ISO/IEC 42001 is the first international standard for AI management systems, and the EU AI Act is making responsible AI a regulatory requirement rather than a talking point. Compyl runs your AI governance program on the same control library as the rest of your GRC, so most of the evidence you need already exists.
The standard is new, the regulation is real, and buyers are already asking. Most teams have an AI policy; very few have a management system they could put in front of an auditor.
The Act entered into force in August 2024, general-purpose AI obligations began in August 2025, and the 2026 Digital Omnibus on AI moved high-risk obligations to December 2027 (August 2028 for AI in regulated products). ISO 42001 is a strong, widely used way to evidence the governance the Act expects.
Security questionnaires now include AI sections. Enterprise buyers want evidence that your AI features are governed, and an ISO 42001 certificate answers the question before it is asked.
AI risk has reached the board agenda. A certifiable management system turns responsible-AI intentions into controls, owners, evidence, and audit results.
Compyl runs your AIMS as an always-on cycle, Annex A controls, impact assessments, and evidence stay in sync automatically.
Integrate cloud, identity, ML, data, and HR systems.
Pull audit evidence automatically, in real time.
Link every artifact to its ISO 42001 control and clause.
Watch controls continuously and flag drift early.
Hand auditors a current evidence pack on demand.
ISO 42001 organizes its 38 Annex A controls into nine categories. Compyl maps live evidence to each, reusing your ISMS wherever the controls overlap.
AI policy, internal organization, roles, and the leadership accountability it starts with.
Assess the impact of each AI system on individuals, groups, and society before and during use.
Objectives, design, verification, deployment, and monitoring across the life of each AI system.
Resources, data provenance, quality, and preparation for the systems that depend on them.
Information for interested parties, responsible use, and supplier and customer relationships.
ISO 42001 follows the same harmonized structure as ISO 27001, and the overlap is large. Compyl maps each control once, so your existing ISMS evidence counts toward your AIMS from day one, and pulls the AI-specific proof from your ML stack.
Collecting evidence is only half the battle; stale or incomplete proof is where certification audits go sideways. Evidence Health continuously scores every artifact the moment it changes, so weak evidence surfaces weeks before the audit, not during it.
Models ship faster than policies update. Compyl monitors every Annex A control continuously, scores your posture in real time, and turns the moment something slips into a tracked task.
ISO 42001 reuses the harmonized management-system structure: context, leadership, planning, support, operation, evaluation, improvement. Compyl cross-maps each control so a large share of your AIMS is satisfied by evidence you already collect.
The regulatory clock and the certification cycle run on different timelines. Compyl keeps you ready for both.
The Act is law across the EU, with obligations phased in by risk class. ISO 42001 is voluntary and gives no legal presumption of conformity, but it is a strong, widely used way to show the governance the Act expects.
An accredited body audits your AIMS in two stages, then returns for surveillance audits each year of the three-year cycle.
Plenty of tools store an AI policy. Compyl runs the whole AIMS, impact assessments, life-cycle evidence, vendor AI oversight, and a posture you can publish.
Annex A controls, assessments, and evidence stay live year-round, so audits never catch you out.
Controls, evidence, risks, and policies in one platform, not a stack of disconnected tools.
Pulls live data from the stack you already run, so posture reflects reality, not snapshots.
AI maps controls, drafts remediations, and offloads busywork, your team stays in control.
ISO 42001 evidence carries over from ISO 27001, SOC 2, and GDPR without redoing the work.
Compyl cross-maps controls so ISO 42001 builds on the ISMS you have, and carries into the next framework on your roadmap.
“It has brought a sense of relief to my life because, for the first time, we have a real solution in place that is proactively keeping us protected.”
ISO/IEC 42001 is the international standard for Artificial Intelligence Management Systems (AIMS), published in December 2023. It defines how an organization governs the development and use of AI responsibly: leadership accountability, AI risk and impact assessments, life-cycle controls, data governance, and continuous improvement, with Annex A controls organized into nine categories. Like ISO 27001, it is certifiable: an accredited body audits your AIMS, and certification runs on a three-year cycle with surveillance audits. Compyl runs your AIMS on the same cross-mapped control library as ISO 27001, so existing ISMS evidence counts from day one, and adds AI risk and impact assessments, life-cycle evidence from your ML stack, policy management, and vendor AI oversight on one platform.
ISO 27001 governs information security; ISO 42001 governs artificial intelligence. They share the same management-system skeleton, which is why they pair so well.
| ISO 27001 | ISO 42001 | With Compyl | |
|---|---|---|---|
| Scope | Information security management system (ISMS) | AI management system (AIMS) | Both on one cross-mapped control library |
| Annex A | 93 controls in 4 themes | 38 controls in 9 categories | Shared controls satisfied once |
| Core assessment | Information security risk assessment | AI risk and AI system impact assessments | Run in the same risk module |
| Certification | Accredited audit, 3-year cycle | Accredited audit, 3-year cycle | One living evidence pack for both |
| Adding it later | — | Reuses the harmonized structure of your ISMS | A fraction of the effort of starting from scratch |
ISO 42001 is the international standard that tells an organization how to govern its use of artificial intelligence responsibly. It works like ISO 27001 but for AI: you build a management system (an AIMS) with policies, risk assessments, controls, and evidence, and an accredited auditor certifies it.
Any organization that develops AI products, embeds AI features, or uses AI in ways that affect customers. Software companies with AI features, regulated industries deploying AI, and vendors selling into enterprises that ask about AI governance are the earliest adopters.
No, ISO 42001 is voluntary. The EU AI Act is the law, and ISO 42001 is not a harmonized standard, so certification gives no presumption of conformity. It is still a strong way to evidence the governance, risk management, and documentation practices the Act expects. Many organizations pursue both together because the work overlaps heavily.
It depends on your starting point. Organizations with an existing ISO 27001 ISMS typically move fastest because the management-system structure and much of the evidence already exist. On a platform with cross-mapped controls, readiness is usually a matter of months rather than a year.
Total cost includes your readiness work, the platform you run your AIMS on, and the certification body’s audit fees. The biggest cost driver is duplicated effort, which is why running ISO 42001 on the same control library as ISO 27001 matters: evidence collected once satisfies both. Compyl includes all 70+ frameworks, so adding ISO 42001 is not a new line item.
ISO 27001 governs information security; ISO 42001 governs artificial intelligence. They share the same management-system skeleton, which is why they pair so well: ISO 27001 protects the data, ISO 42001 governs what your AI does with it.
Yes. ISO 42001 is one of the 70+ frameworks in Compyl’s cross-mapped control library, with evidence blueprints, AI risk assessment workflows, policy management, and vendor AI oversight on the same platform as the rest of your GRC program.
After the Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on July 27, 2026, obligations for Annex III high-risk systems apply from December 2, 2027. Annex I systems embedded in regulated products follow from August 2, 2028. The original date was August 2, 2026.
No. ISO/IEC 42001 is not a harmonized standard under the AI Act, so certification gives no legal presumption of conformity. It helps evidence the governance, risk and documentation practices the Act expects, but compliance still has to be shown requirement by requirement.
ISO/IEC 42006:2025, published in July 2025, sets requirements for the certification bodies that audit ISO/IEC 42001 AI management systems, including auditor competence and audit time. Choosing an accredited body that works to 42006 makes your certificate more credible.
ISO 42001 Annex A calls for AI system impact assessments. ISO/IEC 42005:2025 is the companion guidance for assessing effects on individuals, groups and society across the AI lifecycle, from design to post-deployment monitoring.
One control library. Your ISMS evidence, working toward your AIMS. See how Compyl gets you to ISO 42001 without starting over.