Trusted by 650+ Clients

McDonald's
Ernst & Young
Sopra Steria
BDO
Wipro
L&T
Airtel
ASTEMO
McDonald's
Ernst & Young
Sopra Steria
BDO
Wipro
L&T
Airtel
ASTEMO
McDonald's
Ernst & Young
Sopra Steria
BDO
Wipro
L&T
Airtel
ASTEMO

Overview: ISO 42001 Compliance

It is an international standard providing requirements and guidance for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS). ISO 42001:2023 applies to organizations of all sizes that use or provide AI-based products or services. It is the world's first AI management system standard.

What Is It?
World's First AI Management System Standard, Published December 2023
What It Certifies
Artificial Intelligence Management System (AIMS)
Annex A Controls
38, Under 9 Control Objectives (A.2 - A.10)
Mandatory Clauses
4 To 10
Audit Structure
Stage 1 (AIMS Documentation) + Stage 2 (AIMS Implementation)
Certificate Validity
3 Years, With Annual Surveillance Audits

ISO 42001 And The EU AI Act

The EU AI Act (Regulation 2024/1689) entered into force on August 1, 2024, and applies in phases. Prohibited practices have applied since February 2025 and general-purpose AI model obligations since August 2025. The Digital Omnibus on AI, in force since July 27, 2026, moved the high-risk deadlines: standalone Annex III systems now apply from December 2, 2027, and AI embedded in regulated products under Annex I from August 2, 2028. A new prohibition covering non-consensual intimate imagery generation applies from December 2, 2026. Penalties reach €35 million or 7% of global annual turnover.

ISO 42001 aligns with key AI Act requirements, including risk management, data governance, documentation, transparency, human oversight, and quality management. Implementing it first can simplify AI Act compliance.

However, ISO 42001 does not replace legal compliance. CE marking, EU registration, prohibited-practice screening, and incident reporting remain separate requirements.

The 38 Annex A Controls

ObjectiveCovers
A.2 Policies Related To AIAI Policy, Alignment With Other Organisational Policies, Review
A.3 Internal OrganizationRoles, Responsibilities, Reporting Of Concerns
A.4 Resources For AI SystemsData, Tooling, Compute, Human Resources
A.5 Assessing Impacts Of AI SystemsImpact On Individuals, Groups And Society; Documentation
A.6 AI System Life CycleResponsible Design, Development, Verification, Deployment
A.7 Data For AI SystemsProvenance, Quality, Preparation, Acquisition
A.8 Information For Interested PartiesDocumentation, Transparency, Incident Reporting To Users
A.9 Use Of AI SystemsResponsible Use, Defined Objectives, Human Oversight
A.10 Third-Party & Customer RelationshipsSupplier Obligations, Allocation Of Responsibility
38 controls across 9 objectives. As with ISO 27001, you are not required to implement all of them; you must review each and justify inclusion or exclusion in a Statement of Applicability, which auditors treat as the central reference across Stage 1 and Stage 2. Kratikal helps you with this.

ISO 42001 AIMS Implementation & Audit with Kratikal

Kratikal supports AIMS implementation and internal audits, helping your organization prepare for external audits and achieve ISO 42001 certification.

Our Approach

01

Gap Assessment

We assess AI governance maturity, identify ISO 42001 gaps, prioritize recommendations, and develop a roadmap for AIMS implementation.

02

Risk Assessment

We identify and categorize technical, ethical, legal, and societal AI risks to design appropriate controls for responsible AI use.

03

Policy Drafting

We develop tailored AIMS policies, including AI Governance and Responsible AI policies, based on identified gaps, risks, and organizational needs.

04

Implementation

We support AIMS implementation by establishing governance roles, integrating responsible AI practices, deploying monitoring tools, and aligning operations.

05

Training

We conduct training sessions to strengthen employee awareness, clarify responsibilities, and build internal capabilities for responsible, compliant AI practices.

06

Internal Audit

We evaluate AIMS effectiveness, identify findings, recommend corrective actions, and ensure organizational readiness and conformity before external certification audits.

07

Certification

We support Stage 1 and Stage 2 audits, address certification findings, and help achieve sustainable ISO 42001 certification.

Why Do Organizations Need ISO 42001?

ISO 42001 is voluntary from a regulatory perspective, but enterprise buyers increasingly expect AI governance standards during procurement. For organizations offering AI-enabled products or services, certification can strengthen trust, meet customer requirements, and unlock new business opportunities.

Who Needs ISO 42001 Certification?

Indian GCCs and IT Services Firms

Indian GCCs and IT Services Firms

SaaS Companies

SaaS Companies

BFSI, NBFCs and Fintech

BFSI, NBFCs and Fintech

Healthtech and Diagnostics

Healthtech and Diagnostics

HR Tech and Staffing Platforms

HR Tech and Staffing Platforms

Organisation Procuring Third-Party AI

Organisation Procuring Third-Party AI

Our Trust Block

Compliance Projects Completed
SME's & Enterprises Served

Client Testimonials

★★★★★

We sincerely appreciate your team's professionalism and diligence throughout the ISO certification process. The structured approach and attention to compliance have been commendable. Your efforts have greatly contributed to strengthening our organization's quality and process standards.

SaikumarNetwork Administrator, CredRight Finance Private Limited
★★★★★

Thanks for prompt response on the project and the follow-ups. Appreciate both Ishita and Kushagra for jumping in quickly to resolve a client-side issue with the report. We might look forward to a few more compliance projects like ISO shortly.

Saumil ChandiraCOO, Co founder, Remasto

Benefits

Independent Audit Readiness

Independent Audit Readiness

Regular third-party audits give customers and boards verifiable proof, not promises.

Regulatory Head Start

Regulatory Head Start

Maps to EU AI Act governance articles and MeitY's seven principles.

Procurement Questions Answered

Procurement Questions Answered

Clears the AI section now appearing in every enterprise security questionnaire.

One Integrated System

One Integrated System

Extends your existing ISO 27001 ISMS rather than duplicating the programme.

FAQs

ISO/IEC 42001:2023 is the world's first AI management system standard. It gives organisations a governance structure for AI-specific risks - bias, explainability, data provenance, drift, and human oversight that information security standards do not address.

Any organisation that develops, provides, or uses AI-based products or services. Demand is strongest among Indian GCCs building AI for European clients, SaaS vendors shipping AI features, and anyone facing AI questions in enterprise procurement.

Annex A contains 38 controls under 9 objectives, numbered A.2 to A.10. They cover AI policies, impact assessment, the AI life cycle, data, transparency, use, and third-party relationships. Controls are selected by risk.

Yes. BIS adopted it as IS/ISO/IEC 42001:2023, an Indian national standard. MeitY's India AI Governance Guidelines name it directly in Annexure 6. Certification is voluntary but increasingly appears in enterprise and public sector procurement.

No. It is a management system standard, not a conformity assessment, and confers no presumption of conformity. It maps closely to the Act's governance obligations but excludes CE marking, EU database registration and incident reporting.

The DPDP Act applies to any AI system processing personal data. MeitY's guidelines are voluntary and rely on existing law for enforcement. ISO 42001 supplies the auditable management system that turns those principles into evidenced practice.

Three years, subject to annual surveillance audits by the certification body in years two and three, with a full recertification audit before the cycle ends. This is the same cycle as ISO 27001.

It evaluates an AI system's consequences for individuals, groups, and society: fairness, discrimination, safety, and transparency.