ISO/IEC 42001:2023 — published December 2023
ISO 42001 Readiness Assessment for AI Products and Organisations
ISO/IEC 42001:2023 is not a regulation with a deadline. It is a certification that enterprise buyers, insurers, and regulated sector clients are increasingly requiring before they will contract with an AI supplier. If you are selling AI into enterprise, you will be asked for it.

WHAT IS ISO 42001 AND WHO NEEDS IT
ISO/IEC 42001:2023 is the world’s first international standard for Artificial Intelligence Management Systems. Published in December 2023 jointly by the International Organization for Standardization and the International Electrotechnical Commission, it defines how organisations develop, provide, and use artificial intelligence responsibly — through seven operative clauses, 38 controls across nine areas, and a certifiable three-year audit cycle with annual surveillance.
ISO 42001 is voluntary. No regulation requires it and no enforcement authority can fine you for not having it. It is becoming a practical necessity through a different mechanism — procurement. Enterprise buyers in financial services, healthcare, public sector, and regulated industries are adding ISO 42001 to their vendor qualification criteria at exactly the rate that ISO 27001 was added in the 2010s. AI suppliers without certification are beginning to face friction in B2B relationships that ISO 27001 holders do not.
The EU AI Act explicitly references management system standards as a means to demonstrate compliance. ISO 42001’s requirements for risk management, AI system lifecycle management, data quality, and transparency map directly to EU AI Act Articles 9 to 13. Certification does not satisfy EU AI Act obligations — it is not currently a harmonised standard and confers no presumption of conformity — but it demonstrates a systematic governance approach that supervisory authorities and notified bodies will recognise and that accelerates EU AI Act documentation work.
For AI and digital product companies, ISO 42001 is immediately relevant if your situation includes any of the following:
- Enterprise sales cycles where buyers are issuing AI governance questionnaires
- Insurance underwriting for AI products where governance documentation is required
- Public sector procurement where AI management system certification is specified
- EU AI Act compliance programmes where an AIMS provides the governance infrastructure
- Investor or acquirer due diligence where AI governance maturity is assessed
- Any regulated sector client relationship where AI supplier governance is a contractual requirement
If any of these apply, ISO 42001 readiness is a commercial question, not a regulatory one — and the organisations asking for it are not waiting for a deadline.
ISO 42001 Readiness Assessment for Your Organisation
A lawyer-built gap analysis of your organisation’s current AI governance practices against ISO/IEC 42001:2023 requirements — clause-by-clause assessment, control gap identification across all nine Annex A areas, Statement of Applicability support, and a documented readiness position your certification body, enterprise buyers, and board can rely on.
How ISO 42001 works for AI-first organisations
Seven operative clauses. Thirty-eight controls. One certifiable framework for responsible AI governance.

ISO 42001 follows the Harmonized Structure shared by ISO 27001, ISO 9001, and other management system standards — meaning organisations already certified to those standards have a structural head start. The standard organises its requirements across seven operative clauses and nine Annex A control areas, each creating specific governance obligations for organisations that develop, provide, or use AI systems.
Context of the organisation — Clause 4
The organisation must understand its internal and external context as it relates to AI, identify interested parties and their requirements, and define the scope of its AI Management System. For AI product companies, scope definition is the most consequential early decision — it determines which AI systems, processes, and organisational functions fall within the AIMS boundary and therefore within the certification scope. A scope that is too narrow fails to satisfy enterprise buyers who want coverage of your whole AI operation. A scope that is too broad creates unmanageable certification overhead. Getting scope right requires understanding both the standard’s requirements and the procurement context in which certification will be used.
Leadership and AI policy — Clause 5
Top management must demonstrate commitment to the AIMS, establish an AI policy covering the organisation’s approach to responsible AI, and assign roles and responsibilities. For AI product companies, the AI policy is the document that enterprise buyers and due diligence teams read first — it must accurately reflect actual governance practice, not aspirational statements. An AI policy that does not match what the organisation actually does creates audit risk and credibility risk simultaneously.
