ISO 42001 AI governance for European healthtech
Asteron builds the management system needed to govern AI across products and internal operations. We connect AI inventory, accountability, risk and impact assessment, data governance, human oversight, suppliers, monitoring and incidents within one auditable system. The engagement combines ISO/IEC 42001:2023 implementation with EU AI Act readiness for healthtech companies operating in the Netherlands, Germany and the wider European market.
- ISO/IEC 42001 AIMS implemented
- EU AI Act roles and risk classes mapped
- Product and supplier evidence connected
- Independent certification readiness prepared
€14,900 with an existing Compliance Core
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the international management-system standard for organisations that develop, provide or use AI systems. It establishes an Artificial Intelligence Management System, or AIMS, for governing AI risks, opportunities and responsibilities throughout the lifecycle.
The standard does not prescribe one model architecture or declare that an AI system is safe. It requires the organisation to understand where AI is used, assign accountability, assess impacts, control development and procurement, monitor results and improve the system when products or risks change.
ISO 42001 can be implemented as a standalone system. It also integrates naturally with ISO 27001, ISO 27701, ISO 13485 and other management systems, allowing established risk, audit, supplier and corrective-action processes to be reused.
ISO 42001 governs how an organisation makes and evidences AI decisions. It does not replace product validation, medical-device conformity assessment or legal classification under the EU AI Act.
ISO 42001 and the EU AI Act are complementary
An ISO 42001 certificate may support governance evidence, but it does not create a presumption that every AI system complies with the AI Act, MDR, IVDR or GDPR.
Who needs an AI management system?
ISO 42001 is relevant to organisations that:
- – develop AI-enabled medical software or digital-health products;
- – use third-party or general-purpose AI models in a regulated product;
- – deploy AI for clinical, operational or customer-facing decisions;
- – provide AI functionality to hospitals, insurers or research organisations;
- – use AI to process health, genetic or biometric information;
- – procure AI tools across several business functions;
- – need repeatable assessment before approving new AI use cases;
- – face recurring customer, investor or regulatory scrutiny.
An organisation does not need hundreds of models to benefit. A small number of clinically or commercially important AI systems can create enough risk to require formal ownership, lifecycle evidence and management oversight.
EU AI Act roles come before obligations
The same organisation may hold different AI Act roles for different systems.
Provider
A provider develops an AI system or has it developed and places it on the EU market or puts it into service under its own name or trademark. A company can become the provider of a third-party system if it substantially modifies it or changes its intended purpose.
Deployer
A deployer uses an AI system under its authority, except for personal non-professional use. Healthtech companies may be providers for customer-facing products and deployers for internal AI tools.
Importer and distributor
Importers and distributors have separate checks and cooperation obligations when making third-country AI systems available in the EU.
General-purpose AI value chain
Companies integrating a general-purpose AI model must distinguish the model provider’s responsibilities from their own obligations for the resulting AI system, intended purpose, integration and use.
Buying an AI model does not outsource accountability for the healthtech product built around it.
How the AI Act classifies systems
Not every healthcare or medical AI system is automatically high-risk. Classification depends on intended purpose, product regulation, market role and whether third-party conformity assessment is required.
AI in medical devices and IVD software
AI incorporated into medical-device or IVD software may be high-risk under the AI Act when:
- the AI is itself a regulated product or a safety component of one; and
- the product requires third-party conformity assessment under the applicable EU product legislation.
For these systems, AI Act requirements must be coordinated with MDR or IVDR quality management, risk management, clinical or performance evidence, software lifecycle, cybersecurity and post-market monitoring.
The evidence should form one controlled product system. Separate AI, medical-device and privacy files that describe different intended purposes, data or human-oversight arrangements create avoidable regulatory risk.
What the AI management system covers
Governance and accountability
- – AIMS scope and organisational context
- – AI policy and objectives
- – AI inventory and ownership
- – Provider, deployer and value-chain roles
- – AI risk and opportunity methodology
- – Impact-assessment criteria
- – Management reporting and escalation
- – Internal audit and continual improvement
Lifecycle and operational controls
- – Data and model governance
- – Development and validation checkpoints
- – Transparency and documentation
- – Human-oversight design
- – Third-party model and supplier governance
- – Performance, drift and incident monitoring
- – Change and substantial-modification assessment
- – Retirement and decommissioning controls
Controls are applied according to the risk and context of each AI system. A low-impact internal tool should not receive the same evidence burden as diagnostic software influencing patient care.
From AI inventory to certification readiness
Scope and AI inventory
Identify AI systems in development, production and procurement. Record intended purpose, users, affected people, data, models, suppliers and deployment markets.
Role and regulatory classification
Map provider, deployer, importer and distributor roles. Assess prohibited practices, high-risk conditions, transparency duties and interaction with MDR, IVDR and GDPR.
Risk and impact assessment
Evaluate safety, privacy, bias, robustness, security, misuse, human oversight and effects on individuals or groups. Define risk acceptance and escalation authority.
Lifecycle controls
Integrate governance into design, procurement, validation, release, supplier management, monitoring, incidents, change and retirement.
Operation and evidence
Run representative assessments, resolve priority gaps and retain evidence that owners follow the system in actual product and purchasing decisions.
Audit and continual improvement
Complete internal audit, management review and corrective actions. Prepare for independent ISO 42001 certification where certification is included.
