ISO/IEC 42001:2023 · AI Governance · AIMS

ISO 42001: AI Governance for Your Company · Turnkey

Your employees use AI tools. Policies are missing, liability is unclear, and data protection is put at risk every day. SIDD implements a complete AI management system under ISO/IEC 42001:2023, documented, auditable, without internal resources.

ISO/IEC 42001:2023 Audit-ready in 4–8 weeks Without internal effort
ISO 42001 AI governance and AI management system for Swiss SMEs
Mandate under Art. 321 SCC Professional secrecy
Swiss provider, Zurich
Fixed fee
Free 30-min consultation
Quote within 24h
Active since 2017

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide

Shadow AI is not an IT problem. It's a liability risk.

Employees use ChatGPT, Copilot, Gemini and dozens of other AI tools, often without management's knowledge, without policies and without checking which data is processed. The consequences:

  • Data breaches through uncontrolled sharing of customer and employee data with external AI services
  • Personal liability of management and the board in the absence of governance (DSG Art. 61, GDPR Art. 83)
  • Reputational damage with customers and partners who increasingly demand evidence of responsible AI use
  • Missing supply-chain security: your customers already ask for ISO 42001-compliant AI governance

ISO/IEC 42001:2023, the world's first certifiable AI standard

ISO 42001 defines the requirements for an AI management system (AIMS). Structurally analogous to ISO 27001: for companies that already run an ISMS, there is no duplicate effort. Specifically, the standard requires:

AreaRequirement
AI inventoryComplete inventory of all AI systems in use and their risk level
PoliciesBinding internal AI policy, usage rules, approval processes
Risk assessmentSystematic assessment of each AI system by purpose and data category
Roles & responsibilitiesClear assignment of who approves, monitors and documents AI use
Supplier controlContractual clauses and due diligence for external AI providers (DPA, TIA)
Continuous improvementAnnual review, audit readiness, adaptation to new systems

From AI inventory to certification readiness, in 30 days

SIDD takes on the complete build-out of the AIMS. You do not need to assign any internal resources.

AI inventory and risk classification (week 1–2)

Inventory of all AI systems in use, assessment of the risk level under ISO 42001 Annex A, prioritisation of the action required.

AI policy and guidelines (week 2–3)

Creation of a binding AI usage policy, approval processes, a provider list with risk status, and training materials for employees.

Contracts and data protection (week 3–4)

Review and adaptation of existing DPAs for AI providers, transfer impact assessments (TIA) for third-country transfers, alignment with DSG/GDPR.

Documentation and audit readiness

Complete AIMS documentation package, internal audit checklist, preparation for external certification by an accredited body (optional).

Not just a consultant. Not just an IT shop. Both.

We are neither a law firm that delivers a standard report nor an IT boutique that forgets about data protection. SIDD combines:

  • Legal expertise: three doctorate-holding lawyers, more than 10 years of international data-protection practice (DSG, GDPR, TDDDG)
  • Technical depth: ISO 27001 lead auditor, CISO-as-a-Service, ISMS experience from regulated mandates (FINMA, NIS2, DORA)
  • Operational delivery: we don't write recommendations, we implement, document and stay on as your fixed point of contact

See also our services External CISO/ISO/Information Security Officer und ISO 27001 and ISMS for the technical basis of your AI governance.

Transparent terms

ServiceDescriptionPrice
ISO 42001 implementation projectAI inventory, policy, contracts, AIMS documentationOn request
Ongoing supportAnnual review, updates, audit supportOn request
Combined with ISMS (ISO 27001)Integrated mandate, no duplicate effortDiscount on request

Final price depends on company size, number of AI systems and existing maturity. No-obligation initial consultation free of charge.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your ISO 42001 AIMS, concretely: LexCommand drafts the AI policy, the Annex A risk classification and the AIMS documentation package as tracked changes with sourced footnotes, and its crosswalk surfaces where your existing ISO 27001 ISMS and your FADP and GDPR duties already cover the requirement.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

Do we have to implement ISO 42001 or only comply with DSG/GDPR?

ISO 42001 is voluntary, not a legal requirement in Switzerland. However, it is increasingly required by customers, partners and insurers as evidence of responsible AI use. Acting in a structured way today avoids rushed corrections tomorrow.

We already have ISO 27001, how much additional effort is involved?

Minimal. ISO 42001 follows the same high-level structure (HLS) as ISO 27001. Existing documents, processes and the ISMS are extended, not rebuilt. In practice: 30 to 40% less effort than a greenfield project.

How long does it take to reach audit readiness?

With SIDD support, typically 4 to 8 weeks, depending on existing maturity. The certification audit by an accredited external body then takes place separately.

Who carries out the mandate at SIDD?

A fixed point of contact from our team, no outsourcing, no subcontracting. You work with the same consultant from kick-off to audit.

Free initial consultation, no obligation

We analyse your current AI use and show you the concrete action required in 30 minutes.