ISO 42001 in 90 Days: The Practical Roadmap for AI Startups
TL;DR
- • ISO 42001 has 38 Annex A controls — not the 100+ number people quote — organized around an AI Management System (AIMS)
- • If you already have ISO 27001, roughly 60% of your evidence is reusable: risk assessment, change management, supplier controls, access, incident response all carry over
- • A 90-day plan is realistic for a 15-person AI startup: four weeks on policies and scope, four weeks on control implementation, four weeks on internal audit and evidence
- • Four core policies (AI Policy, AI Risk Management, Data Governance, AI Impact Assessment) cover roughly 20 of the 38 controls if written well
- • Stage 1 auditors mostly look for scope clarity, an AI system inventory, and a completed impact assessment — not perfect evidence
Two years ago, ISO 42001 was a curiosity. Today it's appearing in enterprise RFPs alongside SOC 2 and ISO 27001 — especially in healthcare, financial services, and public-sector procurement. If your buyer just checked the "ISO 42001 required" box, you don't need a two-year program. You need a 90-day plan that gets you certifiable.
Who Is Actually Asking for ISO 42001?
A year ago it was mostly EU buyers preparing for the AI Act. Now it's broader:
- • Healthcare buyers who want their AI vendors to have an auditable governance system before touching PHI
- • Financial services procurement teams checking "responsible AI" boxes in vendor risk questionnaires
- • Public sector, especially in the EU, UK, and Canada — where AI Act, DSIT AI Assurance, or federal AI directives cite ISO 42001
- • Fortune 500 companies whose internal AI governance teams need a standard to point at when they evaluate vendors
You don't need to be certified today. You need to be able to answer "yes, we're implementing ISO 42001, here's our roadmap" when the security review team asks. A certification-in-progress letter, plus a documented AI Management System, unblocks most deals.
What ISO 42001 Actually Requires
ISO 42001 is structured like ISO 27001. You establish an AI Management System (AIMS), define its scope, identify AI risks and impacts, implement controls from Annex A, run internal audits, and go through a Stage 1 (documentation) and Stage 2 (implementation) certification audit.
The 38 Annex A controls sit in four groups:
The Overlap With ISO 27001
If you have ISO 27001, you've already implemented most of A.3 (organization), A.4 (resources), A.6 (life cycle change control), and A.10 (supplier relationships). The genuinely new work is:
- →AI system inventory — a register of every AI system, its purpose, data class, and lifecycle stage.
- →AI Impact Assessment (AIIA) — for each AI system, a documented review of impacts on individuals, groups, and society. Sits between a DPIA and a full risk assessment.
- →Data governance for AI — where training and inference data comes from, how it's labeled, how bias is managed, how data quality is tracked.
- →Transparency to affected parties — user-facing disclosure that AI is involved, along with the ability to contest an automated decision.
The 90-Day Plan
Weeks 1-4: Scope, Policies, and Inventory
Get the paperwork right before you touch controls.
- • Define the AIMS scope — which products, which teams, which AI systems are in scope. Write it down as a scope statement.
- • Build the AI system inventory. One row per system: purpose, model, data class, sensitivity, owner, lifecycle stage.
- • Adopt the four foundational policies: AI Policy (why we do AI and where we won't), AI Risk Management Policy, Data Governance Policy for AI, AI Impact Assessment Procedure.
- • Name the roles: AI accountable owner (usually CTO), AI ethics reviewer, model owner per system.
- • Draft the AI Impact Assessment for your one or two highest-impact systems.
Weeks 5-8: Implement the Genuinely New Controls
Everything else you can map from ISO 27001; these are the ones you need to build.
- • A.5.2 AI Impact Assessment — completed for every in-scope AI system, reviewed by the AI ethics reviewer.
- • A.6.2.2 Objectives for the AI system — documented objectives per system, including intended purpose, limitations, and out-of-scope use.
- • A.7 Data controls — data provenance records, quality checks, bias assessment output for training data.
- • A.8.2 Information for users — user-facing disclosure of AI involvement, mechanism to contest a decision, feedback channel.
- • A.9.3 Human oversight — documented human-in-the-loop for automated decisions above your defined impact threshold.
- • A.10 Third-party AI — sub-processor list including model providers, DPAs, and periodic review.
Weeks 9-12: Internal Audit and Stage 1 Prep
Run the AIMS the way an auditor will run it.
- • Internal audit against the 38 Annex A controls plus the management-system clauses (4-10).
- • Management review meeting with documented minutes.
- • Fix Stage 1 findings before the certification body arrives — usually document gaps, not implementation gaps.
- • Certification body kickoff. Stage 1 audit is documentation-only; Stage 2 comes 4-8 weeks later.
AI-BOM Template
One artifact does double duty across A.4 (resources), A.6 (life cycle), A.7 (data), and A.10 (third parties): the AI Bill of Materials. Keep it as a table with one row per model or major component.
| Field | Example |
|---|---|
| Component ID | gpt-4o-2025-08 |
| Provider | OpenAI |
| Purpose | Support ticket categorization |
| Data class in | Customer PII (name, email, ticket body) |
| Data class out | Category label, confidence score |
| Region | EU (data residency clause active) |
| Contract | Enterprise DPA + zero-retention addendum |
| Owner | alice@company.com (Support Eng lead) |
| Impact assessment | AIIA-2026-04 (medium impact) |
Stage 1 Audit Prep Checklist
How LowerPlane Accelerates ISO 42001
- →Pre-built ISO 42001 control library with the 38 Annex A controls, evidence templates, and SoA generator
- →AI system inventory and AI-BOM as first-class objects — not spreadsheets
- →AI Impact Assessment workflow with a documented reviewer, sign-off, and version history
- →Shared controls between ISO 42001, ISO 27001, SOC 2, and NIST AI RMF — evidence submitted once counts for all
- →Internal audit workflow and Stage 1 readiness report so you know before the auditor knows
Get ISO 42001-Ready in 90 Days
LowerPlane gives AI startups the AI Management System, evidence pack, and internal audit workflow to move from "we'll get to it" to Stage 1 audit in one quarter.
Book a Demo