ISO/IEC 42001:2023 / EU AI Act aligned

Answer the AI Questionnaire With a Date, Not a Blank.

An AI management system built on real AI security work, integrated with your ISO 27001 ISMS, mapped to the EU AI Act obligations you actually have, and kept alive after the certificate by an AIMS owner seat.

Readiness from $18,000. AIMS owner seat from $1,500 per month. Fixed.

Integrated with ISO 27001Grounded in AI security testingIndependent internal audit
ISO 42001 AI management system readiness for AI vendors by Atlant Security
Alexander Sverdlov, founder of Atlant Security
Alexander SverdlovFounder, Atlant SecurityCISSP, CEH, CHFI, Mandiant

Runs the ISO 42001 readiness work and separates real AI governance from paperwork.

Connect on LinkedIn

Why AI Vendors Are Asking About ISO 42001 Now

A Fortune 500 questionnaire now asks for ISO 42001 certified or roadmap

Through 2025 large buyers began writing ISO 42001 into vendor due diligence for any supplier shipping AI features. Fewer than roughly 350 to 400 certificates existed worldwide by spring 2026, so most vendors answer that question with a blank. A credible roadmap, and then a certificate, closes the deal.

The EU AI Act dates are now real

Article 50 transparency obligations have applied since 2 August 2026. Annex III high-risk obligations follow on 2 December 2027 and Annex I embedded systems on 2 August 2028. ISO 42001 is the management-system evidence behind all of them, and certification bodies are quoting six-month backlogs for stage 2 audits.

Your ISO 27001 ISMS does not cover the AI system

The ISMS protects data. It does not inventory models, assess AI impact on individuals, govern training data, document human oversight or manage the lifecycle of a system that changes with every retraining. Those are the 38 Annex A controls of ISO 42001, and they need a security foundation to mean anything.

~350-400ISO 42001 certificates worldwide by spring2026Enterprise buyers began writing the standard into vendor due diligencethrough 2025. Most suppliers still answer that question with a blank.
Early certified organisations include Anthropic, Snowflake, Salesforce, ServiceNow and BCG, which sets the expectation for their suppliers.
EU AI Act dates that drive the AIMS2 Aug 2026Article 50 appliesTransparency and markingobligations2 Dec 2026Watermarking graceendsFor systems already on themarket2 Dec 2027Annex III high-riskRisk management,documentation, oversight2 Aug 2028Annex I embeddedHigh-risk systems insideregulated products
Certification bodies were quoting six-month backlogs for stage 2 audits in 2025. Start the body selection early.

What the 38 Annex A Controls Actually Cover

Annex A of ISO 42001 groups its controls around policy, internal organisation, resources, impact assessment, the AI system lifecycle, data, information for interested parties, use of AI systems and third-party relationships. The controls that take real work are the ones that require you to know, document and test what your AI systems do.

AI system inventory
Every model, agent and AI feature classified by role, risk and data
Impact assessment
Effects on individuals, groups and society, documented and reviewed
Data governance
Provenance, quality, bias and rights across training and inference data
Lifecycle management
Design, verification, deployment, monitoring, retraining and retirement
Transparency and oversight
What users are told, what humans can override, and how
Third parties
Model providers, APIs and agent tooling assessed as suppliers
The 38 Annex A controls, groupedAI system inventoryEvery model, agent and feature classified byrole, risk and dataImpact assessmentEffects on individuals, groups and society,documented and reviewedData governanceProvenance, quality, bias and rights acrosstraining and inferenceLifecycle managementDesign, verification, deployment,monitoring, retraining, retirementTransparency and oversightWhat users are told, what humans canoverride, and howThird partiesModel providers, APIs and agent toolingassessed as suppliers
Your ISO 27001 ISMS protects data. It does not do any of the above.
Who is being asked for ISO 42001SaaS shipping AI featuresEnterprise questionnaires now ask for certified or a roadmapFintech using modelsCredit, fraud, KYC and trading decisionsHealthtech and biometricsWhere AI touches health or special-category dataHR-tech and recruitmentPlatforms making decisions about people
The AI Act adds regulatory pressure on top of the commercial pressure through 2027.
An AIMS built on testing, not on paperworkHow we build itGrounded in AI security assessment and agent testingOne integrated ISMS and AIMS, shared clauses handled onceEvery control mapped to the AI Act obligation you actuallyhaveIndependent internal audit under clause 9.2An AIMS owner seat after the certificateWhat we will not doIssue a certificate; only accredited bodies canAudit an AIMS we designed ourselvesShip a policy pack with the word AI insertedGovern a system nobody has tested
Prompt injection, agent tool abuse, retrieval leakage and model supply chain are the threats these controls exist to manage.

Built on Security, Not on Policy Writing

An AI management system governs risk in systems that are being attacked in new ways: prompt injection through retrieved content, agents with over-broad credentials, poisoned models and tooling in the supply chain. If nobody has tested the system for those, the Annex A controls describe a risk nobody has measured.

We pair readiness with AI application testing and agent security review, so the impact assessment reflects what the system does under attack and the controls are grounded in evidence. That is also what makes the resulting system credible to a certification body auditor who has seen a dozen policy-only AIMS implementations.

After the certificate, the AIMS owner seat keeps the inventory, assessments and monitoring current between surveillance audits.

Who Is Being Asked for It?

