AI Governance Training

    ISO/IEC 42001 Training for Organisations

    ISO/IEC 42001 is the international standard for AI management systems — the framework that helps organisations govern how they build and use AI responsibly. Day Seven currently delivers live workshops and train-the-trainer support covering standard fundamentals, roles and responsibilities, risk-assessment awareness and audit preparation. Self-paced Academy content remains in development. We are a training partner, not a certification body.

    What is ISO/IEC 42001?

    ISO/IEC 42001 is the international management system standard for artificial intelligence. It gives organisations a structured way to govern AI — covering leadership accountability, AI policy, risk and impact assessment, lifecycle controls, supplier oversight and continual improvement.

    In practice it does for AI what ISO 27001 does for information security: a documented, auditable set of controls that shows regulators, customers and boards that your use of AI is deliberate and responsible. It applies whether you build AI systems, deploy third-party AI, or both.

    Who needs ISO/IEC 42001 training?

    • Organisations deploying AI at scale and needing a defensible management system around it
    • Regulated industries — financial services, healthcare, legal, public sector — where AI oversight is now expected
    • Suppliers being asked by enterprise customers for AI assurance or evidence of governance
    • Teams aligning their AI practices with the EU AI Act and other emerging global regulation
    • L&D, risk, compliance and CIO teams preparing staff before an ISO/IEC 42001 implementation project begins

    What our ISO/IEC 42001 training covers

    Awareness and readiness training — designed so your people understand the standard and their role under it long before an auditor walks in.

    Standard fundamentals

    What ISO/IEC 42001 is, how it relates to other management-system standards (ISO 27001, ISO 9001) and why it matters for AI-using organisations.

    Roles and responsibilities

    Who does what under an AI management system — leadership, AI owners, risk, data, legal, and the day-to-day teams building or using AI.

    Risk and impact assessment awareness

    How AI risk and impact assessments work in practice, what good looks like, and how staff should flag and escalate concerns.

    Policy and safe-use alignment

    Turning your AI policy and the standard's controls into practical do's and don'ts staff will actually follow at their desks.

    Preparing for audit

    What internal and external auditors typically look for, what evidence teams need to be ready to show, and how staff should engage with an audit conversation.

    How we deliver it

    Live workshops and train-the-trainer are available now. Self-paced digital modules are planned but remain in development.

    Bespoke digital learning modules — in development

    Planned self-paced content in the Day Seven Academy style. This format is in development and is not currently available to buy.

    Live workshops

    In-person or online workshops for leadership, AI owners and cross-functional teams, focused on real scenarios from your organisation.

    Train-the-trainer

    Enable your internal L&D, risk or compliance leads to keep training fresh and roll it out across regions and business units.

    Frequently asked questions

    ISO/IEC 42001 is the international standard for AI management systems. It sets out how an organisation should govern its use and development of AI — covering leadership accountability, risk and impact assessment, lifecycle controls, and continual improvement — so that AI is used responsibly and can be audited.

    Training itself is not legally mandatory. However, if your organisation is implementing ISO/IEC 42001, aligning with the EU AI Act, or being asked for AI assurance by enterprise customers, staff awareness and role-based training are a practical requirement — auditors and customers will expect evidence that your people understand the standard and their responsibilities under it.

    No. Day Seven is a training and enablement partner, not a certification body. Formal certification to ISO/IEC 42001 is issued by accredited certification bodies following an independent audit. What we do is prepare your people and organisation — awareness, role-based training and implementation readiness — so that when your certification body arrives, your teams know the standard and how it applies to their work.

    A focused awareness programme for a leadership team or a single business unit can be delivered in a few weeks. A full staff rollout across a larger organisation, with role-based paths for leadership, AI owners and general staff, typically runs 2–6 months alongside your implementation project. We scope this openly around your timeline and audit target.

    Yes. Every programme is built around your sector, your AI use cases and your existing policies. We regularly tailor content for regulated industries such as financial services, healthcare, legal and the public sector, as well as for enterprise suppliers being asked for AI assurance by their customers.

    Get your people ready for ISO/IEC 42001

    Tell us where you are in your ISO/IEC 42001 journey — awareness, implementation readiness or refresher training. We will come back with a tailored programme.

    For a practical starting point, read the AI governance framework for UK businesses.