Idest GmbH is among the first organizations in the German-speaking region to achieve certification to ISO/IEC 42001 by DQS. The decision was not driven by regulatory pressure, but by a strategic objective: Idest wanted to establish a robust AI governance framework within its own organization before advising customers on its implementation. This practical case study illustrates how the company's organic use of AI evolved into a certified AI management system and shares the experiences Idest gained throughout its certification journey with DQS.

Why Responsible AI Use Matters

Responsible AI use creates transparency, clear responsibilities, and reliable processes. It helps companies systematically manage risks and meet regulatory requirements in a traceable manner. At the same time, it strengthens the trust of customers and partners – and thus the company’s own market position. 

A customized AI Management System (AIMS) provides the organizational framework for this. It reveals where and how AI is used within the company, defines responsibilities, and ensures that opportunities and risks are assessed according to consistent criteria. In this way, the use of AI is not left to chance but is permanently embedded in controlled and auditable processes.

ISO 42001 supports organizations in establishing these structures systematically and demonstrating them credibly to external stakeholders. This not only facilitates compliance with regulatory requirements but also strengthens communication with customers, business partners, and contracting authorities. As this ISO/IEC 42001 case study illustrates, a demonstrably responsible approach to AI is increasingly becoming a key differentiator and competitive advantage – particularly in regulated industries and in public procurement and tendering processes.

Why Commit to ISO/IEC 42001 Early?

Idest views ISO 42001 not as a reaction to external pressure, but as a strategic investment in its artificial intelligence service concept. The company wanted to gain its own practical experience, strengthen its consulting expertise, and prepare early on for the increasing demands of customers and clients. 

Many organizations only begin addressing new management system standards when customers, regulatory authorities, or business partners require evidence of compliance.

Idest deliberately took a different approach with regard to ISO 42001: “In our experience, a proactive approach – without external pressure and driven by strong intrinsic motivation – is always the better way,” explains Managing Director Hendrik Schlademann. And he knows what he’s talking about: After all, the Eschborn-based IT consulting company has been supporting clients in the financial and public sectors for many years on sensitive topics such as data protection, information security, and AI governance. As trusted advisors, the consultants have already guided countless organizations through the implementation of regulatory requirements – most recently, with increasing frequency in the context of AI usage.

ISO 42001 Checklist_EN
Loading...
Free White Paper Offers Guidance

ISO/IEC 42001 – Checklist

This checklist provides a structured starting point for identifying how AI is used within your organization. It helps you assess existing AI governance structures and better understand the key requirements of the international ISO/IEC 42001 standard.

For the two Idest managing directors, Hendrik Schlademann and Christian Specker, it was clear from the very beginning: Anyone who wants to credibly advise companies on the new ISO 42001 standard should ideally have firsthand experience with the certification process. As Hendrik Schlademann puts it: “To provide good advice, you need to have experienced the challenges your clients face yourself.”

The decision to pursue certification became even more compelling as ISO/IEC 42001 increasingly appeared as a preferred – and in some cases mandatory – requirement in tenders, particularly in the public sector. “At that point, we knew it was time to gain first-hand experience and position ourselves as an early adopter,” says Christian Specker. “Our decision was not a reaction to immediate pressure but a strategic investment in our future capabilities and credibility.”

 

Why Is Responsible AI Use a Mark of Trust and Competence?

Clear governance, transparent processes, and effective safeguards demonstrate that an organization is able to manage AI responsibly. At the same time, practical implementation experience provides tangible proof of expertise – as the ISO/IEC 42001 certification journey of Idest illustrates.

When Idest decided to implement the ISO standard, generative AI tools – most notably ChatGPT – had already become an integral part of everyday work, as they had in many other organizations. The team recognized the significant productivity gains these technologies could deliver, while also understanding the new expectations around transparency, risk management, and compliance that accompany organization-wide AI adoption. This created a strong incentive to implement an AI management system in practice.

This is precisely where ISO 42001 comes in: The management system standard establishes a structured framework for the responsible use of AI systems and requires, among other things, clear responsibilities, risk assessments, training, documentation, and procedures for continuous improvement.

The objective is twofold. Internally, the standard helps organizations understand the maturity of their AI governance and identify areas for improvement. Externally, customers and business partners increasingly expect transparency about which AI systems are being used, how risks are assessed, and what safeguards are in place. Particularly in regulated industries, simply claiming to use AI responsibly is no longer sufficient – organizations are expected to demonstrate it through transparent processes and credible evidence.

Our free whitepaper offers practical guidance and expert insights into ISO 42001, making it a valuab
Loading...
Free White Paper

AI Governance with ISO/IEC 42001

Valuable information on AI management systems

To ensure the responsible use of AI, companies need clear governance structures. ISO/IEC 42001 offers a risk-based approach to transparent and traceable management. Our free white paper offers in-depth insights into the standard and its requirements.