Planning — Clause 6
The organisation must identify risks and opportunities relating to AI, establish AI objectives, and plan how to achieve them. ISO 42001 introduces AI-specific risk assessment requirements that differ from the IT security risk assessment most organisations already have — covering risks from AI decision-making, training data, model behaviour, and impacts on affected individuals and groups. Planning also covers the AI system impact assessment — a structured assessment of the potential impacts of AI systems on individuals, groups, and society — which maps directly to the EU AI Act’s Fundamental Rights Impact Assessment requirement.
Support — Clause 7
The organisation must ensure adequate resources, competence, awareness, and communication for the AIMS, and maintain documented information to the extent necessary to support the operation of the AIMS. For AI product companies, the documented information requirement creates a structured record of AI governance decisions — training data provenance, model selection rationale, bias testing results, human oversight measures — that simultaneously supports EU AI Act technical documentation obligations.
Operation — Clause 8
The organisation must plan, implement, control, and review the processes needed to meet requirements and implement actions determined in planning — including AI system lifecycle management from development through deployment and decommissioning. This is the clause most directly relevant to AI product teams: it governs how AI systems are designed, trained, tested, deployed, monitored, and retired, and requires that each stage is controlled, documented, and reviewed against the organisation’s AI policy and objectives.
Performance evaluation — Clause 9
The organisation must monitor, measure, analyse, and evaluate its AIMS, conduct internal audits, and undertake management reviews. For AI product companies, performance evaluation includes monitoring AI system behaviour after deployment — a requirement that maps directly to the EU AI Act’s post-market monitoring obligations and creates ongoing governance infrastructure rather than a point-in-time compliance exercise.
Improvement — Clause 10
The organisation must continually improve the suitability, adequacy, and effectiveness of its AIMS — addressing non-conformities and implementing corrective actions. For AI product companies, continual improvement includes updating governance practices as AI systems evolve, as new risks emerge, and as regulatory requirements develop — ensuring that ISO 42001 certification remains current rather than becoming a dated credential that does not reflect current practice.
Who ISO 42001 applies to
ISO 42001 applies to any organisation of any size or sector that develops, provides, or uses AI systems. Unlike sector-specific regulations, it has no threshold, no exemption for SMEs, and no geographic limitation — it is a global standard adopted by organisations that want to demonstrate responsible AI governance regardless of where they operate.
| Organisation type | ISO 42001 relevance | Primary driver |
|---|---|---|
| AI product company selling to enterprise | High — procurement requirement emerging | Enterprise buyers adding to vendor qualification criteria |
| AI company selling to financial sector | High — DORA and EU AI Act governance overlap | Regulated sector supply chain requirements |
| AI company selling to healthcare | High — MDR and EU AI Act governance overlap | Clinical governance and regulatory requirements |
| AI company seeking EU AI Act compliance | High — AIMS maps directly to Articles 9-13 | EU AI Act governance infrastructure |
| Non-EU AI company entering EU market | High — demonstrates governance maturity | Enterprise and regulatory credibility |
| AI company seeking investment or acquisition | Medium-high — due diligence governance assessment | Investor AI governance maturity requirements |
| Organisation using third-party AI systems | Medium — deployer governance obligations | EU AI Act deployer requirements and supply chain risk |
| Public sector AI deployer | High — procurement and accountability requirements | Public sector AI accountability frameworks |
| AI company with ISO 27001 certification | High — structural head start on AIMS | Existing management system infrastructure |
| Small AI company with no enterprise clients | Low — voluntary, no immediate commercial pressure | Useful foundation but not urgent without procurement driver |
The ISO 42001 requirement most AI companies underestimate
ISO 42001’s AI system impact assessment — required under Clause 6 and Annex A — is the control most AI product teams have not built into their development process, and the one that creates the most friction in enterprise procurement and EU AI Act compliance simultaneously.
The AI system impact assessment is a structured assessment of the potential negative impacts of an AI system on individuals, groups, and society — conducted before deployment and updated as the system develops. Three things AI product teams consistently misunderstand:
An AI system impact assessment is not a risk assessment. Risk assessment under ISO 42001 covers risks to the organisation — financial, reputational, operational. The impact assessment covers risks to people affected by the AI system — users, third parties, vulnerable groups, and society. The two assessments are complementary but distinct, and both are required. Most AI governance programmes conflate them or omit one entirely.
