A customer security questionnaire lands in your inbox, and one line asks whether you're "ISO 42001 certified or working toward it." You built an AI feature into your product eight months ago. Nobody on the team has heard the term before today.
So, what is ISO 42001 in plain terms? It's the international standard for an AI Management System (AIMS), published jointly by ISO and the International Electrotechnical Commission (IEC) in December 2023 as ISO/IEC 42001:2023. It sets out how an organization governs the way it designs, develops, deploys, or uses AI responsibly, and certification against it proves that governance system actually works, day to day, not just that a policy exists somewhere in a shared drive.
This guide is written for founders, security leads, and product leaders at early-stage SaaS companies deciding whether ISO 42001 is relevant to them yet, not for an enterprise AI governance team already deep into implementation.
Here's what I'll cover:
- What ISO 42001 actually is, and what an AI Management System (AIMS) means in practice
- Whether it's mandatory, and who realistically needs to care
- Why it matters for AI-building startups specifically, right now
- The 10 ISO 42001 clauses and Annex A controls that make up the standard
- How certification actually works, how long it takes, and roughly what it costs
- How ISO 42001 relates to ISO 27001
- The most common misconceptions worth clearing up before you start
One quick disambiguation before the rest of this guide: ISO 42001 the standard is not the same thing as an AI governance policy document. The next section draws that line clearly, and if drafting the policy document itself is what actually brought you here, ComplyJet's guide to writing an AI governance policy is the more direct read.
What Is ISO 42001? The AI Management System Standard, Defined
ISO 42001 is the AIMS standard: the international standard that specifies requirements for an Artificial Intelligence Management System, or AIMS. Its full name is ISO/IEC 42001:2023, published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) in December 2023, the first global standard of its kind.
An AIMS isn't a checklist you complete once. Like any AIMS standard, ISO 42001 defines an ongoing system of policies, processes, risk assessments, and controls that governs how an organization builds or uses AI responsibly, reviewed and improved on a real cycle, the same way an information security management system never really "finishes."
What Is an AI Management System (AIMS)?
AIMS stands for AI Management System. It's worth defining plainly and early, since the acronym gets used constantly in AI compliance content as if everyone already knows what it means.
An AIMS runs on the same Plan-Do-Check-Act logic as an ISO 27001 Information Security Management System (ISMS): build the system, run it, check whether it's actually working, then improve it based on what you find. If your team already holds ISO 27001, a meaningful amount of the operating muscle an AIMS needs, documented scope, management review, internal audit, corrective action, is already in place. You're extending a habit, not building one from nothing.
What Is ISO 42001, Really, and What Isn't It? (ISO 42001 vs. an AI Governance Policy)
Here's the confusion worth naming directly: ISO 42001 is the certifiable standard for the management system. An AI governance policy is a document. They get used almost interchangeably in some vendor content, and that's a real problem for anyone trying to figure out what they actually need to do.
A company can write a thorough AI governance policy and never pursue ISO 42001 certification at all. A company can also hold ISO 42001 certification with its AI governance policy sitting as just one artifact inside a much larger system, alongside risk assessments, impact assessments, training records, and audit evidence.
ComplyJet's own guide to the topic puts it plainly: under ISO 42001, the AI governance policy is a core component of the AI management system, not a stand-in for the system itself.
If drafting that policy document is genuinely your next step, not evaluating the standard itself, ComplyJet's AI governance policy guide covers what to put in one. This article stays focused on the standard.
What Is ISO 42001 Required For? Who Actually Needs It (and Is It Mandatory?)
ISO 42001 is a voluntary, certifiable standard. It isn't a legal or regulatory requirement in most jurisdictions today. Nobody is required by law to hold it the way, say, a payment processor is required to meet PCI DSS.
That said, "voluntary" doesn't mean "optional to ignore." Enterprise customers evaluating AI vendors are increasingly asking about it directly in security reviews and procurement questionnaires, the same way SOC 2 and ISO 27001 went from nice-to-have to table stakes over the last decade. A-LIGN's own research frames it as a standard likely to become an industry benchmark even without a legal mandate behind it, and that's consistent with what we're seeing across the frameworks ComplyJet supports.
Who actually needs to care isn't limited to companies selling AI as their core product. It's any organization that designs, develops, deploys, or supplies AI systems, which now includes a SaaS company that shipped one LLM-powered feature last quarter just as much as a company built around AI from day one.
