Ask a room of business owners whether they have an AI policy and a fair number will say yes. Ask where it lives and you will usually hear a shared drive, or an induction pack, or somebody's inbox. Ask what happens when an employee ignores it on a Tuesday afternoon because a client deadline is tighter than the rules, and the room goes quiet.
That gap has a name now. In December 2023 the first international standard for an AI management system arrived: ISO/IEC 42001. It gives businesses a structured, auditable way to govern how they build and use AI, and it has become the credential enterprises reach for when they sell into regulated markets.
It is a genuinely useful standard. It is also widely misread, in a way that costs SMEs time and money.
A management system is a framework, not a product
The most important thing to understand about ISO 42001 is what it deliberately leaves out.
The standard specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. It covers AI policies, roles and responsibilities, risk assessment, controls, monitoring and continual improvement. What it does not do is prescribe specific technical controls or AI techniques.
That omission is intentional and sensible. A standard that named particular tools would age badly, and the same governance outcome can be reached in very different ways by a hospital and a marketing agency.
But it has a practical consequence that catches people out. You can satisfy every documentary requirement of the standard and still have staff pasting client contracts into a personal chatbot account. The paperwork says the risk is assessed. The behaviour says otherwise.
Where the gap opens
Think about what a management system asks you to demonstrate, and then ask how each item is actually achieved in a 40-person business.
Define approved AI use. Easy to write down. Much harder to make true, because the approved route has to be genuinely available at the moment someone needs it. If the sanctioned option is slower than the unsanctioned one, people choose speed.
Assess risk by data sensitivity. Straightforward as an exercise. The difficulty is that the assessment lives in a spreadsheet while the decisions happen in a browser tab, hundreds of times a week, made by people who are not thinking about risk categories.
Assign roles and access boundaries. Fine in a diagram. Meaningless unless something actually stops a request that falls outside them.
Keep records of AI use. This is where most SMEs quietly fail. Nobody logs their own chatbot sessions. If the record depends on people choosing to create it, the record does not exist.
Notice the pattern. Every requirement is achievable on paper and every one of them depends, in practice, on something enforcing it while work is happening.
Two halves of the same job
It helps to separate governance into the part that describes and the part that enforces.
The descriptive half is the management system itself: policies, risk registers, ownership, review cycles, improvement plans. This is what a certification auditor examines. It is real work and it matters.
The operational half is what happens between an employee having an idea and a model producing an answer. Was this request allowed? Which data was involved? Should it have run somewhere private? Who asked, and what came back? None of that is optional if you want your management system to reflect reality, and none of it can be done by a document.
Buying a governance tool that only produces registers and questionnaires gives you a better-organised version of the descriptive half. It does not touch the operational half at all. That distinction is worth being precise about when comparing vendors, because the market blurs it constantly.
What actually closes the gap
Four things turn a written system into a working one.
An approved route people prefer. Adoption is a control. If the compliant path gives staff more context, better answers and less friction than a public tool, the shadow usage that undermines your whole system stops being attractive. You cannot enforce your way past a worse product.
Checks that run before the model does. Policy has to be evaluated at request time, not reviewed afterwards. Allowed, warned, blocked, or moved somewhere private: the decision belongs in the path of the work.
Routing tied to sensitivity. Risk assessment becomes operational the moment it changes where a request executes. Ordinary drafting can use approved external models under zero-retention terms. Client files and proprietary IP should run on infrastructure you control, which is the job Kubrius Core exists to do.
Records as a byproduct. Evidence has to be automatic. Every request, including the ones that were blocked, logged with who asked, what was decided, which rule applied and where it ran. Ask people to log their own AI use and you will get a beautifully incomplete dataset.
Do smaller businesses need certification?
Usually not, at least not first.
Certification is voluntary, runs on a three-year cycle through an accredited body, and makes most sense when a client, insurer or regulator wants independent assurance, or when you are selling into the EU and regulated sectors where it has become the expected credential. Anthropic, Microsoft and AWS all hold it, which tells you something about who the standard was designed with in mind.
For a 30-person firm, the certification programme itself is often disproportionate. The structure behind it is not. Knowing which AI tools are in use, which workflows are approved, where sensitive data goes and what evidence exists is valuable whether or not anyone ever audits you. It is also the honest answer when a client asks how you manage AI, which is happening far more often than it was a year ago.
The sensible order is to get the operational half working, then decide whether the certificate is worth pursuing. Doing it the other way round produces a folder of documents describing a business that does not exist.
Where to start
Start with visibility, because you cannot govern usage you cannot see. Map which teams use AI, for what, with what data. That exercise is what the AI Control Scorecard is built around, and it typically surfaces two or three workflows nobody had thought about.
Then pick the workflows worth controlling first and give people a better route through them. Document Q&A and policy questions are usually the fastest wins. If you want the argument for doing this before buying more AI tools, I wrote about it in why SMEs need an AI control layer.
Only then worry about the paperwork. By that point most of it describes something you can actually point at.
Frequently Asked Questions
What is an AI management system?
An AI management system is the set of policies, roles, risk assessments, controls and records an organisation uses to govern how it develops and uses AI. ISO/IEC 42001, published in December 2023, is the first international standard defining one. It is a management framework rather than a piece of software.
Does ISO 42001 tell you which technical controls to use?
No. The standard focuses on organisational processes: setting AI policies, defining roles and responsibilities, assessing risk, implementing controls, monitoring performance and improving over time. It does not prescribe specific technical controls or AI techniques, which is why two organisations can both meet it with very different implementations.
Do SMEs need ISO 42001 certification?
Certification is voluntary. It matters most when selling into regulated markets, or when a client or insurer asks for independent assurance. Many smaller businesses get the practical benefit by adopting the structure, defining approved use, assessing risk and keeping records, without running a full certification programme.
What is the difference between an AI policy and an AI management system?
A policy is a single document stating what is and is not allowed. A management system is the wider machinery that keeps that policy alive: who owns it, how risk is assessed, how it is enforced in practice, what evidence is produced, and how it gets reviewed and improved.
How does an AI management system relate to the EU AI Act?
They overlap without being the same thing. The EU AI Act is legislation, with obligations that depend on how a system is classified; ISO 42001 is a voluntary standard. Implementing the standard covers a substantial share of the documentation expected for high-risk systems, which is why it is often used as a practical route toward demonstrating conformance. It is not a substitute for legal advice.
The short version
A standard can tell you what a well-governed business looks like. It cannot make your business look like that on a Tuesday afternoon when someone is up against a deadline.
Whatever you write down, something has to sit between your people and the models, applying the rules and keeping the receipts. Get that part working and the documentation becomes a description of how you already operate, which is the only kind worth having.
Kubrius does not provide legal advice or certify compliance. We build the visibility, controls and evidence that support your own governance work.
See what your AI usage looks like today.
The AI Control Scorecard maps where AI is already being used across your business, what data is exposed, and which controls are worth putting in first.