Your employees use AI tools. Policies are missing, liability is unclear, and data protection is put at risk every day. SIDD implements a complete AI management system under ISO/IEC 42001:2023, documented, auditable, without internal resources.
Working for regulated industries and SMEs
Employees use ChatGPT, Copilot, Gemini and dozens of other AI tools, often without management's knowledge, without policies and without checking which data is processed. The consequences:
ISO 42001 defines the requirements for an AI management system (AIMS). Structurally analogous to ISO 27001: for companies that already run an ISMS, there is no duplicate effort. Specifically, the standard requires:
| Area | Requirement |
|---|---|
| AI inventory | Complete inventory of all AI systems in use and their risk level |
| Policies | Binding internal AI policy, usage rules, approval processes |
| Risk assessment | Systematic assessment of each AI system by purpose and data category |
| Roles & responsibilities | Clear assignment of who approves, monitors and documents AI use |
| Supplier control | Contractual clauses and due diligence for external AI providers (DPA, TIA) |
| Continuous improvement | Annual review, audit readiness, adaptation to new systems |
SIDD takes on the complete build-out of the AIMS. You do not need to assign any internal resources.
Inventory of all AI systems in use, assessment of the risk level under ISO 42001 Annex A, prioritisation of the action required.
Creation of a binding AI usage policy, approval processes, a provider list with risk status, and training materials for employees.
Review and adaptation of existing DPAs for AI providers, transfer impact assessments (TIA) for third-country transfers, alignment with DSG/GDPR.
Complete AIMS documentation package, internal audit checklist, preparation for external certification by an accredited body (optional).
We are neither a law firm that delivers a standard report nor an IT boutique that forgets about data protection. SIDD combines:
See also our services External CISO/ISO/Information Security Officer und ISO 27001 and ISMS for the technical basis of your AI governance.
| Service | Description | Price |
|---|---|---|
| ISO 42001 implementation project | AI inventory, policy, contracts, AIMS documentation | On request |
| Ongoing support | Annual review, updates, audit support | On request |
| Combined with ISMS (ISO 27001) | Integrated mandate, no duplicate effort | Discount on request |
Final price depends on company size, number of AI systems and existing maturity. No-obligation initial consultation free of charge.
Our tool: LexCommand
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your ISO 42001 AIMS, concretely: LexCommand drafts the AI policy, the Annex A risk classification and the AIMS documentation package as tracked changes with sourced footnotes, and its crosswalk surfaces where your existing ISO 27001 ISMS and your FADP and GDPR duties already cover the requirement.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
ISO 42001 is voluntary, not a legal requirement in Switzerland. However, it is increasingly required by customers, partners and insurers as evidence of responsible AI use. Acting in a structured way today avoids rushed corrections tomorrow.
Minimal. ISO 42001 follows the same high-level structure (HLS) as ISO 27001. Existing documents, processes and the ISMS are extended, not rebuilt. In practice: 30 to 40% less effort than a greenfield project.
With SIDD support, typically 4 to 8 weeks, depending on existing maturity. The certification audit by an accredited external body then takes place separately.
A fixed point of contact from our team, no outsourcing, no subcontracting. You work with the same consultant from kick-off to audit.
We analyse your current AI use and show you the concrete action required in 30 minutes.