AI Governance and ISO/IEC 42001 Readiness Assessment
The AI Governance and ISO/IEC 42001 Readiness Assessment is a 4-week gap assessment against ISO/IEC 42001, the international standard for AI management systems. IT Partner inventories your AI footprint — Microsoft 365 Copilot, agents, embedded and shadow AI — assesses your practices against the standard's requirements and Annex A controls, drafts the core AI governance policy set, maps Microsoft Purview, Defender, and Entra controls to the standard, and delivers a prioritized roadmap to certification readiness. Pricing starts at $7,500 and is scoped by the size of your AI footprint. IT Partner is not a certification body: the certification audit itself is performed by an accredited third party, and this engagement prepares you for it.
What this engagement is
AI governance stopped being a theoretical exercise the moment customers started putting it in vendor questionnaires and regulators started publishing enforcement timelines. ISO/IEC 42001:2023 is the anchor most of those questions now point at: the first international management-system standard for AI, structured like ISO 27001 but aimed at how an organization governs its use and development of AI — policies, risk and impact assessment, human oversight, data governance, and lifecycle accountability, backed by an Annex A catalog of controls. Major providers, Microsoft among them, have pursued ISO/IEC 42001 certification for their AI services, and their customers are increasingly expected to show the same discipline. This engagement is the same motion as IT Partner's ISO 27001 and SOC pre-audit services, applied to the new standard: we establish what AI you actually run (including Copilot, Copilot Studio agents, AI features embedded in SaaS, and the unsanctioned tools nobody registered), assess your current practices against the standard clause by clause and control by control, draft the policy set an AI management system needs, and map the Microsoft security and compliance stack you already own — Purview, Defender, Entra — to the controls it can evidence. You leave with an honest gap picture and a sequenced roadmap to certification readiness. The boundary matters and we state it plainly: IT Partner does not issue ISO/IEC 42001 certificates. Certification audits are performed by accredited certification bodies, and this assessment exists to get you through one — not to replace it.
Success criteria
What you receive
How the work unfolds
Confirm drivers (customer RFPs, board mandate, EU AI Act exposure, certification target), agree the assessment boundary, and size the AI footprint that drives the quoted scope: business units, AI systems, development versus use-only posture, and the Microsoft 365 estate in play.
Build the AI register through stakeholder interviews and tenant-side discovery of Microsoft 365 Copilot, agents, and app integrations, plus a structured sweep for embedded and shadow AI. Each entry gets an owner, purpose, data classification exposure, and lifecycle stage.
Assess current policies, practices, and technical controls against the standard's management-system clauses and the Annex A controls — governance and policy, impact assessment, AI lifecycle, data for AI systems, transparency to interested parties, and third-party relationships — recording evidence and findings per control.
Draft the core policy set and workshop it with the future owners. In parallel, map Purview (sensitivity labels, DLP, audit, data lifecycle), Defender, and Entra capabilities to the controls they can evidence for Copilot and agent scenarios, and document the configuration deltas.
Consolidate findings into the certification-readiness roadmap: what to remediate, in what order, with what effort class and owner. Deliver the executive readout, hand off all working documents in editable form, and agree next steps — remediation, ongoing governance, or engaging an accredited certification body.
Prerequisites
Who does what
IT Partner
- Plan and run the assessment, interviews, and tenant-side discovery.
- Produce the AI inventory, gap assessment, policy drafts, Microsoft control mapping, Statement of Applicability starter, and roadmap.
- Ground every finding in the standard's requirements rather than generic AI-governance opinion.
- Deliver the executive readout and route follow-on work (remediation, ongoing governance, certification-body engagement) honestly, including where IT Partner is not the right party.
Your team
- Provide the sponsor, coordinator, and stakeholder availability for interviews and workshops.
- Grant the agreed read access or execute agreed discovery queries with IT Partner guidance.
- Review and comment on the draft policy set — the policies must end up owned by your organization, not by your consultant.
- Decide the post-assessment path: remediation sequencing, certification timing, and selection of an accredited certification body.
- Own all final risk-acceptance and governance decisions; the assessment informs them but does not make them.
What's not included
Limitations & technical notes
Frequently asked questions
What is the AI Governance and ISO/IEC 42001 Readiness Assessment?
It is a 4-week consulting engagement that inventories your organization's AI use, assesses it against ISO/IEC 42001 — the international AI management system standard — drafts your core AI governance policies, maps your Microsoft security and compliance stack to the standard's controls, and delivers a prioritized roadmap to certification readiness. It prepares you for a certification audit performed by an accredited third party; it is not the audit itself.
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the first international management-system standard for artificial intelligence. Like ISO 27001 for information security, it defines requirements for how an organization governs AI — leadership, policy, risk and impact assessment, lifecycle management, data governance, and continual improvement — supported by an Annex A catalog of controls covering areas from AI policy through third-party relationships. Organizations can be certified against it by accredited certification bodies.
Does IT Partner certify us against ISO/IEC 42001?
