ISO/IEC 42001:2023 AIMS - Annex A Controls and the Seven Mandatory Documents
In November 2025, a $4.2B enterprise software vendor with EU operations walked into a Stage 2 ISO/IEC 42001 audit with a confident posture and a 38-control gap-assessment matrix. Six weeks later the audit report came back with eleven major nonconformities and a deferred certification decision. The cause was not the controls: the vendor had policies, an AIMS, a Responsible AI Officer, a quarterly committee. The cause was that the seven mandatory documented elements were scattered across nine SharePoint sites, the AIMS scope statement excluded the customer-facing chatbot the engagement letter explicitly listed, and the internal-audit results sampled showed no operating effectiveness for A.6.1.1 lifecycle controls in the prior quarter. This lesson is the slow walk the program team should have done eighteen months earlier: the 38 Annex A controls in nine areas, the seven mandatory documented elements, Stage 1 / Stage 2 audit mechanics, the four certification bodies most enterprises will engage in 2026 (Schellman, A-LIGN, BSI, KPMG), and the cross-walk to EU AI Act Articles 9, 15, 17, 26, 72 and to NIST AI RMF Govern/Map/Measure/Manage that turns one AIMS into evidence for three regulators.
Why ISO/IEC 42001:2023 Matters in 2026 - Assurance, Customer Demand, and EU AI Act Article 17 Evidence
ISO/IEC 42001:2023 was published December 2023 as the world's first international management-system standard for AI. By May 2026 it has moved from "interesting standard" to the artifact customers, regulators, and procurement officers ask for. Three forces drove the transition.
First, EU AI Act Article 17 contemplates ISO 42001 as QMS evidence for high-risk providers. Article 17 requires Annex III providers to maintain a documented QMS covering compliance strategy, design and development, examination/testing/validation, post-market monitoring, incident reporting, authority communication, record-keeping, resource management, and accountability. An AIMS covers all ten Article 17 sub-areas in one auditable structure. CEN-CENELEC JTC 21's draft Article 40 harmonised-standard guidance is expected to designate ISO 42001 as a presumed-conformity pathway by Q4 2027. Until then it is the de facto Article 17 evidence pack.
Second, customer assurance has made ISO 42001 a procurement-blocker. By May 2026 every Fortune 500 security questionnaire for an AI-powered SaaS vendor asks for ISO 42001 status alongside SOC 2 Type II and ISO 27001. Public-sector procurement in Germany, France, the Netherlands, Ireland, and increasingly U.S. federal after the December 2025 GSA AI marketplace pilot, references ISO 42001 in technical-suitability scoring.
Third, insurers and boards treat ISO 42001 as the benchmark of a defensible AI program. Lloyd's syndicates writing AI liability cover in 2026 cite it in underwriting. The NACD Director's Handbook on AI Oversight (March 2026 update) names ISO 42001 as one of three "external benchmarks the board should ensure the AI program tracks against" alongside NIST AI RMF and the EU AI Act.
ISO 42001 in 2026 sits where ISO 27001 sat in 2012, voluntary on paper, structurally mandatory in practice. The L1 question is which 12 of the 38 Annex A controls the organization can pass today and which 26 require the next 18 months. The L1 artifact is the 12-control gap-assessment matrix.
Standard Structure - Clauses 4-10 and the Annex A 38 Controls in 9 Areas
ISO/IEC 42001:2023 follows the ISO High-Level Structure used for all modern management-system standards: the same shape as ISO 27001, ISO 9001, ISO 14001, ISO 22301. An organization already certified ISO 27001 has ~35-40% of the documentation infrastructure in place. The AI-specific work concentrates in Clause 6.1.4 (AI risk assessment) and Annex A (the 38 AI-specific controls).
The Seven Numbered Clauses
Clause 4 - Context. Internal and external issues, interested parties (regulators, customers, employees, Article 3(32) affected persons), scope of the AIMS, the AIMS itself. Clause 4.3 scope is one of the seven mandatory documents and the single decision that most often makes or breaks a first-time audit.
Clause 5 - Leadership. Top management commitment, AI policy (5.2, mandatory document), roles and responsibilities (5.3, mandatory document).
Clause 6 - Planning. AI risk assessment (6.1.2), AI risk treatment (6.1.3), AI system impact assessment (6.1.4, the AIMS analog of Article 27 FRIA), AI objectives (6.2, mandatory document).
Clause 7 - Support. Resources, competence, awareness, communication, documented information (7.5, drives the seven-mandatory-document list).