The startups asking me about ISO 42001 right now aren't AI companies in the way people mean that term. They're SaaS teams that added one AI feature, closed one enterprise deal that asked hard questions about it, and realized they had no structured answer. That gap is exactly what an AIMS closes, and it doesn't require enterprise headcount to close it. — Upendra Varma, CTO at ComplyJet
A lean, right-sized AIMS is realistic at that size, not just something a large enterprise with a dedicated AI governance team can pull off. It just needs to be scoped to what the company is actually doing with AI, not modeled on how a 2,000-person enterprise would do it.
Why ISO 42001 Matters for AI-Building Startups Right Now
The stakes here aren't theoretical. Three things are converging at once: the EU AI Act's obligations are phasing in through 2026 and 2027 and demand exactly the governance discipline ISO 42001 formalizes (risk management, documentation, human oversight, monitoring), customer security questionnaires are starting to name ISO 42001 specifically rather than asking generic "how do you handle AI" questions, and AI vendor risk has become a standard line item in enterprise procurement diligence, not an edge case.
None of that requires starting from zero if you already hold another framework. Drata has disclosed that its existing SOC 2, ISO 27001, and privacy framework work already covered roughly 35-40% of ISO 42001's requirements when it pursued its own certification, a genuinely useful data point for any team wondering how much of this overlaps with work they've already done.
Real-world proof this isn't just enterprise theater: AWS, Anthropic, and Microsoft all now hold ISO 42001 certification for specific AI products and services (Amazon Bedrock and Textract, Claude and Anthropic's AI research activities, and Microsoft's Azure AI Foundry Models and Copilot products, respectively). None of that requires a 20-person team to match their scope. It confirms the standard is being actively used as a real evaluation signal, not a paper credential nobody checks.
What Is ISO 42001 Made Of? Clauses and Annex A Controls Explained
ISO 42001 has two structural pieces: 10 clauses that define the management system itself, and Annex A, a catalogue of controls an organization selects from based on its own AI risk profile. This is where the concrete ISO 42001 requirements actually live, not just a name-check of "10 clauses." Both pieces are confirmed consistently across ISO's harmonized structure (the same skeleton ISO 27001, ISO 9001, and ISO 22301 all share) and every certification-body source we checked.
| Clause | What it actually requires |
|---|---|
| 1. Scope | Defines what the standard covers; no organization-specific requirement |
| 2. Normative references | Points to related standards used for shared terms and definitions; no organization-specific requirement |
| 3. Terms and definitions | Shared vocabulary for the standard; no organization-specific requirement |
| 4. Context of the organization | Understand the organization, its interested parties, and the scope of the AIMS |
| 5. Leadership | Top management commits to the AIMS, sets AI policy, and assigns roles and responsibilities |
| 6. Planning | Assess AI-related risks and opportunities, and set AIMS objectives to address them |
| 7. Support | Provide the resources, competence, awareness, and documented information the AIMS needs |
| 8. Operation | Run the operational core: AI risk assessment, AI system impact assessment, and lifecycle controls |
| 9. Performance evaluation | Monitor, measure, internally audit, and formally review the AIMS |
| 10. Improvement | Correct nonconformities and drive continual improvement based on what evaluation finds |
Clauses 4 through 10 are the mandatory, auditable core. Clauses 1 through 3 are front matter, the same convention this standard shares with ISO 27001 and ISO 22301, so if you've read a ComplyJet guide to either of those, this structure will already look familiar.
The 10 ISO 42001 Clauses, at a Glance
- Context: who you are, who's affected, what's in scope
- Leadership: top management owns this, not delegated entirely to engineering
- Planning: what could go wrong, and what you're doing about it
- Support: the resources and training the system actually needs to run
- Operation: risk assessment and impact assessment for each AI system in scope
- Performance evaluation: checking whether the system is actually working
- Improvement: fixing what performance evaluation finds
What Is ISO 42001 Annex A? 38 Controls Across 9 Objectives
Annex A contains the 38 ISO 42001 controls, grouped under 9 control objectives numbered A.2 through A.10. Sources don't fully agree on this number: Vanta's dedicated Annex A controls page states 38, and OneTrust's blog states 39.
38 is the correct figure. Vanta's controls page lists all 9 objectives and 38 controls by name, and six further independent, non-competing sources (Konfirmity, ISMS.online, Mindsetcyber, RiskProfs, Tempo Audits, and DeepInspect) all converge on the same count. OneTrust's 39 is the outlier here, unsupported by any other source checked.
ISO's own standard preview page returns a 403 on direct access, a recurring block on ISO.org rather than a content issue, so it couldn't serve as a direct additional confirmation. The weight of agreement across seven independent sources is strong enough to state 38 with confidence.
