ISO 42001 Consulting Hero Banner
ISO 42001 Consulting

ISO 42001 Consulting and AI Management System Certification Readiness

ISO/IEC 42001 is the certifiable international standard for an AI Management System. IRM designs and implements your AIMS, runs the AI risk and impact assessments, and gets you audit-ready in 90 days.

  • All 38 Annex A controls
  • Certified AI Auditor and Ethicist
  • From $4,250 per month

What is ISO 42001 Consulting?

ISO/IEC 42001 is the international management system standard for artificial intelligence, published in December 2023. It specifies how an organization establishes, operates, and continually improves an AI Management System (AIMS): governance of AI, risk and impact assessment for each AI system, and 38 Annex A controls covering the AI lifecycle from data and development through deployment, monitoring, and third-party AI use. Like ISO 27001, it is certifiable by an accredited certification body.

ISO 42001 consulting is the work of getting a company from "we use AI" to a certifiable AIMS. IRM scopes the AI systems in play, runs the gap assessment against all 38 controls, performs the AI risk and AI impact assessments the standard requires, writes the AI policy and procedures, and prepares the internal audit and management review a certification auditor will ask to see. For companies already holding ISO 27001, the two systems share the same clause structure and we integrate them rather than building a second management system.

The practice is led by an AI-Native Virtual CISO who is a Certified AI Auditor and Ethicist, so the same engagement covers the adjacent obligations: NIST AI RMF alignment, EU AI Act readiness for high-risk systems, and the AI questions now appearing in enterprise security questionnaires. See the broader AI governance services if your need is a program rather than a certification.

What the Engagement Includes

  • AIMS scope: which AI systems, roles (provider, deployer, or both), and interested parties are in
  • Gap assessment against all 38 Annex A controls with a risk-ranked plan
  • AI risk assessment and AI system impact assessment methodology, run on each in-scope system
  • AI policy, acceptable use, data governance for AI, and lifecycle procedures
  • Statement of Applicability and AI system inventory
  • Human oversight, transparency, and incident handling controls for AI systems
  • Internal audit and management review, delivered and recorded
  • Certification body selection and Stage 1 and Stage 2 audit support

When you do not need ISO 42001 Yet

If AI is a feature you call through a vendor API and no customer, regulator, or investor has asked how you govern it, an AI policy and a documented risk assessment are usually enough for now. Certification is a 6 to 12 month commitment with annual surveillance audits, and it only pays off when a buyer or regulator will recognize it.

If you build or fine-tune models, sell AI into healthcare, finance, HR, or the public sector, or answer AI questions in every enterprise security review, the certificate settles those questions in one document. Run the free gap assessment first; it will show you whether the gap is 6 controls or 30.

Who ISO 42001 Consulting is for, by ARR Stage

ISO 42001 demand tracks how much of your revenue depends on customers trusting your AI. This is how we size the work.

Who ISO 42001 Consulting is for, by ARR Stage
StageTypical ARRWhat You NeedIRM Engagement
Pre-seed and bootstrappedUnder $1M ARRAn AI policy, a system inventory, and a documented risk assessment to answer investor and customer questions.Free ISO 42001 gap assessment, then a Crawling tier sprint to produce the AI policy set and first risk assessment.
Seed$1M to $5M ARRA working AIMS aligned to ISO 42001 and NIST AI RMF, without certifying yet, so enterprise AI questionnaires stop blocking deals.Walking tier, 90 days to an operating AIMS with all 38 controls addressed.
Series A and B$5M to $25M ARRISO 42001 certification, usually integrated with ISO 27001 or SOC 2, and EU AI Act readiness for any high-risk use.Walking or Running tier, 90 days to audit-ready, certification audit in months 4 to 6.
Growth and PE-backed$25M+ ARRCertified AIMS maintained across product lines, surveillance audits passed, and board reporting on AI risk.Running tier managed AI governance program with a named AI-Native vCISO.

The 90-Day ISO 42001 Plan

This is the sequence we run to take a company from no formal AI governance to audit-ready. Certification audits with an accredited body typically follow in months 4 to 6.

Days 1 to 30

Scope and Assess

  • Inventory every AI system, model, and AI vendor in use, and assign provider or deployer roles
  • Gap assessment against all 38 Annex A controls, scored by likelihood and impact
  • AI risk assessment and AI system impact assessment run on the highest-exposure systems
  • Decide the integration path with any existing ISO 27001 ISMS or SOC 2 controls
Days 31 to 60

Design and Document

  • AI policy, objectives, roles, and the Statement of Applicability approved
  • Lifecycle procedures: data for AI, development, verification, deployment, monitoring, decommissioning
  • Human oversight, transparency, and AI incident response controls implemented
  • Third-party AI supplier requirements added to vendor risk management
Days 61 to 90

Operate and Prove

  • Controls operate for a full cycle with monitoring and performance evidence recorded
  • Internal audit of the AIMS completed and nonconformities closed
  • Management review held and minuted against the standard's inputs
  • Certification body selected and Stage 1 audit scheduled

ISO 42001 Consulting Pricing

ISO 42001 work is delivered as a monthly AI-Native Virtual CISO subscription, so the certification project and the ongoing AI governance program use the same engagement.

