing and wiring in the change-management process the standard expects, so it's followed automatically, not remembered by one engineer.
Evidence Packages for Certification Audits
Compiling logs, approvals, and control records into the format an accredited certifying body's audit actually checks against.
What You Receive
Common questions.
Straight answers to the questions we actually get asked before someone commits budget.
Related Engineering Services
Bring us the audit you're not ready for yet.
Whether you need a gap assessment scored against the standard, or a full inventory, risk register, and evidence package built out, we'll walk through where you actually stand before we recommend anything.
No hype · No forced roadmap · Just a clear view of what the evidence needs next