Clause 8 - Operation. Operational planning, impact-assessment operationalization, AI system lifecycle. Most day-to-day AIMS work lives in Clause 8 sourced from Annex A controls.
Clause 9 - Performance evaluation. Monitoring, internal audit (9.2, mandatory document via results), management review (9.3). Internal audit is the most underbuilt clause in first-time implementations.
Clause 10 - Improvement. Continual improvement and nonconformity / corrective action. Pairs with Clause 9 findings to drive the corrective-action backlog Stage 2 samples.
Annex A - The 38 AI-Specific Controls in 9 Areas
Annex A is the AI-specific control framework, 38 controls in 9 areas labelled A.2 through A.10 (A.1 is the implementation guidance reference). Each applicable control requires documented applicability, implementation evidence, and any modifications in the Statement of Applicability (SoA, the analog of ISO 27001 SoA). "Not applicable" requires SoA justification. The auditor examines the SoA at Stage 1 and samples evidence for applicable controls at Stage 2.
The nine areas:
- A.2 Policies related to AI, 2 controls.
- A.3 Internal organization, 3 controls.
- A.4 Resources for AI systems: 6 controls (data, tooling, system, human, computing).
- A.5 Assessing impacts of AI systems, 5 controls.
- A.6 AI system lifecycle: 8 controls (objectives, requirements, design, V&V, deployment, operation, monitoring, technical documentation).
- A.7 Data for AI systems, 5 controls.
- A.8 Information for interested parties, 4 controls.
- A.9 Use of AI systems, 3 controls.
- A.10 Third-party and customer relationships, 3 controls.
The 38 controls cluster into two operational halves. A.2 through A.5 (16 controls) is the governance half, easier passing path for organizations with existing ISO 27001 / SOC 2 maturity. A.6 through A.10 (22 controls) is the engineering-and-operations half, where most first-time audits surface nonconformities, because these controls require AI-engineering evidence that did not exist in the ISO 27001 / SOC 2 control families.
The Seven Mandatory Documented Elements - What Auditors Expect at Stage 1
ISO/IEC 42001:2023 designates seven documented elements as mandatory, the documents the auditor requests at Stage 1 and uses as anchoring artifacts for the audit dialogue. The list spans Clauses 4.3, 5.2, 6.2, 6.1.4, 5.3, 4.4 (the AIMS itself), and 9.2 (internal audit results). In auditor-request order:
Document 1 - AIMS Scope Statement (Clause 4.3)
The scope names AI systems, organizational units, geographies, and roles. A common Stage 1 finding is scope-mismatch: engagement letter lists three product lines, scope statement names two, operations evidence references four. Too narrow and the certification has limited customer-assurance value; too broad and the organization commits to evidence it cannot sustain.
A defensible 2026 scope names: in-scope AI systems by system-card ID; EU AI Act actor classification per system (Article 3(3) provider / Article 3(4) deployer / both); risk tier; deployment geographies; organizational units; supporting functions (engineering, data, security, legal, compliance, internal audit); explicit exclusions with justification. Length 3-5 pages.
Document 2 - AI Policy (Clause 5.2)
The AI policy is the top-level statement of organizational intent. Signed by top management, it references AI principles, names objectives and risk appetite, names in-scope frameworks (EU AI Act, NIST AI RMF, ISO 42001, applicable U.S. state laws), references the AIMS scope, and commits to specific practices (impact assessment; Article 50 transparency; Article 14 oversight; Article 73 reporting; Article 4 literacy; A.10 supplier/customer obligations). Length 4-8 pages.
Stage 1 asks "does the policy drive the program?" Stage 2 traces sample evidence, a prior-quarter AI system intake, to verify policy commitments operated. A policy that exists on paper but does not appear in the intake form, the FRIA workflow, or the architecture-review-board log is a finding.
Document 3 - AI Objectives (Clause 6.2)
AI objectives are measurable targets operationalizing the policy. 2026-defensible examples: "Reduce chatbot confabulation rate below 0.5% on quarterly evaluation by Q4 2026"; "Complete FRIA for all Annex III high-risk systems before Dec 2, 2027"; "Achieve ISO 42001 certification by Q3 2026 with no major nonconformities"; "Train 100% of in-scope staff on Article 4 literacy by end-FY26"; "Weekly bias-monitoring on hiring-AI by Q2 2026". The objective document references where measurement evidence lives; the auditor pulls it to verify operating effectiveness.
Document 4 - AI Impact-Assessment Process (Clause 6.1.4)
The impact-assessment process evaluates AI system impacts on individuals, groups, and society: the AIMS analog of Article 27 FRIA, NIST AI RMF Map, and U.S. state impact-assessment requirements (Colorado SB 24-205, NYC LL 144, Texas TRAIGA). The process specifies triggers (new intake; substantial modification under Article 43; new use context; data-source change), content (intended purpose; affected individuals and groups; societal impacts; foreseeable misuse; benefit-and-harm; mitigations; residual risk), conductor and approver, and integration with AI risk treatment.
Best practice: one artifact satisfying Clause 6.1.4, Article 27, and the applicable U.S. state requirement. Write once, cite three times.
Document 5 - Roles, Responsibilities, and Authorities (Clause 5.3)
Names persons and functions: typically Responsible AI Officer (top-management designee), AI Governance Committee chair, AI Risk Officer, AI Privacy Officer, AI Security Officer, AI Internal Audit Lead, engineering function leads, data lead, legal/compliance lead, third-party-risk lead. Specifies the Responsible AI Officer's reporting line to top management (one of the most-scrutinized A.3.2 evidence items), committee charter and cadence, and AIMS RACI.
Stage 1 looks for clear authority, the Responsible AI Officer must have explicit authority to halt a non-compliant deployment, not just to recommend. Stage 2 samples evidence (committee minutes, escalation records, halt decisions) to verify the authority operates.
Document 6 - The AIMS Itself (Clause 4.4)
The integrating artifact referencing all applicable Annex A controls, the Statement of Applicability, AI risk-assessment methodology, risk-treatment plan, operational procedures for Clauses 7-10, supplier-and-third-party obligations, and integration with broader management systems (ISO 27001 ISMS, ISO 9001 QMS, ISO 22301 BCMS). A notified body or external auditor reads this first to understand the organization's claim.
Document 7 - Internal Audit Results (Clause 9.2)
Internal audit must be planned, conducted, and documented before Stage 2, covering all clauses and a representative subset of the 38 controls in operating-effectiveness terms. Best-practice 2026 cycle: one full AIMS audit per year (6-8 weeks) plus quarterly focused audits on highest-risk areas (A.6, A.7, A.8, A.10). Auditors must be qualified and independent.
Annex A Controls Walkthrough - The Nine Areas in Operational Detail
A.2 Policies Related to AI, 2 Controls
A.2.2 AI policy (maps to Clause 5.2 mandatory doc). Evidence: signed AI policy, distribution log, acknowledgment records, annual review record. Board or executive signature, version history, intranet integration expected.
A.2.3 Alignment with other organizational policies. Evidence: cross-references between AI policy and related policies (information security, privacy, ethics, risk, BCM, vendor management), gap analysis vs. ISO 27001 information-security policy. The auditor checks for contradictions and clean delineation.
A.3 Internal Organization, 3 Controls
A.3.2 AI roles and responsibilities (maps to Clause 5.3 mandatory doc). Evidence: RACI matrix, role descriptions, reporting-line documentation, authority statement. Cross-walks to EU AI Act Article 17(1)(k) (designated QMS person) and NIST AI RMF Govern 2.
A.3.3 Reporting of concerns. Evidence: AI-specific reporting channel (often integrated with the ethics hotline with AI intake categories), case-management workflow, anonymous reporting, response-time metrics. The auditor samples reports to verify the workflow operated.
A.4 Resources for AI Systems, 6 Controls
A.4.2 Resource documentation: resource inventory per in-scope system, capacity planning, budget allocation. A.4.3 Data resources: data catalogue, classification, governance integration, training-data inventory; cross-walks to A.7 and Article 10. A.4.4 Tooling resources: tooling inventory (training, evaluation, monitoring, red-team frameworks), version control, security baseline. A.4.5 System and computing resources: infrastructure inventory, capacity records, GPU/TPU allocation, cloud-provider attestations. A.4.6 Human resources: AI-role headcount, AI-literacy training records (cross-walks to Article 4 deployer literacy obligation), competency framework. A.4.6 is one of the most-scrutinized A.4 controls because Article 4 carries operational deadlines.
A.5 Assessing Impacts of AI Systems, 5 Controls
A.5.2 AI system impact assessment process (maps to Clause 6.1.4 mandatory doc). Evidence: documented procedure, triggers, completed assessments, integration with AI risk treatment. Cross-walks to Article 27 FRIA.
A.5.3 Documentation of impact assessments. Evidence: completed records, review-and-approval signatures, version history. The auditor samples completed assessments to verify methodology and defensible conclusions.
