ISO/IEC 42001: the audit an AI vendor is actually asked to pass
ISO/IEC 42001 is the international standard for an AI management system — the policies, roles, impact assessments, data controls and oversight that decide how your organisation builds and runs AI. Unlike a framework you can adopt quietly, it ends in a certificate granted by an accredited certification body after it has audited you.
That external gate is what makes it different from the EU AI Act. The Act is law and carries the penalties, but for most high-risk systems it is self-assessed: Article 43 sends Annex III points 2 to 8 through the Annex VI internal-control procedure, “which does not provide for the involvement of a notified body”. Seven of the eight Annex III headings never meet an external auditor. ISO/IEC 42001 is where that auditor is — which is why it is what your buyer asks for.
Conformly prepares and maintains the evidence an auditor samples. It does not issue certificates — an accredited certification body does, and no software can promise their decision.
Who is actually asked for it
Almost nobody pursues ISO/IEC 42001 for its own sake. The demand arrives from outside — from a buyer, a tender, or a customer passing their own obligations down the chain.
You sell AI into an EU enterprise
Vendor-risk teams have started adding an AI-governance question to the security questionnaire. ISO/IEC 42001 is the answer that ends the thread, because it is the one answer a procurement reviewer can verify without reading your documentation.
You bid for public-sector work
Public buyers award on evidence, not assurances. A management-system certificate is a recognised, scoreable artefact in a tender; an internal policy PDF is not.
You are the AI supplier in someone else's supply chain
Your customer's own obligations flow down to you. Certification turns an open-ended diligence exercise into a document exchange, and it is reusable across every buyer instead of being rewritten per deal.
You already run ISO 27001 and added AI
27001 governs information security; it says nothing about model impact, data provenance or human oversight. 42001 is the management system built for those, and it is designed to bolt onto the one you already operate.
How it relates to the EU AI Act
These two get conflated constantly, usually by someone selling one of them. Here is each claim we will make, with the limit on it stated next to it.
ISO/IEC 42001 certification is not EU AI Act compliance. It is a different instrument with a different authority behind it: a voluntary international standard, certified by an accredited body, against a law that is enforced by market-surveillance authorities.
The limit: No certificate discharges an obligation under Regulation (EU) 2024/1689. A regulator will ask about your systems, not about your management system.
It does, however, cover most of the ground Article 17 asks for. The Article 17 quality management system — documented policies, responsibilities, design and development control, data management, post-market monitoring, record keeping, and accountability — is largely the same machinery ISO/IEC 42001 requires you to build and keep running.
The limit: 'Largely the same machinery' is not 'automatically satisfied'. Article 17 has AI Act-specific items, and conformity is assessed against the Act's own text, not against your certificate.
The two are cheapest to do together. Impact assessments, data governance records, human-oversight measures and incident handling are each demanded by both. Done once and stored once, they evidence both.
The limit: The evidence is shared; the assessments are separate. You still run an AI Act classification per system and a 42001 audit per management system.
For most high-risk providers, 42001 is the only place an accredited auditor will ever look. Article 43 sends Annex III points 2 to 8 through the Annex VI internal-control procedure, which does not provide for the involvement of a notified body — so seven of the eight Annex III headings are self-assessed.
The limit: The exception matters: Annex III point 1 (biometrics) can require a notified body, and Annex I product-safety AI inherits whatever conformity route its underlying product legislation already imposes.
New to the law itself? Start with the EU AI Act guide.
The Annex A control set — all 38
This is the same control library the product runs, grouped by the standard’s A.2–A.10 objectives. Against each control is what Conformly produces towards it: automated checks where a machine can honestly answer, work reused from your EU AI Act obligations where the two overlap, and in every case a Statement of Applicability row that an auditor can read.
Policies related to AI
3 controlsPolicy templates, an approval and acknowledgement trail, and a check that flags a policy which has gone too long without review.
The organisation documents an AI policy that sets direction and commitment for the responsible development and use of AI.
Approve a top-level AI policy covering objectives, scope and principles, and have staff acknowledge it.
Conformly produces: 2 automated checks (policy.all-approved, policy.acknowledged) · evidence reused from your EU AI Act work (ai_literacy, quality_management) · a Statement of Applicability row with a justification field
The AI policy is consistent with the organisation's other policies (security, privacy, quality).
Cross-reference the AI policy against existing security/privacy/quality policies and resolve conflicts.
