ISO/IEC 42001 for AI management systems

ISO/IEC 42001 readiness, without guessing at the scope

ISO/IEC 42001 is the international management-system standard for artificial intelligence. It asks you to govern the AI you build or use — who is accountable, what each system is for, how its risks and impacts are assessed, and what evidence shows the whole thing operates. If you already run ISO 27001, the structure will look familiar; the subject matter will not. Comparing frameworks? See all frameworks, or the broader AI risk and governance practice this sits inside.

Cyber AB RP (CPN 76768) · CISSP · CRISC · CCSK v5 · CCZT  |  Fixed-fee  |  Veteran-owned

What ISO 42001 is asking for

  • A defined scope — which AI systems the management system covers, and which it does not.
  • Named accountability for AI decisions, not just for the software that runs them.
  • Risk assessment covering the AI system itself, plus an impact assessment covering effects on the people it touches.
  • Policies and controls proportionate to what each system actually does.
  • Records that show the system operates and is reviewed — the part that fails audits.

How it differs from ISO 27001

ISO 27001 protects information. ISO 42001 governs the system making decisions about it, and asks questions a security standard never does: what was this trained on, who does it affect, how are its outputs monitored, and what happens when it behaves unexpectedly.

The impact assessment is the clearest difference. It looks outward — at individuals and at society — where a security risk assessment looks inward at the organization. An existing ISMS is a head start on the clauses, not a substitute for the subject.

When ISO 42001 comes up

  • An enterprise customer's vendor AI review, or new AI questions bolted onto a security questionnaire.
  • Preparing for regulatory expectations such as the EU AI Act.
  • Governing AI the business already runs, with no certification goal at all — the standard works as a structure either way.

Sometimes certification is the requirement. More often, right now, a customer wants to see that you follow the principles and can show your work.

Start with discovery, not with the standard

A management system cannot govern what nobody has inventoried, and in most organizations the honest first answer to "what AI are we running?" is incomplete. Shadow AI — tools adopted team by team without review — is where the data-exposure risk usually sits.

Establishing what is actually in use, and what data reaches it, comes before any decision about scope or certification is worth making. See AI risk and governance for that work, and AIUC-1 readiness if you are selling an AI agent to enterprises.

Certification is not ours to grant

Certification audits and certification decisions are performed by independent accredited certification bodies. No consultancy can both prepare you and certify you without destroying the independence that makes the certificate mean anything — so Cyberneza does the readiness, implementation, advisory and coordination, and the certification body does the audit. We work alongside your chosen body rather than in place of one.

What it costs

Fixed fees, published up front

Every engagement is a fixed fee — you know the number before work begins, and we do not bill hourly.

  • Security Health Check — a read-only diagnostic, including what AI is actually in use, so you know what to address first before committing to anything bigger.
  • AI governance gap assessment — a control-by-control review against ISO/IEC 42001, with an evidence inventory and an executive summary. Scoped to the AI systems in play.
  • Full ISO 42001 readiness — a custom fixed fee, scoped after a free call. AI management system build through certification-audit coordination, as one number in writing before we start.

Entry engagements carry a published fixed fee — see pricing — and whichever you start with is credited in full toward your next engagement when it starts within 90 days. Assessing ISO 42001 alongside ISO 27001 is quoted at scoping: the management-system clauses overlap substantially, so the second framework costs meaningfully less than double.

See full pricing and what each package includes →

FAQ

Common questions

What is ISO/IEC 42001?

ISO/IEC 42001 is the international management-system standard for artificial intelligence. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system (AIMS) — governance roles, AI-specific risk and impact assessment, policies, controls, and the records that show the system operates. It is structured like ISO/IEC 27001 and ISO 9001, so an organization already running a certified management system will recognize the shape of it.

How is ISO 42001 different from ISO 27001?

ISO 27001 governs information security — protecting the confidentiality, integrity and availability of information. ISO 42001 governs the AI system itself, and asks questions security standards do not: what the system is for, who it affects, how it was trained and on what data, how outputs are monitored, and what happens when it behaves unexpectedly. It adds an AI impact assessment covering effects on individuals and society, not just on the organization. The two overlap in structure rather than in subject, which is why an existing ISMS is a head start rather than a substitute.

Who is asking for ISO 42001?

Most commonly enterprise customers running vendor AI reviews, procurement teams that have added AI questions to their security questionnaires, and organizations preparing for regulatory expectations such as the EU AI Act. It is also used internally as a structure for governing AI a company already deploys, without any certification goal — the standard is useful as a framework whether or not a certificate follows.

Does Cyberneza certify us against ISO 42001?

No, and no consultancy can. Certification audits and certification decisions are performed by independent accredited certification bodies, and the same firm cannot both prepare you and certify you without compromising that independence. Cyberneza provides readiness, implementation, advisory and coordination — defining scope, building the management system, running internal audits, and preparing the evidence — and the certification body performs the audit.

Do we need ISO 42001 if we only use AI vendors rather than building models?

Possibly. The standard applies to organizations that provide or use AI systems, so a company that only buys AI still has obligations around what it deploys, what data it exposes to those systems, and how it oversees outputs. In practice the scope for an AI user is narrower than for an AI developer, and settling that scope honestly is the first piece of work rather than something to assume in either direction.

Where should we start if we do not know what AI we are running?

With discovery, because a management system cannot govern what nobody has inventoried. Shadow AI — tools adopted by individual teams without review — is common and is usually where the data-exposure risk sits. A Security Health Check or a scoped AI discovery pass establishes what is actually in use before any decision about certification is worth making. See AI risk and governance →

Start with what you are actually running.

Tell us which AI systems are in use or in development, who is asking you about them, and whether a certificate is the goal or a customer review is the deadline. We will come back with the applicable scope, the gap between where you are and what ISO 42001 expects, and the work required — as a fixed fee, before anything starts.

Start a conversation