Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
ISO 42001

ISO 42001: AI governance that is checked, not just filed

Every ISO/IEC 42001 clause and Annex A control mapped to automated checks and structured evidence, the AI systems you build and buy and their impact assessments recorded against those controls, and the certification audit run in the same place the evidence lives.

What is ISO 42001?

ISO/IEC 42001 is the international standard for an AI management system, an AIMS: the policies, objectives, roles, risk and impact assessments, and controls an organization uses to develop, provide or use AI responsibly. Published in December 2023, it follows the same high-level structure as ISO 27001, so the two integrate: shared context, leadership, planning, support and improvement clauses, with AI-specific additions. Annex A lists 38 controls across nine themes, including AI policies, internal organization, resources for AI systems, impact assessment, the AI system life cycle, data for AI, information for interested parties, use of AI systems, and third-party relationships. Certification is issued by an accredited body after a Stage 1 readiness review and a Stage 2 audit of operating effectiveness, and buyers increasingly ask for it alongside SOC 2 or ISO 27001 from any vendor that ships AI features.

In one paragraph

ISO/IEC 42001:2023 is the first international standard for an AI management system: the policies, roles, risk and impact assessments, and controls an organization uses to develop and use AI responsibly. Certification follows the same two-stage audit model as ISO 27001 and is designed to integrate with it.

Who it's for

Companies that ship AI features or run AI inside their operations and are asked by enterprise buyers, regulators or partners how that AI is governed.

With Viglyn

How Viglyn runs ISO 42001

  • The inventory of the AI systems you build and buy, with an accountable owner, intended use and status for each, held as dated evidence with a full audit trail
  • AI system impact assessments recorded against your Statement of Applicability, with the reasons for every inclusion and exclusion
  • Every ISO 42001 clause and Annex A control mapped to a control in the library, with automated checks where the evidence lives in your connected systems and structured evidence requests where it does not
  • Shared evidence with ISO 27001: the clauses the two standards share are satisfied once, so ISO 42001 is a head start rather than a second project
  • Stage 1 and Stage 2 run inside Viglyn, with scoped auditor access and workpapers that export with integrity hashes
Straight answers

The ISO 42001 questions that decide it

Do we need ISO 42001 if we already have ISO 27001?

ISO 27001 covers information security; ISO 42001 covers how you govern AI: its intended use, its risks and impacts, the data it learns from, human oversight and transparency. If you ship AI features, buyers will ask about both. The two share their structure, so in Viglyn the shared clauses are satisfied once.

How long does ISO 42001 take?

Three to six months is typical when an ISO 27001 management system already exists, because the shared clauses carry over. The AI-specific work, the system inventory, the impact assessments and the controls around data and oversight, is where the time goes; Viglyn's automated checks and structured evidence requests are built to make it the shorter part.

How much does ISO 42001 cost?

ISO 42001 counts as one of the frameworks included in your plan: two on Starter and Growth, three on Scale, from $2,699 a year with implementation by our practitioners included. The certification body's fee is separate and paid by you directly; we take no commission.

Compared with

ISO 42001 against the standards it is weighed with

FAQ

More ISO 42001 questions

What counts as an AI system under ISO 42001?
Any system that uses machine learning or similar techniques to make or support decisions, generate content or interact with people, whether you built it, embedded a model from a provider, or bought a tool that runs AI. In Viglyn you record each one, who owns it and what it is for, as dated evidence against the controls that ask for it.
Which ISO 42001 controls can be checked automatically?
The ones whose evidence lives in systems Viglyn connects to: access to AI resources, change management for AI components, and data governance in your cloud and code systems. Policy, process and inventory controls carry structured evidence requests with a full audit trail instead, so the auditor sees who owns each item and when it was last reviewed.
Can we run ISO 42001 and SOC 2 together?
Yes. The underlying security controls are shared, and every plan includes at least two frameworks on one evidence base.

See ISO 42001 run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.