Skip to content
ByteDel

Guides · Compliance & Certifications · iso-42001 · ai-governance

ISO 42001 Explained: The AI Certification Buyers Ask About

· 5 min read

ISO/IEC 42001 is the international standard for an AI management system (AIMS) — a certifiable framework for how your company governs the AI it builds or deploys, published by ISO in December 2023. If you sell an AI product into enterprises, procurement teams have started asking for it the way they ask for SOC 2. Most startups do not need it yet; AI-native companies selling to regulated enterprise buyers increasingly do. The good news: a large share of the work overlaps with SOC 2 and ISO 27001, so if your infrastructure is already audit-ready, you are closer than you think.

Diagram comparing ISO 27001, SOC 2, and ISO 42001 side by side, showing that all three certifications rest on the same shared infrastructure foundation of access control, change management, logging, vendor review, and incident response.

What does ISO 42001 actually cover?

ISO 42001 certifies a management system, not a model. Like ISO 27001’s ISMS, it follows the standard ISO management-system structure — leadership, planning, support, operations, continual improvement — plus an Annex A of 38 controls covering the AI lifecycle: how systems are designed, tested, deployed, monitored, and retired, and how you assess their impact on the people who use them. You select which controls apply through a risk assessment and document exclusions in a Statement of Applicability, the same mechanism ISO 27001 uses.

Per Vanta’s guidance, the controls are not a mandatory checklist — you justify inclusion and exclusion from your own risk and impact assessments. The themes auditors probe: documented AI policy, defined roles for AI accountability, impact assessments for AI systems, data governance for training and inference data, transparency to users, and human oversight of automated decisions. When Anthropic announced its certification in January 2025 — issued by Schellman, one of the first for a frontier lab — it framed the scope as exactly this: policies for ethical design and deployment, rigorous testing, transparency, and governance roles.

Who actually needs ISO 42001?

You need it when your buyers ask for it, and the buyers asking are enterprises procuring AI products — especially in financial services, healthcare, and the public sector. The standard is voluntary; no regulator mandates it today. But security questionnaires now routinely include an AI governance section, and a certificate answers it in one line.

Concretely, prioritize it if:

  • Your product is AI — the model or agent is the thing you sell, not a feature bolted on.
  • Enterprise procurement has already asked about AI governance, the EU AI Act, or model risk.
  • You operate in a regulated vertical where buyers face their own AI oversight obligations.

If AI is just how your team writes code, you almost certainly do not need ISO 42001 — your buyers care about that through SOC 2, and we cover how auditors treat coding assistants in our SOC 2 and AI assistants guide. A-LIGN notes the standard addresses AI providers, producers, and users alike, but in practice procurement pressure lands on companies selling AI, not merely using it.

How much overlaps with SOC 2 and ISO 27001?

A lot. All three rest on the same operational foundation — access control, change management, logging, vendor management, incident response — so a company with a clean SOC 2 program reuses most of that machinery. What ISO 42001 adds is the AI-specific layer: impact assessments, lifecycle documentation, data provenance, and human-oversight controls that neither SOC 2 nor ISO 27001 asks about.

SOC 2 ISO 27001 ISO 42001
Core question Can we trust your operations? Is information secure? Is your AI governed?
Output CPA attestation report Certificate (3-year cycle) Certificate (3-year cycle)
Control set Trust Services Criteria Annex A (93 controls) Annex A (38 controls)
AI-specific? No No Yes — lifecycle, impact, oversight

Vanta recommends most companies build the security foundation first (ISO 27001 or SOC 2), then layer ISO 42001 — but suggests AI-native startups run ISO 27001 and 42001 as one parallel program, since the management-system clauses are nearly identical and one integrated audit is cheaper than two sequential ones. If you have neither yet, start with our take on ISO 27001 vs SOC 2 sequencing and the broader startup compliance roadmap.

What does the infrastructure evidence look like?

Auditors want proof the management system operates, not a binder that says it exists. On the infrastructure side, ISO 42001 evidence looks familiar to anyone who has been through SOC 2 — with an AI-shaped twist:

  • Environment separation and change control for model and prompt changes: a prompt or model-version change should flow through the same reviewed, logged pipeline as a code change.
  • Data governance in the pipeline: where training and inference data lives, who can access it, retention and deletion controls — enforced in IAM and storage policy on AWS, GCP, or Azure, not in a doc.
  • Logging and monitoring of AI behavior: inference logs, model-version tags on deployments, alerting on anomalous output patterns — your existing observability stack, extended.
  • Vendor evidence for upstream model providers: their certifications and DPAs become inputs to your own audit.

Compliance platforms already automate much of this — Vanta advertises 400+ integrations for continuous evidence collection, and we compare the options in our Vanta vs Drata breakdown. But the platform only reports on infrastructure that is actually controlled. That is the part we build: our SOC 2 infrastructure package puts the shared foundation in place — access control, change management, logging — so SOC 2, ISO 27001, and ISO 42001 all draw evidence from the same well.

Should you get ISO 42001 before SOC 2?

No — unless a specific deal demands it. SOC 2 remains the default ask in US enterprise procurement, and ISO 42001 assumes the management-system discipline SOC 2 or ISO 27001 builds. The pragmatic sequence for an AI startup: SOC 2 Type II first (or ISO 27001 if your buyers are European), then add ISO 42001 when procurement pressure makes it revenue-relevant. One caution from Vanta worth repeating: do not book the certification audit early — the AIMS has to be demonstrably running before the Stage 2 assessment, and a rushed program fails there.

If buyers are already asking and you want a straight answer on how far your infrastructure is from audit-ready, that is a fixed-scope conversation — see our audit and pricing. This post is engineering guidance, not legal advice; scope questions for your specific regulatory exposure belong with counsel.

ShareLinkedInXHacker News
Ask AI about thisChatGPTPerplexityClaude

Newsletter

One practical DevOps guide a week

Real numbers, honest trade-offs, no vendor fog — same as everything here. Unsubscribe anytime.

More on Compliance & Certifications

SOC 2, ISO 27001, HIPAA, PCI, GDPR — what each standard actually requires from your infrastructure.

All compliance & certifications guides →

Need these controls implemented, not just listed?

A 15-minute call is enough to tell you exactly what we'd do and what it costs. No pitch deck, no pressure.