Automate ISO 42001 readiness with adaptive compliance
For companies shipping AI features, ISO 42001 has become the first question in enterprise security review. See how growing teams close the gap between using AI and governing it.

ISO 42001: Prove you govern AI deliberately
Unified by design. Built for the AI era.
Iru AI is designed from the ground up to connect a grid of agents behind the scenes—across identity, endpoint, and compliance. Powered by the Iru Context Model, it understands your users, apps, and devices to act safely, intelligently, and in context across your organization.
Iru shows you which AI tools your people are actually using, then keeps the evidence behind your management system current, so your ISO 42001 scope reflects reality, not guesswork.
Implement ISO 42001 controls, don't just document them
ISO 42001 asks you to set the boundaries of your AI management system before anything else. That's harder than it sounds. Most organizations find their people are already using AI tools nobody catalogued, and you can't govern what you can't see.
Automate evidence collection
Automatically pull evidence from collected sources via Iru Compliance Automation, so internal audit and management review draw on current state rather than a snapshot.Maintain your Statement of Applicability
Keep your SoA and risk treatment plan current as controls change via Iru Compliance Automation, with every change logged for your auditors to reviewShare compliance posture externally
Iru Trust Center publishes your AI governance posture and drafts responses to the questionnaires, so the answer arrives before the follow-up call.Inventory what AI tools are installed
Iru Endpoint Management inventories what's installed across your Mac and Windows fleetCapture what AI apps are being used
Iru Workforce Identity shows which AI services your people are actually signing into, and lets you control that access rather than discovering it laterCustomize ISO 42001 controls for your unique business
Most compliance tools turn frameworks into generic checklists. Iru generates controls that are specific to your organization, in plain language, broken down into sub-tasks.
- Iru AI generates tailored controls, based on your company context and audit details
- You can migrate existing controls over from other products, or upload your own custom control set
- Controls become actions the moment they are created, with suggested owners and due dates

Automate your ISO 42001 evidence collection
For connected and activated sources, Iru can discover and attach relevant artifacts to the supported control actions, reducing manual uploads. And because you can manage your devices and identity within Iru, that data is pulled natively.
- Evidence flows in continuously from supported devices, integrations and systems
- Iru AI helps to identify stale, missing or potentially irrelevant evidence for you to review
- You stay better prepared before fieldwork begins, with fewer fire drills before your engagement

Ensure continuous ISO 42001 audit readiness
Iru's Adaptive Compliance capabilities watch for changes in your organization, and automatically suggest updates to your controls and actions.
- Iru AI regularly checks for changes to your sources, artifacts or company profile
- If a change is detected, a control update recommendation is surfaced for you to review, often within 24 hours
- No changes are made without your approval, and every change is logged for your auditors to review

