ISO/IEC 42001 · AIMS · CERTIFIABLE

You already have more of ISO/IEC 42001 than you think.

Clauses 4 to 10 carry over from any certified management system. The impact assessment, Annex A and the lifecycle evidence do not.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Readiness is not the same as a certificate
AIMS Clauses 4-10 Annex A Statement of Applicability Impact assessment

Our promise

“Certification is a date. The system is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework readiness assessment produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this readiness assessment
The case file

ISO 42001, in three chapters

The Standard

Published in December 2023, ISO/IEC 42001 is the first international standard for an AI management system — and the only AI framework you can hold a certificate for. It runs clauses 4 to 10 on the harmonised structure every ISO standard shares, plus Annex A and its set of 38 controls.

The Gap

Teams holding ISO 27001 assume they are most of the way there. The structure genuinely does carry — document control, competence, internal audit, management review. Three things do not: the impact assessment, the Annex A control set, and the clause 8 lifecycle evidence.

The Office

The independent read before the auditor arrives. We assess every clause and all 38 controls against the evidence you actually hold, and hand you the gap register, the Statement of Applicability and the evidence index. We do not certify, and by the rules of accreditation we could not.

What is an AIMS?

A system you operate, not a project you finish.

The governance, roles, controls and records around how you build and run AI, on a plan, do, check, act cycle.

Who this is for № 01
  • Companies selling AI into enterprise procurement
  • Teams already certified to ISO 27001 or ISO 9001
  • Regulated industries answering a supervisor
  • Anyone with EU AI Act exposure to reduce
ISO 42001 · iDharma · Presented for assay
What the standard is made of № 02
  • Clauses 4-10 - the harmonised management structure
  • Annex A - 38 controls across nine groups, A.2 to A.10
  • Annexes B, C and D - guidance, risk sources, domains
  • A Statement of Applicability accounting for every control
ISO 42001 · iDharma · Presented for assay
Who owns it

The system is yours. The certificate is theirs.

You

Top management owns the system

Clause 5 places accountability for the AI management system on top management, and it is not delegable. The policy, the objectives, the resourcing and the management review are theirs. An AIMS run out of a compliance function alone is what a stage 2 auditor notices first of all.

Your certification body

The people who issue the certificate

Audits your management system and certifies it. It does not design it, does not write your Statement of Applicability, and cannot consult on the thing it will later audit without compromising its accreditation. That separation is the entire point of the certificate you end up holding, and it is not negotiable.

The catch

What ISO 27001 does not carry over

The harmonised structure means clauses 4 to 10 feel familiar and much of the machinery is reusable - document control, competence, internal audit, corrective action. Three things have no predecessor: the impact assessment under clause 6.1.4, the Annex A control set, and the clause 8 lifecycle evidence.

What most teams assume

“We hold 27001, so we’re most of the way to 42001.”

What the standard asks

The structure carries. The AI content does not.

It is the most common finding we write up.

  • Who it is for
  • AI product companies
  • Enterprise platform teams
  • Regulated industries
  • Legal & compliance
  • ISO 27001 holders
Why this matters in 2026
A thick bound volume lying open on a dark desk beside the base of a brass lamp, a red ribbon marker running out of the page block, the top page carrying columns of set text beside a bar chart and a pie chart, with a fountain pen and a clipped sheaf of paper laid out below it.
01 Nobody is fined for skipping a voluntary standard. You lose the deal instead - it is the certificate enterprise procurement and vendor security review now name by number.
02

Where it converges with the EU AI Act: lifecycle risk management, data governance, human oversight, monitoring and impact assessment.

03

Where it diverges: ISO certifies a management system; the Act regulates named systems by tier, and adds bans, disclosures and CE marking.

04

Which one first: the Act's conformity route runs on harmonised European standards. ISO 42001 lowers the cost of that work, not the duty.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a readiness call.

0 of 3

Existing MSS -

This is the reuse arithmetic. The harmonised structure means clauses 4 to 10 are largely common across ISO management system standards, so an existing certificate is the single biggest reduction in what is left to build.

Impact records -

A DPIA is not one of these. Clause 6.1.4 asks for consequences to individuals, groups and society - broader than a data-protection assessment, and the requirement with no ISO 27001 predecessor at all.

Annex A SoA -

A 27001 SoA transfers as a format. Its contents do not - those are security controls. All 38 AI controls need their own included-or-excluded decision, each with the reasoning recorded.

