ISO 42001 / AI

ISO 42001 in 90 Days: The Practical Roadmap for AI Startups

LowerPlane Team••11 min read

TL;DR

  • • ISO 42001 has 38 Annex A controls — not the 100+ number people quote — organized around an AI Management System (AIMS)
  • • If you already have ISO 27001, roughly 60% of your evidence is reusable: risk assessment, change management, supplier controls, access, incident response all carry over
  • • A 90-day plan is realistic for a 15-person AI startup: four weeks on policies and scope, four weeks on control implementation, four weeks on internal audit and evidence
  • • Four core policies (AI Policy, AI Risk Management, Data Governance, AI Impact Assessment) cover roughly 20 of the 38 controls if written well
  • • Stage 1 auditors mostly look for scope clarity, an AI system inventory, and a completed impact assessment — not perfect evidence

Two years ago, ISO 42001 was a curiosity. Today it's appearing in enterprise RFPs alongside SOC 2 and ISO 27001 — especially in healthcare, financial services, and public-sector procurement. If your buyer just checked the "ISO 42001 required" box, you don't need a two-year program. You need a 90-day plan that gets you certifiable.

Who Is Actually Asking for ISO 42001?

A year ago it was mostly EU buyers preparing for the AI Act. Now it's broader:

You don't need to be certified today. You need to be able to answer "yes, we're implementing ISO 42001, here's our roadmap" when the security review team asks. A certification-in-progress letter, plus a documented AI Management System, unblocks most deals.

What ISO 42001 Actually Requires

ISO 42001 is structured like ISO 27001. You establish an AI Management System (AIMS), define its scope, identify AI risks and impacts, implement controls from Annex A, run internal audits, and go through a Stage 1 (documentation) and Stage 2 (implementation) certification audit.

The 38 Annex A controls sit in four groups:

A.2
Policies related to AI
2 controls
A.3
Internal organization
3 controls
A.4
Resources for AI systems
5 controls
A.5
Assessing impacts of AI systems
5 controls
A.6
AI system life cycle
9 controls
A.7
Data for AI systems
4 controls
A.8
Information for interested parties
4 controls
A.9
Use of AI systems
4 controls
A.10
Third-party and customer relationships
2 controls

The Overlap With ISO 27001

If you have ISO 27001, you've already implemented most of A.3 (organization), A.4 (resources), A.6 (life cycle change control), and A.10 (supplier relationships). The genuinely new work is:

The 90-Day Plan

Weeks 1-4: Scope, Policies, and Inventory

Get the paperwork right before you touch controls.

  • • Define the AIMS scope — which products, which teams, which AI systems are in scope. Write it down as a scope statement.
  • • Build the AI system inventory. One row per system: purpose, model, data class, sensitivity, owner, lifecycle stage.
  • • Adopt the four foundational policies: AI Policy (why we do AI and where we won't), AI Risk Management Policy, Data Governance Policy for AI, AI Impact Assessment Procedure.
  • • Name the roles: AI accountable owner (usually CTO), AI ethics reviewer, model owner per system.
  • • Draft the AI Impact Assessment for your one or two highest-impact systems.

Weeks 5-8: Implement the Genuinely New Controls

Everything else you can map from ISO 27001; these are the ones you need to build.

  • • A.5.2 AI Impact Assessment — completed for every in-scope AI system, reviewed by the AI ethics reviewer.
  • • A.6.2.2 Objectives for the AI system — documented objectives per system, including intended purpose, limitations, and out-of-scope use.
  • • A.7 Data controls — data provenance records, quality checks, bias assessment output for training data.
  • • A.8.2 Information for users — user-facing disclosure of AI involvement, mechanism to contest a decision, feedback channel.
  • • A.9.3 Human oversight — documented human-in-the-loop for automated decisions above your defined impact threshold.
  • • A.10 Third-party AI — sub-processor list including model providers, DPAs, and periodic review.

Weeks 9-12: Internal Audit and Stage 1 Prep

Run the AIMS the way an auditor will run it.

  • • Internal audit against the 38 Annex A controls plus the management-system clauses (4-10).
  • • Management review meeting with documented minutes.
  • • Fix Stage 1 findings before the certification body arrives — usually document gaps, not implementation gaps.
  • • Certification body kickoff. Stage 1 audit is documentation-only; Stage 2 comes 4-8 weeks later.

AI-BOM Template

One artifact does double duty across A.4 (resources), A.6 (life cycle), A.7 (data), and A.10 (third parties): the AI Bill of Materials. Keep it as a table with one row per model or major component.

FieldExample
Component IDgpt-4o-2025-08
ProviderOpenAI
PurposeSupport ticket categorization
Data class inCustomer PII (name, email, ticket body)
Data class outCategory label, confidence score
RegionEU (data residency clause active)
ContractEnterprise DPA + zero-retention addendum
Owneralice@company.com (Support Eng lead)
Impact assessmentAIIA-2026-04 (medium impact)

Stage 1 Audit Prep Checklist

□AIMS scope statement signed by leadership
□AI Policy, AI Risk Management Policy, Data Governance Policy, AIIA Procedure — all approved and version-controlled
□AI system inventory / AI-BOM populated for every in-scope system
□AI Impact Assessments completed for high-impact systems
□Statement of Applicability (SoA) with justification for any excluded Annex A control
□Internal audit report and management review minutes
□Sub-processor list including all model providers with signed DPAs
□User-facing AI disclosure copy (in-product text, terms of service, or help doc)
□Named AI accountable owner and AI ethics reviewer

How LowerPlane Accelerates ISO 42001

  • →Pre-built ISO 42001 control library with the 38 Annex A controls, evidence templates, and SoA generator
  • →AI system inventory and AI-BOM as first-class objects — not spreadsheets
  • →AI Impact Assessment workflow with a documented reviewer, sign-off, and version history
  • →Shared controls between ISO 42001, ISO 27001, SOC 2, and NIST AI RMF — evidence submitted once counts for all
  • →Internal audit workflow and Stage 1 readiness report so you know before the auditor knows
Explore ISO 42001 with LowerPlane

Get ISO 42001-Ready in 90 Days

LowerPlane gives AI startups the AI Management System, evidence pack, and internal audit workflow to move from "we'll get to it" to Stage 1 audit in one quarter.

Book a Demo