Walking tier, Seed stage

From $4,250 per month

20 to 40 hours per month, sprint under 6 months. Excludes certification body audit fees.

Companies that only need the AI policy set and a first risk assessment start on the Crawling tier from $2,000 per month (15 to 20 hours). Integrated ISO 42001 plus ISO 27001 or SOC 2 programs, and certified AIMS maintenance, sit on the Running tier from $6,950 per month. Pre-packaged Cyber and AI bundles start at $4,950.

See all Pricing Tiers

Check your ISO 42001 Readiness first for Free

Free, no signup, runs in your browser

Free ISO 42001 Gap Assessment

Assess all 38 Annex A controls (65 items with the management system clauses), score each gap on a 5x5 risk matrix, and download a remediation roadmap. Your answers stay in your browser.

Run the ISO 42001 Gap AssessmentBook a Free Consultation

Related: the free AI Governance Playbook generates a starter AI policy from your intake, and SOC 2 compliance covers the security assurance most SaaS buyers ask for alongside AI governance.

floating circle
Frequently Asked Questions

Frequently Asked Questions about ISO 42001 Consulting

ISO/IEC 42001:2023 is the international management system standard for artificial intelligence. It specifies the requirements for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS), including AI risk and impact assessments and 38 Annex A controls that cover the AI lifecycle. It is certifiable by an accredited certification body in the same way as ISO 27001.

An ISO 42001 consultant scopes the AI systems and roles in play, runs the gap assessment against the Annex A controls and the management system clauses, performs the AI risk and impact assessments, writes the AI policy and procedures, and prepares the internal audit and management review a certification auditor expects. IRM's consultant is also a Certified AI Auditor and Ethicist, so the same engagement covers NIST AI RMF and EU AI Act readiness.

Companies that build, fine-tune, or deploy AI systems where a customer, regulator, or investor wants assurance of how that AI is governed. In practice that means AI-first SaaS vendors selling to enterprises, companies deploying AI in healthcare, finance, HR, and the public sector, and any vendor now fielding AI questions in every security questionnaire. Companies that call a vendor API for one feature usually need an AI policy and a risk assessment rather than certification.

IRM's program reaches audit-ready in 90 days for a company with a manageable number of AI systems and an existing ISO 27001 or SOC 2 foundation. The certification body's Stage 1 and Stage 2 audits typically follow in months 4 to 6. Companies starting with no management system at all, or with many AI products, should plan for 6 to 12 months.

IRM delivers ISO 42001 as a monthly AI-Native Virtual CISO subscription starting at $4,250 per month on the Walking tier (20 to 40 hours) for a typical certification program, or $2,000 per month on the Crawling tier for an AI policy set and first risk assessment. Certification body audit fees are additional and vary with the number of sites and AI systems in scope.

Both use the same harmonized management system structure (context, leadership, planning, support, operation, performance evaluation, improvement), so an existing ISO 27001 ISMS gives you most of the management system already. ISO 42001 adds AI-specific requirements: AI risk assessment, AI system impact assessment, and Annex A controls for the AI lifecycle. IRM integrates the two into one system rather than building a parallel one.

NIST AI RMF is a voluntary framework organized around Govern, Map, Measure, and Manage; ISO 42001 is a certifiable management system. They cover the same ground, and an ISO 42001 AIMS can evidence NIST AI RMF alignment. The EU AI Act is law; for high-risk AI systems it requires a risk management system, data governance, documentation, human oversight, and monitoring, which ISO 42001 controls map onto well. Certification is not a legal safe harbor, but it is the most credible way to demonstrate the required practices.

It is the ISO 42001 requirement to assess the potential consequences of an AI system on individuals, groups, and society, covering fairness, transparency, safety, privacy, and accountability, before and during deployment. It is distinct from the organizational AI risk assessment, which looks at risks to the company. IRM provides the methodology and runs the first assessments with your team on the highest-exposure systems.

You are an AI deployer in ISO 42001 terms, and the standard still applies to how you select, configure, monitor, and govern that AI, but certification is rarely necessary at that stage. What you need is an AI acceptable use policy, an inventory of AI tools and the data they touch, vendor due diligence, and a documented risk assessment. That work is the Crawling tier engagement and takes about a month.

They are grouped into areas covering AI policies, internal organization and roles, resources for AI systems, impact assessment, the AI system lifecycle (requirements, design, verification, deployment, operation, monitoring), data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. IRM's free ISO 42001 Gap Assessment lists all of them, with the management system clauses, as 65 assessable items.

Yes. SOC 2 is an attestation against the Trust Services Criteria and ISO 42001 is a certified management system, so they remain separate reports, but the underlying controls overlap in access control, change management, logging, vendor management, and incident response. IRM builds one control set and evidence library that serves both, which is the normal configuration for an AI-first SaaS company selling to North American enterprises.

Yes. IRM's free ISO 42001 Gap Assessment at irmcon.com/products/iso42001/ assesses all 38 Annex A controls plus the management system clauses, scores each gap on a 5x5 risk matrix, and produces a downloadable remediation roadmap. It runs in your browser, and the free AI Governance Playbook can generate a starter AI policy from a short intake.
Get in touch

Contact Us

Contact Us
Our Blogs

Cybersecurity & AI insights

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.