HomeFrameworksCross-Industry Management SystemsISO 42001

Framework  Cross-Industry Management Systems

ISO 42001

ISO/IEC 42001 is the first international management system standard for artificial intelligence. Published in December 2023, it gives an organization that develops, provides, or uses AI systems a structure for governing them: an AI policy, defined roles, risk and impact assessments for AI systems, controls over the AI life cycle, and ongoing monitoring and improvement.

It follows the same high-level structure as ISO 27001 and ISO 9001, so it is usually bolted onto an existing management system rather than built alone.

In writing, the standard expects an AI policy, a scope statement listing the AI systems and roles in scope, an AI risk assessment and treatment plan, AI system impact assessments, a statement of applicability against the Annex A controls, documented processes for the AI life cycle (data, development, deployment, operation, retirement), records of responsibilities and competence, and the usual internal audit, management review, and corrective action records.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedAI policy v1by name, on record
Clause 7.5 Handledwith AllyMatter
Govern the Model the Modern WayYour AI policy, acknowledged by everyone who builds or uses it
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every engineer and user on record
Who read which version, and when
03
Hand the registrar the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Voluntary. Adopted by AI vendors, cloud and SaaS providers, and enterprises using AI at scale, mostly to answer customer due diligence and to show a governance program that lines up with laws such as the EU AI Act. No regulator currently mandates certification.

What the assessor asks to see

AI policy and scope; inventory of AI systems and their roles (provider, user, developer); AI risk assessment methodology, results, and treatment plan; AI system impact assessments; statement of applicability and control implementation evidence; data management and data quality records; development, testing, deployment, and monitoring procedures; supplier and third-party AI controls; incident and change records; competence and awareness records; internal audit, management review, and corrective action records.

Where the requirement sits: 5.2 AI policy; 7.3 awareness; 7.5; 6.1.2 AI risk assessment; 6.1.4 impact assessment; Annex A A.2 policies, A.3 roles

Accreditation status

Because the standard is new, the accredited certification body pool is still expanding. Before signing, check the certification body appears in an accreditation body directory (for example the ANAB directory) with ISO/IEC 42001 in its scope. Unaccredited certificates exist in the market and carry less weight with customers.

Public estimates put the number of certified organizations worldwide in the hundreds as of early 2026.

What AllyMatter does here

Writes, approves and proves acknowledgment of the AI policy set - the 5.2 / 7.3 / A.2 layer.

AllyMatter publishes this site.

Assessors

Who assesses ISO 42001

Accredited certification body accredited to ISO/IEC 17021-1 with ISO/IEC 42006 requirements for AI management system certification. Accredited by National accreditation bodies; ANAB launched its ISO/IEC 42001 accreditation program in January 2024 and several US and international certification bodies now hold ANAB accreditation for it.

Other accreditation bodies have followed or are in progress (verify for the specific certification body you choose).

Public register of assessors: https://search.anab.org/

No firm has claimed a ISO 42001 assessor listing yet. Claim yours →

Consultants

Who helps with ISO 42001

A fast-growing consultant ecosystem exists, largely the same firms that implement ISO 27001 and SOC 2. Implementers inventory AI systems, run risk and impact assessments, draft the AI policy and life cycle procedures, map controls to the Annex A list, and prepare the organization for audit. Engagements commonly run three to six months where an ISO 27001 system already exists.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

ArchlightMinneapolis, MN, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
BEMOUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Control and FunctionDenver, CO, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Coral EsecureNew Jersey, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
CycoreMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Genius GRCWoodstock, GA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
IllumenPacific Northwest, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Neutral PartnersMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Securis360Pittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Soter AdvisoryUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TestprosReston, VA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TrustedCISORemote, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. AI lifecycle risk management: ISO/IEC 42001:2023 for AI governanceWalks the AIMS clause structure across the AI lifecycle and shows where impact assessment sits relative to ordinary risk assessment.Amazon Web Services
  2. Lessons learned from auditing and implementing ISO 42001An accredited certification body on what organizations get wrong in early ISO 42001 audits, and what evidence assessors expect.Schellman
  3. What to expect in the ISO 42001 certification processDescribes the Stage 1 and Stage 2 audit split, the three-year cycle and the surveillance visits in between.Schellman

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for ISO 42001

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of ISO 42001 in AllyMatter

Approve the policies ISO 42001 asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.