First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/AI Governance and ISO/IEC 42001 Readiness Assessment
AssessmentCompliance

AI Governance and ISO/IEC 42001 Readiness Assessment

The AI Governance and ISO/IEC 42001 Readiness Assessment is a 4-week gap assessment against ISO/IEC 42001, the international standard for AI management systems. IT Partner inventories your AI footprint — Microsoft 365 Copilot, agents, embedded and shadow AI — assesses your practices against the standard's requirements and Annex A controls, drafts the core AI governance policy set, maps Microsoft Purview, Defender, and Entra controls to the standard, and delivers a prioritized roadmap to certification readiness. Pricing starts at $7,500 and is scoped by the size of your AI footprint. IT Partner is not a certification body: the certification audit itself is performed by an accredited third party, and this engagement prepares you for it.

Timeline 4 weeksService owner Dan ApplebyMicrosoft 365 CopilotMicrosoft PurviewMicrosoft 365

What this engagement is

AI governance stopped being a theoretical exercise the moment customers started putting it in vendor questionnaires and regulators started publishing enforcement timelines. ISO/IEC 42001:2023 is the anchor most of those questions now point at: the first international management-system standard for AI, structured like ISO 27001 but aimed at how an organization governs its use and development of AI — policies, risk and impact assessment, human oversight, data governance, and lifecycle accountability, backed by an Annex A catalog of controls. Major providers, Microsoft among them, have pursued ISO/IEC 42001 certification for their AI services, and their customers are increasingly expected to show the same discipline. This engagement is the same motion as IT Partner's ISO 27001 and SOC pre-audit services, applied to the new standard: we establish what AI you actually run (including Copilot, Copilot Studio agents, AI features embedded in SaaS, and the unsanctioned tools nobody registered), assess your current practices against the standard clause by clause and control by control, draft the policy set an AI management system needs, and map the Microsoft security and compliance stack you already own — Purview, Defender, Entra — to the controls it can evidence. You leave with an honest gap picture and a sequenced roadmap to certification readiness. The boundary matters and we state it plainly: IT Partner does not issue ISO/IEC 42001 certificates. Certification audits are performed by accredited certification bodies, and this assessment exists to get you through one — not to replace it.

Success criteria

01The AI system inventory is complete enough that leadership signs off on it as the organization's register of AI use, including Microsoft 365 Copilot, agents, embedded AI, and known shadow AI.
02Every applicable requirement of ISO/IEC 42001 and every Annex A control has a documented current-state finding: met, partially met, not met, or not applicable with rationale.
03The draft AI policy set (acceptable use, AI risk and impact assessment methodology, human oversight and accountability) is delivered in editable form and reviewed with the stakeholders who will own it.
04Microsoft Purview, Defender, and Entra capabilities are mapped to the controls they can evidence for Copilot and agent scenarios, with configuration gaps identified.
05Leadership receives a prioritized, sequenced certification-readiness roadmap and an executive readout they can put in front of a board or a customer without translation.

What you receive

AI system inventory and register: sanctioned and shadow AI, Microsoft 365 Copilot and Copilot Studio agents, AI features embedded in business applications, and third-party AI dependencies, each with owner, purpose, and data exposure.
Gap assessment report against ISO/IEC 42001 management-system requirements and the Annex A control catalog, with per-control findings and maturity ratings.
Draft AI governance policy set in editable form: AI acceptable-use policy, AI risk and impact assessment methodology, and human oversight and accountability policy, tailored to your organization rather than boilerplate.
Microsoft control mapping for Copilot and agents: which ISO/IEC 42001 controls your Purview, Defender for Cloud Apps / Defender for Office 365, and Entra capabilities can evidence today, and which require configuration or licensing changes.
Statement of Applicability starter document, pre-populated from the gap assessment.
Prioritized certification-readiness roadmap with sequencing, effort classes, and owner recommendations, plus an executive readout session and deck.

How the work unfolds

1. Kickoff and AI footprint scoping

Confirm drivers (customer RFPs, board mandate, EU AI Act exposure, certification target), agree the assessment boundary, and size the AI footprint that drives the quoted scope: business units, AI systems, development versus use-only posture, and the Microsoft 365 estate in play.

2. AI inventory and stakeholder interviews

Build the AI register through stakeholder interviews and tenant-side discovery of Microsoft 365 Copilot, agents, and app integrations, plus a structured sweep for embedded and shadow AI. Each entry gets an owner, purpose, data classification exposure, and lifecycle stage.

3. Gap assessment against ISO/IEC 42001

Assess current policies, practices, and technical controls against the standard's management-system clauses and the Annex A controls — governance and policy, impact assessment, AI lifecycle, data for AI systems, transparency to interested parties, and third-party relationships — recording evidence and findings per control.

