ISO 42001 Readiness for AI Vendors
An AI management system built on real AI security work, integrated with your ISO 27001 ISMS, mapped to the EU AI Act obligations you actually have, and kept alive after the certificate by an AIMS owner seat.
Readiness from $18,000. AIMS owner seat from $1,500 per month. Fixed.

Why AI Vendors Are Asking About ISO 42001 Now
A Fortune 500 questionnaire now asks for ISO 42001 certified or roadmap
Through 2025 large buyers began writing ISO 42001 into vendor due diligence for any supplier shipping AI features. Fewer than roughly 350 to 400 certificates existed worldwide by spring 2026, so most vendors answer that question with a blank. A credible roadmap, and then a certificate, closes the deal.
The EU AI Act dates are now real
Article 50 transparency obligations have applied since 2 August 2026. Annex III high-risk obligations follow on 2 December 2027 and Annex I embedded systems on 2 August 2028. ISO 42001 is the management-system evidence behind all of them, and certification bodies are quoting six-month backlogs for stage 2 audits.
Your ISO 27001 ISMS does not cover the AI system
The ISMS protects data. It does not inventory models, assess AI impact on individuals, govern training data, document human oversight or manage the lifecycle of a system that changes with every retraining. Those are the 38 Annex A controls of ISO 42001, and they need a security foundation to mean anything.


What the 38 Annex A Controls Actually Cover
Annex A of ISO 42001 groups its controls around policy, internal organisation, resources, impact assessment, the AI system lifecycle, data, information for interested parties, use of AI systems and third-party relationships. The controls that take real work are the ones that require you to know, document and test what your AI systems do.



Built on Security, Not on Policy Writing
An AI management system governs risk in systems that are being attacked in new ways: prompt injection through retrieved content, agents with over-broad credentials, poisoned models and tooling in the supply chain. If nobody has tested the system for those, the Annex A controls describe a risk nobody has measured.
We pair readiness with AI application testing and agent security review, so the impact assessment reflects what the system does under attack and the controls are grounded in evidence. That is also what makes the resulting system credible to a certification body auditor who has seen a dozen policy-only AIMS implementations.
After the certificate, the AIMS owner seat keeps the inventory, assessments and monitoring current between surveillance audits.
Who Is Being Asked for It?
Compared With Typical ISO 42001 Consulting
| Atlant Security | Typical consultancy | |
|---|---|---|
| Foundation | Built on AI security assessment, threat modelling and agent testing | A policy pack with the word AI inserted |
| Integration | One integrated ISMS and AIMS, shared clauses handled once | A second, parallel management system |
| After the certificate | AIMS owner seat and independent internal audit available | Consultant gone; system decays before surveillance |
| Regulatory mapping | Every control mapped to the EU AI Act obligations you actually have | Generic references to responsible AI |
| Pricing | Published fixed prices | Quoted after the free consultation |
Readiness in Four Steps
AI system inventory and classification
Every AI system, agent and third-party model in use, classified by purpose, autonomy, data and EU AI Act risk tier. This is the artefact that makes the rest possible and that buyers ask for first.
Gap analysis against Annex A
The 38 controls assessed against your current state, integrated with your ISO 27001 ISMS where you have one so shared clauses are handled once.
Impact assessments, governance and controls
AI impact assessment methodology applied, data governance, transparency, human oversight and lifecycle controls implemented with your engineering team. Paired with AI application testing so the controls are real.
Internal audit, management review, hand-off
Independent internal audit and management review, then certification body selection and stage 1 support. The AIMS owner seat keeps it alive after the certificate.


ISO 42001 Pricing
Published and fixed. The certification body charges its own audit fee separately; we tell you what to expect and which bodies have realistic lead times.
ISO 42001 Readiness
Organisations of roughly 30 to 150 staff with a defined set of AI systems.
- AI system inventory and classification register
- Gap analysis against the 38 Annex A controls
- Impact assessment methodology and first assessments
- Control implementation with your engineering team
- AI application and agent security testing
- Independent internal audit and management review
AIMS Owner Seat
Keeps the system current between audits, as an add-on to a vCISO or ISMS engagement.
- Inventory and classification kept current
- Impact assessments for new systems and retraining
- Third-party model and tooling reviews
- Monitoring and incident input for AI systems
- Management review preparation
- Surveillance audit readiness
Larger or multi-product organisations are quoted in writing before we start. You review each deliverable before you pay.
Answer the Questionnaire With a Date, Not a Blank
One call to inventory what you actually run and confirm the AI Act tier, then a fixed-price plan to certification readiness.
Book Your AI Governance Call