Conformly produces: 1 automated check (policy.all-approved) · evidence reused from your EU AI Act work (quality_management) · a Statement of Applicability row with a justification field
The AI policy is reviewed at planned intervals to ensure it stays suitable and effective.
Schedule a periodic policy review (management review is the natural trigger) and record the outcome.
Conformly produces: 1 automated check (monitoring.recent-review) · a Statement of Applicability row with a justification field
Internal organization
2 controlsA named owner on every AI system, and an incident register that surfaces items left unresolved.
Roles and responsibilities for AI are defined and allocated across the organisation.
Name an accountable owner for every AI system and document governance roles.
Conformly produces: 1 automated check (inventory.owner-assigned) · a Statement of Applicability row with a justification field
A process exists for people to report concerns about AI systems.
Provide a channel to raise AI concerns and make sure raised items are tracked to resolution (incident register).
Conformly produces: 1 automated check (incident.none-stale) · a Statement of Applicability row with a justification field
Resources for AI systems
5 controlsA documented resource, data and tooling picture per system, an environment scan that keeps the tooling list honest, and training completion records.
Resources needed for AI systems (data, tooling, compute, people) are identified and documented.
Maintain documentation of the resources each AI system depends on.
Conformly produces: evidence reused from your EU AI Act work (technical_documentation) · a Statement of Applicability row with a justification field
Data resources used by AI systems are documented, including their characteristics and provenance.
Record the categories and sources of data each high-risk system processes.
Conformly produces: 1 automated check (data.types-documented) · evidence reused from your EU AI Act work (data_governance) · a Statement of Applicability row with a justification field
The tools and services used to develop and run AI systems are known and documented.
Keep an inventory of AI tooling; an environment scan keeps it honest against what is actually installed.
Conformly produces: 1 automated check (discovery.scan-recent) · a Statement of Applicability row with a justification field
System and computing resources supporting AI systems are documented and adequate.
Document the compute/infrastructure each system relies on and confirm it is sufficient and monitored.
Conformly produces: 1 automated check (discovery.scan-recent) · a Statement of Applicability row with a justification field
People involved in AI systems have the necessary competence, verified and maintained.
Assign and complete AI literacy / competence training for staff working with AI.
Conformly produces: 1 automated check (training.completion) · evidence reused from your EU AI Act work (ai_literacy) · a Statement of Applicability row with a justification field
Assessing impacts of AI systems
4 controlsThe impact-assessment workflow: per-system classification, recorded risks to individuals and groups, and the retained assessment record.
A process is defined for assessing the potential impacts of AI systems.
Run the risk-classification wizard and record risks per system; that is the impact-assessment process in action.
Conformly produces: 2 automated checks (highrisk.risk-assessment, inventory.all-classified) · evidence reused from your EU AI Act work (risk_management) · a Statement of Applicability row with a justification field
The results of AI system impact assessments are documented and retained.
Keep the completed impact assessments and technical file for each high-risk system.
Conformly produces: 1 automated check (highrisk.annex-iv) · evidence reused from your EU AI Act work (risk_management, technical_documentation) · a Statement of Applicability row with a justification field
The impact of AI systems on individuals and groups of individuals is assessed.
Document affected persons and the risks of harm to them (the FRIA covers this for relevant deployers).
Conformly produces: 1 automated check (highrisk.risk-assessment) · evidence reused from your EU AI Act work (risk_management) · a Statement of Applicability row with a justification field
Broader societal impacts of AI systems are considered and assessed.
Include societal / group-level considerations in the impact assessment where relevant.
Conformly produces: 1 automated check (highrisk.risk-assessment) · evidence reused from your EU AI Act work (risk_management) · a Statement of Applicability row with a justification field
AI system life cycle
9 controlsTechnical documentation per system, obligation progress across design, verification and deployment, and post-market monitoring that keeps running afterwards.
Objectives for responsible development are defined and guide the life cycle.
State responsible-development objectives in policy and flow them into system requirements.
Conformly produces: 1 automated check (policy.all-approved) · evidence reused from your EU AI Act work (quality_management) · a Statement of Applicability row with a justification field
Documented processes govern the responsible design and development of AI systems.
Follow and evidence a defined development process; obligation progress reflects it.
Conformly produces: 1 automated check (highrisk.obligations-progress) · evidence reused from your EU AI Act work (quality_management) · a Statement of Applicability row with a justification field
Requirements and specifications for AI systems are defined.
Capture functional and compliance requirements in the technical file for each system.
Conformly produces: 1 automated check (highrisk.annex-iv) · evidence reused from your EU AI Act work (technical_documentation) · a Statement of Applicability row with a justification field
The design and development of AI systems is documented.
