ISO/IEC 42001 is the certifiable international standard for an AI Management System. IRM designs and implements your AIMS, runs the AI risk and impact assessments, and gets you audit-ready in 90 days.
ISO/IEC 42001 is the international management system standard for artificial intelligence, published in December 2023. It specifies how an organization establishes, operates, and continually improves an AI Management System (AIMS): governance of AI, risk and impact assessment for each AI system, and 38 Annex A controls covering the AI lifecycle from data and development through deployment, monitoring, and third-party AI use. Like ISO 27001, it is certifiable by an accredited certification body.
ISO 42001 consulting is the work of getting a company from "we use AI" to a certifiable AIMS. IRM scopes the AI systems in play, runs the gap assessment against all 38 controls, performs the AI risk and AI impact assessments the standard requires, writes the AI policy and procedures, and prepares the internal audit and management review a certification auditor will ask to see. For companies already holding ISO 27001, the two systems share the same clause structure and we integrate them rather than building a second management system.
The practice is led by an AI-Native Virtual CISO who is a Certified AI Auditor and Ethicist, so the same engagement covers the adjacent obligations: NIST AI RMF alignment, EU AI Act readiness for high-risk systems, and the AI questions now appearing in enterprise security questionnaires. See the broader AI governance services if your need is a program rather than a certification.
If AI is a feature you call through a vendor API and no customer, regulator, or investor has asked how you govern it, an AI policy and a documented risk assessment are usually enough for now. Certification is a 6 to 12 month commitment with annual surveillance audits, and it only pays off when a buyer or regulator will recognize it.
If you build or fine-tune models, sell AI into healthcare, finance, HR, or the public sector, or answer AI questions in every enterprise security review, the certificate settles those questions in one document. Run the free gap assessment first; it will show you whether the gap is 6 controls or 30.
ISO 42001 demand tracks how much of your revenue depends on customers trusting your AI. This is how we size the work.
| Stage | Typical ARR | What You Need | IRM Engagement |
|---|---|---|---|
| Pre-seed and bootstrapped | Under $1M ARR | An AI policy, a system inventory, and a documented risk assessment to answer investor and customer questions. | Free ISO 42001 gap assessment, then a Crawling tier sprint to produce the AI policy set and first risk assessment. |
| Seed | $1M to $5M ARR | A working AIMS aligned to ISO 42001 and NIST AI RMF, without certifying yet, so enterprise AI questionnaires stop blocking deals. | Walking tier, 90 days to an operating AIMS with all 38 controls addressed. |
| Series A and B | $5M to $25M ARR | ISO 42001 certification, usually integrated with ISO 27001 or SOC 2, and EU AI Act readiness for any high-risk use. | Walking or Running tier, 90 days to audit-ready, certification audit in months 4 to 6. |
| Growth and PE-backed | $25M+ ARR | Certified AIMS maintained across product lines, surveillance audits passed, and board reporting on AI risk. | Running tier managed AI governance program with a named AI-Native vCISO. |
This is the sequence we run to take a company from no formal AI governance to audit-ready. Certification audits with an accredited body typically follow in months 4 to 6.
ISO 42001 work is delivered as a monthly AI-Native Virtual CISO subscription, so the certification project and the ongoing AI governance program use the same engagement.
From $4,250 per month
20 to 40 hours per month, sprint under 6 months. Excludes certification body audit fees.
Companies that only need the AI policy set and a first risk assessment start on the Crawling tier from $2,000 per month (15 to 20 hours). Integrated ISO 42001 plus ISO 27001 or SOC 2 programs, and certified AIMS maintenance, sit on the Running tier from $6,950 per month. Pre-packaged Cyber and AI bundles start at $4,950.
See all Pricing TiersAssess all 38 Annex A controls (65 items with the management system clauses), score each gap on a 5x5 risk matrix, and download a remediation roadmap. Your answers stay in your browser.
Run the ISO 42001 Gap AssessmentBook a Free ConsultationRelated: the free AI Governance Playbook generates a starter AI policy from your intake, and SOC 2 compliance covers the security assurance most SaaS buyers ask for alongside AI governance.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.