Certification provides exactly this level of transparency, explains Hendrik Schlademann: “We wanted the audit to clearly demonstrate that our use of AI is not left to chance but follows defined structures and processes. At the same time, implementing a certified AI management system has strengthened our consulting expertise. Having applied the requirements of the standard ourselves, we understand the practical challenges organizations face – from identifying relevant use cases to risk assessment and documentation.”

 

ISO/IEC 42001 in Practice – How Did Idest Transform Organic AI Use into a Certified AIMS?

Idest began by systematically identifying the AI services and use cases already in operation. The company then introduced controlled AI tools and developed a tailored AI Management System (AIMS). Existing management systems provided a solid foundation but were enhanced with governance processes and controls specifically designed to address AI-related risks.

The process started with a simple question: Which AI tools are we actually using, for what purpose, and with what data? This initial assessment led to the creation of an AI inventory, followed by the documentation of all relevant use cases. Based on these findings, the project team was able to provide employees with approved, high-performing AI tools that met their day-to-day needs – avoiding the risks associated with uncontrolled “shadow AI.”

“When we evaluated our use cases, we concluded that all scenarios relevant to our business – including research, text analysis, and proposal development – could be effectively supported with ChatGPT,” explains Idest Managing Director Christian Specker. “We therefore decided to roll out ChatGPT Business across the organization as our first step – with training exclusion enabled, a comprehensive AI policy, and dedicated user accounts for every employee.”

To establish the foundations for the ISO/IEC 42001-compliant use of ChatGPT, the project team designed and implemented a tailored AI Management System (AIMS). Key elements include:

  • An AI policy defining roles, responsibilities, and rules for AI use
  • An AI register documenting all AI use cases
  • Structured risk and opportunity assessments
  • Processes for training, incident management, and continual improvement
  • Data protection and compliance assessments for individual AI use cases

When designing the AIMS, Idest was able to build on a robust foundation, as the consulting company has been using certified management systems in accordance with ISO 9001 (quality management) and ISO 14001 (environmental management) for several years. The company was therefore already well-versed in the basic requirements of the Harmonized Structure (HS) of the ISO standards and management systems and was able to adopt and expand upon many of these guidelines. 

At the same time, implementing an AI management system in practice demonstrates that effective AI governance brings with it a range of new and distinct challenges. As this ISO/IEC 42001 case study shows, AI-related risks cannot simply be managed in the same way as traditional quality or information security risks. Issues such as hallucinations, incorrect outputs, data leakage, bias, and a lack of transparency require dedicated risk assessment methods and appropriate control mechanisms.

 

ISO/IEC 42001 in Practice – What Is the Role of Independent Certification?

Certification of the AI management system by an independent third party confirms that the implemented structures not only exist in theory but also meet the requirements of ISO/IEC 42001 and are effective in practice. At the same time, it provides a robust, external assessment of the level of maturity achieved. 

With the successful rollout of its AI Management System, Idest had established the foundations for secure and compliant AI use. However, for the company's managing directors, one important milestone remained: an independent audit and certification by an external certification body.

As Christian Specker explains: “Especially with a relatively new standard such as ISO/IEC 42001, the key question is how robust your own processes really are. Internal policies and self-assessments provide valuable guidance, but only an independent certification allows you to benchmark your organization reliably. That's why we asked DQS to audit our AI Management System – marking our first collaboration with a certification body known for its rigorous auditing approach.”

The audit was intended to verify whether the measures taken actually met the standard’s requirements and had been effectively embedded within the organization. In doing so, the auditor evaluates not so much the individual documents as the interrelationship between governance, risk analysis, responsibilities, controls, and practical implementation, explains Peter Mezger, the DQS auditor who conducted the certification:  

“During the audit, we look above all for a clear and consistent governance approach. We assess whether the organization has correctly identified and prioritized its AI-related risks, whether appropriate measures have been implemented in response, and whether these processes are designed to be effective and reviewed on a regular basis. With Idest, it was immediately evident that the organization was already very familiar with the Harmonized Structure. As a result, we were able to award the certificate at the first attempt without any nonconformities. Given that this was also our first ISO/IEC 42001 audit, it was certainly an encouraging milestone for everyone involved.”

What Are the Benefits of ISO/IEC 42001 Certification?

Certification provides organizations with greater transparency over their use of AI, strengthens risk awareness, and offers customers objective evidence of reliable governance processes. At the same time, implementing an AI Management System enhances organizational credibility and strengthens consulting expertise through proven practical experience.

