{{item.title}}
{{item.text}}
{{item.text}}
Across boardrooms in Switzerland and beyond, the conversation about artificial intelligence has shifted. The question is no longer "What can AI do for us?" - it has become "How do we know we can trust it?"
Customers want assurance that the algorithms shaping their experiences are fair. Regulators want evidence that high-risk systems are controlled. Boards want confidence that AI investments will not become tomorrow's reputational crisis. And employees want to understand how AI is being deployed alongside - and on top of - their work.
The organisations that will succeed with AI are not necessarily those that deploy it fastest. They are the ones that can prove their AI is trustworthy - through governance, controls, independent review, and formal certification.
This is where ISO/IEC 42001:2023, the world's first international management system standard for Artificial Intelligence, becomes a strategic lever.
The trust gap is now AI's biggest barrier to scale
ISO/IEC 42001 defines the requirements for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS) within an organisation. It addresses the unique risks AI introduces - bias, opacity, brittleness, drift, and misalignment with business objectives - and provides a structured framework to manage them across the entire AI lifecycle: design, data, verification, deployment, operation, monitoring, and decommissioning.
Importantly, ISO/IEC 42001 follows the same harmonised management system structure and standards your organisation likely already uses, such as ISO/IEC 27001 for information security. This means it integrates naturally with existing governance, risk, and control environments rather than duplicating them.
For organisations under pressure from customers, regulators, boards, or competitive dynamics, certification is becoming more than a "nice to have". It is rapidly evolving into an expected baseline. A credible, evidence-based answer to the question of whether your AI is responsibly governed.
At PwC Switzerland, we help organisations move from ambition to certified, audit-ready AI governance. Our services can be used as standalone engagements or as a connected journey along the certification lifecycle.
Before pursuing certification, organisations need to understand where they stand. Our gap analysis establishes a clear baseline of your current maturity against ISO/IEC 42001 requirements. Through structured interviews, documentation review, and walkthroughs of real AI use cases, we identify non-conformities and deliver a prioritised remediation roadmap – so you know exactly what needs to change, in what order, and why.
Whether you have a mature internal audit function that needs AI-specialist support, or no internal audit capability at all, we provide independent, risk-based assessments of your AI Management System's effectiveness. We work in co-sourcing models alongside your team, or as a fully outsourced internal audit partner, bringing AI specialists who understand both the technical and governance dimensions of the work.
Our certification audits are conducted in two stages, in line with ISO/IEC 17021-1:
Successful completion leads to formal ISO/IEC 42001 certification, a credential recognised internationally.
Certification is not a one-off event. We provide annual surveillance audits in years one and two, followed by a broader recertification audit in year three, ensuring that your AI Management System continues to mature and remain valid as your AI portfolio evolves.
Several aspects set our approach apart in the Swiss market:
Multidisciplinary teams: Our engagements combine certified ISO/IEC 42001 Lead Auditors and Implementors, AI specialists capable of technical testing for bias, drift, accuracy and explainability, and seasoned risk, governance, and legal professionals. This breadth matters - AI assurance cannot be done credibly by auditors alone, nor by data scientists alone.
Strict independence: We maintain a clear separation between our implementation advisory services and our certification body services, in line with ISO/IEC 17021-1 requirements. This is non-negotiable for credible assurance.
Certification body. PwC is an ISO/IEC 42001 certification body, accredited to certify AI Management Systems for Swiss companies. Certification is delivered by a Switzerland-based ISO/IEC 42001 accredited audit team. We can provide these services in German, French, and English.
Holistic lifecycle view: We assess AI from design and data through to deployment, monitoring, and decommissioning - not just at the model level, but across the surrounding governance and operational environment.
Flexibility in reporting: Where formal third-party assurance is needed beyond certification itself - for regulators, customers, or investors - we can align audit reporting with ISAE 3000 (Revised) standards.
Based on what we are seeing across the Swiss market, ISO/IEC 42001 is becoming a near-term priority for:
AI will only scale successfully where trust is present. ISO/IEC 42001 gives organisations a concrete instrument to demonstrate, in a structured and internationally recognised way, that their AI is being governed responsibly. PwC's AI Trust and Assurance services are designed to help you get there - efficiently, credibly, and in a way that integrates with the management systems you already operate.
The organisations that act now will meet rising expectations from regulators and customers while turning AI trust into a strategic advantage.
If you are exploring ISO/IEC 42001 certification, evaluating your current AI governance maturity, or seeking specialist support for AI-related internal audit work, our team would welcome a conversation.
Contact our ISO/IEC 42001 Auditors and Implementors in our Digital Trust & Assurance team:
Carlos Arias
{{item.text}}
{{item.text}}