ISO 42001 Certification:Prove Your AI IsActually Governed
ISO/IEC 42001:2023 is the first AI management system standard you can certify against. It uses the same structure as ISO 27001 — clauses 4 to 10, a Statement of Applicability, internal audit and management review — with a different Annex A: 38 controls across nine objectives covering impact assessment, data provenance and the AI life cycle.
Book a call
[01] Why Companies Certify to ISO 42001
ISO 42001 answers the AI questionnaire ISO 27001 cannot, reuses the management system you already run, and gives EU AI Act obligations a process that produces evidence rather than a scramble per request.
// The Reality
Buyers who accepted a security questionnaire for a SaaS product are sending a separate AI governance questionnaire for anything with a model in it. ISO 42001 is the first certifiable answer to it.
// Business Impact
An AI feature inside an otherwise certified product reopens a review that ISO 27001 had already closed. The questions are about training data, impact assessment and human oversight, and a security certificate does not answer any of them.
// What Buyers Ask
- What data trained the model, and where it came from
- Whether an impact assessment exists for this system
- Who is accountable when the system is wrong
- How the system is monitored once deployed
- What is disclosed to the people it affects
// Strategic Advantage
Certification is new enough that having it is still a differentiator rather than a baseline. That window closes the way it closed for ISO 27001.
[02] What ISO 42001 Actually Is
ISO 42001 is seven clauses and nine control objectives: the clauses say what the management system must do, and Annex A's 38 controls say what you select from — with the Statement of Applicability recording which apply and why.
Clause 4
Context of the Organization
Determine the issues and interested parties relevant to your AI, fix the scope of the AI management system, and state the roles you occupy — provider, producer, user — because every later requirement reads differently depending on which you are.
Clause 5
Leadership
Top management owns the AIMS: an AI policy, assigned responsibilities and authorities, and demonstrated commitment. The auditor tests whether leadership can describe the system without reading from it.
Clause 6
Planning
Risks and opportunities, AI objectives and the plans to reach them, and the AI risk assessment and treatment process — plus the Statement of Applicability that records which Annex A controls apply and why.
Clause 7
Support
Resources, competence, awareness, communication, and the documented information the standard mandates. This clause is where most of the paperwork obligations live.
Clause 8
Operation
Operational planning and control, the AI risk assessment and treatment carried out in practice rather than on paper, and the AI system impact assessment run for real systems.
Clause 9
Performance Evaluation
Monitoring, measurement, analysis and evaluation, internal audit, and management review. Certification turns on evidence that these ran, not that they were scheduled.
Clause 10
Improvement
Nonconformity and corrective action, and continual improvement. An AIMS with no recorded nonconformities tends to read as one that is not being used.
[03] Understanding ISO 42001 Certification
Certification tests a system, not a model — stage 1 checks that the AI management system is designed and documented, stage 2 checks that it operates, and the evidence has to exist before either.
[1/6] AI INVENTORY & SCOPE (WEEK 1-3)
Find the AI systems you actually run, decide which are in scope, and establish the roles you occupy for each. Everything downstream keys off this, and most organisations discover more systems than they expected.
// What Happens
A defensible inventory of AI systems with owners, and a scope statement a certification body can audit against.
// Deliverables
- AI system inventory with owner and purpose per system
- Role determination per system — provider, producer or user
- Scope statement for the AI management system
- Interested-party and context analysis under clause 4
// Effort
- Timeline: 2-3 weeks
- Your involvement: 15-25 hours
// activities
- System Discovery: Shadow AI, embedded vendor features, internal tooling
- Role Determination: Different duties attach to provider versus user
- Scope Boundary: What is in, what is out, and why it is defensible
- Context Analysis: Issues and interested parties under clause 4
- Ownership: A named owner per system, not a team
[05] A Smarter Security Investment
When platform, service, and execution are considered together, Konfirmity delivers security and compliance with fewer tradeoffs and clearer long-term costs.
DIY Manual
Platform
None
Service
None
Audit
$15K
Year 1 total
$15K
Annual
$5K
Generic Platform
Platform
$25K
Service
None
Audit
$15K
Year 1 total
$40K
Annual
$30K
Traditional Consultant
Platform
None
Service
$50K
Audit
$15K
Year 1 total
$65K
Annual
$25K
Konfirmity
Platform
Included
Service
Included
Audit
$15K
Year 1 total
$50K
Annual
$35K
[05] FAQ's
What ISO 42001 Certification Actually Involves
Not formally — ISO 42001 is a standalone standard and you can certify to it without ISO 27001. In practice most organisations sequence ISO 27001 first, because the two share the harmonised clause structure, the Statement of Applicability mechanism, internal audit, management review and corrective action. Building that machinery once and adding the AI scope on top is materially less work than standing up a management system from scratch for AI alone.
No, and treat any claim that it does as a reason to check what else is being overstated. ISO 42001 is a voluntary management system standard; the EU AI Act is law with its own obligations and timelines. What certification gives you is the processes the Act expects to find — risk management, technical documentation, human oversight, post-market monitoring and data governance — running on a cycle that produces evidence repeatedly rather than per request.
38 Annex A controls, grouped under nine control objectives running from A.2 to A.10: policies related to AI, internal organization, resources for AI systems, assessing impacts of AI systems, AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. As in ISO 27001, you select from them and record the selection and any exclusions in the Statement of Applicability.
Two things, consistently. The impact assessment under A.5 has the least precedent in an existing ISMS — it asks about effects on individuals, groups and society rather than on the business, which is a genuinely different exercise. And the data controls under A.7 require provenance for development and enhancement data, which is the one thing most teams cannot reconstruct after the fact. Both are worth starting before the rest of the programme.
No. Certification says a management system exists, is scoped, and was audited against the standard — that impact assessments are performed, data provenance is recorded, oversight paths exist and the system is audited on a cycle. It makes no claim about the accuracy, fairness or safety of any particular model. Conflating the two is the fastest way to lose a technical buyer, and the scope statement on the certificate is what sophisticated buyers read first.
Certification runs on the same rhythm as ISO 27001: a stage 1 documentation and readiness review, a stage 2 operational effectiveness audit, annual surveillance audits, and recertification on a three-year cycle. Implementation time depends almost entirely on how many AI systems are in scope and whether data provenance was recorded as the systems were built — the data and life-cycle work in Annex A objectives A.6 and A.7 is normally the long pole, not the policy work.
Organisations that build AI into a product their customers buy, and organisations whose customers have begun sending a separate AI governance questionnaire alongside the security one. The role matters: the standard distinguishes providers, producers and users of AI systems, and the duties differ. A company embedding a third-party model has real obligations under A.10 for third-party and customer relationships even though it trains nothing itself.
[07] get started
Get started in the way that fits you best -- see the platform in action, speak directly with a security expert, or get real proof through a free external scan of your environment.
See the platform in action. We'll show you:
Adaptation to your specific stack
Integration with your existing tools
Custom evidence collection workflows
Dashboard views for stakeholders
Speak directly with one of our security experts:
Security program design for your industry
Compliance roadmap (SOC 2 → ISO)
Risk assessment and treatment planning
Vendor security review guidance
Want proof? We'll scan your surface for free:
Exposed assets and misconfigurations
SSL/TLS vulnerabilities
Vendor risk in your supply chain
Comparison to industry benchmarks
Guides
ISO 42001 guides & articles