The impact assessment must be conducted before deployment — not after a procurement questionnaire asks for it. An assessment produced in response to a buyer’s request, based on a system already in operation, is a documentation exercise rather than a governance control. Certification bodies and sophisticated enterprise buyers can tell the difference. The assessment has governance value only if it was conducted at a point where its findings could have changed design decisions.
ISO 42001’s impact assessment maps directly to the EU AI Act’s Fundamental Rights Impact Assessment requirement for deployers of high-risk AI systems — but they are not identical. The FRIA covers fundamental rights specifically; the ISO 42001 impact assessment covers broader societal impacts.
Organisations that conduct the ISO 42001 impact assessment will have most of the work done for the FRIA — but will still need to address the fundamental rights framing explicitly. A readiness assessment maps exactly what is covered by which requirement and what additional work is needed.
What ISO 42001 readiness assessment requires
These are the ISO 42001 requirements that a readiness assessment addresses — building the gap analysis your certification body, enterprise buyers, and EU AI Act compliance programme need.
Cross-framework mapping — identification of where ISO 42001 controls map to EU AI Act Articles 9 to 13, GDPR data governance obligations, DORA ICT risk management requirements for financial sector AI, and MDR quality management system requirements for medical device AI — showing where one governance programme satisfies multiple frameworks simultaneously.
Scope determination — assessment of which AI systems, processes, and organisational functions should fall within the AIMS boundary, balancing certification credibility against implementation feasibility — the decision that determines the cost and complexity of everything that follows.
Clause-by-clause gap analysis — assessment of your current AI governance practices against each of ISO 42001’s seven operative clauses, identifying what exists, what is partially in place, and what needs to be built before a certification audit.
Annex A control gap analysis — assessment of your current practices against all 38 controls across the nine Annex A areas: organisational policies, internal organisation, resources for AI systems, AI system lifecycle, data for AI systems, information for interested parties about AI systems, use of AI systems, human oversight and control, and documentation obligations.
Statement of Applicability support — assistance in preparing the Statement of Applicability — the document that identifies which Annex A controls apply to your organisation, which are excluded and why, and what the implementation status of each applicable control is. The SoA is the central governance document that certification bodies and enterprise buyers use to assess the scope and depth of your AIMS.
AI system impact assessment review — assessment of whether your current AI system impact assessment process satisfies ISO 42001’s requirements under Clause 6 and Annex A, and maps to EU AI Act FRIA obligations for high-risk systems.
Certification pathway — identification of an appropriate accredited certification body for your scope, sector, and geography, and a realistic assessment of the time and resource required to achieve certification from your current position.
Living Compliance File™ — audit-ready governance record structured by clause and control area, formatted so a certification body, enterprise buyer, or investor’s due diligence team can open it and find what they need.
One engagement. Every ISO 42001 gap identified and documented.
A lawyer-built ISO 42001 readiness assessment covering scope determination, clause-by-clause gap analysis, Annex A control assessment across all nine areas, Statement of Applicability support, AI system impact assessment review, certification pathway guidance, and cross-framework mapping against your EU AI Act, GDPR, DORA, and MDR position where all apply.
Frequently Asked Questions About ISO 42001 Readiness
What is ISO 42001 and why does it matter for AI companies?
ISO/IEC 42001:2023 is the world’s first international standard for AI Management Systems, published in December 2023. It defines how organisations develop, provide, and use AI responsibly through seven operative clauses and 38 controls. It is voluntary — no regulation requires it — but it is becoming a practical commercial necessity as enterprise buyers, insurers, and regulated sector clients add it to vendor qualification criteria. The trajectory mirrors ISO 27001, which moved from voluntary to effectively mandatory for technology suppliers in enterprise sales over a decade. ISO 42001 is moving faster.
Is ISO 42001 the same as EU AI Act compliance?
No — they address different things through different mechanisms. ISO 42001 is a management system standard covering how your organisation governs AI across its lifecycle. The EU AI Act is a product regulation covering the specific obligations that apply to your AI system based on its risk classification. However, they overlap significantly — ISO 42001’s risk management, data governance, transparency, and human oversight controls map directly to EU AI Act Articles 9 to 13 — but certification to ISO 42001 does not satisfy EU AI Act obligations. It is not currently a harmonised standard and confers no presumption of conformity. The two are complementary, not substitutes.
Does ISO 42001 apply to organisations that use AI but do not develop it?
