ISO 42001 Implementation Roadmap: 90-Day Plan

A practical week-by-week plan from project kickoff to Stage 1 audit readiness. Realistic for organisations that already hold ISO 27001 or NIST AI RMF maturity; treat as the accelerated path.

Who this plan is for

This 90-day plan is realistic for organisations that already have some adjacent maturity: ISO 27001 in place, NIST AI RMF partial implementation, or documented AI governance practices. Greenfield organisations (no prior management-system experience, no documented AI governance) should expect 6–12 months rather than 90 days, use this as the structure of the work, not the timeline.

The Professional tier of our toolkit includes PRO-90_Day_Roadmap.xlsx, a spreadsheet version of this plan with 13 weekly sprints, dependencies, owner assignments, and progress tracking. This web page is the narrative summary.

Pre-work (Week 0)

  • Identify an AIMS sponsor (typically CTO, CIO, or Chief Risk Officer).
  • Assign an AIMS Owner (day-to-day implementation lead).
  • Assemble the core project team: AI Risk Lead, Data Lead, one or two AI system owners, Legal/Compliance representative.
  • Set weekly standup cadence.
  • Procure the toolkit tier that matches your scope (Professional recommended for 90-day pace).

Sprint 1, Foundation (Weeks 1–2)

Establish the AIMS structure: who we are, what's in scope, what our policy is.

  • Week 1: Complete AIMS-02 Scope Statement. Define which AI systems are in/out of scope and why.
  • Week 1: Customise AIMS-01 AI Policy. Get top management sign-off.
  • Week 2: Customise AIMS-03 AI Objectives and AIMS-11 Competence Matrix.
  • Week 2: Complete AIMS-18 AI System Inventory, every AI system the organisation uses, builds, or ships.

Milestone: Signed AI Policy, ratified Scope, baseline AI System Inventory.

Sprint 2, Risk framework (Weeks 3–4)

  • Week 3: Customise AIMS-04 Risk Assessment Methodology. Decide: qualitative, quantitative, or hybrid? What's your risk appetite?
  • Week 3: Populate AIMS-05 AI Risk Register with risks identified from the System Inventory. Score against methodology.
  • Week 4: Complete AIMS-07 Statement of Applicability. For all 38 Annex A controls, document "Applicable" or "Not Applicable" with justification.
  • Week 4: Customise AIMS-06 Risk Treatment Plan. For each unacceptable-risk row in the register, identify treatment.
  • Week 4: Expand each treatment into AIMS-06a Risk Treatment Action Catalogue: description, verification method, independent verifier, evidence, and target risk score. Every action ID must reconcile with AIMS-06 and AIMS-07 in both directions.

Milestone: Complete risk framework. Documented, defensible.

Sprint 3, Impact assessments (Weeks 5–6)

  • Week 5: Customise AIMS-08 Impact Assessment Procedure. Use the Professional tier's industry variant (SaaS, FinTech, HealthTech) if applicable.
  • Week 5–6: Run impact assessments for your top 3–5 AI systems using AIMS-09.
  • Week 6: Run gap analysis against the Professional tier's 64-formula Gap Analysis Workbook. Identify highest-priority gaps.

Milestone: Impact assessments complete for in-scope systems. Gap-analysis baseline established.

Sprint 4, Operational procedures (Weeks 7–9)

  • Week 7: Customise AIMS-19 Lifecycle Procedure (A.6 operationalisation). Customise AIMS-20 Data Management Procedure (A.7).
  • Week 8: Customise AIMS-21 Supplier Management Procedure (A.10) and AIMS-22 Incident Response Procedure (A.8.4, EU AI Act Art. 73).
  • Week 9: Customise AIMS-10 Document Control Procedure (7.5), AIMS-12 Communication Plan (7.4), AIMS-16 Nonconformity and CAPA Procedure (10.2).

Milestone: Operational procedures in place. Evidence collection begins.

Sprint 5, Governance cycle (Weeks 10–11)

  • Week 10: Complete AIMS-13 Internal Audit Programme. Plan first internal audit.
  • Week 10: Conduct first internal audit. Use AIMS-14 Internal Audit Report Template.
  • Week 11: Hold first management review meeting. Use AIMS-15 Management Review Minutes Template.
  • Week 11: Log any findings from internal audit into AIMS-17 Nonconformity Register. Plan corrective actions.

Milestone: Governance cycle executed at least once. Demonstrates the AIMS is operating, not just documented.

Sprint 6, Audit readiness (Weeks 12–13)

  • Week 12: Run AR-01 Pre-Audit Self-Assessment (Audit-Ready tier). Honestly score every item. Any ✗ items: remediate immediately.
  • Week 12: Assemble AR-02 Stage 1 Evidence Binder. Every required document in one place.
  • Week 13: Engage certification body. Send AR-04 Auditor Briefing Pack. Schedule Stage 1.
  • Week 13: Pre-audit communication briefing for staff who may be interviewed.

Milestone: Stage 1 audit booked. AIMS operational.

Post-90 days

Stage 1 audit usually happens in the 2–4 weeks after booking. If Stage 1 findings are minor, Stage 2 follows 4–12 weeks later. Certificate typically arrives 2–6 weeks after Stage 2. Factor in another 4–12 weeks between Stage 1 and Stage 2, and your realistic end-to-end timeline (with this 90-day accelerated implementation) is 5–7 months from kickoff to certificate.

For greenfield organisations, the timeline typically doubles, but the structure of the work doesn't change.

Ready to start?

The 22-document Starter pack takes you from purchase to signed AI Policy in 7 days. The Professional tier adds Annex A deep-dives, crosswalks, a 64-formula Gap Analysis workbook, and industry variants. The Audit-Ready tier prepares you for Stage 1.