Beginner Guides
amit-gupta
2026-07-07
ISO 42001: The Complete Guide to the AI Management System Standard (2026)
ISO 42001 is the first AI management system standard. Learn what it covers, its 38 controls, certification steps, cost, and how it maps to ISO 27001.

Beginner Guides
satyam-bajpai
2026-07-09
ISO 42001 Requirements: A Clause-by-Clause Guide to the Standard
The ISO 42001 requirements live in Clauses 4 to 10. See what the AI management system standard mandates in each clause before an auditor tests it.

Security Controls & Practices
samkit-jain
2026-07-11
ISO 42001 Controls: The 38 Annex A Controls, Explained
A reference to the ISO 42001 controls: all 38 Annex A controls across nine objectives (A.2 to A.10), what each requires, and the evidence auditors expect.

Legal & Contracts
amit-gupta
2026-07-14
ISO 42001 and the EU AI Act: A Compliance Guide for the August 2026 Deadline
ISO 42001 will not make you EU AI Act compliant on its own, but it builds the AI governance the Act demands. See what changes on 2 August 2026.

Templates & Checklists
tanmay-naik
2026-07-12
The ISO 42001 Checklist: A Step-by-Step Path to Certification
A step-by-step ISO 42001 checklist: scope, gap analysis, the mandatory documents and records, and the two-stage audit. Tick each item off, then download it.

Comparisons
niranjan-rajendran
2026-07-10
ISO 42001 vs ISO 27001: How the AI and Security Standards Compare
ISO 42001 vs ISO 27001 compared: AIMS vs ISMS, 38 vs 93 controls, where they overlap, whether you need both, and how to certify them as one program.

Audit & Readiness
amit-gupta
2026-07-08
ISO 42001 Certification: The Full Path to the Certificate
ISO 42001 certification explained end to end: choosing an accredited body, the Stage 1 and Stage 2 audit, plus real cost ranges and timelines.