AI Governance & ISO/IEC 42001 Readiness
Enterprise buyers ask how you govern AI before they sign, and security questionnaires now carry a section for it. I build the AI policy, the risk map, and the controls underneath them — shaped to ISO/IEC 42001 and NIST AI RMF — so your answer arrives with evidence attached.
AI governance is the set of policies, controls, and review routines that decide how a company builds and uses AI: who approves a use case, what data may enter a model, who owns the risk when it goes wrong. ISO/IEC 42001 is the international standard that turns those pieces into an auditable AI management system, roughly what ISO 27001 does for information security. Oleg Sotnikov builds that system with you — an inventory of your AI systems, a risk map, a policy pack your team will follow, and the evidence trail an auditor asks for. He prepares organizations for certification; the certificate itself is issued by an accredited certification body.
What an AI Management System Contains
Six parts, built in the order that reduces your exposure fastest.
AI inventory and risk map
Every model, API, copilot, and quietly adopted tool, listed with what it touches: customer data, money, hiring decisions, safety. This is AI risk management with names attached: risk ratings come out of that list rather than out of a workshop.
A policy pack people follow
Acceptable use, which data may enter which tool, rules for AI vendors and their sub-processors, and an approval path for new use cases. Short enough that engineers read it before they ask.
ISO/IEC 42001 gap analysis
A clause-by-clause read of where you stand: context, leadership, planning, operation, performance evaluation, improvement. You get a gap list with owners and effort estimates.
NIST AI RMF alignment
US buyers often ask for NIST AI RMF language rather than an ISO certificate. I map the same controls onto Govern, Map, Measure, and Manage, so one body of work answers both questionnaires.
LLM-specific controls
Prompt injection, data leakage into vendor logs, over-permissioned tools, provider concentration, AI-code provenance. The list is short; the point is that each item turns into a control with an owner.
Training and rollout
A policy nobody has read governs nothing. I run the sessions, set the review cadence, and leave decision templates for the cases that surface after the engagement ends.
How the Work Runs
Assessment
An inventory of the AI systems in use, a risk rating for each, and a gap analysis against ISO/IEC 42001 — plus NIST AI RMF where your buyers ask for it.
Close the gaps
Policies, controls, and the records that show they run: approval logs, risk reviews, vendor assessments, and incident handling for the failures only AI systems produce.
Operate
The management system settles into a routine: a review cycle, a named owner, documents that stay current. Bring in a certification body after that and you are attending an audit, not preparing for one.
Why Me
- I introduced AI into a regulated fintech product (FluxoPay), where the founder's first question was about risk, not features
- 45+ certifications, including CEH and ITIL — control language, audit evidence, and service management are familiar ground
- AppMaster runs 11B+ tokens a month in production, so the LLM controls I write are ones I operate myself
Frequently Asked Questions
What is ISO/IEC 42001?
ISO/IEC 42001 is the international standard for an AI management system — roughly what ISO 27001 is for information security. It requires an organization to define how AI is governed: who is accountable, how risks and impacts get assessed, which controls apply, and how the system is reviewed and improved. The certificate is issued by an accredited certification body after an audit.
Do we need the certificate, or just the management system?
Most companies need the system first. The policies, the risk register, and the controls reduce your real exposure, answer what security questionnaires ask about, and take the longest to build. Certification earns its cost once a specific enterprise deal or procurement process demands the certificate — the readiness work is identical either way.
Can you certify us to ISO 42001?
No. Certificates come from accredited certification bodies, which have to stay independent from whoever built the management system. My work stops at that line and covers everything before it: gap analysis, policies, controls, evidence, and a dry run so the audit holds no surprises.
ISO 42001 or NIST AI RMF?
They complement each other, and for AI governance they are the two worth building against. NIST AI RMF is a voluntary risk framework with no certificate attached; ISO/IEC 42001 is a certifiable management system. The underlying controls overlap heavily, so I map your work across both and you answer either questionnaire from one document set.
What LLM-specific risks do you cover?
Prompt injection against agents and RAG pipelines, customer data leaking into vendor logs or training data, tools handed more permissions than the task needs, concentration risk on a single model provider, and the provenance of AI-generated code entering your codebase. Each one gets a control someone can check, not a paragraph of intent.
Where do we start?
Two ways in. Book a readiness call and we walk through what you run today and what your buyers are asking for. Or take the free AI policy template, adapt it to your company, and come back when you want the risk work and the ISO/IEC 42001 gap analysis behind it.
Start with a shadow AI audit
Governance that ignores the AI your teams already use off the books is paperwork. The audit finds what is running and what it exposes.
See the shadow AI auditDraft your AI policy in minutes
The free generator turns a short form into a complete, adaptable company AI policy — the document every governance program starts from.
Open the AI policy generatorSee Where You Stand
A readiness call covers the AI you run today, what your buyers and auditors are asking for, and how far that sits from ISO/IEC 42001.
Engagements are scoped to the size of your AI footprint. I prepare you for certification; an accredited body issues the certificate.
Related reading
AI risk, governance, and running AI in production without surprises.