A.5.4 Impact on individuals or groups of individuals. Evidence: individual/group analysis, methodology for identifying affected individuals (cross-walks to Article 3(32) "affected persons"), severity/likelihood analysis. Most-scrutinized A.5 control for employment, credit, education, essential services.
A.5.5 Societal impacts. Evidence: societal-impact section, methodology for broader social effects (NIST Map 3 context-related risks), external-stakeholder engagement.
A.5 produces the impact-assessment artifact the auditor traces back into the AI policy and forward into risk treatment. Strong A.5 evidence makes the rest of the audit substantially easier.
A.6 AI System Lifecycle, 8 Controls (The Engineering Core)
A.6 is the largest area in Annex A and the operational heart of the AIMS, the full AI system lifecycle from objective-setting through decommissioning.
A.6.1.1 Objectives for development. Evidence: intended-purpose statement per system, use-case documentation, success criteria. Cross-walks to Article 3(1) intended-purpose definition and NIST Map 1.
A.6.1.2 Responsible design and development. Evidence: secure-development lifecycle for AI (often NIST SSDF + existing SDLC), responsible-AI-by-design checklist, model-card and system-card templates, design-review records.
A.6.1.3 Verification and validation. Evidence: V&V plan, evaluation suite results, accuracy/robustness/bias test results, V&V acceptance criteria, sign-off records. Cross-walks to Article 15 accuracy/robustness/cybersecurity and NIST Measure 2.
A.6.1.4 Deployment. Evidence: deployment plan, pre-deployment review, approval, rollback plan, monitoring activation.
A.6.1.5 Operation and monitoring. Evidence: operational monitoring dashboard, drift detection, performance monitoring, incident detection. Cross-walks to Article 72 post-market monitoring and NIST Measure 3 + Manage 4.
A.6.1.6 Technical documentation. Evidence: model card, system card, data card, Annex IV-aligned documentation. Cross-walks to Article 11 + Annex IV.
A.6.1.7 Event logs. Evidence: logging architecture, retention policy, integrity controls, review procedures. Cross-walks to Article 12 automatic logging.
A.6.2 AI system requirements. Evidence: requirements specification, traceability matrix, review records. Cross-walks to EU AI Act tiering memo and NIST Map 2.
A.6 is the most concentrated source of Stage 2 nonconformities. Most common gap: A.6.1.5 monitoring, deployment stood up but monitoring absent or without documented review cadence. Fix: integrate AI monitoring into existing SRE/observability with explicit AI dashboards and a designated reviewer.
A.7 Data for AI Systems, 5 Controls
A.7.2 Data for development and enhancement. Evidence: training-data inventory, source documentation, licensing, train/validation/test split. Cross-walks to Article 10(1)-(4).
A.7.3 Acquisition of data. Evidence: acquisition procedure, vendor licensing, TDM opt-out compliance records (cross-walks to Article 53(1)(c) GPAI copyright and GPAI Code of Practice copyright chapter), approval records.
A.7.4 Quality of data. Evidence: data-quality framework, metrics (completeness, accuracy, consistency, timeliness, validity, uniqueness), monitoring, remediation backlog. Cross-walks to Article 10(3).
A.7.5 Data provenance. Evidence: data lineage, provenance metadata, ML-BoM / SBOM-AI integration (CycloneDX 1.7 + CDXA). One of the highest-leverage controls for Article 10 and NIST Map 4.
A.7.6 Data preparation. Evidence: preparation procedures, transformation documentation, bias-mitigation steps, preparation logs.
A.8 Information for Interested Parties, 4 Controls
A.8.2 System documentation and information for users. Evidence: user documentation, instructions for use (Article 13), purpose statement, system limitations. The auditor compares what users actually receive against what the standard requires.
A.8.3 External reporting. Evidence: external transparency cadence (model card publication, system card, public AI usage disclosure), regulator-facing reporting (Article 72 post-market, Article 73 serious-incident). Cross-walks to NIST Measure 2.7 and Govern 4.
A.8.4 Communication of incidents. Evidence: incident-communication procedure, classification rubric, templates, regulator-notification workflow. Cross-walks to Article 73 (15-day standard / 2-day for critical-infrastructure widespread / 10-day for serious-and-irreversible disruption of critical-infrastructure).
A.8.5 Information for interested parties. Evidence: stakeholder communication plan, stakeholder map, communication records, feedback intake. Cross-walks to NIST Govern 5 and Article 86 affected-person right.
A.9 Use of AI Systems, 3 Controls
A.9.2 Processes for responsible use. Evidence: responsible-use procedures, deployer-facing guidelines, monitoring of actual vs. intended use, deviation-detection. Cross-walks to Article 26 deployer obligations and Article 14 human oversight.
