ISO/IEC 42001:2023 / EU AI Act aligned

ISO 42001 Readiness for AI Vendors

An AI management system built on real AI security work, integrated with your ISO 27001 ISMS, mapped to the EU AI Act obligations you actually have, and kept alive after the certificate by an AIMS owner seat.

Readiness from $18,000. AIMS owner seat from $1,500 per month. Fixed.

Integrated with ISO 27001Grounded in AI security testingIndependent internal audit
ISO 42001 AI management system readiness for AI vendors by Atlant Security

Why AI Vendors Are Asking About ISO 42001 Now

A Fortune 500 questionnaire now asks for ISO 42001 certified or roadmap

Through 2025 large buyers began writing ISO 42001 into vendor due diligence for any supplier shipping AI features. Fewer than roughly 350 to 400 certificates existed worldwide by spring 2026, so most vendors answer that question with a blank. A credible roadmap, and then a certificate, closes the deal.

The EU AI Act dates are now real

Article 50 transparency obligations have applied since 2 August 2026. Annex III high-risk obligations follow on 2 December 2027 and Annex I embedded systems on 2 August 2028. ISO 42001 is the management-system evidence behind all of them, and certification bodies are quoting six-month backlogs for stage 2 audits.

Your ISO 27001 ISMS does not cover the AI system

The ISMS protects data. It does not inventory models, assess AI impact on individuals, govern training data, document human oversight or manage the lifecycle of a system that changes with every retraining. Those are the 38 Annex A controls of ISO 42001, and they need a security foundation to mean anything.

Around 350 ISO 42001 certificates issued worldwide by spring 2026
EU AI Act dates that set the pace for ISO 42001 readiness

What the 38 Annex A Controls Actually Cover

Annex A of ISO 42001 groups its controls around policy, internal organisation, resources, impact assessment, the AI system lifecycle, data, information for interested parties, use of AI systems and third-party relationships. The controls that take real work are the ones that require you to know, document and test what your AI systems do.

AI system inventory
Every model, agent and AI feature classified by role, risk and data
Impact assessment
Effects on individuals, groups and society, documented and reviewed
Data governance
Provenance, quality, bias and rights across training and inference data
Lifecycle management
Design, verification, deployment, monitoring, retraining and retirement
Transparency and oversight
What users are told, what humans can override, and how
Third parties
Model providers, APIs and agent tooling assessed as suppliers
ISO 42001 has 38 Annex A controls covering inventory, impact assessment, data governance and oversight
Which AI vendors are being asked for ISO 42001
ISO 42001 readiness built on AI security testing rather than policy writing

Built on Security, Not on Policy Writing

An AI management system governs risk in systems that are being attacked in new ways: prompt injection through retrieved content, agents with over-broad credentials, poisoned models and tooling in the supply chain. If nobody has tested the system for those, the Annex A controls describe a risk nobody has measured.

We pair readiness with AI application testing and agent security review, so the impact assessment reflects what the system does under attack and the controls are grounded in evidence. That is also what makes the resulting system credible to a certification body auditor who has seen a dozen policy-only AIMS implementations.

After the certificate, the AIMS owner seat keeps the inventory, assessments and monitoring current between surveillance audits.

Who Is Being Asked for It?

SaaS vendors shipping AI features into enterprise customers
Fintechs using models for credit, fraud, KYC or trading decisions
Healthtech and any vendor whose AI touches health or biometric data
HR-tech and recruitment platforms making decisions about people

Compared With Typical ISO 42001 Consulting

Atlant SecurityTypical consultancy
FoundationBuilt on AI security assessment, threat modelling and agent testingA policy pack with the word AI inserted
IntegrationOne integrated ISMS and AIMS, shared clauses handled onceA second, parallel management system
After the certificateAIMS owner seat and independent internal audit availableConsultant gone; system decays before surveillance
Regulatory mappingEvery control mapped to the EU AI Act obligations you actually haveGeneric references to responsible AI
PricingPublished fixed pricesQuoted after the free consultation

Readiness in Four Steps

1

AI system inventory and classification

Every AI system, agent and third-party model in use, classified by purpose, autonomy, data and EU AI Act risk tier. This is the artefact that makes the rest possible and that buyers ask for first.

2

Gap analysis against Annex A

The 38 controls assessed against your current state, integrated with your ISO 27001 ISMS where you have one so shared clauses are handled once.

