Compliance 13 min read

Customer Vendor Review Asking About ISO 42001? Next Steps

J

September 29, 2026

A customer's security or procurement team sends over the annual vendor questionnaire, and somewhere between the SOC 2 questions and the data retention questions there is a new line: "Is your organization certified to ISO/IEC 42001, or do you have a plan to be?" If that landed in your inbox this week, you are not alone, and you have more room to maneuver than the wording suggests.

I work with companies in exactly this spot. The panic is almost always bigger than the actual ask. In most cases the customer wants evidence that you govern the AI in your product or service, and they are using ISO/IEC 42001:2023 as shorthand for that evidence. What you do in the next 30 days matters more than whether you hold a certificate today.

This guide walks through what the question means, how to answer it honestly, what certification involves, and how to decide whether to pursue it.

What is ISO 42001, and why is a customer asking about it?

ISO/IEC 42001:2023 is the first international management system standard for artificial intelligence. It was published in December 2023 and specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system (AIMS). It is certifiable, which means an accredited third party can audit you against it and issue a certificate.

Customers ask about it for three practical reasons.

  1. They are inheriting your AI risk. If your software, service, or data pipeline uses machine learning or generative AI on their data, an AI failure at your end becomes their incident, their regulatory problem, or their headline.
  2. Regulation is pulling them. Regulation (EU) 2024/1689, the EU AI Act, places obligations on deployers and providers of AI systems, and buyers who fall under it want upstream suppliers who can show structured governance. A management system standard is a convenient way to show it.
  3. Procurement teams need a checkbox. Questionnaires are easier to score when there is a recognized standard to point at. ISO 27001 played this role for information security for years, and ISO 42001 is starting to play it for AI.

The standard follows the same high-level structure as ISO 9001 and ISO 27001, with clauses 4 through 10 covering context, leadership, planning, support, operation, performance evaluation, and improvement. If you already run one of those systems, the skeleton will look familiar.

What is the vendor actually asking for?

Read the exact wording before you react, because the same line can mean four different things.

What the questionnaire says What it usually means What a good response looks like
"Are you ISO 42001 certified?" Do you hold a certificate from an accredited certification body? An honest yes or no, plus a dated roadmap if no
"Do you align with ISO 42001?" Can you show that your practices map to the standard's requirements? A control mapping or gap assessment summary
"Do you have an AI governance program?" Do you have a policy, named owners, and a risk process for AI? AI policy, roles, AI system inventory, risk register
"Do you plan to certify?" Is this a durable vendor relationship worth continuing to invest in? A timeline with a named executive sponsor

Most vendor reviews I see are asking for the second or third item, even when the phrasing sounds like the first. Ask your customer contact directly, which is a perfectly normal thing to do. A short note such as "Are you looking for a certificate, or evidence that we govern AI to the standard's requirements?" often changes the entire conversation.

What should you do in the first 30 days?

Resist the urge to answer "yes, we're working on it" without a plan behind it. That answer gets checked at the next renewal. Here is the sequence I would follow.

Week 1: Find out what you have

Build an inventory of every AI system you develop, deploy, or use as part of your product or service. That includes the obvious machine learning models and also the embedded third-party features: a large language model behind a support chatbot, a scoring algorithm from a vendor, a code assistant your engineers use on customer projects. ISO 42001 Annex A, control A.4, deals with resources for AI systems, and A.10 covers third-party and customer relationships, so suppliers count.

For each system, write down its purpose, its data sources, who is affected by its outputs, and who inside your company owns it. If nobody owns it, that is your first finding.

Week 2: Read the standard against what you do today

Do a rough gap assessment. The clauses that most often expose gaps are these:

  • Clause 5.2, AI policy. Do you have a documented policy that top management has approved and that fits your organization's purpose?
  • Clause 6.1.2, AI risk assessment. Do you have a defined process for identifying and analyzing AI risks, with criteria for what is acceptable?
  • Clause 6.1.4, AI system impact assessment. Do you assess consequences for individuals and groups affected by your AI systems? Most organizations have never done this in a formal way.
  • Clause 6.1.3, AI risk treatment. Do you produce a Statement of Applicability that justifies which Annex A controls you apply and which you exclude?
  • Clause 9.2 and 9.3. Have you audited the system internally and had management review it?

Annex A of the standard lists 38 controls organized under nine control objectives (A.2 through A.10). Annex B provides implementation guidance for them. You do not have to implement all 38, but you must justify every exclusion in your Statement of Applicability. A structured ISO 42001 gap assessment is the fastest way to turn this exercise into something a customer will accept as evidence.

