All articles

ISO 42001

ISO 42001, Sized for SMBs: The AI Certificate Your Buyers Will Ask For Before the Regulator Does

ISO 42001 is the first certifiable AI management system standard. What's inside, what it costs an SMB, and why buyers will ask before the regulator does.

Sylvio Sorel··5 min read
A team reviewing AI governance documentation together at a desk in a bright modern office.

The AI Omnibus is law. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force three days later, after the Parliament endorsed it on 16 June and the Council on 29 June. The deferral is now official: standalone high-risk obligations under Annex III of the AI Act bite on 2 December 2027 rather than August 2026, and AI embedded in products already covered by EU product-safety law — Annex I — moves to 2 August 2028. Plenty of boards will read that as eighteen months of breathing room. Your customers read it differently. AI questions are already appearing in the security questionnaires enterprise buyers send their suppliers — who governs your AI use, what data feeds it, how you’d know if it failed. The AI Act’s deadline moved. Your customers’ deadlines didn’t. And there is exactly one certifiable way to answer them: ISO/IEC 42001.

ISO 42001 in 60 seconds

Published in December 2023, ISO/IEC 42001 is the first certifiable standard for an Artificial Intelligence Management System — an AIMS. It is to AI governance what ISO 27001 is to information security: not a product certificate, not an audit of your models, but proof that your organisation governs its AI use as a system. Policies, named roles, risk and impact assessment, lifecycle discipline, data controls, supplier oversight — established, operated, and improved on a cycle an external auditor can verify. It applies whether you build AI or merely deploy it; a 60-person firm rolling out an AI assistant is as certifiable as the vendor that built the model. That deployer coverage is precisely why buyers like it.

What’s actually inside

The standard’s requirements live in Clauses 4 to 10, and they follow the same harmonised structure as ISO 27001: context, leadership, planning, support, operation, performance evaluation, improvement. The AI-specific substance sits in Annex A: 38 controls across nine domains — AI policies, internal organisation, resources, impact assessment, system lifecycle, data for AI systems, information for interested parties, responsible use, and third-party relationships. Annex B walks through implementation guidance for every control.

Two features distinguish it from its infosec sibling. The first is the AI system impact assessment: you must assess consequences for the individuals and groups your AI affects — not just risks to your own business. The second is lifecycle accountability: documented requirements from design through retirement, including the AI you buy rather than build.

ISO 42001 at a glance: the management system, the 38 controls, and what certification proves One standard, three layers: a management system in Clauses 4–10, 38 controls in Annex A, and accredited proof your buyers can verify.

Why 2026 is the tipping point

Two things changed this year. First, accredited certification became real. ISO/IEC 42006:2025 — the standard governing the bodies that certify AIMS — was published in 2025, and accreditation bodies such as UKAS, ANAB and DAkkS have since accredited certifiers including BSI, Schellman, DNV and SGS. Before that, an ISO 42001 certificate was only as credible as the logo on it. Now there is a verifiable difference between accredited proof and certificate-mill paper — check for the accreditation mark before you buy an audit.

Second, the certified pool is still tiny. BCG announced itself among the first 100 certified organisations in January 2026; by April, press releases were citing the first 350. Compare that with the roughly 70,000 ISO 27001 certificates worldwide. Microsoft and SAP already hold ISO 42001 for their AI services — and it is their procurement standards that trickle down into the questionnaires you receive. A certified SMB in 2026 is ahead of the curve. In 2028 it will be table stakes.

What it does — and doesn’t — do for the AI Act

Here is the part most vendors won’t tell you: ISO 42001 certification gives you no presumption of conformity with the AI Act. That legal mechanism, under Article 40, runs through European harmonised standards — and the first of them now exists. CEN-CENELEC published EN 18286:2026, Artificial intelligence — Quality management system for EU AI Act regulatory purposes, on 31 July 2026. It builds on ISO 42001 without being ISO 42001, and it is not yet cited in the Official Journal, so the presumption of conformity it will eventually carry does not bite yet. When it does, it will attach to EN 18286 — not to your 42001 certificate. Anyone selling 42001 as “AI Act compliance in a box” is overselling.

What it actually gives you is the operational spine the Act assumes you have. AI literacy under Article 4 and the prohibited-practice bans in Article 5 have applied since February 2025. Transparency duties under Article 50 have applied since 2 August 2026 — the Omnibus did not move them, and they bind deployers, not only providers. Deployer obligations under Article 26 follow in December 2027. Every one of those maps onto AIMS controls you would already be running. Our AI Governance & Security service exists precisely to keep those two tracks — the certificate and the regulation — moving as one programme.

Sized for an SMB

The economics are smaller than the headlines suggest. For an organisation under 100 people with a scoped AI footprint, a realistic all-in envelope — implementation support, certification audit, first surveillance — is €10,000–35,000, with the audit itself typically €7,000–20,000 of that. Timelines run 6–12 months from a standing start.

If you already hold ISO 27001, both numbers drop sharply. The shared clause structure means your ISMS documentation, risk method, internal audit cycle and management review carry over; implementers report 30–50% savings, and 4–6 months becomes a realistic path. An integrated audit against both standards with one certification body is usually the cheapest route of all. And scope is your friend: certify the AI systems your customers touch, not every experiment in the building.

Your first 30 days

You don’t start with a consultant. You start with five moves. Inventory every AI system in use — including the unofficial ones in browsers. Decide the scope that matters commercially: what your customers rely on. Name one accountable owner. Run a gap check against the 38 Annex A controls — most SMBs find a third already covered by existing ISO 27001 controls. Then make the certify-or-align decision with evidence: even an AIMS aligned but not yet certified answers a buyer’s questionnaire better than a blank row. As we argued in our analysis of the AI Omnibus when the deferral was only a political agreement, a delayed regulation is not a delayed risk — it is quiet time to build before the queue forms at the certification bodies.

The SMB path to ISO 42001: the first 30 days The first 30 days: five moves, no consultants required — and a certificate decision you make with evidence, not instinct.

Sylvio Sorel

CISSP, PECB ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor — founder, Cyber-Management.

Take the next step

Talk to a security practitioner, not a salesperson.

Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.