The 9 objective categories, in plain language:
- A.2 Policies related to AI: the AI policy itself and how it's governed
- A.3 Internal organization: roles, responsibilities, and reporting lines for AI governance
- A.4 Resources for AI systems: the people, tooling, and data resourcing AI work needs
- A.5 Assessing impacts of AI systems: the impact-assessment process, covering things like bias and fairness
- A.6 AI system life cycle: design, development, testing, deployment, and monitoring (the largest single objective)
- A.7 Data for AI systems: data quality, provenance, and handling for training and operation
- A.8 Information for interested parties: transparency toward users, customers, and other stakeholders
- A.9 Use of AI systems: how deployed systems are actually operated and monitored
- A.10 Third-party and customer relationships: vendor and supply-chain AI risk
What Is ISO 42001 Certification, and How Does It Work?
The certification path, sourced from certification-body process documentation, runs in this order:
- Readiness or gap assessment against ISO 42001 requirements: the 10 clauses and applicable Annex A controls
- AIMS implementation: policies, AI risk assessment, impact assessments, and the controls the risk assessment selects
- Internal audit to confirm the AIMS is operating as designed before an external body ever looks at it
- External Stage 1 audit: a documentation review, checking the AIMS's policy, scope, and records actually exist and cover what they need to
- External Stage 2 audit: operational verification that the AIMS is genuinely running, not just written down
- Certification, followed by annual surveillance audits across a three-year cycle
This is overview depth on purpose. Every organization's starting point is different, and a genuinely useful step-by-step walkthrough depends on specifics this guide isn't scoped to assume.
How Long Does ISO 42001 Certification Take?
| Starting point | Realistic timeline |
|---|---|
| No existing management system | Several months to roughly a year, depending on team size and how much of the AIMS has to be built from scratch |
| Already running an ISO 27001 ISMS | Meaningfully shorter, since scope, management review, and internal audit can extend rather than start over |
One concrete data point competitors rarely state: the gap between Stage 1 and Stage 2 audits typically shouldn't exceed six months. If it does, some certification bodies will require re-verifying the Stage 1 findings before Stage 2 proceeds, which is a real reason not to let readiness work drag once Stage 1 is booked.
What Does ISO 42001 Certification Cost? (At a Glance)
Current sources put a small organization's first-year, all-in cost, gap analysis, consulting if used, audit fees, and tooling, roughly in the $15,000-$60,000 range, varying significantly with scope, whether outside consultants are involved, and organization size. Treat this as a rough orientation figure, not a quote.
A full cost breakdown, with audit fees separated from consulting and tooling costs by organization size, deserves deeper treatment than an overview like this one can give it. What's here is enough to get oriented with, not a firm quote.
How ISO 42001 Relates to ISO 27001
ISO 42001 shares the same Annex SL high-level management-system structure as ISO 27001, the identical clause-numbering logic (context, leadership, planning, support, operation, performance evaluation, improvement) mapped onto AI governance instead of information security. An organization already certified to ISO 27001 has a real head start, for the same reason an ISO 27001-certified company finds ISO 22301 lighter to add than building from zero.
This is a brief pointer, not a full comparison. For the complete side-by-side breakdown, including where the two frameworks' controls genuinely overlap and where they diverge, see ComplyJet's dedicated ISO 27001 and AI compliance comparison. This article stays focused on defining ISO 42001 itself.
What Is ISO 42001, Actually? Common Misconceptions Worth Clearing Up
- Treating ISO 42001 Annex A as a mandatory, top-to-bottom checklist. Covered above, and worth repeating because it's the single most common misreading of the standard: you select controls based on risk, not implement all 38 by default.
- Scoping the AIMS across the entire company instead of the actual AI systems in play. A five-person company with one AI feature doesn't need every team and process in scope. Scope to the systems that actually use or produce AI, then expand as the business grows.
- Assuming "we have an AI governance policy" is the same as being ISO 42001 certified. It's one artifact inside a larger system, covered in the definitions section above. A policy without a functioning risk assessment process, internal audit, and management review behind it isn't a certifiable AIMS.
- Missing shadow AI from the AIMS scope entirely. Unauthorized or unofficial internal use of AI tools, an engineer running production data through a public chatbot, a support team pasting customer messages into an unapproved tool, is squarely in scope for a real risk assessment, even when it's uncomfortable to surface.
- Assuming ISO 27001 certification alone automatically satisfies ISO 42001. The shared Annex SL skeleton gives you a real head start on management-system fundamentals. It doesn't cover AI-specific requirements like impact assessment for bias and fairness, or AI system lifecycle controls, on its own.
- Skipping the management review requirement. Clause 9 isn't optional paperwork. Auditors expect to see it actually happening, on a real cadence, with real decisions coming out of it.
