ISO 42001: AI governance that is checked, not just filed
Every ISO/IEC 42001 clause and Annex A control mapped to automated checks and structured evidence, the AI systems you build and buy and their impact assessments recorded against those controls, and the certification audit run in the same place the evidence lives.
What is ISO 42001?
ISO/IEC 42001 is the international standard for an AI management system, an AIMS: the policies, objectives, roles, risk and impact assessments, and controls an organization uses to develop, provide or use AI responsibly. Published in December 2023, it follows the same high-level structure as ISO 27001, so the two integrate: shared context, leadership, planning, support and improvement clauses, with AI-specific additions. Annex A lists 38 controls across nine themes, including AI policies, internal organization, resources for AI systems, impact assessment, the AI system life cycle, data for AI, information for interested parties, use of AI systems, and third-party relationships. Certification is issued by an accredited body after a Stage 1 readiness review and a Stage 2 audit of operating effectiveness, and buyers increasingly ask for it alongside SOC 2 or ISO 27001 from any vendor that ships AI features.
ISO/IEC 42001:2023 is the first international standard for an AI management system: the policies, roles, risk and impact assessments, and controls an organization uses to develop and use AI responsibly. Certification follows the same two-stage audit model as ISO 27001 and is designed to integrate with it.
Companies that ship AI features or run AI inside their operations and are asked by enterprise buyers, regulators or partners how that AI is governed.
How Viglyn runs ISO 42001
- The inventory of the AI systems you build and buy, with an accountable owner, intended use and status for each, held as dated evidence with a full audit trail
- AI system impact assessments recorded against your Statement of Applicability, with the reasons for every inclusion and exclusion
- Every ISO 42001 clause and Annex A control mapped to a control in the library, with automated checks where the evidence lives in your connected systems and structured evidence requests where it does not
- Shared evidence with ISO 27001: the clauses the two standards share are satisfied once, so ISO 42001 is a head start rather than a second project
- Stage 1 and Stage 2 run inside Viglyn, with scoped auditor access and workpapers that export with integrity hashes
The ISO 42001 questions that decide it
Do we need ISO 42001 if we already have ISO 27001?
ISO 27001 covers information security; ISO 42001 covers how you govern AI: its intended use, its risks and impacts, the data it learns from, human oversight and transparency. If you ship AI features, buyers will ask about both. The two share their structure, so in Viglyn the shared clauses are satisfied once.
How long does ISO 42001 take?
Three to six months is typical when an ISO 27001 management system already exists, because the shared clauses carry over. The AI-specific work, the system inventory, the impact assessments and the controls around data and oversight, is where the time goes; Viglyn's automated checks and structured evidence requests are built to make it the shorter part.
How much does ISO 42001 cost?
ISO 42001 counts as one of the frameworks included in your plan: two on Starter and Growth, three on Scale, from $2,699 a year with implementation by our practitioners included. The certification body's fee is separate and paid by you directly; we take no commission.
ISO 42001 against the standards it is weighed with
More ISO 42001 questions
What counts as an AI system under ISO 42001?
Which ISO 42001 controls can be checked automatically?
Can we run ISO 42001 and SOC 2 together?
See ISO 42001 run on your stack
A 30-minute walkthrough with your systems and your framework. No commitment.
