Certifiable AI by Kai London
An AI management system is the difference between governing AI and reviewing it case by case. ISO/IEC 42001 gives the structure; making it work inside a real organisation is the harder part. This toolkit takes an implementation team from scoping through internal audit to certification readiness.
What the book covers
Scoping the management system
Defining boundaries, interested parties and objectives so the scope is both meaningful and auditable.
Roles, policy and competence
Leadership commitment, accountable roles, policy structure and the competence evidence auditors expect.
Risk and impact assessment
Running AI risk assessment and impact assessment as repeatable processes rather than one-off exercises.
Controls and the statement of applicability
Selecting, justifying and evidencing controls across the AI lifecycle.
Internal audit and management review
Audit programme design, nonconformity handling and continual improvement that is real.
Alignment with regulation
Reusing management-system evidence to support EU AI Act obligations and the NIST AI RMF.
General guidance, not legal advice, and no substitute for the standard itself. This is an independent work with no endorsement by or affiliation with ISO, IEC, any certification body or any regulator.
Who it is for
AI governance and compliance leads, quality managers, internal auditors, data and AI engineering leadership, and consultants running 42001 implementations.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.