Turn ISO 42001 preparation into an always-on workflow
Iru's AI-powered compliance solution helps IT, security and GRC teams spend less time on manual compliance work and stay audit-ready all year.
Let your team focus on what matters
Iru replaces fragmented tools with one AI-powered platform, so IT & security spend less time chasing tickets and more time improving the business.
Frequently asked
questions
Get answers to commonly asked questions
Who developed and maintains ISO 42001 reporting requirements?
ISO/IEC 42001 is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), and developed by ISO/IEC JTC 1/SC 42 — the joint subcommittee for artificial intelligence.
ISO doesn't certify anyone. Certification is issued by independent certification bodies, which are in turn accredited by national accreditation bodies such as ANAB in the United States and UKAS in the United Kingdom.
What does ISO 42001 evaluate?
Whether you actually run an AI management system, not whether your AI is “good”.
Explained further, ISO 42001 doesn't assess model accuracy, benchmark performance, or certify any individual AI system. It evaluates governance: whether you've defined the scope of your AI activity, assessed the risks and the impacts on affected people, assigned accountability, and built a system that reviews and improves itself.
Do we need ISO 42001 if we only use AI rather than build it?
Often, yes. The standard explicitly covers organizations in three roles: AI Producers (those that produce AI), AI Providers (those that develop or provide it), and AI Subjects (those that use it).
In practice, most companies asked for ISO 42001 by a customer are in the third category. If your teams run AI tools against customer data, your buyer's concern is the same whether you trained the model or subscribed to it.
Do we have to implement all 38 Annex A controls?
No. This is the single most common misconception, and it's inherited from the same misconception about ISO 27001.
Annex A is a reference set. You determine the controls your risk treatment actually needs, then compare that set against Annex A to confirm nothing necessary was inadvertently left out. You document the result — what applies, why, and your justification for anything excluded — in a Statement of Applicability.
How does ISO 42001 relate to ISO 27001?
They're complementary, and neither substitutes for the other.
ISO 27001 governs information security. ISO 42001 governs AI. They share the same harmonized management system structure: leadership, risk assessment, internal audit, management review. This means that if you already run an ISO 27001 management system, the machinery will be familiar and some of it is reusable. What isn't reusable is the substance: AI impact assessment, data governance for AI systems, transparency, and human oversight have no ISO 27001 equivalent.
Most organizations pursuing both run them as one integrated management system. Certification bodies often run combined ISO 27001 + ISO 42001 audits, unlocking savings for your business.
How does ISO 42001 relate to the EU AI Act?
ISO 42001 is not a harmonized standard under the AI Act and does not confer presumption of conformity with it. It's useful supporting evidence of governance maturity, and the two are often discussed together — but they are separate instruments, and anyone telling you certification makes you AI Act compliant is overselling.
What does an ISO 42001 audit look like?
Initial certification runs in two stages, both performed by an accredited certification body.
- Stage 1 reviews your management system on paper — scope, AI risk and impact assessments, Statement of Applicability, and whether you're ready to be audited properly.
- Stage 2 tests whether the system is genuinely operating: evidence sampling, interviews, and a look at whether your documented governance matches what your teams actually do.
What does an ISO 42001 engagement produce?
A certificate issued by the certification body, plus an audit report.
The certificate names your scope — which parts of your organization and which AI activity it covers. As with ISO 27001, a scope covering one product line is not a scope covering your company, and sophisticated buyers read it.
What should our ISO 42001 scope statement cover?
Clause 4.3 requires you to determine the boundaries and applicability of the ISMS, taking account of internal and external issues, interested-party requirements, and the interfaces and dependencies between what you do and what other organisations do on your behalf. The scope has to exist as documented information.
In practice the scope statement names five things:
-
What it protects: the products, services, or business activities the ISMS covers.
-
Which part of the organisation: the legal entity, and whether it's the whole entity or specific divisions, teams, or functions.
-
Where: physical locations. Offices, data centres, and increasingly a statement about remote working.
-
Which systems: the technology boundary. Networks, infrastructure, applications, and which cloud services are inside it.
-
What's excluded, and why: anything carved out needs justification you can defend to an auditor.
By convention the statement also references your Statement of Applicability by version and date, which ties the scope to the specific set of controls you declared applicable at the time.
This matters because the scope statement is printed on the certificate, and it's chosen by you. A certificate covering one product line, one office, or one subsidiary is entirely legitimate — and it isn't a certificate covering your company. Sophisticated buyers read it before they read the badge, which is why it's worth writing a scope you'd be comfortable having quoted back at you rather than the narrowest one you can certify.
ISO 42001 has to account for your role: whether you develop AI, provide it, or use it. This will impact the scope statement, as well as your controls.
How long does the certification process typically take?
No standards body publishes a timeline, so treat any specific number — including this one — as an estimate rather than a fact.
For a first-time certification, plan for six to twelve months from decision to certificate. That's longer than a comparable ISO 27001 engagement, for two reasons specific to this standard.
You can't certify a management system that started last week. Before Stage 2, you need to have actually run the AIMS — completed at least one internal audit and one management review, and accumulated records showing your controls operating over a period. That's a floor on the timeline no amount of implementation speed removes.
Finding an accredited certification body can be the constraint. ISO/IEC 42006 — the standard governing bodies that audit and certify AI management systems — was only published in July 2025. ANAB opened its accreditation program in January 2024 and reports that only a handful of certification bodies are nearing the end of initial accreditation. Booking an accredited auditor is a live scheduling question right now in a way it isn't for older standards.
One accelerator: if you already run an ISO 27001 management system, the machinery transfers. Both use the same harmonized structure, so leadership, risk assessment, internal audit, and management review are familiar processes rather than new ones. What doesn't transfer is the substance — AI impact assessment, data governance for AI systems, transparency, and human oversight have no ISO 27001 equivalent.
What are the potential outcomes of an ISO 42001 engagement?
There's no graded opinion for ISO 42001 the way there is with SOC 2. Findings are recorded as nonconformities.
A major nonconformity (a systemic failure or a missing required element) must be corrected and verified before certification can be granted or maintained. A minor nonconformity is typically handled through a corrective action plan without blocking certification. Auditors may also raise observations, which carry no obligation.
So you can straightforwardly fail to achieve certification, and an existing certificate can be suspended or withdrawn if major nonconformities go unresolved.
How long is an ISO 42001 certification valid for?
An ISO 42001 is valid for three years.
Surveillance audits happen at least annually, and a full recertification audit takes place before the three years expire.
Is ISO 42001 required by law?
No. It's a voluntary international standard and no law requires it.
Where it shows up is commercial: enterprise security reviews and vendor questionnaires increasingly ask what governs your AI, and a certificate answers that faster than a policy document does.
Can Iru certify us, or issue an ISO 42001 certificate?
No compliance software can issue an ISO 42001 certificate. Certification must come from an independent certification body, accredited by a recognized accreditation body — that independence is the entire basis of the certificate's value.
What Iru does is everything up to that point: mapping your AI footprint, generating and maintaining controls, keeping your Statement of Applicability current, and collecting the evidence your auditor will sample. If you would like to work with one of the certification bodies we partner with, please book a demo to explore the compliance solution. Existing customers can reach out to their rep for info about our audit partners.