As with most certifications, the actual benefits of the project for Idest extended far beyond the audit and confirmation of compliance:

  • Idest gained complete transparency regarding the use of AI within the company. Roles and responsibilities were clearly defined, processes were standardized, and AI-related risks were assessed systematically.
  • The project improved internal awareness. Employees now have a better understanding of the opportunities AI offers, as well as the risks associated with its use. This aspect in particular is often underestimated – after all, most policy violations do not stem from malicious intent, but from a lack of understanding. 
  • Another benefit lies in communication with customers. The certification provides objective proof that Idest takes a structured and systematic approach to AI, data protection, risk management, and governance. This facilitates discussions with customers and reduces the effort required for compliance and supplier audits. 
  • The certification has strengthened Idest’s credibility and consulting services. The experience gained from our own implementation is now directly incorporated into client projects. Our consultants know the requirements of the standard not only from training or technical literature, but from their own practical implementation.

 

AI Management Systems in Practice – Why ISO/IEC 42001 Can Become a Competitive Advantage

ISO/IEC 42001 enables organizations to demonstrate the responsible use of AI in a credible way, address regulatory requirements systematically, and build trust with customers and business partners. As a result, it can improve success in tenders, facilitate access to regulated markets, and create meaningful opportunities for differentiation.

However, it is already becoming clear that the importance of ISO 42001 certification will be significantly greater in the future: The EU AI Act is fundamentally changing the regulatory landscape for artificial intelligence, requiring organizations to document, govern, and demonstrate their use of AI systems more comprehensively than ever before. At the same time, customers, regulators, and business partners across many industries are increasingly seeking reliable evidence of effective AI governance. In regulated sectors in particular, independent certification is becoming an important factor in supplier selection.

These developments are turning ISO/IEC 42001 from a voluntary mark of quality into a strategic business tool. After all, it helps companies… 

  • build trust with customers and partners, 
  • systematically address regulatory requirements, 
  • clarify internal responsibilities, 
  • reduce risks, and 
  • strengthen their competitiveness.

Our case study on AI management shows that, for many organizations, certification is thus becoming an indispensable ticket to regulated markets. Already today, AI governance requirements are increasingly finding their way into requests for proposals and procurement processes. As AI becomes more widespread, this trend is likely to intensify further. And there is yet another aspect that should not be underestimated: While certifications for management systems such as ISO 9001 (quality management) or ISO 27001 (information security management) are already standard in many industries, ISO 42001 currently offers exciting opportunities to visibly differentiate oneself from the competition. Companies that act early, like Idest, can demonstrate their expertise and forward-thinking approach to customers and business partners particularly clearly. 

The experience of Idest also shows that this path is by no means limited to large enterprises. As this ISO/IEC 42001 case study illustrates, small and medium-sized organizations can successfully implement an effective AI Management System and realize its benefits. For Idest, certification was far more than a compliance exercise. It provided clear visibility into how AI is used across the organization, identified the risks that require effective governance, and created credible evidence that is increasingly valued by customers.

About Idest GmbH

Headquartered in Eschborn near Frankfurt am Main, Idest GmbH combines deep expertise in compliance, data protection, and IT security with the practical experience gained through its own ISO/IEC 42001 certification. As one of the first consulting firms in Germany to achieve this certification, Idest supports organizations in implementing the responsible use of artificial intelligence in a structured, standards-based, and auditable way.

Talk to DQS

Find out how the EU AI Act applies to your organization and what added value an AI management system provides.

DQS is accredited by the U.S.-based ANSI National Accreditation Board (ANAB) and is therefore authorized to issue accredited ISO/IEC 42001 certificates.

Contact us

Trust and Expertise 

Our texts and brochures are written exclusively by our standards experts or long-standing auditors. If you have any questions for our author regarding the content of the texts or our services, please feel free to send us an email: [email protected].

Note: For the sake of readability, we use the generic masculine form. However, this directive generally includes people of all gender identities, to the extent necessary for the statement. 

Author

Ingo Unger

DQS Business Development Manager with many years of experience in international projects, especially in the IT and storage environment for global companies and currently in the area of information security with a focus on ISMS expertise, especially in the automotive environment (e.g. TISAX), combined with global business development of ISO 42001, ISO 21434 and the Cyber Resilience Act.

Loading...

You Might Also Enjoy These Reads

Discover more articles that dive deep into related themes and ideas.
Blog
Loading...

NIS2 and ISO 27001: How ISO 27001 certification helps organizations meet the NIS2 cybersecurity requirements

Blog
Loading...

A best practice guide for creating effective ISMS objectives for ISO 27001

Blog
Loading...

ISO 42001 Certification in Hong Kong: Should Your Business Get Certified Now?