A.9.3 Objectives for responsible use. Evidence: use-objective per system, alignment with intended purpose, restriction documentation.
A.9.4 Intended use of AI system. Evidence: intended-use documentation (cross-walks to A.6.1.1), use-context analysis, foreseeable-misuse analysis (cross-walks to Article 9(2)(b)).
A.10 Third-Party and Customer Relationships, 3 Controls
A.10 is the supply-chain area and one of the most consequential for organizations with significant third-party AI exposure (almost every organization deploying foundation-model-based applications).
A.10.2 Allocating responsibilities. Evidence: responsibility-allocation matrix per relationship, contract clauses, escalation pathways. Cross-walks to Article 25 value-chain (substantial-modification reassignment and Article 25(4) upstream-provider cooperation).
A.10.3 Suppliers. Evidence: AI-supplier inventory (foundation-model providers, RAG-infrastructure providers, evaluation tools, monitoring tools), due-diligence framework, Annex XI / XII receivable verification for GPAI upstream, supplier-incident workflow. Cross-walks to NIST Govern 6 (AI risks along the value chain).
A.10.4 Customers. Evidence: customer-facing obligation documentation (Article 25(4) cooperation), customer-information procedures, customer-incident coordination, customer-feedback intake. For Article 3(3) providers this is the cooperation-obligation evidence.
A.10 is the most-scrutinized area at Stage 2 for organizations with foundation-model upstream exposure. The auditor pulls the supplier inventory, samples suppliers, asks for due-diligence records, Annex XII receivable verification (for GPAI providers), and substantial-modification change-control (where the supplier shipped a model update). A weak A.10 evidence pack will not certify.
The 12 Controls Closest to Passing Today - The L1 Gap-Assessment Artifact
The L1 deliverable is a 12-control gap-assessment matrix identifying which 12 of the 38 controls the organization is closest to passing, the gap, and remediation backlog. A representative 2026 matrix for an enterprise SaaS vendor with prior ISO 27001 certification:
- A.2.2 AI policy, Gap: board signature and AI-risk-appetite reference. ~6 weeks.
- A.2.3 Policy alignment, Gap: cross-reference table to existing ISO 27001 policies. ~2 weeks.
- A.3.2 Roles and responsibilities, Gap: explicit Responsible AI Officer designation with CEO reporting line and committee charter. ~4 weeks.
- A.3.3 Reporting of concerns, Gap: AI-specific intake category in ethics hotline. ~3 weeks.
- A.4.3 Data resources, Gap: AI-specific training-data inventory keyed to systems. ~8 weeks.
- A.4.4 Tooling resources, Gap: tooling inventory with version control and security baseline. ~6 weeks.
- A.4.6 Human resources, Gap: AI-literacy training records keyed to roles and Article 4 deployer obligation. ~10 weeks.
- A.6.1.6 Technical documentation, Gap: model-card alignment to Annex IV and A.8.2 user-information requirements. ~8 weeks.
- A.6.1.7 Event logs, Gap: AI-specific log content and retention. ~6 weeks.
- A.7.2 Data for development, Gap: training-data documentation keyed to each system. ~10 weeks.
- A.8.4 Communication of incidents, Gap: AI-specific incident classification and Article 73-aligned regulator-notification workflow. ~6 weeks.
- A.10.3 Suppliers, Gap: AI-specific due-diligence questionnaire and Annex XII receivable verification capability. ~12 weeks.
The 12 cover all nine areas. The other 26 - A.5 impact assessment, A.6.1.1-1.5 lifecycle, A.7.3-7.6 data, A.8.2/8.3/8.5 information, A.9 use, A.10.2/10.4, require AI-specific work absent from the ISO 27001 / SOC 2 baseline. Typical 2026 timeline: ~6 months for the 12-control foundation, ~9 months for the next 16, ~3 months of operating-history before Stage 2, total ~18 months.
Stage 1 / Stage 2 Audit Mechanics - Timelines, Sampling, Certification Cycle
ISO/IEC 17021-1 prescribes a two-stage initial audit followed by surveillance audits and recertification. The ISO 42001 mechanics follow the same pattern as ISO 27001 with AI-specific evidence requirements.
Stage 1 - Documentation Review (~2-4 Weeks)
Stage 1 assesses whether AIMS documentation supports Stage 2. The auditor examines all seven mandatory documents, the Statement of Applicability (with justification for all 38 controls), the AI risk-assessment methodology, risk-treatment plan, and supporting documentation. Typically 2-4 weeks elapsed, 3-5 days auditor effort. Output: readiness report with areas of concern and gaps to remediate before Stage 2.
Common Stage 1 findings: scope-statement ambiguity (Document 1 mismatched with engagement letter); missing impact-assessment process (Document 4); internal-audit results missing or covering only Clauses 4-10 without sampling the 38 controls (Document 7); SoA with inadequate "not applicable" justification.
Stage 2 - Operating-Effectiveness Audit (~3-6 Weeks)
Stage 2 evaluates operating effectiveness through sampling across clauses and applicable controls. For a mid-market enterprise with focused scope: 3-6 weeks elapsed, 8-15 days auditor effort.
The auditor pulls in-scope systems and traces AIMS evidence across the lifecycle; samples impact assessments into risk treatment; reviews committee minutes against the charter; samples A.10.3 supplier due-diligence; samples Article 73 incident records; verifies A.6 lifecycle operating effectiveness (V&V, approvals, monitoring); verifies A.7 data evidence (inventory accuracy, quality monitoring, provenance); verifies A.8 information evidence (user docs, model cards, external transparency); verifies internal-audit work papers and corrective-action follow-through; interviews the Responsible AI Officer, committee chair, Risk Officer, engineering leads.
Findings: major nonconformity, minor nonconformity, or opportunity for improvement. Majors require remediation and verification before certification (30-90 day window). Minors require a documented plan, verified at the first surveillance audit.
The 3-Year Certification Cycle and Annual Surveillance
ISO certification runs a 3-year cycle with annual surveillance audits (Years 1-2) verifying continued operating effectiveness. Surveillance is typically 30-50% of Stage 2 effort, focused on highest-risk areas and prior-finding remediation. Year 3 recertification (60-80% of Stage 2 effort) renews for the next cycle.
ISO 42001 surveillance will emphasize controls tracking regulatory developments, A.5 and A.6 as Article 27 FRIA deadlines approach (Dec 2, 2027 for Annex III per Omnibus VII; Aug 2, 2028 for Annex I); A.10 as the GPAI Code of Practice matures; A.8 as Article 50(2) marking enforcement begins (Dec 2, 2026 per Omnibus VII acceleration). GPAI enforcement Aug 2, 2026 unchanged.
The Four Certification Bodies - Schellman, A-LIGN, BSI, KPMG
Four certification firms have established a meaningful ISO 42001 audit practice by May 2026. Each has a different orientation, geography, and pricing profile. Selection criteria: industry alignment, geography, customer-procurement expectations, depth in adjacent assurance services (SOC 2, ISO 27001, ISO 9001).
Schellman
U.S.-headquartered, ANAB-accredited, the largest ISO 42001 practice in tech. Schellman built capability by extending its very large SOC 2 and ISO 27001 practice. Most common selection for U.S. SaaS vendors already on Schellman SOC 2 Type II and ISO 27001 who want to consolidate. Auditors familiar with cloud-architecture controls, translates well to A.4 tooling, A.6 lifecycle, A.10 supplier evidence. Mid-market initial pricing: $80K-$180K Stage 1+2; surveillance 30-40% annually.
A-LIGN
U.S.-headquartered, ANAB-accredited, broad cybersecurity-and-compliance practice spanning SOC 2, ISO 27001, ISO 27701, ISO 22301, PCI, HITRUST, FedRAMP, and ISO 42001. Broader industry coverage than Schellman (healthcare, financial services, government contractors). Most common for organizations with multi-framework programs wanting one firm. Similar pricing range.
BSI
British Standards Institution, U.K.-headquartered, UKAS-accredited, one of the original developers of management-system standards. Largest international footprint of the four, U.K., Germany, France, Netherlands, Ireland, India, Australia. Most common for European HQ or significant EU operations, and where regulator-facing UKAS recognition matters. Auditors align with EU AI Act language, translates well to A.5 and A.6 cross-walks. Comparable pricing with regional variation.
KPMG
Big 4 advisory and audit firm with ISO 42001 certification practice within a broader AI assurance offering. Differentiator: synergy between certification, pre-certification advisory (gap assessment, remediation, internal-audit support), and post-certification AI assurance (board reporting, regulator engagement, M&A AI due diligence). Most common for large multinationals wanting advisory-to-certification-to-assurance under one roof. Upper-end pricing.
2026 selection heuristic: U.S. tech vendor on existing Schellman SOC 2/ISO 27001 - Schellman. Multi-framework U.S. - A-LIGN. EU HQ or significant EU operations, BSI. Multinational advisory-led, KPMG.
AIMS Cross-Walk - One Implementation, Three Frameworks of Evidence
The operational case for ISO 42001 in 2026 is cross-walk efficiency. One AIMS produces evidence satisfying ISO 42001 certification, EU AI Act Article 17 QMS, NIST AI RMF Govern/Map/Measure/Manage, and most U.S. state governance expectations. Independent practitioner reviews estimate ISO 42001 covers ~70% of EU AI Act high-risk documentation expectations: the remaining 30% are EU-Act-specific (Article 47 Declaration of Conformity, Article 71 EU database registration, CE marking, Annex IV section-by-section content) that integrate with AIMS evidence.
Key Control-to-Article-to-NIST Cross-Walks
- A.5.2 / A.5.3 / A.5.4 impact assessment โ Article 27 FRIA โ NIST Map 1, Map 3.
- A.6.1.1 objectives โ Article 3(1) intended-purpose scope โ NIST Map 1.
- A.6.2 requirements โ EU AI Act tiering memo โ NIST Map 2.
- A.6.1.3 V&V โ Article 15 accuracy/robustness/cybersecurity โ NIST Measure 2.
- A.6.1.5 operation and monitoring โ Article 72 post-market monitoring โ NIST Measure 3 + Manage 4.
- A.6.1.6 technical documentation โ Article 11 + Annex IV โ NIST Govern 4.
- A.6.1.7 event logs โ Article 12 automatic logging โ NIST Measure 2.9.
- A.7.2 data for development โ Article 10(1)-(4) โ NIST Map 4.
- A.7.5 data provenance โ Article 10 + Article 53(1)(c) GPAI copyright โ NIST Map 4.
- A.8.2 information for users โ Article 13 instructions for use โ NIST Measure 2.7.
- A.8.3 external reporting โ Article 50 + Article 72 โ NIST Measure 2.7.
- A.8.4 incident communication โ Article 73 serious-incident reporting โ NIST Manage 4.
- A.9.2 responsible use โ Article 26 deployer + Article 14 human oversight โ NIST Govern 4 + Manage 1.
- A.10.2 allocating responsibilities โ Article 25 value chain โ NIST Govern 6.
- A.10.3 suppliers โ Article 25(4) cooperation + Annex XI / XII receivables โ NIST Govern 6 + Map 4.
The cross-walk makes the AIMS a triple-duty artifact: the auditor sees ISO 42001 evidence; the notified body (or internal control under Article 43) sees Article 17 QMS evidence; the board or regulator sees NIST AI RMF maturity. Write once; reference from Annex IV technical file, Article 47 declaration of conformity, Article 73 incident reporting, Article 27 FRIA, AI risk register, board dashboard, customer trust portal.
Adjacent ISO Standards - ISO/IEC 23894 and ISO/IEC 5338
Two adjacent standards inform AIMS implementation. ISO/IEC 23894:2023 - AI risk management provides the methodology operationalizing Clauses 6.1.2 (risk assessment) and 6.1.3 (risk treatment); adopting 23894 satisfies both the AIMS clauses and the Article 9 RMS requirement for high-risk systems. ISO/IEC 5338:2023 - AI system lifecycle processes provides the lifecycle process model operationalizing Annex A.6. Together, 42001 (management system), 23894 (risk methodology), 5338 (lifecycle methodology), form the operating triad for a 2026 AI program.
Common ISO 42001 Implementation Mistakes
Mistake 1 - Treating Stage 2 as a One-Time Deliverable
Certification starts a 3-year cycle with annual surveillance, ongoing operating-effectiveness evidence, and Clause 10 continuous-improvement obligations. Organizations that de-prioritize the AIMS after Stage 2 scramble at Year 1 surveillance when the auditor pulls post-certification evidence. Fix: build operating cadence (quarterly committee, monthly control-evidence reviews, annual internal audit) from Day 1.
Mistake 2 - Wrong AIMS Scope (Too Broad or Too Narrow)
The scope statement is the most consequential governance decision. Too broad, the organization commits to evidence it cannot sustain. Too narrow, certification has limited customer-assurance value. Fix: scope to AI systems with material customer or regulator exposure that can be sustainably evidenced; expand in Year 2/3 surveillance once operating muscle is built.
Mistake 3 - Siloing the AIMS from NIST AI RMF and EU AI Act Work
Implementing ISO 42001 separately from NIST AI RMF or EU AI Act work produces three parallel evidence stacks instead of one. The ~70% cross-walk efficiency is lost. Fix: design AIMS evidence as a multi-framework artifact from inception, with explicit cross-references in each control evidence document to corresponding articles and NIST categories.
