ISO 42001 AI governance.
The first international standard for artificial intelligence management systems. If you build or deploy AI, enterprise procurement will start asking for this, and today almost nobody can answer.
At a glance
- Standard
- ISO/IEC 42001:2023
- Covers
- AI management system across the full lifecycle
- Timeline
- 4 to 8 months, faster if ISO 27001 exists
- Pairs with
- ISO 27001, EU AI Act readiness
- Why now
- Procurement questionnaires are already asking
What this actually is.
Every enterprise security questionnaire we see is growing an AI section. Most vendors answer it with a paragraph of reassurance. ISO 42001 lets you answer it with a certificate, and right now that is close to a unique position in almost every market.
What we cover.
Who needs this.
- Companies building AI features into products sold to enterprise
- Businesses deploying AI in regulated decisions such as credit, hiring or clinical support
- Vendors already receiving AI questions in security questionnaires
- Organisations preparing for the EU AI Act
- Anyone who wants a genuine procurement differentiator while the field is empty
Frequently asked.
Is anyone actually asking for ISO 42001 yet?
Increasingly, and earlier than most vendors expect. The pattern matches SOC 2 a decade ago: a handful of large buyers ask, it becomes a differentiator, then it becomes a requirement. The advantage belongs to whoever moves before the second phase.
How does this relate to the EU AI Act?
They are different instruments. The AI Act is law with risk-tiered obligations. ISO 42001 is a voluntary management system standard. Building the 42001 management system produces much of the governance evidence the Act expects, which is why we usually approach them together.
We already have ISO 27001. Does that help?
Substantially. ISO 42001 uses the same harmonised management system structure, so your existing scope, risk methodology, internal audit and management review largely carry across. The incremental effort is the AI-specific controls.
We only use third-party AI models. Does this still apply?
Yes, and this is the most common misunderstanding. Deploying someone else's model is still deploying an AI system. Your obligations around impact, transparency, monitoring and vendor risk apply regardless of who trained it.
Related services.
The international standard for information security management. Heavier than SOC 2 up front, more durable afterwards, and the one European and Asian enterprise buyers recognise immediately.
CMP 07Data PrivacyCCPA, India's DPDP Act and the growing patchwork of state and national privacy laws. One programme built on a single data inventory, rather than a separate scramble for each jurisdiction.
SVC 02API TestingYour mobile app and your single-page front end are just API clients. The API is the real target, and it is usually tested least. We test REST, GraphQL and the authorisation logic underneath both.
Find out what stands between you and certification.
Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.