WATCHUR6 // ISO 42001 // AUDIT READINESS

"Trust our AI" isn't a strategy.
ISO 42001 is the proof buyers want.

ISO 42001 is the world's first AI management system standard — and fast becoming the credential enterprise buyers ask for before they'll trust your AI. It's an independently certified governance program built on 38 AI controls, and the strongest foundation for the EU AI Act. We build the system and the certification.

Book an ISO 42001 Strategy Call
ISO/IEC 42001:2023 38 ANNEX A CONTROLS AI IMPACT ASSESSMENT VETERAN-LED

// WHY ISO 42001, WHY NOW

Buyers stopped taking "responsible AI" on faith. They want it certified.

1ST

The first AI governance standard

Published December 2023, ISO 42001 is the world's first international AI management system standard — the credential procurement teams are starting to require.

38

AI-specific Annex A controls

Across nine areas and four operational domains, selected through a Statement of Applicability — with the AI Impact Assessment as the substantive core.

EU AI ACT

The foundation, not the finish line

Its 38 controls map onto many high-risk EU AI Act requirements. ISO 42001 is the governance backbone — a strong start toward the Act, though not legal compliance by itself.

// A POLICY ISN'T A SYSTEM

We have an AI policy, so our AI is governed.
ISO 42001 certifies a system — documented, audited, and improving.

A policy on a page isn't governance a buyer can verify. ISO 42001 certifies an AI management system: an AI inventory, an AI Impact Assessment that weighs societal and ethical risk, lifecycle and data-governance controls, human-oversight mechanisms, and a Statement of Applicability — all independently audited and continually improved. The difference between "we have an AI policy" and a certified AIMS is the difference between a claim and third-party-validated proof that survives an enterprise security review.

// THE FOUR ANNEX A CONTROL DOMAINS

38 controls. One domain that makes it about AI.

Annex A's 38 controls group into four operational domains. AI System Lifecycle & Risk is the substantive core — the AI Impact Assessment and responsible-AI work that justify a separate standard. The other three are the management-system foundation it sits on.

AI System Lifecycle & Risk The substantive core · anchored by the AI Impact Assessment

The reason ISO 42001 exists apart from ISO 27001: the AI Impact Assessment, AI lifecycle management, and AI risk treatment, plus the responsible-AI principles — bias, explainability, human oversight, model drift, fundamental rights. The three domains below provide the governance scaffolding; this is the AI-specific substance the rest exists to support.

// CONTEXT & LEADERSHIP

Organizational Context

AI policy committed by leadership, defined AI roles, and how AI fits your risk landscape.

// RESOURCES & DATA

Data Governance

Compute, data, human, and supplier resources; data quality, lineage, and training-data governance.

// OPERATIONS & IMPROVEMENT

Operations

Transparency to interested parties, responsible-use guidance, and third-party AI relationships.

Controls are risk-selected via a Statement of Applicability — scope decides what applies.

ISO/IEC 42001:2023 · THE FIRST AIMS STANDARD Annex SL · INTEGRATES WITH ISO 27001 AI Impact Assessment · THE CORE ARTIFACT

// THE PATH

Six stages to a certified AIMS.

The familiar ISO management-system path — if you've done ISO 27001, it'll feel recognizable. The amber stages are where the accredited certification body enters: the Stage 1 and Stage 2 audits.

Scope

AI Inventory & Context

WK 1–4

Build

AIMS + Impact Assessment

MO 1–3

Implement

Annex A + Internal Audit

MO 3–7

Stage 1

Documentation Audit

MO 7–8

Stage 2

Implementation Audit

MO 8–10

Sustain

Surveillance & Recert

Y1 / Y2 / Y3

Amber stages are where the accredited certification body enters — the Stage 1 documentation audit and Stage 2 implementation audit. Certification runs on a three-year cycle: annual surveillance, full recertification in year three.

// IS THIS YOU?

Three signs ISO 42001 is your next move.

// 01 // BUYER ASK

Customers are asking about your AI

Enterprise security reviews now include AI-governance questions you can't answer with a policy doc. An ISO 42001 certificate is the credible answer that unblocks the deal.

// 02 // YOU SHIP AI

You build or deploy AI in your product

If AI is in your product or workflows, you carry risks — bias, drift, explainability, data lineage — that no security framework covers. ISO 42001 is built for exactly that.

// 03 // EU AI ACT

The EU AI Act is on your radar

You sell into the EU or expect to. ISO 42001 is the governance foundation its high-risk requirements map onto — build it first, then gap-map to the Act.

// WHAT WE DO

The AI inventory, the impact assessment, and the certification.

