ISO 42001 Certification
For responsible, secure AI

Delivered by a cybersecurity firm, not a compliance shop.
Led by senior cybersecurity practitioners.
Gap Assessment. AI Risk & Impact. AIMS Build. Internal Audit. Certification.
ISO 42001 basics

What is ISO 42001?

ISO/IEC 42001 is the first certifiable international standard for an AI management system (AIMS): the policies, roles, risk and impact assessments, and controls an organization uses to develop, provide, or use AI responsibly. Published in December 2023, it follows the same management system structure as ISO 27001.
Certification is performed by an accredited certification body, and since 2025 ISO/IEC 42006 has set the competence requirements those bodies must meet to audit AI. For companies building AI into their products or operations, it is becoming the clearest way to show customers your AI is governed, secure, and trustworthy.
Why it matters

Proof your AI is governed, not just promised

Customer trust

Answer AI questions before they stall a deal
Buyers now ask how you train, test, and control your AI. An ISO 42001 certificate answers with independent proof.

Responsible AI by design

Catch bias, safety, and misuse risks early
Required AI risk and impact assessments surface problems before a model reaches customers, not after.

Regulatory readiness

Stay ahead of emerging AI rules
An AIMS gives you the governance, documentation, and oversight that frameworks like the NIST AI RMF and new state and federal AI requirements expect.

Builds on ISO 27001

Extend the security program you already run
ISO 42001 shares the ISO 27001 management system structure, so existing policies, audits, and reviews carry over.
Inside the standard

A management system plus 38 AI controls

Clauses 4 to 10 define the management system, including AI risk assessment and AI system impact assessment. Annex A lists 38 reference controls across nine objectives, and your Statement of Applicability records which ones apply and why.
A.2 to A.3

AI governance

AI policy, roles and responsibilities, and a way for people to report concerns about AI systems.
A.4 to A.5

Resources and impact

The data, tools, compute, and people behind each AI system, and assessments of its impact on individuals and society.
A.6 to A.7

Life cycle and data

Responsible design, verification, deployment, and monitoring of AI systems, and the quality and provenance of their data.
A.8 to A.10

Transparency and use

Information for users and interested parties, responsible use of AI, and obligations shared with suppliers and customers.
ISO 42001 and ISO 27001

ISO 42001 or ISO 27001: how do they fit together?

The two standards share the same management system structure, so many organizations run them as one integrated program. The difference is what each one protects.
Area
ISO 42001
ISO 27001
Focus
Responsible development and use of AI systems
Protection of information and the systems that hold it
Key risks
Bias, transparency, safety, misuse, and AI-specific security
Confidentiality, integrity, and availability of information
Core assessments
AI risk assessment plus AI system impact assessment
Information security risk assessment
Annex A
38 controls across nine objectives
93 controls across four themes
Management system
Clauses 4 to 10, shared structure
Clauses 4 to 10, shared structure
Best fit for
Companies that build, provide, or use AI in products or operations
Companies that want a full security management program
Our ISO 42001 approach

Cybersecurity at our core. Compliance built on it

Compliance should validate good cybersecurity, not substitute for it.

InfoGuard brings 30+ years of cybersecurity leadership and hands-on management system experience to AI governance, so your AIMS protects real systems, not just paperwork.

AI security expertise

Governance that covers how AI actually fails
We address model, data, and pipeline risks such as poisoning, prompt injection, and data leakage alongside policy.

Risk-driven, not template-driven

Invest only in controls that reduce real risk
Your AI risk and impact assessments, not a generic template, decide which Annex A controls you implement.

Hands-on senior leadership

Senior experts on your engagement, start to finish
Senior practitioners work alongside your product, data, and engineering teams from gap assessment through certification.

One effort, multiple frameworks

Do the work once, reuse it for ISO 27001 and more
We build one integrated program, so ISO 42001, ISO 27001, and SOC 2, including its 2026 AI requirements, share policies, audits, and evidence.

Your compliance investment should deliver more than checklists and documentation.
It should improve your cybersecurity as well.

How we help

From gap assessment to certification, and beyond

01

AI Inventory & Gap Assessment

We inventory the AI systems you build, provide, or use, assess your practices against ISO/IEC 42001, and define a practical AIMS scope.
02

AI Risk & Impact Assessment

We assess AI risks and the impact of each system on individuals and society, then build the treatment plan and Statement of Applicability.
03

AIMS & Controls Build

We write the AI policy and procedures, implement life cycle, data, and oversight controls, and set up the evidence your auditor will ask for.
04

Internal Audit & Review

An objective internal audit and a management review, both required by the standard, confirm the AIMS works before the certification body arrives.
05

Certification Audit

An accredited certification body performs the Stage 1 and Stage 2 audits. We stay engaged throughout, clarifying evidence and closing any findings.
06

Surveillance & Sustain

We keep impact assessments, model changes, and reviews on schedule so annual surveillance audits and recertification are routine.
FAQ

ISO 42001 questions, answered

Certification and scope

Any organization that develops, provides, or uses AI systems, from SaaS companies adding AI features to businesses relying on AI in their operations. It is especially valuable when customers ask how your AI is governed and secured.
An accredited certification body performs a Stage 1 audit of your AIMS design and documentation, then a Stage 2 audit to confirm it operates in practice. Certificates follow a three-year cycle with annual surveillance audits.
A structured review of how an AI system could affect individuals, groups, and society, performed before deployment and after significant changes. It is one of the defining requirements of ISO 42001.
Yes. The standard applies to AI you use as well as AI you build, and Annex A includes controls for suppliers and third parties.

Planning, timing, and cost

A lot. Both standards share the same management system clauses, so your internal audit, management review, document control, and many policies extend to ISO 42001. The new work centers on AI risk and impact assessments and the AI-specific controls.
Yes. An AIMS gives you the governance, risk management, documentation, and oversight those frameworks expect, so you can map to them without starting over.
It depends on how many AI systems are in scope and whether you already run ISO 27001. Most organizations need several months to build and operate the AIMS before the certification audit. We give you a realistic timeline once we have scoped your environment.
Cost depends on your scope, the number of AI systems, and how much of the AIMS needs to be built. There is no flat fee. We provide a firm quote after an initial gap assessment.
Cybersecurity first

A checkbox compliance provider won't cut it

You need real cybersecurity expertise to govern AI systems that can be attacked, misused, or fail in new ways, and to pass an audit built to find the gaps.
Next step

Tell us where you stand

Tell us how you build or use AI. We’ll reply with next steps, whether that’s an AI gap assessment, an impact assessment, or a plan for ISO 42001 alongside ISO 27001.