4. Policy drafting and Microsoft control mapping

Draft the core policy set and workshop it with the future owners. In parallel, map Purview (sensitivity labels, DLP, audit, data lifecycle), Defender, and Entra capabilities to the controls they can evidence for Copilot and agent scenarios, and document the configuration deltas.

5. Roadmap and executive readout

Consolidate findings into the certification-readiness roadmap: what to remediate, in what order, with what effort class and owner. Deliver the executive readout, hand off all working documents in editable form, and agree next steps — remediation, ongoing governance, or engaging an accredited certification body.

Prerequisites

An executive sponsor and a named coordinator who can schedule stakeholders across IT, security, legal/compliance, and the business functions using AI.
Read access to relevant Microsoft 365 admin and compliance surfaces (or an administrator who runs agreed queries with us) for the tenant-side inventory and control mapping.
Existing policies, risk registers, and any prior audit or assessment reports that touch AI, security, or data governance, shared under NDA.
Honesty about shadow AI — the assessment is only as good as the inventory, and unregistered tools are precisely what auditors and customers ask about.

Who does what

IT Partner

  • Plan and run the assessment, interviews, and tenant-side discovery.
  • Produce the AI inventory, gap assessment, policy drafts, Microsoft control mapping, Statement of Applicability starter, and roadmap.
  • Ground every finding in the standard's requirements rather than generic AI-governance opinion.
  • Deliver the executive readout and route follow-on work (remediation, ongoing governance, certification-body engagement) honestly, including where IT Partner is not the right party.

Your team

  • Provide the sponsor, coordinator, and stakeholder availability for interviews and workshops.
  • Grant the agreed read access or execute agreed discovery queries with IT Partner guidance.
  • Review and comment on the draft policy set — the policies must end up owned by your organization, not by your consultant.
  • Decide the post-assessment path: remediation sequencing, certification timing, and selection of an accredited certification body.
  • Own all final risk-acceptance and governance decisions; the assessment informs them but does not make them.

What's not included

The ISO/IEC 42001 certification audit itself, certification decisions, or issuance of certificates — those belong exclusively to accredited certification bodies, and IT Partner is not one. We prepare you for that audit; we do not perform it.
Any guarantee that your organization will achieve certification or pass a customer or regulator review.
Full AI management system implementation or operation — building out every process, running the risk program, and operating governance over time are separate, scoped follow-on work (see the vCISO service for the ongoing model).
Hands-on remediation of identified gaps: writing procedures beyond the delivered policy set, configuring Purview, Defender, or Entra controls, or changing operational processes, unless separately scoped.
Legal advice of any kind, including EU AI Act classification opinions, contractual AI clauses, or regulatory representations — findings reference legal frameworks as context, and your counsel owns legal conclusions.
Deep technical assessment, penetration testing, red-teaming, or model evaluation of AI systems — the engagement assesses governance and management-system readiness, not model internals.
Assessment of non-Microsoft technology stacks beyond inventory level; the technical control mapping is scoped to the Microsoft 365 and Azure estate.
Selection fees, audit fees, or any costs charged by certification bodies.

Limitations & technical notes

!ISO/IEC 42001 certification is performed by third-party certification bodies accredited for the standard; readiness work by any consultant, including IT Partner, does not shortcut that process and cannot bind an auditor's judgment.
!The assessment reflects your environment during the engagement window; AI tools, vendors, and Microsoft capabilities change quickly, and the inventory and mapping are a governed snapshot, not a living service.
!Regulatory context, including the EU AI Act, is evolving — obligations phase in over several years and dates have already shifted; the roadmap treats regulation as a planning input, not legal advice.
!The quality of the gap assessment depends on the completeness of stakeholder participation and disclosed documentation; gaps in either become gaps in the findings.
!Findings about Microsoft control coverage assume your current licensing; some Purview and Defender capabilities in the mapping may require plans you do not yet own, and the report flags these rather than assuming purchases.

Frequently asked questions

What is the AI Governance and ISO/IEC 42001 Readiness Assessment?

It is a 4-week consulting engagement that inventories your organization's AI use, assesses it against ISO/IEC 42001 — the international AI management system standard — drafts your core AI governance policies, maps your Microsoft security and compliance stack to the standard's controls, and delivers a prioritized roadmap to certification readiness. It prepares you for a certification audit performed by an accredited third party; it is not the audit itself.

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the first international management-system standard for artificial intelligence. Like ISO 27001 for information security, it defines requirements for how an organization governs AI — leadership, policy, risk and impact assessment, lifecycle management, data governance, and continual improvement — supported by an Annex A catalog of controls covering areas from AI policy through third-party relationships. Organizations can be certified against it by accredited certification bodies.

Does IT Partner certify us against ISO/IEC 42001?

No, and we say this plainly because it matters: certification audits and certificates come only from certification bodies accredited for the standard. IT Partner is a readiness consultant. We get you to the point where engaging an accredited body is a sensible next step rather than an expensive discovery exercise — the same separation of duties our ISO 27001 pre-audit service maintains.