No, and we say this plainly because it matters: certification audits and certificates come only from certification bodies accredited for the standard. IT Partner is a readiness consultant. We get you to the point where engaging an accredited body is a sensible next step rather than an expensive discovery exercise — the same separation of duties our ISO 27001 pre-audit service maintains.
Who should buy this assessment?
Organizations getting AI governance questions they cannot yet answer well: enterprise customers adding AI sections to vendor questionnaires and RFPs, boards asking who owns AI risk, regulators and frameworks like the EU AI Act creating exposure, or leadership targeting ISO/IEC 42001 certification and needing to know how far away it is. If you use Microsoft 365 Copilot or agents in production, you already have an AI footprint worth governing.
What does "scoped by AI footprint" mean for the price?
Pricing starts at $7,500 and grows with what we actually have to assess: how many AI systems and business units are in scope, whether you develop AI or only use it, and the size of the Microsoft 365 estate for the control mapping. After the scoping conversation you receive a fixed quote in writing before any work begins, and you pay after you approve delivery.
What exactly does the gap assessment cover?
Both layers of the standard: the management-system requirements (context, leadership, planning, support, operation, performance evaluation, and improvement) and the Annex A controls, which span AI policy and governance, impact assessment, the AI system lifecycle, data for AI systems, information for interested parties, and use of and third-party relationships around AI systems. Every applicable item gets a documented finding — met, partially met, not met, or not applicable with rationale.
Which policies do you actually draft?
Three core documents, delivered in editable form and workshopped with their future owners: an AI acceptable-use policy for the workforce, an AI risk and impact assessment methodology, and a human oversight and accountability policy defining who is answerable for AI-assisted decisions. These are the backbone documents an AI management system — and most customer questionnaires — expect to see.
How does our Microsoft 365 environment fit into an AI governance standard?
Heavily, if Copilot and agents are part of your AI footprint. Much of the evidence an auditor or customer wants — data classification, DLP, audit trails, access governance, threat protection — maps to Microsoft Purview, Defender, and Entra capabilities you may already license. The assessment maps those capabilities to the standard's controls for your Copilot and agent scenarios and identifies exactly where configuration or licensing gaps remain.
Do we need ISO 27001 before pursuing ISO/IEC 42001?
No — ISO/IEC 42001 stands on its own. But the standards share the same management-system architecture, so an existing ISMS accelerates readiness considerably: risk processes, document control, and internal audit muscles transfer directly. If you are weighing both, we can sequence them; IT Partner also offers an ISO 27001 pre-audit readiness assessment.
How does this relate to the EU AI Act?
The EU AI Act creates obligations that phase in over several years, and an AI management system is a practical way to organize your response: the inventory tells you what you run, the impact-assessment methodology gives you a repeatable classification process, and the policy set establishes oversight. To be precise about the boundary, though: this engagement is not legal advice, and questions of legal classification or exposure under the Act belong with your counsel. We provide the governance machinery; your lawyers provide the legal conclusions.
How long does the assessment take?
Four weeks is the standard schedule for a typical mid-size footprint: scoping and inventory in the first half, gap assessment, policy drafting, and control mapping in the second, closing with the roadmap and executive readout. Very large or multi-entity footprints are scoped honestly at quote time rather than squeezed into the standard window.
What happens after the assessment?
Three paths, usually in sequence: remediate the prioritized gaps (your team, IT Partner under separate scope, or a mix), operate the governance rhythm the policies define — the vCISO service is the ongoing model for organizations without a security leader to own it — and, when the roadmap says you are ready, engage an accredited certification body for the Stage 1 and Stage 2 audits. We can support you through remediation and audit preparation, but the certification decision is always the auditor's.
Does the inventory cover custom agents and shadow AI?
Yes — that is much of its value. Copilot Studio agents, AI features switched on inside SaaS products, and the unsanctioned browser-tab AI your teams already use all carry governance obligations under the standard. The discovery combines tenant-side signals with structured stakeholder interviews, because shadow AI by definition does not show up in an asset database.
Can the deliverables help us answer customer security questionnaires about AI?
They are built with that use in mind: the inventory, policy set, Statement of Applicability starter, and executive readout give you documented, honest answers to the AI sections now appearing in vendor assessments — including the accurate answer that you are executing a roadmap toward ISO/IEC 42001 readiness, which lands far better than improvisation.
Do you guarantee we will achieve ISO/IEC 42001 certification?
No. Certification depends on the remediation you complete and on the judgment of an independent accredited auditor, and no honest readiness consultant guarantees another party's decision. What we commit to is a rigorous, standard-grounded assessment, usable policy drafts, an accurate map of your Microsoft control coverage, and a roadmap that tells you the real distance to ready.
Is our information safe with you during the assessment?
The engagement runs under NDA, access is read-only or executed by your administrators with our guidance, and IT Partner carries cyber insurance with third-party verification available. You can verify our operating claims — response SLAs, insurance, Microsoft partnership history — on our public verification page.