Week 3: Decide what you can honestly claim

There are three honest positions, and each one is defensible when it is documented.

  • "We are certified." Only true once an accredited certification body has issued a certificate against your scope.
  • "We are implementing and have scheduled our audit." True if you have a named sponsor, a budget, and a date.
  • "We align with the standard and are assessing whether certification is warranted." True if you have completed at least a gap assessment.

What you should not claim is "ISO 42001 compliant" as a loose phrase. The standard has no self-declaration path that carries the weight of a certificate, and a customer who later asks for the audit report will find the difference. In my view, an accurate "we are two months into implementation" builds more trust than a vague claim of compliance.

Week 4: Respond in writing

Send the customer a short response that includes your scope, your current status, your target audit window, and the executive who owns the program. Attach your AI policy if you have one. Ask whether their deadline is tied to a contract renewal or a regulatory date, because that will shape everything you do next.

What does ISO 42001 certification involve?

The process mirrors other ISO management system certifications, and it is helpful to see the whole path before you commit.

  1. Define scope and context (clause 4). Which AI systems, business units, and locations are in the AIMS? A narrow, well-chosen scope is a legitimate strategy.
  2. Establish governance (clause 5). Approve the AI policy, assign roles, and confirm top management commitment.
  3. Assess risk and impact (clause 6). Complete AI risk assessments, AI system impact assessments, and the Statement of Applicability.
  4. Implement controls and documentation (clauses 7 and 8). Put the applicable Annex A controls into practice and keep records that prove it.
  5. Run an internal audit and management review (clauses 9.2 and 9.3). Both must happen before your certification audit.
  6. Undergo a two-stage certification audit. Stage 1 reviews documentation and readiness. Stage 2 tests whether the system operates in practice.
  7. Maintain the certificate. Certificates run on a three-year cycle with surveillance audits in between, following the usual conformity assessment practice under ISO/IEC 17021-1.

Certification bodies that audit AI management systems are expected to meet the requirements in ISO/IEC 42006:2025, which sets competence and process requirements for those bodies. When you choose a certification body, ask whether it is accredited for ISO/IEC 42001 in your industry sector, because a certificate from an unaccredited body may not satisfy the customer who asked.

How long does ISO 42001 certification take?

There is no fixed number in the standard, so any figure I give is a judgment based on how organizations typically progress. The variables matter more than the average.

Situation Typical shape of the effort
Already ISO 27001 certified, small AI footprint, narrow scope Shortest path, often a matter of a few months, because much of the management system already exists
ISO 9001 certified, moderate AI use Moderate, because the quality system covers documentation and audits but AI-specific risk work is new
No existing management system, AI is core to the product Longest, commonly the better part of a year, because you are building governance from scratch
Multiple AI products, several business units Longest, unless you phase the scope

The work that takes time is rarely the documentation. It is the impact assessments, the data governance decisions, and getting engineering, legal, and product to agree on who owns what. If your customer has given you a date, work backward from it and phase your scope so the systems they care about are covered first.

What does ISO 42001 cost?

Cost has four parts, and only some of them show up on a quote.

  • Certification body fees. These cover the Stage 1 and Stage 2 audits and annual surveillance. They scale with the number of employees, sites, and the complexity of your scope, and each body publishes its own schedule.
  • Consulting or gap assessment support, if you use it.
  • Tooling, which can range from a spreadsheet-based risk register to a governance platform.
  • Internal time. This is the largest cost and the one most often left out. Engineers, product managers, legal, and an executive sponsor all spend hours on it.

I would not trust any article that quotes a single price for certification without asking about your scope, because it cannot be accurate. Get quotes from at least two accredited certification bodies once your scope is defined, and compare them against the revenue that depends on the customer relationship in question. Sometimes that math makes the decision obvious in either direction.

How does ISO 42001 relate to ISO 27001?

If you already hold ISO 27001, you have a real head start, and it is worth knowing where the overlap ends.

Both standards use the same harmonized clause structure, so the management system mechanics (document control, internal audit, management review, corrective action, continual improvement) carry over directly. Your ISO 27001 risk process can be extended to cover AI risk, and your supplier management can be extended to cover AI vendors.

What ISO 27001 does not give you is the AI-specific content. It does not ask you to assess impact on affected individuals, address bias or fairness, define the intended use of an AI system, manage the AI system lifecycle, or govern training and test data quality. Those live in ISO 42001 clause 6.1.4 and Annex A. Many organizations pursue an integrated audit so the two certifications share internal audits and management review, which can reduce the burden. If your ISO 27001 program is healthy, the ISO 27001 certification work you have already done is the foundation, and the AI layer goes on top of it.

