
Your investor deck has a slide titled “Responsible AI.” Your enterprise prospect just asked you to prove it. The EU AI Act starts biting in 2026, and within three years every serious AI buyer will demand a certificate most of your competitors don’t have yet. This is your first-mover window - ISO/IEC 42001:2023 is open, the auditors are ready, the market hasn’t fully moved.
The world’s first AI management system standard
Of controls overlap with ISO/IEC 27001:2022
To certify if ISO/IEC 27001:2022 is already in place
Certificate validity, with annual surveillance
1
Published in December 2023, it sits next to ISO/IEC 27001:2022 the way ISO 13485 sits next to ISO 9001:2015 - shared management-system DNA, with sector-specific extensions. Its Annex A adds controls specific to AI: training-data governance, model lifecycle management, transparency and explainability, human oversight, bias and fairness testing, and incident response for AI-specific failures.
About 40% of the controls overlap with ISO/IEC 27001:2022 - which is why ISO/IEC 27001-certified companies reach ISO/IEC 42001:2023 in 3–6 months instead of 9–12. The audit cycle is identical to ISO/IEC 27001:2022: a two-stage audit, a three-year certificate, and annual surveillance to keep it alive.
2
ISO/IEC 42001:2023 stops being a “later” problem the moment one of these describes you.
Vendor AI-governance questionnaires are the new vendor security questionnaires. Buyers will ask - you can be the answer or the excuse.
Credit scoring, employment, education, healthcare, public services, migration, critical infrastructure. The Act enters full force in August 2026, and ISO/IEC 42001:2023 is the most defensible evidence that you took it seriously before the deadline.
Every downstream customer inherits your governance. They need to prove their stack is governed; you need to prove yours is. The certificate makes that math work.
Sophisticated VCs now ask AI-governance questions in diligence. A certificate shifts the conversation from “tell us about your approach” to “here’s the audit report.”
3
We could write four paragraphs of marketing copy - instead:
Replace the AI-governance section of every RFP with one PDF. One certificate answers the question your competitors are still drafting paragraphs about.
Hedge the EU AI Act. The Act will demand documented governance for high-risk systems. ISO/IEC 42001:2023 is the most mature framework available today for delivering it.
Earn investor and board credibility. AI governance is moving from optional to expected. Showing up with a certificate is showing up serious.
Reduce model risk in production. Documented evaluation pipelines, bias testing and incident response mean fewer drift incidents reach production.
Be the AI vendor the cautious enterprise can finally say yes to. The biggest deals are blocked by the most cautious buyers - and caution wants evidence.
4
Where ISO/IEC 27001:2022’s Annex A governs information security, ISO/IEC 42001:2023’s adds the controls a classic ISMS never covered — the ones that make AI auditable. You select what applies to your systems; here are the domains they fall into.
How training, validation and test data is sourced, documented, quality-controlled and kept fit for purpose across the model’s life.
Disciplined development, versioning, deployment and decommissioning of models - so what runs in production is what was actually assessed.
Making system behaviour, limitations and decisions intelligible to the people who rely on, oversee or are affected by them.
Defined points where a human can understand, intervene in and override the system - oversight by design, not by aspiration.
Systematic testing for unfair or discriminatory outcomes, with the evidence trail to show it was done and acted upon.
Detection, handling and learning for AI-specific failures - the kind a classic security playbook was never written to cover.
5
The EU AI Act enters full force in August 2026 and will demand documented governance for high-risk systems. ISO/IEC 42001:2023 is the most defensible evidence that you took it seriously before the deadline.
The Act will require documented governance for high-risk systems. ISO/IEC 42001:2023 is the most mature framework available today for delivering it - and the certificate shifts a diligence conversation from “tell us about your approach” to “here’s the audit report.”
6
The same transparent, digital-first workflow as our ISO/IEC 27001:2022 audits. Your client portal gives real-time visibility into audit status, reports and non-conformities at every stage.
DIGITAL
Submit your details and AI scope through streamlined digital forms. You receive a clear, transparent proposal tailored to your systems and size.
HYBRID / ONSITE
We review your AI management system: policies, the Annex A controls you’ve selected, risk and impact assessments - confirming you’re ready for the main audit.
HYBRID / ONSITE
We verify the AI controls work in practice - that data governance, oversight, bias testing and incident response are embedded in how models are actually built and run.
OUTCOME
On success you receive your ISO/IEC 42001:2023 certificate - valid three years, subject to annual surveillance, on the same cycle as ISO/IEC 27001:2022.
7
ISO/IEC 42001:2023 doesn’t start from zero. About 40% of its controls overlap with ISO/IEC 27001:2022’s Annex A - the same evidence, extended to cover models and data. If the ISMS already exists, the AI management system is months of work, not a year.
And it rarely stands alone. SOC 2, ISO/IEC 27017, ISO/IEC 27018 and BSI C5 all assume an ISO/IEC 27001:2022-class foundation, and the EU AI Act reads ISO/IEC 42001:2023 as the governance framework. Build the foundation once and every subsequent certificate costs less - one coordinator across the whole engagement.
ISO/IEC 27001:2022
EU AI Act
SOC 2
ISO/IEC 27017
ISO/IEC 27018
BSI C5
Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.
8