Maintain the Annex IV technical documentation across design and development.
Conformly produces: 1 automated check (highrisk.annex-iv) · evidence reused from your EU AI Act work (technical_documentation) · a Statement of Applicability row with a justification field
AI systems are verified and validated against their requirements.
Record testing, accuracy and robustness results; drive open obligations to completion.
Conformly produces: 1 automated check (highrisk.obligations-progress) · evidence reused from your EU AI Act work (accuracy_robustness) · a Statement of Applicability row with a justification field
AI systems are deployed under controlled conditions consistent with their assessment.
Ensure no prohibited practice reaches production and deployment follows the assessed conditions.
Conformly produces: 1 automated check (prohibited.none-active) · evidence reused from your EU AI Act work (post_market_monitoring) · a Statement of Applicability row with a justification field
AI systems are operated and monitored throughout their life.
Keep post-market monitoring active and review compliance regularly.
Conformly produces: 1 automated check (monitoring.recent-review) · evidence reused from your EU AI Act work (post_market_monitoring) · a Statement of Applicability row with a justification field
Technical documentation for AI systems is produced and kept up to date.
Generate and maintain the Annex IV technical file for each high-risk system.
Conformly produces: 1 automated check (highrisk.annex-iv) · evidence reused from your EU AI Act work (technical_documentation) · a Statement of Applicability row with a justification field
AI systems record event logs to enable traceability.
Ensure record-keeping / logging obligations are met so system behaviour is traceable.
Conformly produces: evidence reused from your EU AI Act work (record_keeping) · a Statement of Applicability row with a justification field
Data for AI systems
5 controlsData categories, sources, provenance and preparation recorded per system, under one data-governance record.
Data used to develop and enhance AI systems is managed appropriately.
Document training/development data categories and governance for each system.
Conformly produces: 1 automated check (data.types-documented) · evidence reused from your EU AI Act work (data_governance) · a Statement of Applicability row with a justification field
Data acquisition for AI systems is controlled and lawful.
Record how data is acquired and the legal basis, within your data-governance obligation.
Conformly produces: 1 automated check (data.types-documented) · evidence reused from your EU AI Act work (data_governance) · a Statement of Applicability row with a justification field
Data quality is assessed and maintained for AI systems.
Define and check data-quality criteria as part of data governance.
Conformly produces: evidence reused from your EU AI Act work (data_governance) · a Statement of Applicability row with a justification field
The provenance of data used by AI systems is documented.
Track where data originates and its lineage in the data-governance records.
Conformly produces: evidence reused from your EU AI Act work (data_governance) · a Statement of Applicability row with a justification field
Data preparation activities are defined and documented.
Document preprocessing, labelling and transformation steps applied to data.
Conformly produces: evidence reused from your EU AI Act work (data_governance) · a Statement of Applicability row with a justification field
Information for interested parties of AI systems
4 controlsInstructions for use, published transparency notices, and incident communication with the reporting deadline tracked.
Users receive the documentation and information they need to use AI systems appropriately.
Provide instructions for use and transparency information to users/deployers.
Conformly produces: evidence reused from your EU AI Act work (transparency_instructions) · a Statement of Applicability row with a justification field
The organisation reports externally as required (e.g. to authorities).
Report serious incidents to the authority within the deadline and keep the record.
Conformly produces: 1 automated check (incident.serious-15day) · a Statement of Applicability row with a justification field
Incidents involving AI systems are communicated to relevant parties.
Track incidents and communicate them; do not let them go stale.
Conformly produces: 1 automated check (incident.none-stale) · a Statement of Applicability row with a justification field
Relevant information is made available to interested parties.
Publish transparency notices and keep interested parties informed (Trust Center covers this).
Conformly produces: evidence reused from your EU AI Act work (transparency_notices) · a Statement of Applicability row with a justification field
Use of AI systems
3 controlsHuman-oversight measures per deployed system, and a check that every system stays classified against its intended use.
Processes govern the responsible use of AI systems in operation.
Follow deployer use obligations and record how systems are used responsibly.
Conformly produces: evidence reused from your EU AI Act work (human_oversight) · a Statement of Applicability row with a justification field
Objectives for responsible use are defined, including human oversight.
Define human-oversight measures and use objectives for each deployed system.
Conformly produces: evidence reused from your EU AI Act work (human_oversight) · a Statement of Applicability row with a justification field
AI systems are used in line with their intended purpose.