// Phase 01 · Scope

AIMS Scoping & AI Inventory

We inventory your AI systems and AI-enabled features, define the AIMS boundary, and run a gap analysis against the 38 Annex A controls — the decision that shapes everything after it.

  • AI system inventory and AIMS boundary
  • Gap analysis against 38 Annex A controls
  • Statement of Applicability and ISO 27001 reuse

// Phase 02 · Build

AIMS, Impact Assessment & Controls

We build the management system and the AI Impact Assessment, then implement your selected Annex A controls across lifecycle, data, and operations — ready for audit, not just on paper.

  • AI policy, roles, and governance structure
  • AI Impact Assessment and AI risk treatment
  • Lifecycle, data-governance, and oversight controls

// Phase 03 · Certify

Audit, Certification & EU AI Act Mapping

We carry you through Stage 1 and Stage 2 audits to certification, sustain the program, and gap-map your controls to the EU AI Act where it applies to you.

  • Internal audit and Stage 1 / Stage 2 readiness
  • Certification body coordination
  • EU AI Act gap mapping and surveillance support

// AI GOVERNANCE IS A BUYING CRITERION NOW

Every deal that stalls on an AI question is one a certificate would have closed.

Book an ISO 42001 Strategy Call

// FREQUENTLY ASKED

The ISO 42001 questions teams keep asking.

What is ISO 42001, and why would we get certified?

ISO/IEC 42001:2023, published December 2023, is the world's first international standard for an AI management system (AIMS) — how an organization establishes, maintains, and improves the governance around how it builds and uses AI. It's becoming the credential enterprise customers and procurement teams ask for as evidence you govern AI responsibly.

The reason to certify is usually commercial before regulatory: an accredited certification is independent, third-party proof of AI governance maturity that shortens vendor reviews and differentiates you in deals where buyers are nervous about AI risk. Because it follows the same Annex SL structure as ISO 27001, it integrates with an existing ISMS rather than standing up a separate program.

Does ISO 42001 make us compliant with the EU AI Act?

No — and the distinction matters. The EU AI Act is a law; for in-scope organizations its obligations are a legal requirement. ISO 42001 is a voluntary management-system certification — a governance maturity and commercial signal. They're complementary but not interchangeable, and you should never represent the certification to customers or regulators as EU AI Act compliance.

That said, it's the strongest practical foundation: there's substantial overlap between its 38 Annex A controls and the Act's high-risk requirements, and several core articles have direct counterparts. Build the AIMS first as the backbone, then classify your AI against the Act's risk tiers and gap-analyze anything high-risk. Note the Act's high-risk timelines are still moving — a simplification package is under consideration — so we treat regulatory dates as current-but-subject-to-change and keep the program anchored on durable governance.

We already have ISO 27001. How much extra work is ISO 42001?

Less than you'd fear, because the two share the same Annex SL backbone — context, leadership, planning, support, operation, performance evaluation, improvement — so the management-system machinery from ISO 27001 (governance, internal audit, management review, document control, corrective action) carries over to the AIMS.

What's genuinely new is the AI-specific substance in Annex A: an AI policy and roles, an AI system inventory, the AI Impact Assessment that evaluates societal and ethical risk rather than just security, AI lifecycle management, data and training-data governance, and responsible-AI principles like bias, explainability, human oversight, and drift. Mature ISO 27001 programs reuse the management layer and focus effort on the AI risk and lifecycle domain — exactly where the standard earns its separate existence. We scope to leverage what you have rather than rebuild it.

What does the certification process and timeline look like?

It follows the familiar ISO management-system path. You scope the AIMS and inventory your AI systems; build the management system and AI Impact Assessment; implement your selected Annex A controls and run an internal audit; then an accredited certification body conducts a Stage 1 documentation audit and a Stage 2 implementation audit. Passing Stage 2 yields certification, maintained over a three-year cycle with annual surveillance and recertification in year three.

A first certification commonly takes on the order of ten to twelve months depending on governance maturity and how many AI systems are in scope; organizations with a strong existing management system move faster. As with every ISO standard, the biggest determinant of timeline is scope and the quality of your documentation and evidence — which is where readiness work pays off before the certification body arrives.

// THE NEXT MOVE

Turn "responsible AI" from a claim into a certificate.

Book a 30-minute ISO 42001 strategy call with a WatchUr6 advisor. Bring how you use or build AI, whether customers are asking about AI governance, whether you hold ISO 27001, and whether the EU AI Act is in play. You'll walk away with a scoped AIMS plan, an honest read on your readiness, and a realistic path to certification — whether you hire us or not.

Book an ISO 42001 Strategy Call

SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED