AsteronAsteron

    ISO 42001 AI governance for European healthtech

    Asteron builds the management system needed to govern AI across products and internal operations. We connect AI inventory, accountability, risk and impact assessment, data governance, human oversight, suppliers, monitoring and incidents within one auditable system. The engagement combines ISO/IEC 42001:2023 implementation with EU AI Act readiness for healthtech companies operating in the Netherlands, Germany and the wider European market.

    View ISO 42001 pricing
    • ISO/IEC 42001 AIMS implemented
    • EU AI Act roles and risk classes mapped
    • Product and supplier evidence connected
    • Independent certification readiness prepared

    €14,900 with an existing Compliance Core

    What is ISO/IEC 42001?

    ISO/IEC 42001:2023 is the international management-system standard for organisations that develop, provide or use AI systems. It establishes an Artificial Intelligence Management System, or AIMS, for governing AI risks, opportunities and responsibilities throughout the lifecycle.

    The standard does not prescribe one model architecture or declare that an AI system is safe. It requires the organisation to understand where AI is used, assign accountability, assess impacts, control development and procurement, monitor results and improve the system when products or risks change.

    ISO 42001 can be implemented as a standalone system. It also integrates naturally with ISO 27001, ISO 27701, ISO 13485 and other management systems, allowing established risk, audit, supplier and corrective-action processes to be reused.

    ISO 42001 governs how an organisation makes and evidences AI decisions. It does not replace product validation, medical-device conformity assessment or legal classification under the EU AI Act.

    ISO 42001 and the EU AI Act are complementary

    ISO/IEC 42001
    How does the organisation govern AI consistently?
    A certifiable AI management system covering policy, risk, lifecycle controls, monitoring and improvement.
    EU AI Act
    What legal obligations apply to this AI system and market role?
    Binding requirements based on role, risk category, intended purpose and use context.
    MDR or IVDR
    Is the medical product safe, performant and conformant?
    Medical-device or IVD regulatory evidence and conformity assessment.
    GDPR
    Is personal-data processing lawful and appropriately protected?
    Legal bases, rights, safeguards, transparency and accountability.

    An ISO 42001 certificate may support governance evidence, but it does not create a presumption that every AI system complies with the AI Act, MDR, IVDR or GDPR.

    Who needs an AI management system?

    ISO 42001 is relevant to organisations that:

    • develop AI-enabled medical software or digital-health products;
    • use third-party or general-purpose AI models in a regulated product;
    • deploy AI for clinical, operational or customer-facing decisions;
    • provide AI functionality to hospitals, insurers or research organisations;
    • use AI to process health, genetic or biometric information;
    • procure AI tools across several business functions;
    • need repeatable assessment before approving new AI use cases;
    • face recurring customer, investor or regulatory scrutiny.

    An organisation does not need hundreds of models to benefit. A small number of clinically or commercially important AI systems can create enough risk to require formal ownership, lifecycle evidence and management oversight.

    EU AI Act roles come before obligations

    The same organisation may hold different AI Act roles for different systems.

    Provider

    A provider develops an AI system or has it developed and places it on the EU market or puts it into service under its own name or trademark. A company can become the provider of a third-party system if it substantially modifies it or changes its intended purpose.

    Deployer

    A deployer uses an AI system under its authority, except for personal non-professional use. Healthtech companies may be providers for customer-facing products and deployers for internal AI tools.

    Importer and distributor

    Importers and distributors have separate checks and cooperation obligations when making third-country AI systems available in the EU.

    General-purpose AI value chain

    Companies integrating a general-purpose AI model must distinguish the model provider’s responsibilities from their own obligations for the resulting AI system, intended purpose, integration and use.

    Buying an AI model does not outsource accountability for the healthtech product built around it.

    How the AI Act classifies systems

    Prohibited practices
    Uses considered incompatible with fundamental rights and EU values.
    Must not be developed or deployed in the prohibited form.
    High-risk AI
    Systems creating significant risks to health, safety or fundamental rights under Article 6 and the relevant annexes.
    May include AI that forms a safety component of a regulated product or is itself a regulated product requiring third-party conformity assessment.
    Transparency-risk systems
    Systems subject to disclosure or information duties, such as certain human-facing or synthetic-content systems.
    May affect chatbots, patient interaction, generated content or AI-assisted communication.
    Other AI systems
    Systems outside prohibited, high-risk and specific transparency categories.
    They may still require GDPR, product, contractual, security and ISO 42001 controls.

    Not every healthcare or medical AI system is automatically high-risk. Classification depends on intended purpose, product regulation, market role and whether third-party conformity assessment is required.

    AI in medical devices and IVD software

    AI incorporated into medical-device or IVD software may be high-risk under the AI Act when:

    1. the AI is itself a regulated product or a safety component of one; and
    2. the product requires third-party conformity assessment under the applicable EU product legislation.

    For these systems, AI Act requirements must be coordinated with MDR or IVDR quality management, risk management, clinical or performance evidence, software lifecycle, cybersecurity and post-market monitoring.

    The evidence should form one controlled product system. Separate AI, medical-device and privacy files that describe different intended purposes, data or human-oversight arrangements create avoidable regulatory risk.

    What the AI management system covers

    Governance and accountability

    • AIMS scope and organisational context
    • AI policy and objectives
    • AI inventory and ownership
    • Provider, deployer and value-chain roles
    • AI risk and opportunity methodology
    • Impact-assessment criteria
    • Management reporting and escalation
    • Internal audit and continual improvement

    Lifecycle and operational controls

    • Data and model governance
    • Development and validation checkpoints
    • Transparency and documentation
    • Human-oversight design
    • Third-party model and supplier governance
    • Performance, drift and incident monitoring
    • Change and substantial-modification assessment
    • Retirement and decommissioning controls

    Controls are applied according to the risk and context of each AI system. A low-impact internal tool should not receive the same evidence burden as diagnostic software influencing patient care.

    From AI inventory to certification readiness

    1. Scope and AI inventory

      Identify AI systems in development, production and procurement. Record intended purpose, users, affected people, data, models, suppliers and deployment markets.

    2. Role and regulatory classification

      Map provider, deployer, importer and distributor roles. Assess prohibited practices, high-risk conditions, transparency duties and interaction with MDR, IVDR and GDPR.

    3. Risk and impact assessment

      Evaluate safety, privacy, bias, robustness, security, misuse, human oversight and effects on individuals or groups. Define risk acceptance and escalation authority.

    4. Lifecycle controls

      Integrate governance into design, procurement, validation, release, supplier management, monitoring, incidents, change and retirement.

    5. Operation and evidence

      Run representative assessments, resolve priority gaps and retain evidence that owners follow the system in actual product and purchasing decisions.

    6. Audit and continual improvement

      Complete internal audit, management review and corrective actions. Prepare for independent ISO 42001 certification where certification is included.

    What Asteron delivers

    Management-system foundation

    • ISO 42001 scope and implementation plan
    • AI policy and governance model
    • AI inventory and classification structure
    • Responsibility and decision matrix
    • AI risk and impact methodology
    • Objectives and management reporting
    • Internal-audit programme
    • Management-review preparation

    Operational AI evidence

    • AI system assessment workflow
    • Provider and deployer role mapping
    • Data and model governance process
    • Human-oversight requirements
    • Supplier and GPAI assessment
    • Validation and release evidence model
    • Monitoring and incident process
    • EU AI Act readiness roadmap

    The precise deliverables depend on the number and risk of AI systems, product roles and existing management systems. Product testing, clinical validation, legal opinions and technical implementation are included only when expressly stated in the proposal.

    EU AI Act application timeline

    1 August 2024
    The EU AI Act entered into force.
    2 February 2025
    Rules on prohibited AI practices and AI-literacy obligations began to apply.
    2 August 2025
    Governance provisions and obligations for general-purpose AI models began to apply.
    2 August 2026
    Under the enacted AI Act, most remaining provisions are scheduled to apply, subject to specific exceptions and subsequent legislative amendments.
    High-risk timeline under review
    As of July 2026, an EU political agreement on the AI Omnibus proposes later application dates for high-risk requirements: December 2027 for certain Annex III systems and August 2028 for AI embedded in regulated products.
    The revised high-risk dates should not be presented as final law until the amending legislation completes adoption and publication. The implementation roadmap must track the final legal text and Commission guidance.

    Netherlands, Germany and wider European deployment

    The AI Act is directly applicable across the EU, but supervision, sector enforcement and market-surveillance coordination are organised nationally.

    For the Netherlands, healthtech companies should connect AI governance with Dutch privacy, healthcare, medical-device and information-security expectations, including NEN 7510 where applicable. National competent-authority arrangements and sector guidance should be tracked as implementation develops.

    For Germany, the roadmap may need to account for federal and state data-protection supervision, medical-device authorities, healthcare-sector requirements and local worker or patient information duties.

    A European AI system should have one controlled intended purpose, classification and evidence base. Dutch, German and other market requirements should be managed as traceable extensions rather than contradictory country files.

    How ISO 42001 connects to other Asteron frameworks

    ISO 27001
    Provides information-security risk management and reusable governance processes.
    ISO 27701
    Manages privacy responsibilities for personal data used by AI systems.
    ISO 13485
    Provides medical-device quality management for AI-enabled medical products.
    ISO 14971
    Structures medical-device product-risk management.
    IEC 62304
    Provides controlled software lifecycle processes for medical-device software.
    IEC 81001-5-1
    Supports secure lifecycle and cybersecurity evidence for health software.
    MDR and IVDR
    Determine medical-device conformity obligations that may trigger high-risk AI classification.

