Sang-Rok Yeo

Sang-Rok Yeo is an ISO/IEC 42001, 27001, 20000, and 22301 lead auditor based in Seoul, South Korea. He founded ITG insights to help organizations prepare for AI governance and management system certification.

Five-step AI risk assessment methodology for ISO/IEC 42001 — build the AI system inventory, analyze context, identify risks, score likelihood and impact, treat risks — covering AI-intrinsic risk categories such as bias, opacity, malfunction, and supply chain

AI Risk Assessment: a Five-Step Methodology That Holds Up in an Audit

A five-step methodology you can apply as-is — built for ISO/IEC 42001, aligned with the EU AI Act Every organization that adopts AI eventually has to answer one question: “What risks can our AI systems actually create?” AI risk assessment is a core requirement of ISO/IEC 42001 and the starting point of EU AI Act […]

AI Risk Assessment: a Five-Step Methodology That Holds Up in an Audit Read More »

The 10 mandatory documents an ISO/IEC 42001 certification audit checks — AI policy, scope, risk assessment and SoA, impact assessment, objectives, competence records, internal audit, management review, corrective-action log, AI supplier records

ISO 42001 Documentation: the 10 Documents Your Certification Audit Will Check

The documented information certification auditors ask for — what each document must contain, and the order to build them in The first wall most organizations hit when preparing for ISO/IEC 42001 certification is a simple question: “What documents do we actually have to produce?” The standard requires extensive documented information, but reading the clause text

ISO 42001 Documentation: the 10 Documents Your Certification Audit Will Check Read More »

Diagram showing how to extend a certified ISO/IEC 27001 ISMS into an ISO/IEC 42001 AIMS, sorting Annex A controls into three groups: reuse and supplement from the ISMS (management-system structure Clauses 4-10, existing policies and roles A.2/A.3), extend to the AI context (AI asset classification A.4, AI system lifecycle A.6, AI supply chain A.10), and build new for AI (AI impact assessment A.5, AI data management A.7, information for stakeholders A.8, use of the system A.9), with audit points marking each transition.

Extending an ISO/IEC 27001 ISMS to ISO/IEC 42001

If you already run an ISO/IEC 27001 ISMS, here is the control-by-control path to an AI management system If your organization already runs an ISO/IEC 27001 ISMS, preparing for ISO/IEC 42001 is not a start-from-scratch exercise. Because both standards share the same Harmonized Structure, their controls fall cleanly into three groups: the ones you reuse

Extending an ISO/IEC 27001 ISMS to ISO/IEC 42001 Read More »

Comparison of ISO 42001 and ISO 27001 in four parts: what they share — common Clauses 4-10 under the ISO harmonized structure (Annex SL), shown as a Plan-Do-Check-Act flow between the two standards; where they differ — ISO 27001 as an ISMS aimed at the CIA triad against external threats, ISO 42001 as an AIMS aimed at responsible AI against bias, opacity, malfunction, and human-oversight risks; what ISO 42001 adds — AI policy, AI impact assessment, AI supply chain, and human oversight; and how to run them together as one integrated management system through shared documentation, extended risk assessment, and combined audits.

ISO 42001 vs ISO 27001: the differences, and how to run them together

Two different standards, two different purposes — and they are designed to run together As organizations adopt AI faster, one question comes up again and again: “We’re already certified to ISO 27001 — do we also need ISO 42001?” The short answer: they are two different standards with two different purposes, and they are designed

ISO 42001 vs ISO 27001: the differences, and how to run them together Read More »