ISO 42001 vs. NIST AI RMF: which one does the customer want?

Customers sometimes ask for one and would accept the other. The two are built for different jobs.

Feature ISO/IEC 42001:2023 NIST AI RMF 1.0 (NIST AI 100-1)
Type Certifiable management system standard Voluntary risk management framework
Published December 2023 January 2023
Structure Clauses 4 to 10 plus Annex A controls Four functions: Govern, Map, Measure, Manage
Third-party certificate Yes, through accredited certification bodies No certification scheme
Typical use Proving governance to customers and regulators Organizing internal risk practices
Origin International (ISO/IEC) United States (NIST)

The practical point is that only ISO 42001 gives you a certificate a customer can file. NIST AI RMF, along with its Generative AI Profile (NIST AI 600-1, published July 2024), is a strong source of practices, and many organizations use it to inform how they run the risk work that ISO 42001 requires. If your customer is a U.S. federal contractor or a company that has built its program on NIST, telling them you have mapped your AIMS to the AI RMF functions is often a helpful addition and not a substitute.

Should you certify or just show alignment?

I think the decision comes down to a few honest questions.

  • Is the customer's requirement tied to a contract clause or renewal date? If yes, the deadline decides for you.
  • Do other customers ask the same thing? One request is a data point. Three requests in a quarter is a market signal, and certification starts to look like a sales asset and not a cost.
  • Is AI central to what you sell? If it is, governance is part of the product, and a certificate supports your pricing and your sales cycle.
  • Are you subject to regulation that expects a structured AI governance approach? Then the work has value whether or not anyone asks for the certificate.

If the answers are mostly no, a gap assessment and a documented alignment statement may be enough for now, and you can revisit certification in a year. There is nothing wrong with that call, provided you say exactly what you have done and no more.

Common mistakes when responding to an ISO 42001 vendor question

  • Claiming compliance without evidence. A customer who asks for the Statement of Applicability or the internal audit record will see the gap immediately.
  • Scoping too broadly. Trying to certify every AI use in the company at once slows everything. Start with the systems the customer depends on.
  • Ignoring third-party AI. If your product calls an external model provider, your supplier controls (Annex A, A.10) need to address it.
  • Treating it as an IT project. The standard requires top management involvement under clause 5.1. A program owned only by the security team tends to stall.
  • Skipping the impact assessment. It is the requirement that organizations find least familiar and that auditors look at closely.

Where to start

If you have a questionnaire on your desk and a deadline attached to it, the first move is small: build the AI inventory, run a quick gap check against clauses 4 through 10, and write a status statement you can defend. From there, the certification decision becomes a business question with real numbers behind it.

If you would like a second set of eyes on the response, or a scoped estimate of the path to certification, you can talk with an ISO 42001 consultant at Certify Consulting. I am happy to look at the exact wording your customer used and tell you what I think they are really asking.

Last updated: 2026-09-29

Frequently Asked Questions

What should I say when a customer asks if we are ISO 42001 certified and we are not?

Say so plainly, then give your status: gap assessment complete, implementation underway, or audit scheduled, with a target date and a named executive owner. Avoid the phrase 'ISO 42001 compliant,' because only an accredited certification body can issue a certificate, and customers may ask for the audit report.

Is ISO 42001 certification mandatory?

No. ISO/IEC 42001:2023 is a voluntary standard. It becomes effectively required only when a customer contract or procurement policy demands it, though it can also support compliance work under laws such as Regulation (EU) 2024/1689, the EU AI Act.

How is ISO 42001 different from ISO 27001?

Both share the same high-level management system structure, so processes like internal audit and management review carry over. ISO 27001 addresses information security. ISO 42001 adds AI-specific requirements, including AI risk assessment (clause 6.1.2), AI system impact assessment (clause 6.1.4), and the Annex A controls on AI system lifecycle and data.

Can NIST AI RMF replace ISO 42001 for a vendor review?

Usually not. NIST AI RMF 1.0 is a voluntary framework with no certification scheme, while ISO 42001 can be audited and certified by an accredited body. Mapping your program to the AI RMF is a useful supplement, but it does not give the customer a certificate.

How long does ISO 42001 certification take?

The standard sets no fixed duration. Organizations with an existing ISO 27001 or ISO 9001 system and a narrow scope generally move faster than those building governance from scratch. The slowest parts are usually impact assessments and agreeing on ownership across engineering, legal, and product.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.