Published in December 2023, ISO/IEC 42001 is the first international standard for an AI management system — and the only AI framework you can hold a certificate for. It runs clauses 4 to 10 on the harmonised structure every ISO standard shares, plus Annex A and its set of 38 controls.
You already have more of ISO/IEC 42001 than you think.
Clauses 4 to 10 carry over from any certified management system. The impact assessment, Annex A and the lifecycle evidence do not.
Our promise
“Certification is a date. The system is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework readiness assessment produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this readiness assessmentISO 42001, in three chapters
Teams holding ISO 27001 assume they are most of the way there. The structure genuinely does carry — document control, competence, internal audit, management review. Three things do not: the impact assessment, the Annex A control set, and the clause 8 lifecycle evidence.
The independent read before the auditor arrives. We assess every clause and all 38 controls against the evidence you actually hold, and hand you the gap register, the Statement of Applicability and the evidence index. We do not certify, and by the rules of accreditation we could not.
A system you operate, not a project you finish.
The governance, roles, controls and records around how you build and run AI, on a plan, do, check, act cycle.
- Companies selling AI into enterprise procurement
- Teams already certified to ISO 27001 or ISO 9001
- Regulated industries answering a supervisor
- Anyone with EU AI Act exposure to reduce
- Clauses 4-10 - the harmonised management structure
- Annex A - 38 controls across nine groups, A.2 to A.10
- Annexes B, C and D - guidance, risk sources, domains
- A Statement of Applicability accounting for every control
The system is yours. The certificate is theirs.
Top management owns the system
Clause 5 places accountability for the AI management system on top management, and it is not delegable. The policy, the objectives, the resourcing and the management review are theirs. An AIMS run out of a compliance function alone is what a stage 2 auditor notices first of all.
The people who issue the certificate
Audits your management system and certifies it. It does not design it, does not write your Statement of Applicability, and cannot consult on the thing it will later audit without compromising its accreditation. That separation is the entire point of the certificate you end up holding, and it is not negotiable.
What ISO 27001 does not carry over
The harmonised structure means clauses 4 to 10 feel familiar and much of the machinery is reusable - document control, competence, internal audit, corrective action. Three things have no predecessor: the impact assessment under clause 6.1.4, the Annex A control set, and the clause 8 lifecycle evidence.
“We hold 27001, so we’re most of the way to 42001.”
The structure carries. The AI content does not.
It is the most common finding we write up.
- Who it is for
- AI product companies
- Enterprise platform teams
- Regulated industries
- Legal & compliance
- ISO 27001 holders
Where it converges with the EU AI Act: lifecycle risk management, data governance, human oversight, monitoring and impact assessment.
Where it diverges: ISO certifies a management system; the Act regulates named systems by tier, and adds bans, disclosures and CE marking.
Which one first: the Act's conformity route runs on harmonised European standards. ISO 42001 lowers the cost of that work, not the duty.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a readiness call.
Your readiness check
Ninety days to audit-ready.
Each phase produces the input the next one needs - so they cannot be added up, and they cannot be run in parallel.
-
Get organised
Days 1-20Fix the scope in writing, inventory every AI system in and out of it, and agree the risk method up front.
-
Close the big gaps
Days 21-50Risk assessment and treatment, the impact assessments, Statement of Applicability, supplier terms.
-
Operationalise
Days 51-75Lifecycle gates, monitoring, awareness training and the incident route - so the system leaves records behind it.
-
Prove it works
Days 76-90A full internal audit, the first management review, findings closed or planned, and the evidence packed by clause.
Ninety days assumes someone is already doing document control and internal audit for something else. From a standing start it takes longer - and the internal audit and the first management review have to have happened, with records, before stage 2 is worth booking.
What the standard asks, what we ship
12 requirement areas, in the order the standard sets them out - and what each one is actually asking you to hold.
- Clause 4 - Context Scope, interested parties, and what the AIMS covers
- A scope statement derived from the inventory rather than asserted above it, with the exclusions named and reasoned.
- Clause 5 - Leadership AI policy, roles, responsibilities and authorities
- Policy and accountability read against what actually happens rather than against the org chart.
- Clause 6 - Planning Risk, impact assessment, objectives and the SoA
- Risk method and results, the impact assessment process, and a Statement of Applicability with a justification per control.
- Clause 7 - Support Competence, awareness, communication, documentation
- Competence and awareness evidence, and whether your document control survives contact with a real audit.
- Clause 8 - Operation Operational planning and control across the lifecycle
- The lifecycle gates in practice - design, verification, deployment, monitoring - and the record each stage leaves.
- Clause 9 - Evaluation Monitoring, internal audit and management review
- The audit programme, its independence, and management review inputs and outputs matched to what the clause asks for.
- Clause 10 - Improvement Nonconformity, corrective action, continual improvement
- A trail an auditor can follow from finding through to closure, rather than a register of intentions.
- Annex A - all 38 controls Nine groups, A.2 through A.10
- Every control reviewed and mapped to the evidence behind it and to your inclusion or exclusion decision.
- AI system impact assessment Clause 6.1.4 and A.5 - no predecessor in 27001
- The assessment process itself, plus a worked assessment per system covering individuals, groups and society.
- Data and lifecycle evidence A.6 and A.7 - provenance, quality, verification
- Design decisions, validation results, deployment approvals and change history, checked as records rather than claims.