- Booking the external audit before the AIMS has been operating long enough to generate real evidence. Stage 2 checks whether the system is genuinely running, not just documented. An AIMS that's two weeks old when the auditor shows up won't have the exercise records, risk assessments, or review minutes Stage 2 actually looks for.
Where ComplyJet Fits Into Your ISO 42001 Program
ComplyJet directly supports and certifies ISO 42001, not as an adjacent framework we mention in passing, but as one we actively build for. That includes ISO 42001-specific policy and procedure templates, a structured AI risk assessment framework, and AI impact assessment templates covering bias, transparency, and fairness.
It also includes automated evidence collection across 350+ integrations, AI supply chain documentation for the model providers and third-party AI components you depend on, and a vetted network of independent ISO 42001 auditors with a dedicated workspace for Stage 1 and Stage 2 audits.
Pricing is flat and per-company, not per-seat, so the cost stays predictable as your team grows from a five-person startup to 30 or 40 people during the certification journey. That's not the cheap option. It's the considered one for a team that's thinking carefully about what compliance actually needs to cost as it scales.
If your next step is drafting the AI governance policy document itself rather than evaluating certification, ComplyJet's AI governance policy guide is the more direct read.
FAQs
What Is ISO 42001?
ISO 42001 is the international standard for an AI Management System (AIMS), published jointly by ISO and IEC in December 2023. It sets out how an organization governs the way it designs, develops, deploys, or uses AI, and certification proves that governance system actually works. See the definition section above for the full breakdown.
Is ISO 42001 Mandatory?
No. It's a voluntary, certifiable standard, not a legal requirement in most jurisdictions today. It's increasingly expected contractually, though, especially in enterprise procurement and security questionnaires. See the "who needs it" section above for more detail.
Who Needs ISO 42001?
Any organization that designs, develops, deploys, or supplies AI systems, not just companies selling AI as their core product. A SaaS company with a single AI-powered feature counts. The full section above covers what that looks like realistically at startup scale.
What Is an AI Management System?
An AI Management System (AIMS) is an ongoing system of policies, processes, risk assessments, and controls governing how an organization builds or uses AI responsibly. It's not a single document. See the AIMS sub-section above for the full definition.
How Is ISO 42001 Different From ISO 27001?
ISO 27001 secures information; ISO 42001 governs AI systems. They share the same Annex SL high-level structure, which gives an ISO 27001-certified organization a real head start. See the relationship section above, and ComplyJet's full ISO 27001-vs-ISO 42001 comparison for the complete breakdown.
How Long Should You Budget for ISO 42001 Certification?
Realistically, several months to roughly a year, depending heavily on your starting point and whether you already hold ISO 27001. See the certification timeline section above for the full range.
How Many Annex A Controls Does ISO 42001 Have?
38 controls across 9 objectives, numbered A.2 through A.10. One source (OneTrust) states 39; the majority of independently checked sources converge on 38, which this guide verified directly against Vanta's dedicated controls page and five additional independent sources. See the Annex A section above for the full list of objectives.
When Was ISO 42001 Published?
December 2023, published jointly by ISO and IEC as ISO/IEC 42001:2023, independently corroborated across multiple sources including Drata, OneTrust, KPMG, and Microsoft's own compliance documentation.
Related Reading
- ISO 27001 and AI Compliance: The Complete Comparison, for the full ISO 27001-vs-ISO 42001 breakdown this article deliberately doesn't re-do
- How to Write an AI Governance Policy, the practical drafting guide for readers whose next step is the document itself, not the standard
- Does SOC 2 Cover AI?, for readers weighing how their existing SOC 2 program does or doesn't already touch AI-specific risk
- Best SOC 2 Compliance Platforms for AI Companies, for readers comparing platforms across their broader AI-and-compliance stack
- ComplyJet's ISO 42001 Framework Page, for readers ready to evaluate certification support directly
Sources: Annex A control count (38 controls, 9 objectives) independently verified against Vanta's ISO 42001 controls guide, ISMS.online's Annex A controls guide, and Mindsetcyber's Annex A controls list, against OneTrust's outlier figure of 39 in "Managing AI Compliance with ISO 42001".
Publication date and standard framing cross-checked against A-LIGN's ISO 42001 explainer and KPMG Switzerland's ISO/IEC 42001 overview. Framework-overlap statistic sourced to Drata's own disclosed ISO 42001 certification experience.
Certification examples sourced to Anthropic's ISO 42001 certification announcement and AWS's ISO/IEC 42001:2023 certification announcement; Microsoft's parallel certification of Azure AI Foundry Models and Security Copilot is publicly announced on Microsoft's own Azure blog.