The roadmap

Ninety days to audit-ready.

Each phase produces the input the next one needs - so they cannot be added up, and they cannot be run in parallel.

  1. Get organised

    Days 1-20

    Fix the scope in writing, inventory every AI system in and out of it, and agree the risk method up front.

  2. Close the big gaps

    Days 21-50

    Risk assessment and treatment, the impact assessments, Statement of Applicability, supplier terms.

  3. Operationalise

    Days 51-75

    Lifecycle gates, monitoring, awareness training and the incident route - so the system leaves records behind it.

  4. Prove it works

    Days 76-90

    A full internal audit, the first management review, findings closed or planned, and the evidence packed by clause.

The trap

Ninety days assumes someone is already doing document control and internal audit for something else. From a standing start it takes longer - and the internal audit and the first management review have to have happened, with records, before stage 2 is worth booking.

Requirement & coverage

What the standard asks, what we ship

12 requirement areas, in the order the standard sets them out - and what each one is actually asking you to hold.

Clause 4 - Context Scope, interested parties, and what the AIMS covers
A scope statement derived from the inventory rather than asserted above it, with the exclusions named and reasoned.
Clause 5 - Leadership AI policy, roles, responsibilities and authorities
Policy and accountability read against what actually happens rather than against the org chart.
Clause 6 - Planning Risk, impact assessment, objectives and the SoA
Risk method and results, the impact assessment process, and a Statement of Applicability with a justification per control.
Clause 7 - Support Competence, awareness, communication, documentation
Competence and awareness evidence, and whether your document control survives contact with a real audit.
Clause 8 - Operation Operational planning and control across the lifecycle
The lifecycle gates in practice - design, verification, deployment, monitoring - and the record each stage leaves.
Clause 9 - Evaluation Monitoring, internal audit and management review
The audit programme, its independence, and management review inputs and outputs matched to what the clause asks for.
Clause 10 - Improvement Nonconformity, corrective action, continual improvement
A trail an auditor can follow from finding through to closure, rather than a register of intentions.
Annex A - all 38 controls Nine groups, A.2 through A.10
Every control reviewed and mapped to the evidence behind it and to your inclusion or exclusion decision.
AI system impact assessment Clause 6.1.4 and A.5 - no predecessor in 27001
The assessment process itself, plus a worked assessment per system covering individuals, groups and society.
Data and lifecycle evidence A.6 and A.7 - provenance, quality, verification
Design decisions, validation results, deployment approvals and change history, checked as records rather than claims.
Third-party and supplier terms A.10 - most AI in a stack was not built in it
Responsibilities allocated across suppliers and customers, and what you can evidence yourself versus obtain.
Documented information set What the standard names explicitly, and no more
The policy and procedure set the clauses require, drafted or gap-listed - not a repository built for its own sake.
The engagement

Your AIMS, read from outside

Every clause, and all 38 Annex A controls.

  1. Scope

    Which systems the AIMS covers, and what is deliberately outside it.

  2. Assess

    Clauses 4 to 10 and all 38 Annex A controls, read against your evidence.

  3. Sign off and hand over

    You see the draft first. Then the report, the gap register and the SoA - dated.

Request a gap assessment
An auditor in a charcoal blazer over a navy crew-neck, with a trimmed beard, standing against a warm pale wall and pointing into the open space alongside.
A control is either evidenced or it is a finding - there is no third state.
Struck in your favour

Why teams bring iDharma in before the certification body

We do not certify

We are not a certification body but the independent read before the auditor arrives. We say so.

Read against the clause

Every finding names the clause or control it fails, so your certification body opens the same map you do.

One engagement

Scope, gap register, Statement of Applicability and evidence index sit in one piece of work, not four.

Records, not documents

A policy nobody follows is a finding. We test for the record each control was meant to leave behind.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Readiness assessment report

The full read: scope, every clause from 4 to 10, all 38 Annex A controls, and what stands between you and a stage 1 audit - each finding named to the clause it fails, with the evidence that closes it, ranked by what a certification auditor reaches for first, and written so your own team can work through it without us in the room.

Workbook

Gap register by clause

Every gap in a workbook with an owner, a due date and the evidence that closes it, so remediation runs as a plan rather than as a memory.

Draft

Statement of Applicability

All 38 controls with an included-or-excluded decision and the justification behind each - the document a certification auditor opens first.

Register

AI system inventory

Every AI system you build or use, with the purpose, data, deployment context and interested parties clause 4 and Annex A expect recorded.

Templates

Impact assessment pack

The clause 6.1.4 process written down, plus one worked assessment on a real system so the template has been driven before you inherit it.

Drafts

Policy and procedure set

The documented information the clauses actually name - policy, scope, objectives, risk method, audit programme - drafted or gap-listed.

Memo

Certification-body brief

What to send the body at enquiry, what stage 1 will ask for, and where your scope is likely to be challenged - so the first call is not the first surprise.

Format & fee

Real numbers, upfront.

Scope
Set by the standard, not by us
Basis
Your systems, clause by clause
Re-check
Before each surveillance - $10,500 against your known baseline

The clause set and the 38 controls are fixed - only the estate is counted, and none of this fee buys a certificate.

Request this assessment
ISO 42001 · Named engagement $12,500 flat
  • Readiness report, clause by clause
  • All 38 Annex A controls reviewed
  • Statement of Applicability, drafted
  • Evidence index for stage 1
Show your hand

Four things you have to be able to produce

A stage 2 auditor is not grading intent. Each of these is either in your hand on the day they ask, or it is not.

The scope,
in writing

A boundary naming the systems, sites and functions inside the AIMS, and the ones outside it. A scope that carves out the AI everyone asks about is worthless to you.

The SoA,
justified

All 38 Annex A controls included or excluded, with the reasoning recorded. An exclusion with a real reason is fine; one with no reason is the first finding written.

The impacts,
assessed

A dated assessment per system of the consequences for individuals, groups and society. This is the clause with no ISO 27001 predecessor, and the weakest one.

The audit,
closed out

An internal audit report, a management review carrying the inputs and outputs the clause names, and corrective actions traced to closure. A plan is not it.

Four cards, and the record behind each one is part of the card.

FAQ

Plain answers

What 27001 carries over, timing, and Annex A. Answered straight.

Request this assessment
We already have ISO 27001. What actually carries over?

The clause 4 to 10 machinery, largely - document control, competence, internal audit, management review, corrective action. What does not carry over is the AI system impact assessment, the Annex A control set, and the lifecycle evidence.

How long does certification take?

For an organisation with an existing management system, roughly three to six months to audit-ready, then the certification body's own stage 1 and stage 2 audits. Starting from nothing, plan for longer than the ninety days on this page.

Do you issue the certificate?

No. iDharma is not a certification body, and could not be one here: a body that consults on a management system cannot then audit it without compromising its own accreditation. We are the independent read before the auditor arrives.

Do we have to implement all 38 Annex A controls?

No - but you have to make and justify a decision about every one of them. That is what the Statement of Applicability is. An exclusion with a real reason is fine; an exclusion with no reason is a finding.

Does ISO 42001 make us EU AI Act compliant?

No, and it is the most expensive assumption on the subject. The Act regulates specific systems by risk tier and adds prohibited practices, transparency duties and conformity assessment with CE marking - none of which a management system certificate supplies.

Get started

Request your gap assessment

Tell us what you run and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this comes out of an afternoon with the people who run the systems, and we tell you exactly what before you commit to anything.

  1. Which AI systems you build, and which you buy in
  2. Whether you hold ISO 27001, 9001 or another such system
  3. Any policies, risk or impact assessments you hold
  4. Who owns AI decisions today, and where that is written
  5. Your target certification date, if you have one

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request a gap assessment
Sources & standing

Where this page gets its facts

Where the claims here come from, and what they are worth - stated, not assumed.

What it is drawn from

  • ISO/IEC 42001:2023 and its Annexes A to D
  • ISO/IEC 27001:2022, for what transfers
Published
December 2023
Reading checked
11 August 2026

What it means

  • General information about what the standard requires — not legal advice, and no professional relationship.
  • Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • iDharma is not a certification body. This engagement is the independent readiness read before the auditor arrives; an accredited body issues the certificate after its own stage 1 and stage 2 audits.
  • The 38-control figure is the one to check. ISO/IEC 42001 is not freely readable, so it is stated here from general circulation rather than from a clause-by-clause count against a licensed copy. Everything else on this page was read on 11 August 2026.

Something on this page out of date?

Tell us