Classify every system and confirm operation stays within the assessed intended use.
Conformly produces: 1 automated check (inventory.all-classified) · a Statement of Applicability row with a justification field
Third-party and customer relationships
3 controlsA vendor register with assessment state and supporting documents, and the responsibility split recorded per third party.
Responsibilities are allocated between the organisation and third parties.
Assess third-party AI vendors and record the split of responsibilities.
Conformly produces: 1 automated check (vendor.assessed) · evidence reused from your EU AI Act work (gpai_documentation) · a Statement of Applicability row with a justification field
AI-relevant suppliers are assessed and managed.
Move every vendor beyond 'invited' to an assessed state and keep supporting documents.
Conformly produces: 1 automated check (vendor.assessed) · a Statement of Applicability row with a justification field
Obligations toward customers regarding AI systems are met.
Provide customers the transparency and instructions they need to meet their own duties.
Conformly produces: evidence reused from your EU AI Act work (transparency_instructions) · a Statement of Applicability row with a justification field
The road to certification, and who owns each step
Two of these steps are not ours and never can be. An accredited certification body has to be independent of the tooling you used to prepare, which is precisely what makes its verdict worth something to your buyer.
- 1Scope and gap assessmentYou
Decide which AI systems, sites and processes the management system covers, then measure the distance between that scope and the Annex A controls. The scope decision drives every cost that follows, so it is worth getting narrow and defensible before anything else starts.
Conformly: An AI system inventory with an owner per system, and a computed state for each of the 38 Annex A controls, so the gap list is generated from evidence rather than assembled by hand.
- 2Build the management systemYou
Write and approve the AI policy, assign roles, run impact assessments, document data provenance and quality, define human-oversight measures, and stand up incident handling. This is the bulk of the first-cycle effort.
Conformly: Policy templates with an approval and acknowledgement trail, the impact-assessment workflow, the vendor register, the incident register, and the deterministic monitoring checks that keep each of them from going stale.
- 3Statement of ApplicabilityYou
Record, control by control, whether it applies, why, and how it is implemented. Every exclusion needs a justification. This is the document the auditor works from, and a stale one is the most common finding.
Conformly: A Statement of Applicability that is generated from live control state and exported as a PDF — including a flag on any control excluded without a justification, which is exactly what a Stage 1 review looks for.
- 4Internal auditYou
Clause 9.2 requires you to audit the management system yourself, against both the standard and your own requirements, before anyone external does. Findings must be recorded and corrected.
Conformly: The evidence trail an internal auditor samples — control history, timestamps, who approved what and when — in one place instead of five drives.
- 5Management reviewYou
Clause 9.3 requires top management to review the system's performance and record decisions on resources, changes and improvement. Absent or undated minutes here are a routine nonconformity.
Conformly: A dated readiness position and the open-gap list to review against, plus a monitoring check that surfaces a review which has gone too long without being repeated.
- 6Stage 1 audit — documentation reviewAccredited certification body
An accredited certification body reviews your documented management system, checks that the scope and Statement of Applicability hold together, and tells you what must be fixed before Stage 2. It is a readiness check, not a pass or fail.
Conformly: Read-only auditor access to the workspace and the exportable evidence pack — so the reviewer reads your system rather than a mailbox of attachments.
- 7Stage 2 audit — certification decisionAccredited certification body
The certification body tests the system in operation: interviews, sampled records, and evidence that the controls have actually run. The certificate, when it is granted, is granted by them.
Conformly: nothing. This step is the certification body’s alone, and the outcome is theirs to decide.
- 8Surveillance and recertificationYou
Certification is a multi-year cycle with periodic surveillance audits in between. The system has to keep running — a management system that goes quiet after the certificate arrives is one that fails its next surveillance visit.
Conformly: Continuous monitoring checks and change tracking, so a control that quietly stops being true surfaces as a gap between audits instead of during one.
What it costs — honestly
We are not going to put a number on your audit. We do not know your scope, and a figure invented here is one you would discover was wrong the moment a real quote arrived. What we can describe is the shape of the cost, which is enough to budget against.
The audit is a separate purchase, from a separate company
Software does not include the audit and cannot. Certification bodies are independently accredited and must remain independent of the tools you use, so their fee is always a second line item. Anyone bundling the two is describing something that is not accredited certification.
The fee tracks auditor days, and auditor days track your scope
Certification bodies price per engagement, from the number of AI systems and sites in scope, headcount, and how complex the system is to sample. A narrow first scope — one product line, one management system — is the single largest lever you have on the number.