    Pricing

    From an existing Compliance Core
    €14,900

    Reuses established governance, risk, supplier, audit, evidence and continual-improvement processes. The work focuses on the AI inventory, AIMS-specific controls, AI risk and impact assessment and EU AI Act readiness.

    As the first framework project
    €19,900

    Establishes the required management-system foundation together with ISO 42001 and AI governance controls.

    These published starting prices apply to the initial 10–50 employee band shown on the Pricing page. Larger organisations, multiple entities or extensive high-risk AI portfolios are priced using the applicable company-size and complexity band.

    The existing-Core route saves €5,000 through reuse of established governance and evidence processes.

    Payment terms (fixed-scope)
    • 40% at signing
    • 40% when the agreed audit-ready milestone is reached
    • 20% after certification

    Prices exclude VAT where applicable.

    View full pricing

    Independent certification and external costs

    Asteron builds the AI management system, prepares the evidence and coordinates certification. Asteron cannot issue the ISO 42001 certificate or audit its own implementation independently because that would create a conflict of interest.

    The client selects, contracts and pays the independent certification body directly. The certification-body payment never passes through Asteron.

    Indicative external certification fees from the approved Pricing page are:

    • €4,500–€6,000 for organisations with 10–50 employees
    • €6,000–€9,000 for organisations with 51–150 employees

    The certification body confirms its own quotation based on scope, locations, headcount, AI portfolio and audit duration.

    ISO certification fees do not include medical-device notified-body assessment, product testing, AI Act conformity work or specialist legal opinions. Those costs are quoted separately by the relevant independent organisation.

    If certification is not achieved because an Asteron deliverable is incomplete or deficient, Asteron corrects that work at no additional professional fee within the contracted scope. This does not override the independent auditor’s judgement and does not cover new AI systems, changed products or client-side implementation failures.

    Responsibilities

    Asteron

    • Builds the agreed ISO 42001 management system
    • Maps AI Act roles and classification assumptions
    • Connects AI governance with existing frameworks
    • Structures risk, impact and lifecycle evidence
    • Prepares process owners and certification evidence
    • Coordinates independent assessment

    Your organisation

    • Provides an accurate inventory of AI systems and suppliers
    • Owns intended-purpose and product decisions
    • Assigns accountable AI and business owners
    • Approves risk acceptance and deployment decisions
    • Implements required product and technical changes
    • Operates monitoring and human oversight
    • Contracts and pays independent assessors

    Frequently asked questions

    What is ISO/IEC 42001?

    ISO/IEC 42001 is the international management-system standard for organisations that develop, provide or use AI systems.

    Is ISO 42001 certification mandatory?

    No. Certification is voluntary. It can provide independent assurance that the organisation operates an AI management system conforming to the standard.

    Does ISO 42001 certification prove AI Act compliance?

    No. It supports governance evidence, but AI Act compliance depends on each system’s role, classification, intended purpose and applicable legal requirements.

    Is every healthtech AI system high-risk?

    No. High-risk classification depends on Article 6 of the AI Act, the intended purpose and whether the AI is part of a regulated product requiring third-party conformity assessment.

    What is the difference between a provider and deployer?

    A provider places an AI system on the market or into service under its name. A deployer uses an AI system under its authority. One organisation can hold both roles for different systems.

    Do third-party AI models need to appear in the inventory?

    Yes. The organisation must understand externally supplied models, services and embedded AI components that affect its products or operations.

    Does the AI Act apply to internal AI tools?

    Potentially. Obligations depend on the use case and role. Even systems outside high-risk categories may be subject to prohibited-practice, literacy, transparency, privacy or employment requirements.

    Does ISO 42001 cover clinical validation?

    It governs the process for managing validation and evidence. It does not replace product-specific clinical or performance evaluation.

    How much does ISO 42001 implementation cost?

    For the initial published company-size band, implementation costs €14,900 from an existing Compliance Core or €19,900 as the first framework project. External certification fees are separate.

    Who issues the ISO 42001 certificate?

    An independent certification body issues the certificate. Asteron prepares the system but cannot independently certify its own work.

    Official references

    • – ISO/IEC 42001:2023 — ISO
    • – Regulation (EU) 2024/1689 — EUR-Lex
    • – European Commission AI Act overview
    • – European Commission AI Act Service Desk and Single Information Platform
    • – Current Commission guidance on high-risk AI classification
    • – MDR and IVDR guidance on AI-enabled medical products
    • – Official AI Act amendment and timeline sources when finalised

    Last reviewed: July 2026

    Asteron is not endorsed by or partnered with the European Commission, any national competent authority or certification body.

    Build AI governance that can survive product, regulatory and model change

    We will assess your AI portfolio, market roles, existing management systems and European regulatory exposure, then define the practical route to ISO 42001 certification and AI Act readiness.

    View ISO 42001 pricing