When customers start asking
Enterprise customers are adding ISO 42001 to vendor security reviews. This page covers what they actually want, how much of it your ISO 27001 or SOC 2 program already gives you, the AI-specific controls you will need to build, and how to decide between documented alignment and a certificate.
"Keep it Simple. Keep it Real."
What Customers Want
For most AI and software companies, ISO 42001 shows up as a line in an enterprise customer's security questionnaire or vendor risk review: are you certified, and if not, how do you govern the AI in your product? The first few hundred organizations to certify were mostly AI platforms and software companies, and procurement teams noticed. Insurers and investors have started asking the same question in their own words.
What the customer actually needs varies more than the question suggests. Some want a certificate from an accredited certification body. More often they want documented alignment: an AI policy, an inventory of the AI in your product and your operations, impact assessments for the features that affect their users, and evidence that the controls run. The honest first step is to ask the customer which one they need, because the difference is months of work.
In our view the useful way to see ISO 42001 is as a management system wrapped around the engineering you already do. Your team already reviews code, tests releases and watches production. The standard asks you to make those habits deliberate for AI, write down who owns them, and be able to show a stranger that they happen.
What You Already Have
Both help. They help in different places, and planning on the wrong one is how projects run long.
| ISO 42001 needs | From ISO 27001 | From SOC 2 |
|---|---|---|
| Management system: policy, objectives, management review, internal audit, improvement | Largely in place; extend to AI | Mostly new |
| Risk assessment and treatment | Method in place; add AI risks | Partial; add a documented method |
| Statement of Applicability | Familiar; write a new one for Annex A of ISO 42001 | New |
| Access, change management, vendor review, logging | In place; extend to models and prompts | In place; extend to models and prompts |
| AI system inventory and AI impact assessments | New | New |
| AI lifecycle, data provenance, information for users | New | New |
Companies with a working ISO 27001 system are often at the short end of the four-to-twelve-month range to certification. The clause-level detail is in ISO 42001 clause by clause and from ISO 27001 to ISO 42001.
What Is New
This is where a security program is usually thinnest, and where customers' reviews have started to probe.
A model upgrade, a new system prompt or a changed retrieval source can change behavior as much as a code release. Treat them as releases: reviewed, tested against known cases, approved and recorded.
Where training, fine-tuning and evaluation data came from, what rights you have to it, and whether customer data is used. Customers ask this first, and the answer has to be a record rather than a recollection.
If you build on a foundation model API, that provider is part of your AI system. What the contract says about data retention, training on your inputs and change notice belongs in your supplier controls.
For each AI feature that affects your customers' users: who could be harmed, how, and what you do about it. Short, specific and revisited when the feature changes.
How you would notice a model behaving differently this month than last: evaluation sets that run on a schedule, alerts on output quality, and an incident path that treats AI failures as incidents.
What you tell customers about how the AI works, its limits and their responsibilities. Annex A expects it, and enterprise legal teams increasingly write it into contracts.
AI Agents
ISO 42001 governs the organization and its AI systems, and its controls do apply to agents, but it was written before tool-using agents were common. Customers buying agent products now ask about things the standard does not spell out: which tools an agent may call, what it can do without a human approving it, how delegation between agents is limited, and how you would reconstruct what an agent did after the fact.
For agent products we add those controls inside the same management system and map them to AIUC-1, an assurance standard written specifically for AI agents that publishes a crosswalk to ISO 42001. The two work together: ISO 42001 at the level of the organization, AIUC-1 at the level of the agent.
How We Work
We do not replace your security program or your assessor. We bring the management-system discipline ISO 42001 requires, which is the part security programs most often lack, and we build it into the policies, tickets and release process your engineers already use so it does not become a second bureaucracy.
Our background is management systems and regulated industries: quality, validation and regulatory work where every change to a system has to be justified and recorded. That habit is what an ISO 42001 auditor is looking for, and it is also why regulated enterprise customers trust vendors who have it. We build and run AI systems of our own, so the lifecycle controls we recommend are ones we have had to live with.
A certification body cannot consult on what it certifies, so the firm that helps you build the system and the firm that audits it are always different. We will help you choose an accredited body and prepare for both audit stages.
Selling Into Europe
The European adoption of ISO 42001 was published in March 2026 but has not been cited in the Official Journal, so certification gives no presumption of conformity with the AI Act. The standard being written for the Act's quality management requirements is prEN 18286. If you are a provider of a high-risk system under the Act, ISO 42001 gives you much of the governance the Act expects, and you will still need the Act's own conformity route.
The detail is in ISO 42001 and the EU AI Act and ISO 42001 vs NIST AI RMF vs the EU AI Act. Costs and timelines are in what ISO 42001 costs and how long certification takes.
Not always. Many enterprise security reviews accept documented alignment with ISO 42001: an AI policy, an inventory of AI systems, impact assessments and the controls you run, with evidence. A certificate becomes worth it when several large customers require it by name, when it is written into contracts, or when it helps you win against competitors who have one. Ask the customer which they need before you commit.
Less than people expect. SOC 2 gives you control evidence, access and change management, vendor review and an audit habit, all of which help. It does not give you the management-system clauses ISO 42001 requires, such as an AI policy with objectives, management review, internal audit and continual improvement, and it does not cover AI-specific risks. Plan to build more than you would from ISO 27001.
Partly. ISO 42001 governs the organization and its AI systems, and its controls apply to agents, but it was not written with tool-using agents in mind. For agent products we add controls for tool authorization, delegation and runtime monitoring, and we map them to AIUC-1, an assurance standard for AI agents that publishes a crosswalk to ISO 42001.
No, not on its own. The European adoption of ISO 42001 has not been cited in the Official Journal, so it gives no presumption of conformity with the AI Act. The standard being written for the AI Act's quality management requirements is prEN 18286. ISO 42001 is still a strong foundation for the governance the Act expects of providers.
Book a free 30-minute call. Tell us what your customers are asking for and what you already have in place, and we will tell you whether documented alignment will do or a certificate is worth it, and what either would take.
Or email us at [email protected]