Who should buy this assessment?

Organizations getting AI governance questions they cannot yet answer well: enterprise customers adding AI sections to vendor questionnaires and RFPs, boards asking who owns AI risk, regulators and frameworks like the EU AI Act creating exposure, or leadership targeting ISO/IEC 42001 certification and needing to know how far away it is. If you use Microsoft 365 Copilot or agents in production, you already have an AI footprint worth governing.

What does "scoped by AI footprint" mean for the price?

Pricing starts at $7,500 and grows with what we actually have to assess: how many AI systems and business units are in scope, whether you develop AI or only use it, and the size of the Microsoft 365 estate for the control mapping. After the scoping conversation you receive a fixed quote in writing before any work begins, and you pay after you approve delivery.

What exactly does the gap assessment cover?

Both layers of the standard: the management-system requirements (context, leadership, planning, support, operation, performance evaluation, and improvement) and the Annex A controls, which span AI policy and governance, impact assessment, the AI system lifecycle, data for AI systems, information for interested parties, and use of and third-party relationships around AI systems. Every applicable item gets a documented finding — met, partially met, not met, or not applicable with rationale.

Which policies do you actually draft?

Three core documents, delivered in editable form and workshopped with their future owners: an AI acceptable-use policy for the workforce, an AI risk and impact assessment methodology, and a human oversight and accountability policy defining who is answerable for AI-assisted decisions. These are the backbone documents an AI management system — and most customer questionnaires — expect to see.

How does our Microsoft 365 environment fit into an AI governance standard?

Heavily, if Copilot and agents are part of your AI footprint. Much of the evidence an auditor or customer wants — data classification, DLP, audit trails, access governance, threat protection — maps to Microsoft Purview, Defender, and Entra capabilities you may already license. The assessment maps those capabilities to the standard's controls for your Copilot and agent scenarios and identifies exactly where configuration or licensing gaps remain.

Do we need ISO 27001 before pursuing ISO/IEC 42001?

No — ISO/IEC 42001 stands on its own. But the standards share the same management-system architecture, so an existing ISMS accelerates readiness considerably: risk processes, document control, and internal audit muscles transfer directly. If you are weighing both, we can sequence them; IT Partner also offers an ISO 27001 pre-audit readiness assessment.

How does this relate to the EU AI Act?

The EU AI Act creates obligations that phase in over several years, and an AI management system is a practical way to organize your response: the inventory tells you what you run, the impact-assessment methodology gives you a repeatable classification process, and the policy set establishes oversight. To be precise about the boundary, though: this engagement is not legal advice, and questions of legal classification or exposure under the Act belong with your counsel. We provide the governance machinery; your lawyers provide the legal conclusions.

How long does the assessment take?

Four weeks is the standard schedule for a typical mid-size footprint: scoping and inventory in the first half, gap assessment, policy drafting, and control mapping in the second, closing with the roadmap and executive readout. Very large or multi-entity footprints are scoped honestly at quote time rather than squeezed into the standard window.

What happens after the assessment?

Three paths, usually in sequence: remediate the prioritized gaps (your team, IT Partner under separate scope, or a mix), operate the governance rhythm the policies define — the vCISO service is the ongoing model for organizations without a security leader to own it — and, when the roadmap says you are ready, engage an accredited certification body for the Stage 1 and Stage 2 audits. We can support you through remediation and audit preparation, but the certification decision is always the auditor's.

Does the inventory cover custom agents and shadow AI?

Yes — that is much of its value. Copilot Studio agents, AI features switched on inside SaaS products, and the unsanctioned browser-tab AI your teams already use all carry governance obligations under the standard. The discovery combines tenant-side signals with structured stakeholder interviews, because shadow AI by definition does not show up in an asset database.

Can the deliverables help us answer customer security questionnaires about AI?

They are built with that use in mind: the inventory, policy set, Statement of Applicability starter, and executive readout give you documented, honest answers to the AI sections now appearing in vendor assessments — including the accurate answer that you are executing a roadmap toward ISO/IEC 42001 readiness, which lands far better than improvisation.

Do you guarantee we will achieve ISO/IEC 42001 certification?

No. Certification depends on the remediation you complete and on the judgment of an independent accredited auditor, and no honest readiness consultant guarantees another party's decision. What we commit to is a rigorous, standard-grounded assessment, usable policy drafts, an accurate map of your Microsoft control coverage, and a roadmap that tells you the real distance to ready.

Is our information safe with you during the assessment?

The engagement runs under NDA, access is read-only or executed by your administrators with our guidance, and IT Partner carries cyber insurance with third-party verification available. You can verify our operating claims — response SLAs, insurance, Microsoft partnership history — on our public verification page.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

From $7,500 (scoped by AI footprint)
4 weeks
Scope my AI governance assessment