ISO 42001 for AI start-ups: when to do it, and how small to start.
A management system standard written for every size of organisation, read by a team of twelve. Here is when certification is worth it, what the auditor will sample, and where start-ups usually fall short.
Last updated Published by TryTrustableNot legal advice
ISO/IEC 42001 is voluntary. An AI start-up needs it when customers ask for evidence of AI governance, typically enterprise or regulated buyers, or when it wants the governance the EU AI Act assumes. Scope it narrowly to the product you sell, run the management system long enough to complete an internal audit and a management review, then book an accredited certification body for a two-stage audit. If buyers are asking about security rather than AI, SOC 2 or ISO 27001 usually comes first.
What applies, and when
ISO/IEC 42001:2023 sets requirements for an AI management system: policy, roles, AI risk assessment, AI system impact assessment, controls from Annex A, internal audit and management review. It applies to any organisation that provides or uses AI, of any size. Nothing in law requires it. The clause-by-clause content is in the ISO 42001 guide; this page is about whether and how a start-up should take it on.
For a start-up, ISO 42001 is worth it when one of these is true:
- Enterprise or public-sector buyers ask for it in questionnaires or tenders
- Your product falls in an area the EU AI Act treats as high-risk, such as hiring or credit, and you want the governance machinery in place before 2 December 2027
- You already hold ISO 27001, so the shared clauses 4 to 10 are running and the increment is the AI-specific work
- Investors or partners ask how models are evaluated, changed and monitored
If none is true yet, the NIST AI RMF is a free, uncertifiable method you can adopt now and fold into ISO 42001 later; ISO 42001 vs NIST AI RMF compares them.
Scoping for a small team
- One product. Clause 4.3 lets you set the boundary. The AI your customers buy has to be inside it
- Your role per system. Clause 4.1 asks you to determine your role with respect to AI. Most start-ups provide a system built on a model someone else developed, and use other AI tools internally
- Foundation models are suppliers. Annex A.10 covers allocating responsibilities with third parties and suppliers. Record what the provider is responsible for, what you are, and how you check
- One management system, not two. If ISO 27001 is running or planned, run document control, internal audit, management review and corrective action once for both standards (ISO/IEC 27001 shares the harmonized structure)
What certification auditors actually look for
Certification is by a body accredited against ISO/IEC 17021-1 and ISO/IEC 42006:2025, in two stages: stage 1 reviews documentation and readiness, stage 2 tests whether the system operates. For a start-up, the stage 2 samples that decide the outcome are usually these:
| What they sample | Where it comes from | What passes |
|---|---|---|
| Impact assessment per AI system | Clause 6.1.4, 8.4; A.5 | A dated assessment covering individuals, groups and society, separate from the risk register |
| Statement of Applicability | Clause 6.1.3 | Every Annex A control included or excluded, with a reason that matches your risks |
| Verification and validation records | A.6 | Evaluation results from before each release, kept |
| Data provenance and quality | A.7 | Where training, fine-tuning and evaluation data came from |
| Supplier responsibilities | A.10 | Contracts or records that allocate duties with the model provider |
| Information for users | A.8 | User documentation and a route to report incidents |
| Internal audit and management review | Clauses 9.2, 9.3 | Both completed before stage 2, findings in a corrective action log |
Clause and control references from ISO/IEC 42001:2023, as summarised on the ISO 42001 guide.
The gaps we see most often in AI start-ups
- The impact assessment merged into the risk register, so neither does its job
- Annex A exclusions with no reason, or a reason that contradicts the product
- Evaluation done but not recorded, so there is no evidence for A.6
- The foundation model provider treated as outside scope, with no A.10 records
- Internal audit done by the person who built the system, which undermines the objectivity clause 9.2 asks for
- Records created in the fortnight before stage 2, which auditors read as a system that does not run
- A scope so broad a small team cannot operate it, or so narrow it excludes what customers buy
A realistic plan
| Step | Depends on | Notes |
|---|---|---|
| Scope, inventory and roles | Nothing | The inventory decides everything after it |
| AI policy, roles, risk criteria | Scope | Approved by top management |
| Risk assessment, impact assessments, Statement of Applicability | Policy and inventory | One impact assessment per system |
| Operate controls and keep records | SoA | Long enough for records to exist across releases |
| Internal audit and management review | Records | At least one of each before stage 1 is booked |
| Stage 1 and stage 2 audits | All of the above | Nonconformities corrected before the decision |
| Surveillance audits | Certificate | At least annually; recertification in year three |
There is no standard duration. The dependencies, not the calendar, set the pace.