Yes. ISO 42001 applies to any organisation that develops, provides, or uses AI systems. Deployers — organisations that use AI systems developed by third parties — are explicitly within scope. The standard addresses the governance of AI use as well as AI development, making it relevant to any organisation using AI in consequential ways regardless of whether it builds the underlying system.
What is the Statement of Applicability under ISO 42001?
The Statement of Applicability is the central governance document in ISO 42001 — it lists all 38 Annex A controls, identifies which apply to the organisation and which are excluded, explains the justification for any exclusions, and records the implementation status of each applicable control. It is the document certification bodies examine to assess the scope and depth of the AIMS, and the document enterprise buyers increasingly request as evidence of governance maturity. Preparing a credible SoA requires systematic assessment of the organisation’s AI activities against every control — which is the core of what a readiness assessment produces.
How long does ISO 42001 certification take?
Typically six to twelve months from starting implementation to achieving certification, depending on AI governance maturity, the number of AI systems in scope, and available resources.
Organisations already certified to ISO 27001 have a structural head start — the Harmonized Structure is shared, governance culture is established, and many documentation practices transfer directly. A readiness assessment establishes your current position and gives you a realistic implementation timeline before you commit to a certification programme.
How does ISO 42001 interact with the EU AI Act?
ISO 42001’s controls across risk management, lifecycle management, data quality, and transparency map directly to EU AI Act Articles 9 to 13. Organisations implementing ISO 42001 build the governance infrastructure that EU AI Act compliance requires — risk management systems, data governance documentation, human oversight measures, and post-market monitoring processes.
ISO 42001 certification does not satisfy EU AI Act obligations directly, but the documentation produced during ISO 42001 implementation provides a significant proportion of the evidence base for EU AI Act technical documentation. A cross-framework assessment identifies exactly where ISO 42001 controls satisfy EU AI Act obligations and where additional specific work is required.
What are the nine Annex A control areas in ISO 42001?
The nine Annex A control areas are: organisational policies for AI — governance framework and policy commitments; internal organisation — roles, responsibilities, and accountability structures; resources for AI systems — human, infrastructure, and data resources; AI system lifecycle — development, deployment, monitoring, and decommissioning; data for AI systems — data quality, provenance, and governance; information for interested parties about AI systems — transparency and disclosure; use of AI systems — responsible use controls and human oversight; human oversight and determination — controls ensuring meaningful human review; and documentation obligations — the documented information the AIMS requires. The readiness assessment covers all nine areas and identifies the gap between your current position and what certification requires.
Is ISO 42001 certification worth it for a startup or SME?
It depends on your sales motion. If your buyers are enterprise organisations, regulated sector entities, or government bodies — ISO 42001 certification will increasingly be a qualification criterion rather than a differentiator. If your buyers are other startups or SMEs without governance requirements, certification adds cost without immediate commercial return. The readiness assessment establishes where you currently stand against the standard and what certification would require — giving you the information to make that decision based on your actual situation rather than general advice.
How does ISO 42001 relate to ISO 27001?
ISO 42001 follows the same Harmonized Structure as ISO 27001, making integrated implementation straightforward for organisations already certified to the information security standard. ISO 27001 addresses information security management across all information assets. ISO 42001 addresses AI management specifically — the governance of AI system development, deployment, and use.
The two standards are complementary: ISO 27001 addresses the security of the data AI systems process; ISO 42001 addresses the governance of how AI systems are built and used. Organisations handling AI and sensitive data benefit from both, and the structural overlap makes integrated implementation significantly more efficient than two separate programmes.
How do I start ISO 42001 readiness for my organisation?
First, determine the scope of your AIMS — which AI systems, processes, and organisational functions should fall within the certification boundary.
Second, conduct a clause-by-clause gap analysis against ISO 42001’s seven operative clauses, identifying what governance practices already exist and what needs to be built.
Third, assess your Annex A control position across all nine areas and prepare a draft Statement of Applicability. Fourth, identify an appropriate accredited certification body and establish a realistic implementation timeline from your current position.
Our readiness assessment covers all four steps and delivers a documented gap analysis, draft SoA, and certification pathway specific to your organisation — mapped against your EU AI Act, GDPR, and sector-specific regulatory position where all apply.