What Asteron delivers
Management-system foundation
- – ISO 42001 scope and implementation plan
- – AI policy and governance model
- – AI inventory and classification structure
- – Responsibility and decision matrix
- – AI risk and impact methodology
- – Objectives and management reporting
- – Internal-audit programme
- – Management-review preparation
Operational AI evidence
- – AI system assessment workflow
- – Provider and deployer role mapping
- – Data and model governance process
- – Human-oversight requirements
- – Supplier and GPAI assessment
- – Validation and release evidence model
- – Monitoring and incident process
- – EU AI Act readiness roadmap
The precise deliverables depend on the number and risk of AI systems, product roles and existing management systems. Product testing, clinical validation, legal opinions and technical implementation are included only when expressly stated in the proposal.
EU AI Act application timeline
Netherlands, Germany and wider European deployment
The AI Act is directly applicable across the EU, but supervision, sector enforcement and market-surveillance coordination are organised nationally.
For the Netherlands, healthtech companies should connect AI governance with Dutch privacy, healthcare, medical-device and information-security expectations, including NEN 7510 where applicable. National competent-authority arrangements and sector guidance should be tracked as implementation develops.
For Germany, the roadmap may need to account for federal and state data-protection supervision, medical-device authorities, healthcare-sector requirements and local worker or patient information duties.
A European AI system should have one controlled intended purpose, classification and evidence base. Dutch, German and other market requirements should be managed as traceable extensions rather than contradictory country files.
How ISO 42001 connects to other Asteron frameworks
Pricing
Reuses established governance, risk, supplier, audit, evidence and continual-improvement processes. The work focuses on the AI inventory, AIMS-specific controls, AI risk and impact assessment and EU AI Act readiness.
Establishes the required management-system foundation together with ISO 42001 and AI governance controls.
These published starting prices apply to the initial 10–50 employee band shown on the Pricing page. Larger organisations, multiple entities or extensive high-risk AI portfolios are priced using the applicable company-size and complexity band.
The existing-Core route saves €5,000 through reuse of established governance and evidence processes.
- – 40% at signing
- – 40% when the agreed audit-ready milestone is reached
- – 20% after certification
Prices exclude VAT where applicable.
Independent certification and external costs
Asteron builds the AI management system, prepares the evidence and coordinates certification. Asteron cannot issue the ISO 42001 certificate or audit its own implementation independently because that would create a conflict of interest.
The client selects, contracts and pays the independent certification body directly. The certification-body payment never passes through Asteron.
Indicative external certification fees from the approved Pricing page are:
- – €4,500–€6,000 for organisations with 10–50 employees
- – €6,000–€9,000 for organisations with 51–150 employees
The certification body confirms its own quotation based on scope, locations, headcount, AI portfolio and audit duration.
ISO certification fees do not include medical-device notified-body assessment, product testing, AI Act conformity work or specialist legal opinions. Those costs are quoted separately by the relevant independent organisation.
Responsibilities
Asteron
- – Builds the agreed ISO 42001 management system
- – Maps AI Act roles and classification assumptions
- – Connects AI governance with existing frameworks
- – Structures risk, impact and lifecycle evidence
- – Prepares process owners and certification evidence
- – Coordinates independent assessment
Your organisation
- – Provides an accurate inventory of AI systems and suppliers
- – Owns intended-purpose and product decisions
- – Assigns accountable AI and business owners
- – Approves risk acceptance and deployment decisions
- – Implements required product and technical changes
- – Operates monitoring and human oversight
- – Contracts and pays independent assessors
Frequently asked questions
What is ISO/IEC 42001?
ISO/IEC 42001 is the international management-system standard for organisations that develop, provide or use AI systems.
Is ISO 42001 certification mandatory?
No. Certification is voluntary. It can provide independent assurance that the organisation operates an AI management system conforming to the standard.
Does ISO 42001 certification prove AI Act compliance?
No. It supports governance evidence, but AI Act compliance depends on each system’s role, classification, intended purpose and applicable legal requirements.
Is every healthtech AI system high-risk?
No. High-risk classification depends on Article 6 of the AI Act, the intended purpose and whether the AI is part of a regulated product requiring third-party conformity assessment.
What is the difference between a provider and deployer?
A provider places an AI system on the market or into service under its name. A deployer uses an AI system under its authority. One organisation can hold both roles for different systems.
Do third-party AI models need to appear in the inventory?
Yes. The organisation must understand externally supplied models, services and embedded AI components that affect its products or operations.
Does the AI Act apply to internal AI tools?
Potentially. Obligations depend on the use case and role. Even systems outside high-risk categories may be subject to prohibited-practice, literacy, transparency, privacy or employment requirements.
Does ISO 42001 cover clinical validation?
It governs the process for managing validation and evidence. It does not replace product-specific clinical or performance evaluation.
How much does ISO 42001 implementation cost?
For the initial published company-size band, implementation costs €14,900 from an existing Compliance Core or €19,900 as the first framework project. External certification fees are separate.
Who issues the ISO 42001 certificate?
An independent certification body issues the certificate. Asteron prepares the system but cannot independently certify its own work.
Official references
- – ISO/IEC 42001:2023 — ISO
- – Regulation (EU) 2024/1689 — EUR-Lex
- – European Commission AI Act overview
- – European Commission AI Act Service Desk and Single Information Platform
- – Current Commission guidance on high-risk AI classification
- – MDR and IVDR guidance on AI-enabled medical products
- – Official AI Act amendment and timeline sources when finalised
Last reviewed: July 2026
Asteron is not endorsed by or partnered with the European Commission, any national competent authority or certification body.
Related services and frameworks
Build AI governance that can survive product, regulatory and model change
We will assess your AI portfolio, market roles, existing management systems and European regulatory exposure, then define the practical route to ISO 42001 certification and AI Act readiness.
