- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Cross-Industry Management Systems
ISO 42001
ISO/IEC 42001 is the first international management system standard for artificial intelligence. Published in December 2023, it gives an organization that develops, provides, or uses AI systems a structure for governing them: an AI policy, defined roles, risk and impact assessments for AI systems, controls over the AI life cycle, and ongoing monitoring and improvement.
It follows the same high-level structure as ISO 27001 and ISO 9001, so it is usually bolted onto an existing management system rather than built alone.
In writing, the standard expects an AI policy, a scope statement listing the AI systems and roles in scope, an AI risk assessment and treatment plan, AI system impact assessments, a statement of applicability against the Annex A controls, documented processes for the AI life cycle (data, development, deployment, operation, retirement), records of responsibilities and competence, and the usual internal audit, management review, and corrective action records.
Who has to comply
Voluntary. Adopted by AI vendors, cloud and SaaS providers, and enterprises using AI at scale, mostly to answer customer due diligence and to show a governance program that lines up with laws such as the EU AI Act. No regulator currently mandates certification.
What the assessor asks to see
AI policy and scope; inventory of AI systems and their roles (provider, user, developer); AI risk assessment methodology, results, and treatment plan; AI system impact assessments; statement of applicability and control implementation evidence; data management and data quality records; development, testing, deployment, and monitoring procedures; supplier and third-party AI controls; incident and change records; competence and awareness records; internal audit, management review, and corrective action records.
Where the requirement sits: 5.2 AI policy; 7.3 awareness; 7.5; 6.1.2 AI risk assessment; 6.1.4 impact assessment; Annex A A.2 policies, A.3 roles
Accreditation status
Because the standard is new, the accredited certification body pool is still expanding. Before signing, check the certification body appears in an accreditation body directory (for example the ANAB directory) with ISO/IEC 42001 in its scope. Unaccredited certificates exist in the market and carry less weight with customers.
Public estimates put the number of certified organizations worldwide in the hundreds as of early 2026.
What AllyMatter does here
Writes, approves and proves acknowledgment of the AI policy set - the 5.2 / 7.3 / A.2 layer.
AllyMatter publishes this site.
Assessors
Who assesses ISO 42001
Accredited certification body accredited to ISO/IEC 17021-1 with ISO/IEC 42006 requirements for AI management system certification. Accredited by National accreditation bodies; ANAB launched its ISO/IEC 42001 accreditation program in January 2024 and several US and international certification bodies now hold ANAB accreditation for it.
Other accreditation bodies have followed or are in progress (verify for the specific certification body you choose).
Public register of assessors: https://search.anab.org/
No firm has claimed a ISO 42001 assessor listing yet. Claim yours →
Consultants
Who helps with ISO 42001
A fast-growing consultant ecosystem exists, largely the same firms that implement ISO 27001 and SOC 2. Implementers inventory AI systems, run risk and impact assessments, draft the AI policy and life cycle procedures, map controls to the Annex A list, and prepare the organization for audit. Engagements commonly run three to six months where an ISO 27001 system already exists.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for ISO 42001
Tools that name this framework in their own material.
Related reading
- AI lifecycle risk management: ISO/IEC 42001:2023 for AI governanceWalks the AIMS clause structure across the AI lifecycle and shows where impact assessment sits relative to ordinary risk assessment.Amazon Web Services
- Lessons learned from auditing and implementing ISO 42001An accredited certification body on what organizations get wrong in early ISO 42001 audits, and what evidence assessors expect.Schellman
- What to expect in the ISO 42001 certification processDescribes the Stage 1 and Stage 2 audit split, the three-year cycle and the surveillance visits in between.Schellman
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for ISO 42001
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of ISO 42001 in AllyMatter
Approve the policies ISO 42001 asks for, keep every version, and record a named acknowledgment from each person who has to read them.