It recurs
Certification runs on a cycle: an initial audit, surveillance audits in between, and recertification at the end. Budget it as an annual cost, not a one-off project.
Ask two or three accredited bodies for a written quote
We do not publish a figure because we would be guessing at your scope, and quotes vary by certification body and country. Check that the body is accredited by a recognised national accreditation body for ISO/IEC 42001 specifically — accreditation for 27001 does not carry over.
In the first cycle, your own time usually costs more than the audit
Evidence collection, the Statement of Applicability, the internal audit and the management review are where the months go. That is the part software compresses — and the only part of this page we are selling.
Conformly’s own price is published in full on the pricing page — no quote call, no scoping exercise.
Frequently asked questions
Does Conformly issue an ISO 42001 certificate?
No. Only an accredited certification body can grant an ISO/IEC 42001 certificate, and it must be independent of the tools and consultants you used to prepare. Conformly builds and maintains the evidence that body will audit: the Annex A control library, the Statement of Applicability, the impact assessments, the monitoring history and the exportable evidence pack. The certification decision is theirs alone, and no software can promise its outcome.
Does ISO 42001 make me EU AI Act compliant?
No. ISO/IEC 42001 is a voluntary international standard; the EU AI Act is law, enforced by market-surveillance authorities against your individual AI systems. A certificate does not discharge an obligation under it. What certification does do is build most of the machinery Article 17 asks of a high-risk provider — documented policies, responsibilities, design and development control, data management, post-market monitoring and record keeping — so the two programmes share their evidence rather than duplicating it.
How long does ISO 42001 certification take?
It depends far more on where you start than on the standard. An organisation that already runs ISO/IEC 27001 has the management-system spine — policy control, internal audit, management review, corrective action — and is extending it. An organisation starting from nothing is building that spine first. The fixed constraint is sequencing rather than speed: you cannot pass Stage 2 without a completed internal audit and management review, and both need the system to have been running long enough to produce records worth sampling.
What will the auditor actually ask for?
Records, not intentions. Expect: the scope statement; the approved AI policy and evidence people acknowledged it; the Statement of Applicability with a justification for every exclusion; an inventory of AI systems with a named owner each; completed impact assessments; data provenance and data-quality records; documented human-oversight measures; the incident register with resolutions; supplier assessments; competence and training records; and the internal audit report and management review minutes, both dated. Anything you claim is implemented, they will sample.
What is a Statement of Applicability?
The mandatory document that lists every Annex A control and states whether it applies to you, why, and how it is implemented. Exclusions must be justified — 'not applicable' with no reason is a finding. It is the map the auditor navigates by, which is why it must be generated from the live state of your controls rather than maintained as a spreadsheet that quietly drifts from reality.
ISO 42001 or ISO 27001 — which do I need?
They answer different questions and neither replaces the other. ISO/IEC 27001 governs information security: confidentiality, integrity and availability of information. ISO/IEC 42001 governs the AI management system: impact on individuals and society, data provenance and quality, human oversight, life-cycle control and third-party AI. If you sell software, buyers will usually ask for 27001 first; if you sell AI, 42001 is the question arriving behind it. Because both follow the same Annex SL management-system structure, the second one costs far less than the first.
Can I use one set of work for both ISO 42001 and the EU AI Act?
For most of the evidence, yes — that is the entire reason to run them together. Impact assessments, data governance records, human-oversight measures, technical documentation, incident handling and supplier assessments are demanded by both instruments. Conformly maps each Annex A control to the AI Act obligations and the automated checks that evidence it, so completing the work once updates both positions. The assessments themselves stay separate: a per-system AI Act classification, and a per-management-system audit.
We are outside the EU. Is ISO 42001 still worth it?
It is the more portable of the two. The EU AI Act binds you only through the EU market — placing a system there, or having its output used there. ISO/IEC 42001 is an international standard recognised by buyers anywhere, and it is increasingly what a large customer means when it asks how you govern AI. If your buyers are global, it travels further than any single jurisdiction's compliance file.
Run the 38 Annex A controls against your own systems, keep a Statement of Applicability that cannot drift from your evidence, and reuse the same work for the EU AI Act.
This page describes ISO/IEC 42001:2023 and its relationship to Regulation (EU) 2024/1689. It is general information, not legal advice, and it is not a substitute for the text of the standard, which is published by ISO. Conformly is a software provider: it is neither an accredited certification body nor a notified body, and it holds no ISO/IEC 42001 certificate of its own.