SaaS vendors shipping AI features into enterprise customers
Fintechs using models for credit, fraud, KYC or trading decisions
Healthtech and any vendor whose AI touches health or biometric data
HR-tech and recruitment platforms making decisions about people

Compared With Typical ISO 42001 Consulting

Atlant SecurityTypical consultancy
FoundationBuilt on AI security assessment, threat modelling and agent testingA policy pack with the word AI inserted
IntegrationOne integrated ISMS and AIMS, shared clauses handled onceA second, parallel management system
After the certificateAIMS owner seat and independent internal audit availableConsultant gone; system decays before surveillance
Regulatory mappingEvery control mapped to the EU AI Act obligations you actually haveGeneric references to responsible AI
PricingPublished fixed pricesQuoted after the free consultation

Readiness in Four Steps

1

AI system inventory and classification

Every AI system, agent and third-party model in use, classified by purpose, autonomy, data and EU AI Act risk tier. This is the artefact that makes the rest possible and that buyers ask for first.

2

Gap analysis against Annex A

The 38 controls assessed against your current state, integrated with your ISO 27001 ISMS where you have one so shared clauses are handled once.

3

Impact assessments, governance and controls

AI impact assessment methodology applied, data governance, transparency, human oversight and lifecycle controls implemented with your engineering team. Paired with AI application testing so the controls are real.

4

Internal audit, management review, hand-off

Independent internal audit and management review, then certification body selection and stage 1 support. The AIMS owner seat keeps it alive after the certificate.

From inventory to certification readiness1InventoryEvery AI system, agent andthird-party model, classifiedby AI Act risk tier2Gap analysisThe 38 Annex A controlsagainst current state,integrated with ISO 270013Build and testImpact assessments, governanceand oversight, paired with AIapplication testing4Audit and hand-offIndependent internal audit,management review,certification body selection
Four to six months for a company with an existing ISMS and a bounded set of AI systems, plus the body lead time.
What you receiveAI system inventoryThe artefact buyers ask for firstAnnex A gap reportAll 38 controls, graded, with ownersImpact assessment methodRepeatable, applied to your current systemsIntegrated management systemISMS and AIMS sharing clauses 4 to 10Internal audit reportClause 9.2, by an auditor who did not builditAI Act obligation mapEvery control tied to the duty it satisfies
The AIMS owner seat keeps all of it current between audits.

ISO 42001 Pricing

Published and fixed. The certification body charges its own audit fee separately; we tell you what to expect and which bodies have realistic lead times.

To certification readiness

ISO 42001 Readiness

Organisations of roughly 30 to 150 staff with a defined set of AI systems.

From $18,000fixed
  • AI system inventory and classification register
  • Gap analysis against the 38 Annex A controls
  • Impact assessment methodology and first assessments
  • Control implementation with your engineering team
  • AI application and agent security testing
  • Independent internal audit and management review
Get Your Governance Plan

AIMS Owner Seat

Keeps the system current between audits, as an add-on to a vCISO or ISMS engagement.

From $1,500per month
  • Inventory and classification kept current
  • Impact assessments for new systems and retraining
  • Third-party model and tooling reviews
  • Monitoring and incident input for AI systems
  • Management review preparation
  • Surveillance audit readiness
Get Your Governance Plan

Larger or multi-product organisations are quoted in writing before we start. You review each deliverable before you pay.

Answer the Questionnaire With a Date, Not a Blank

One call to inventory what you actually run and confirm the AI Act tier, then a fixed-price plan to certification readiness.

Book Your AI Governance Call

Get Your AI Governance Plan

ISO 42001 FAQ

What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the international standard for an Artificial Intelligence Management System, an AIMS. Published in December 2023, it follows the same harmonised structure as ISO 27001, with clauses 4 to 10 and an Annex A of 38 controls covering AI policy, roles, resources, impact assessment, lifecycle, data, information for interested parties, use of AI systems and third-party relationships. Certification is issued by accredited certification bodies after a two-stage audit.
Who is asking for it?
Enterprise and regulated buyers of AI-enabled software, increasingly through vendor questionnaires that ask for ISO 42001 certified or a roadmap. Early certified organisations include Anthropic, Snowflake, Salesforce, ServiceNow and BCG, which sets the expectation for their suppliers. Insurers and EU AI Act enforcement add further pressure through 2027.
How does it relate to the EU AI Act?
The AI Act sets legal obligations by risk tier; ISO 42001 is the management system that evidences how you meet them. Article 50 transparency obligations have applied since 2 August 2026, Annex III high-risk obligations apply from 2 December 2027 and Annex I embedded high-risk systems from 2 August 2028. An AIMS with a proper inventory and impact assessment process is the fastest route to demonstrating compliance with all three.
We hold ISO 27001. How much overlap is there?
Substantial at the management-system level: context, leadership, planning, support, performance evaluation and improvement share the same structure and can be operated as one integrated system. The AI-specific content, roughly the 38 Annex A controls, is new. We integrate rather than duplicate.
Can Atlant Security certify us?
No. Certificates are issued only by accredited certification bodies, and a body that consulted on your system cannot certify it. We do readiness, the independent internal audit clause 9.2 requires, and the ongoing AIMS owner seat, and we help you select a certification body with realistic lead times.
What does readiness cost?
Readiness for an organisation of roughly 30 to 150 staff with a defined set of AI systems starts at $18,000 fixed, including the inventory, gap analysis, impact assessment methodology, control implementation support and internal audit. The AIMS owner seat, which keeps the system current between audits, starts at $1,500 per month as an add-on to a virtual CISO or ISMS engagement. Larger or multi-product organisations are quoted in writing before we start.
How long does it take?
Four to six months to certification readiness for a company with an existing ISMS and a bounded set of AI systems, plus the certification body lead time, which was six months or more at major bodies in 2025. Start the body selection early.
Why do you pair it with AI security testing?
Because an AIMS that governs an AI system nobody has tested is paperwork. Prompt injection, agent tool abuse, data leakage through retrieval and supply chain risk in models and MCP servers are the threats the controls exist to manage. We test the system so the controls are grounded in what it actually does.

Related Services