3

Impact assessments, governance and controls

AI impact assessment methodology applied, data governance, transparency, human oversight and lifecycle controls implemented with your engineering team. Paired with AI application testing so the controls are real.

4

Internal audit, management review, hand-off

Independent internal audit and management review, then certification body selection and stage 1 support. The AIMS owner seat keeps it alive after the certificate.

ISO 42001 readiness in four steps from inventory to certification hand-off
ISO 42001 readiness deliverables

ISO 42001 Pricing

Published and fixed. The certification body charges its own audit fee separately; we tell you what to expect and which bodies have realistic lead times.

To certification readiness

ISO 42001 Readiness

Organisations of roughly 30 to 150 staff with a defined set of AI systems.

From $18,000fixed
  • AI system inventory and classification register
  • Gap analysis against the 38 Annex A controls
  • Impact assessment methodology and first assessments
  • Control implementation with your engineering team
  • AI application and agent security testing
  • Independent internal audit and management review
Book Free Governance Call

AIMS Owner Seat

Keeps the system current between audits, as an add-on to a vCISO or ISMS engagement.

From $1,500per month
  • Inventory and classification kept current
  • Impact assessments for new systems and retraining
  • Third-party model and tooling reviews
  • Monitoring and incident input for AI systems
  • Management review preparation
  • Surveillance audit readiness
Book Free Governance Call

Larger or multi-product organisations are quoted in writing before we start. You review each deliverable before you pay.

Answer the Questionnaire With a Date, Not a Blank

One call to inventory what you actually run and confirm the AI Act tier, then a fixed-price plan to certification readiness.

Book Your AI Governance Call

Schedule Your Free AI Governance Call

ISO 42001 FAQ

What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the international standard for an Artificial Intelligence Management System, an AIMS. Published in December 2023, it follows the same harmonised structure as ISO 27001, with clauses 4 to 10 and an Annex A of 38 controls covering AI policy, roles, resources, impact assessment, lifecycle, data, information for interested parties, use of AI systems and third-party relationships. Certification is issued by accredited certification bodies after a two-stage audit.
Who is asking for it?
Enterprise and regulated buyers of AI-enabled software, increasingly through vendor questionnaires that ask for ISO 42001 certified or a roadmap. Early certified organisations include Anthropic, Snowflake, Salesforce, ServiceNow and BCG, which sets the expectation for their suppliers. Insurers and EU AI Act enforcement add further pressure through 2027.
How does it relate to the EU AI Act?
The AI Act sets legal obligations by risk tier; ISO 42001 is the management system that evidences how you meet them. Article 50 transparency obligations have applied since 2 August 2026, Annex III high-risk obligations apply from 2 December 2027 and Annex I embedded high-risk systems from 2 August 2028. An AIMS with a proper inventory and impact assessment process is the fastest route to demonstrating compliance with all three.
We hold ISO 27001. How much overlap is there?
Substantial at the management-system level: context, leadership, planning, support, performance evaluation and improvement share the same structure and can be operated as one integrated system. The AI-specific content, roughly the 38 Annex A controls, is new. We integrate rather than duplicate.
Can Atlant Security certify us?
No. Certificates are issued only by accredited certification bodies, and a body that consulted on your system cannot certify it. We do readiness, the independent internal audit clause 9.2 requires, and the ongoing AIMS owner seat, and we help you select a certification body with realistic lead times.
What does readiness cost?
Readiness for an organisation of roughly 30 to 150 staff with a defined set of AI systems starts at $18,000 fixed, including the inventory, gap analysis, impact assessment methodology, control implementation support and internal audit. The AIMS owner seat, which keeps the system current between audits, starts at $1,500 per month as an add-on to a virtual CISO or ISMS engagement. Larger or multi-product organisations are quoted in writing before we start.
How long does it take?
Four to six months to certification readiness for a company with an existing ISMS and a bounded set of AI systems, plus the certification body lead time, which was six months or more at major bodies in 2025. Start the body selection early.
Why do you pair it with AI security testing?
Because an AIMS that governs an AI system nobody has tested is paperwork. Prompt injection, agent tool abuse, data leakage through retrieval and supply chain risk in models and MCP servers are the threats the controls exist to manage. We test the system so the controls are grounded in what it actually does.

Related Services