Your AI policy says one thing. Your AI systems do another.
Most organizations using AI have two documents that don't match. The first is a published AI policy affirming fairness, transparency, and human oversight - approved by a committee, endorsed by leadership. The second is the list of AI systems actually running: scoring credit, screening r sum s, flagging transactions, setting prices. Where those two documents diverge, regulatory action, public failure, and preventable audit findings follow.
ISO/IEC 42001, published in December 2023, is the first international standard designed to close that gap.
This is a practitioner's guide to that standard - written by a certified ISO/IEC 42001 Senior Lead Auditor for the people who have to build the management system, not merely describe it.
Inside this book
A clause-by-clause walkthrough of Clauses 4-10: what each requirement means, how to implement it, and what an auditor will actually askA five-phase implementation roadmap - Assess, Build, Certify, Operate, Integrate - with realistic timelines for reaching certification in 10 to 18 monthsThe certification journey in full: selecting an accredited certification body, Stage 1 and Stage 2 audits, nonconformity handling, surveillance, and recertificationTwelve ready-to-use templates: gap assessment, AI system inventory, risk assessment, AI impact assessment, model card, clause-by-clause audit checklist, and moreA complete worked example - a credit-decisioning system carried through every template, from inventory entry to signed impact assessmentRegulatory mappings to the EU AI Act, NIST AI RMF, and ISO 27001, plus APJ alignment covering Korea's AI Framework Act, Japan, and SingaporeA section you won't find in other ISO/IEC 42001 books
Part IV extends the framework to quantum computing: the Harvest Now, Decrypt Later threat that is active today, the finalized NIST post-quantum standards (FIPS 203, 204, 205), and two original governance frameworks - Q-NAV and QT-QMS - for organizations beginning to assess quantum exposure.
Written for
Chief Information Security Officers explaining AI risk to boards that lack the vocabulary. Compliance officers cross-applying ISO/IEC 42001 with the EU AI Act. AI leaders who know how to build models but have never documented a risk treatment plan. Internal auditors preparing for their first ISO/IEC 42001 audit.
About the author
Jae P. Hong is an ISO/IEC 42001 Senior Lead Auditor and ISO 9001:2015 Lead Auditor with more than 25 years in AI, data governance, and enterprise transformation. His career spans the mainframe era, the dot-com boom, SAP's enterprise software peak, cloud transformation at HP, IBM, and Kyndryl, and now the convergence of AI and quantum computing.
ISO/IEC 42001 does not require perfect AI governance. It requires systematic governance - and this book shows you how to build it.