ISO 42001 certification

Get ISO 42001 certified without building an AI governance team first.

ISO/IEC 42001 is the first certifiable standard for managing AI. A dedicated SecureSlate compliance lead scopes your AI systems, runs the impact assessment, and prepares the Statement of Applicability, while our compliance automation platform reuses the evidence your security program already produces. One fixed price covers the work.

Annex A, ISO 42001:202338 controls

Annex A, ISO 42001:2023: 38 controls, 3 Policies related to AI, 2 Internal organization, 5 Resources for AI systems, 4 Assessing impacts of AI systems, 9 AI system life cycle, 5 Data for AI systems, 4 Information for interested parties, 3 Use of AI systems, 3 Third-party and customer relationships. 6 highlighted: Head start from an ISO 27001 program.

Head start from an ISO 27001 programAI-specific, built with your compliance lead
Current version
ISO/IEC 42001:2023
Certificate
Valid for 3 years, audited every year
Maps to
ISO 27001, NIST AI RMF, EU AI Act
The standard

ISO 42001 certification audits how you govern AI, not whether you have an AI policy.

ISO/IEC 42001:2023 follows the same management system structure as ISO 27001, then adds requirements that only make sense for AI.

An AI management system that actually runs

Clauses 4 to 10 define the AIMS: the AI systems in scope and your role for each, leadership commitment, AI risk assessment and treatment, objectives, internal audit, management review, and corrective action. The structure matches ISO 27001, so an existing ISMS gives you most of the skeleton.

Impact assessments, not only risk

Clause 6.1.4 asks you to assess the consequences of each AI system for individuals, groups, and society, and to act on the results. It has no equivalent in ISO 27001, and it is usually where most of the new work sits.

38 Annex A controls across 9 objectives

Annex A covers AI policy, internal organization, resources, impact assessment, the AI system life cycle, data, information for interested parties, responsible use, and third-party relationships. Your Statement of Applicability justifies each control you include or exclude.
How it works

We build your AI management system with you, then keep it current as your AI changes.

Four stages from the scoping call to a certificate, with a named compliance lead accountable at every one.

Scope your AI systems and roles

We list the AI systems you build, buy, or embed, and define your role for each, such as AI provider, producer, or customer. That decides which controls apply and keeps the certificate focused on the systems your customers ask about.

Assess risk and impact

Your compliance lead runs the AI risk assessment and the AI system impact assessment with the people who build and operate each system, then records treatment decisions in a Statement of Applicability that references real controls.

Build on what you already run

Policies, roles, asset inventory, logging, incident response, and supplier management carry over from ISO 27001 or SOC 2 where you have them. We add the AI-specific pieces: data provenance, verification and validation, responsible use, and information for users.

Certification, then every year after

We coordinate with an accredited certification body, prepare evidence for Stage 1 and Stage 2, and stay with you through fieldwork. Surveillance audits follow in years two and three, and continuous monitoring keeps the AIMS current as models and use cases change.
What is included

Everything your ISO 42001 auditor samples, prepared before they ask.

ISO 42001 compliance software and the expert who runs it arrive together under one fixed price, so AI governance does not become a side project for your engineers.

A dedicated compliance lead

One experienced practitioner owns your ISO 42001 program end to end. They scope AI systems, facilitate impact assessments, draft the documentation, and answer the certification body directly, so your team reviews and approves instead of learning the standard.

AI risk and impact assessments

Risk scenarios and impact assessments for each AI system in scope, scored against criteria you agree, with owners and treatment decisions recorded and revisited when a model or use case changes.

A Statement of Applicability for Annex A

All 38 controls marked included or excluded, with a justification tied to your risk and impact assessments. We draft it, you approve it, and we keep it current between surveillance audits.

Evidence from the stack you already run

Connect your cloud provider, identity provider, code host, and devices once. Controls that ISO 42001 shares with your security program are tested continuously, so AI governance does not become a second evidence project.

AI vendors and model providers

Model APIs, labeling services, and data suppliers fall under Annex A 10. We keep the supplier inventory, due diligence, and allocation of responsibilities current, so you can answer which models touch customer data.

A Trust Center for AI questions

Publish your ISO 42001 certificate, an AI policy summary, and your subprocessors on a live page, so buyers find answers to their AI governance questions before they send a questionnaire.
Reuse from ISO 27001

Several ISO 42001 controls build directly on an ISO 27001 program.

If you already hold ISO 27001, these controls start from evidence you collect today. Your compliance lead extends them for AI instead of rebuilding them.
A.3.2 builds on ISO 27001 5.2

AI roles and responsibilities

The roles you defined for information security extend to AI: who approves a model for use, who owns its risks, and who responds when it behaves unexpectedly.
A.4.2 builds on ISO 27001 5.9

Resource documentation

Your asset inventory becomes the record of the data, tooling, compute, and people behind each AI system, which is what auditors sample when they test Annex A 4.
A.6.2.6 builds on ISO 27001 8.16

AI system operation and monitoring

Monitoring you already run for infrastructure extends to model performance, drift, and failures, with thresholds and response owners documented.
A.6.2.8 builds on ISO 27001 8.15

Recording of event logs

Logging covers AI systems too: inputs, outputs, and decisions recorded to the level your impact assessment calls for, and retained under the same policy.
A.8.4 builds on ISO 27001 5.24 to 5.26

Communication of incidents

Your incident process gains AI-specific triggers and a duty to inform affected users, instead of a parallel process for AI failures.
A.10.3 builds on ISO 27001 5.19 to 5.22

Suppliers

Supplier due diligence extends to model providers and data sources, with the responsibilities for each AI system allocated in writing.
Beyond ISO 42001

Run ISO 42001 and your security program as one management system.

ISO 42001 shares its structure with the standards your buyers already recognize, and it prepares the groundwork for AI regulation.

ISO 27001

Many teams certify ISO 27001 first or alongside. The shared clause structure means one internal audit and one management review can cover both standards.

EU AI Act

ISO 42001 builds the governance, risk management, and documentation the Act expects, though certification alone does not prove conformity with the regulation.

NIST AI RMF

The US voluntary framework for AI risk. Its govern, map, measure, and manage functions line up with much of the ISO 42001 risk and impact work.

SOC 2

US buyers still ask for a SOC 2 report. Access, change, and vendor controls serve both, so AI features do not need a separate program.

GDPR

AI systems that process personal data still need a lawful basis, transparency, and data protection impact assessments. ISO 42001 impact assessment work feeds straight into them.

ISO 27701

Privacy information management for teams whose AI systems train on or process personal data at scale.
ISO 42001 guides

What the ISO 42001 audit actually tests

Three deep dives your team can read before the scoping call, from the controls themselves to keeping the certificate after year one.

38
Annex A controls explained, with what auditors look for in each
Stage 2
How to work with ISO 42001 auditors from Stage 1 through fieldwork
3 years
Keeping an ISO 42001 certificate current through surveillance audits
Resources

Read up before your scoping call.

Practical guides to ISO 42001, from who needs it to what the certification audit costs.

FAQs

What teams ask before starting ISO 42001.

Find out what your ISO 42001 certificate will take

Bring the AI systems in scope and the buyer asking about them. You will leave the call with a gap summary, a timeline, and a fixed price, whether or not you work with us.

Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?