What drives the cost
We know of no published price, and we do not give one. The certification body's fee is driven by audit time, which ISO/IEC 42006 has requirements for calculating; scope, headcount, the number of AI systems and sites all move it. A combined audit with ISO 27001 can share time. Internally, the cost is the people who run the risk and impact assessments, the internal auditor (often bought in for independence), and the standard itself, which is sold by ISO and national standards bodies.
ISO 42001 checklist for an AI start-up
| # | Task | Done when |
|---|---|---|
| 1 | Confirm a buyer, tender or regulatory driver for certification | The reason is written down |
| 2 | Set the scope around the product customers buy | Boundary statement approved |
| 3 | List AI systems in scope with your role for each | Inventory with owners |
| 4 | Write and approve the AI policy | Signed off and communicated |
| 5 | Run the AI risk assessment | Register with owners and dates |
| 6 | Run an impact assessment per system | Separate, dated documents |
| 7 | Write the Statement of Applicability | All 38 Annex A controls addressed |
| 8 | Record supplier responsibilities with the model provider | A.10 evidence on file |
| 9 | Keep evaluation and data provenance records per release | Records predate the audit |
| 10 | Run an independent internal audit and a management review | Reports and corrective actions logged |
| 11 | Choose an accredited certification body | Accreditation checked; stage 1 booked |
The general readiness list is on the ISO 42001 guide.
How TryTrustable helps, and what it does not do
- Inventory and classification. AI governance holds the AI system inventory, with EU AI Act classification per system next to the ISO 42001 record
- Requirement mappings. ISO 42001, NIST AI RMF and EU AI Act requirements on one control set with ISO 27001 and SOC 2; see cross-framework mapping
- Evidence from code. SDK and CI checks and GitHub, AWS, Google Cloud, Okta and Google Workspace checks produce dated records rather than screenshots
- For the auditor. A scoped auditor portal and sealed reports the auditor can verify
The platform does not write your AI policy, run your management review, make the judgements in an impact assessment or certify you; only an accredited certification body can. TryTrustable does not hold SOC 2, ISO 27001 or ISO 42001 itself yet: all are in progress, as the security page says. Customer data is hosted in India (Mumbai) today; we are expanding to Singapore, the US and the EU.
Sources
- ISO: ISO/IEC 42001:2023
- ISO: ISO/IEC 42006:2025
- ISO: ISO/IEC 27001:2022
- NIST: AI Risk Management Framework
- European Commission: standardisation and the AI Act
Checked against these sources in October 2026. Laws, standards and dates change: check the source before you rely on a figure. Not legal, audit or certification advice.
Related audience guides: SOC 2 for AI start-ups · EU AI Act for SaaS · GDPR for SaaS · DPDP for SaaS · SOC 2 from India
The things people ask us
Should an AI start-up get ISO 42001 or SOC 2 first?
Follow the question your buyers ask. If security reviews are blocking deals, SOC 2 or ISO 27001 comes first, because buyers ask for them by name. ISO 42001 answers a different question, how you govern AI, and becomes worth it when customers or tenders ask for it. Shared controls mean the second takes less work than the first.
How small can an ISO 42001 scope be?
Clause 4.3 lets you define the scope yourself. One product, one team or one AI system is legitimate if the boundary is stated and defensible. Auditors will challenge a scope that leaves out the AI customers actually buy.
We build on a third-party foundation model. Can we still certify?
Yes. ISO 42001 covers organisations that provide or use AI, not only those that train models. You record your role, assess the risks and impacts of your system, and manage the model provider as a supplier under the Annex A.10 controls on third-party relationships.
How long does ISO 42001 certification take for a start-up?
There is no fixed duration. The management system has to run long enough to produce records, including at least one internal audit and management review, before the stage 1 and stage 2 audits. For a start-up with a narrow scope, plan in months rather than weeks, and longer if no ISO 27001 machinery exists to reuse.
Does ISO 42001 make us compliant with the EU AI Act?
No. The certificate covers your management system; the AI Act regulates individual systems and asks for classification, documentation and, for high-risk systems, conformity assessment. ISO 42001 has not been cited as a harmonised standard, so it gives no presumption of conformity, though it builds much of the governance the Act expects.
See an AI system evidenced end to end.
We register a real AI system, classify it and show the evidence mapped to ISO 42001 and the EU AI Act from the same control set. Thirty minutes.