- Third-party and supplier terms A.10 - most AI in a stack was not built in it
- Responsibilities allocated across suppliers and customers, and what you can evidence yourself versus obtain.
- Documented information set What the standard names explicitly, and no more
- The policy and procedure set the clauses require, drafted or gap-listed - not a repository built for its own sake.
Your AIMS, read from outside
Every clause, and all 38 Annex A controls.
-
Scope
Which systems the AIMS covers, and what is deliberately outside it.
-
Assess
Clauses 4 to 10 and all 38 Annex A controls, read against your evidence.
-
Sign off and hand over
You see the draft first. Then the report, the gap register and the SoA - dated.
Why teams bring iDharma in before the certification body
We do not certify
We are not a certification body but the independent read before the auditor arrives. We say so.
Read against the clause
Every finding names the clause or control it fails, so your certification body opens the same map you do.
One engagement
Scope, gap register, Statement of Applicability and evidence index sit in one piece of work, not four.
Records, not documents
A policy nobody follows is a finding. We test for the record each control was meant to leave behind.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Readiness assessment report
The full read: scope, every clause from 4 to 10, all 38 Annex A controls, and what stands between you and a stage 1 audit - each finding named to the clause it fails, with the evidence that closes it, ranked by what a certification auditor reaches for first, and written so your own team can work through it without us in the room.
Gap register by clause
Every gap in a workbook with an owner, a due date and the evidence that closes it, so remediation runs as a plan rather than as a memory.
Statement of Applicability
All 38 controls with an included-or-excluded decision and the justification behind each - the document a certification auditor opens first.
AI system inventory
Every AI system you build or use, with the purpose, data, deployment context and interested parties clause 4 and Annex A expect recorded.
Impact assessment pack
The clause 6.1.4 process written down, plus one worked assessment on a real system so the template has been driven before you inherit it.
Policy and procedure set
The documented information the clauses actually name - policy, scope, objectives, risk method, audit programme - drafted or gap-listed.
Certification-body brief
What to send the body at enquiry, what stage 1 will ask for, and where your scope is likely to be challenged - so the first call is not the first surprise.
Real numbers, upfront.
- Scope
- Set by the standard, not by us
- Basis
- Your systems, clause by clause
- Re-check
- Before each surveillance - $10,500 against your known baseline
The clause set and the 38 controls are fixed - only the estate is counted, and none of this fee buys a certificate.
Request this assessment- Readiness report, clause by clause
- All 38 Annex A controls reviewed
- Statement of Applicability, drafted
- Evidence index for stage 1
Four things you have to be able to produce
A stage 2 auditor is not grading intent. Each of these is either in your hand on the day they ask, or it is not.
The scope,
in writing
A boundary naming the systems, sites and functions inside the AIMS, and the ones outside it. A scope that carves out the AI everyone asks about is worthless to you.
The SoA,
justified
All 38 Annex A controls included or excluded, with the reasoning recorded. An exclusion with a real reason is fine; one with no reason is the first finding written.
The impacts,
assessed
A dated assessment per system of the consequences for individuals, groups and society. This is the clause with no ISO 27001 predecessor, and the weakest one.
The audit,
closed out
An internal audit report, a management review carrying the inputs and outputs the clause names, and corrective actions traced to closure. A plan is not it.
Four cards, and the record behind each one is part of the card.
Plain answers
What 27001 carries over, timing, and Annex A. Answered straight.
Request this assessmentWe already have ISO 27001. What actually carries over?
The clause 4 to 10 machinery, largely - document control, competence, internal audit, management review, corrective action. What does not carry over is the AI system impact assessment, the Annex A control set, and the lifecycle evidence.
How long does certification take?
For an organisation with an existing management system, roughly three to six months to audit-ready, then the certification body's own stage 1 and stage 2 audits. Starting from nothing, plan for longer than the ninety days on this page.
Do you issue the certificate?
No. iDharma is not a certification body, and could not be one here: a body that consults on a management system cannot then audit it without compromising its own accreditation. We are the independent read before the auditor arrives.
Do we have to implement all 38 Annex A controls?
No - but you have to make and justify a decision about every one of them. That is what the Statement of Applicability is. An exclusion with a real reason is fine; an exclusion with no reason is a finding.
Does ISO 42001 make us EU AI Act compliant?
No, and it is the most expensive assumption on the subject. The Act regulates specific systems by risk tier and adds prohibited practices, transparency duties and conformity assessment with CE marking - none of which a management system certificate supplies.
Request your gap assessment
Tell us what you run and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have. Most of this comes out of an afternoon with the people who run the systems, and we tell you exactly what before you commit to anything.
- Which AI systems you build, and which you buy in
- Whether you hold ISO 27001, 9001 or another such system
- Any policies, risk or impact assessments you hold
- Who owns AI decisions today, and where that is written
- Your target certification date, if you have one
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims here come from, and what they are worth - stated, not assumed.
What it is drawn from
- ISO/IEC 42001:2023 and its Annexes A to D
- ISO/IEC 27001:2022, for what transfers
- Published
- December 2023
- Reading checked
- 11 August 2026
What it means
- General information about what the standard requires — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- iDharma is not a certification body. This engagement is the independent readiness read before the auditor arrives; an accredited body issues the certificate after its own stage 1 and stage 2 audits.
- The 38-control figure is the one to check. ISO/IEC 42001 is not freely readable, so it is stated here from general circulation rather than from a clause-by-clause count against a licensed copy. Everything else on this page was read on 11 August 2026.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.