ISO 42001 without a consultant: the 5 documents that do the heavy lifting
By BigJay Jang · former IBM & Deloitte strategy consultant
A global-firm engagement will produce a beautiful binder. But if you look at what an auditor actually opens first, five documents carry most of the weight. Build these well and you've done the majority of the real work — long before you spend a cent on consulting.
1 · The AI policy
Everything hangs off a short, top-management-approved AI policy (Clause 5, control A.2). It states your commitment, scope and objectives for responsible AI. Auditors read it first because it tells them whether leadership is actually behind the system or whether this is a compliance theatre exercise. Keep it to two pages, make it specific to how your company uses AI, and — this is the part teams skip — get it genuinely signed off at the top. An unsigned policy is a mandatory gap, full stop.
2 · The scored risk register
ISO 42001 is a risk-based standard, so the risk register (Clause 6.1, control A.5) is its beating heart. For each AI system you list what could go wrong, score it by likelihood × impact, and record how you'll treat it — with an owner and a date. The single most common mistake is listing risks without distinguishing inherent risk (before controls) from residual risk (after). Auditors want to see that you understood the exposure and then did something measurable about it.
3 · The AI impact assessment
Where the risk register protects the business, the impact assessment (controls A.5.2–5) looks outward: how could this system affect individuals, groups and society? For higher-risk uses this is also where the EU AI Act's fundamental-rights impact assessment (Art. 27) plugs in. Done honestly, it's the document that most impresses a sceptical buyer, because it shows you thought about the people on the other end of your model — not just your own liability.
4 · Roles & the RACI matrix
"Who is responsible for AI here?" should have a one-name answer. The RACI matrix (Clause 5.3, and it doubles as your EU AI Act deployer role map) assigns Responsible, Accountable, Consulted and Informed across every governance activity. The iron rule: exactly one Accountable per activity. Two accountable owners means none. This document is quick to build and disproportionately reassuring to an auditor, because diffuse accountability is where governance quietly dies.
5 · The Statement of Applicability
The Statement of Applicability (SoA) is the auditor's index. It lists all 38 Annex A controls and, for each, whether it applies to you and why (or a justification if it doesn't). It's the map that ties every other document to the standard. Build it last, because it references everything else — and treat any control you mark "not applicable" as something you'll have to defend out loud.
What a consultant actually adds
Not the documents — templates for those exist, including here. What a good consultant adds is judgement: which risks are real for your context, which controls you can honestly scope out, and where an auditor will push. The Govern42 approach is to give you the documents and the strict assessment for free, so the only thing you'd ever pay for is that judgement — applied to your case, at a mid-market price.
Educational orientation, not legal advice. ISO/IEC 42001 references current as of August 2026. Certification is performed by accredited bodies.