Mistake 4 - Weak Management Review (Clause 9.3)
A 15-minute item on a quarterly executive agenda with no documented inputs, outputs, or traceable decisions is a Stage 2 finding. The auditor expects the standard's required inputs (prior-action status; external/internal issue changes; AIMS performance; improvement opportunities; risk-assessment updates; corrective-action status; audit results) and documented decisions on each. Fix: a 60-90 minute dedicated quarterly session with formal agenda, pre-read, and documented decisions.
Mistake 5 - Over-Reliance on Vendor Evidence for A.10 Controls
Organizations with foundation-model upstream exposure are tempted to rely on vendor attestations (ISO 42001 certificate, SOC 2 report, model card) as A.10 evidence. The auditor will not accept upstream attestation as a substitute: the organization must demonstrate its own due-diligence, Annex XII receivable verification, substantial-modification change-control, and supplier-incident workflow. Vendor evidence is an input, not a substitute.
Mistake 6 - Under-Investing in Internal Audit Competence (Clause 9.2)
Stage 2 samples internal-audit work papers and expects competent, independent audit of all clauses and a representative sample of the 38 controls. A common failing: internal audit lacks AI-specific competence, auditors can audit the ISO 27001 ISMS but cannot meaningfully audit A.6 or A.7 without AI knowledge. Fix: upskill internal audit (ISACA AI audit certification, IIA AI audit guidance, vendor training) or augment with an AI-specialist external auditor for AI-specific control areas.
Key Takeaways
- ISO/IEC 42001:2023 is the world's first AI management-system standard (December 2023): by May 2026 structurally mandatory through EU AI Act Article 17 QMS expectation, customer procurement, and board / insurer benchmarking.
- Standard structure: Clauses 4-10 (context, leadership, planning, support, operation, performance evaluation, improvement) plus Annex A with 38 AI-specific controls in 9 areas (A.2-A.10).
- Seven mandatory documented elements: AIMS scope (4.3); AI policy (5.2); AI objectives (6.2); AI impact-assessment process (6.1.4); roles, responsibilities, authorities (5.3); the AIMS itself (4.4); internal-audit results (9.2).
- The 9 Annex A areas: A.2 Policies (2); A.3 Internal organization (3); A.4 Resources (6); A.5 Impact assessment (5); A.6 Lifecycle (8, the engineering core); A.7 Data (5); A.8 Information (4); A.9 Use (3); A.10 Third-party and customer relationships (3).
- Stage 1 / Stage 2 mechanics: Stage 1 documentation review ~2-4 weeks; Stage 2 operating-effectiveness ~3-6 weeks; 3-year cycle with annual surveillance; major nonconformities require 30-90 day remediation before certification.
- Four dominant certification bodies (May 2026): Schellman (U.S. tech, ANAB-accredited, common SOC 2/ISO 27001 consolidation); A-LIGN (broad multi-framework U.S.); BSI (largest international footprint, EU strength, UKAS-accredited); KPMG (Big 4 advisory-to-certification-to-assurance integration).
- ISO 42001 covers ~70% of EU AI Act high-risk documentation expectations. Key cross-walks: A.5 โ Article 27 FRIA + NIST Map 1/3; A.6.1.5 โ Article 72 + NIST Measure 3; A.6.1.6 โ Article 11 + Annex IV + NIST Govern 4; A.7 โ Article 10 + NIST Map 4; A.8 โ Articles 13, 50, 72, 73 + NIST Measure 2.7; A.10 โ Article 25 + NIST Govern 6.
- Adjacent ISO standards form the operating triad: 42001 (management system); 23894:2023 (AI risk methodology, operationalizes Clauses 6.1.2/6.1.3); 5338:2023 (AI lifecycle methodology, operationalizes A.6).
- The L1 artifact is the 12-control gap-assessment matrix, typically A.2.2, A.2.3, A.3.2, A.3.3, A.4.3, A.4.4, A.4.6, A.6.1.6, A.6.1.7, A.7.2, A.8.4, A.10.3 for a mid-market enterprise with prior ISO 27001 / SOC 2 maturity, with an ~18-month remediation backlog to full Stage 2 readiness.
- Six common implementation mistakes: Stage 2 as one-time deliverable; wrong AIMS scope (too broad or too narrow); siloing the AIMS from NIST AI RMF and EU AI Act work; weak management review (9.3); over-reliance on vendor evidence for A.10; under-investing in internal-audit competence (9.2).
Skill.re