ISO 42001

4.9
Based on 100+ G2 reviews

Certify your AI governance.
Before your clients ask for it.

ISO 42001 is the internationally recognized standard for AI management systems — the credential that proves your organization governs AI responsibly, with independently audited controls covering the full AI lifecycle. Johanson Group conducts ISO 42001 certification audits for organizations at every stage of AI maturity.

Market leaders choose Johanson Group:

Experienced Practitioners

Our audit team brings decades of combined experience across security and compliance frameworks — seasoned practitioners, not junior staff learning on your engagement.

Platform Experts

Former GRC platform experts on staff. We audit inside your existing tools — no manual exports, no spreadsheets.

Our Staff

Every audit is managed and conducted by experienced, qualified professionals with real operational knowledge of the standards being assessed.

Expert Network

Tap into our trusted ecosystem of MSP and vCISO partners to strengthen your full security posture — not just your audit.

Relevant services

ISO 42001 certification audits — conducted right.

Johanson Group conducts ISO 42001 certification audits across a two-stage process: a documentation review that confirms your AIMS satisfies the standard, followed by a full implementation audit that tests whether your AI governance controls actually operate as designed. Every audit is led by an assessor with specific ISO 42001 expertise — not a generalist applying an ISO 27001 template to an AI context.

What Is ISO 42001

Responsible AI, made auditable.

Published in December 2023, ISO/IEC 42001 is the world's first international standard for Artificial Intelligence Management Systems (AIMS). It specifies requirements for establishing, implementing, maintaining, and continually improving an AIMS — providing organizations with a structured, auditable framework for governing how AI is developed, deployed, and used responsibly.

The standard is designed for any organization that provides or uses AI-based products or services — from technology companies building AI models to enterprises deploying AI in business operations, to public sector organizations using AI in critical decision-making. It applies regardless of size, sector, or geography.

Unlike voluntary AI ethics frameworks, ISO 42001 is a certifiable management system standard — modeled on the same high-level structure as ISO 27001 and ISO 9001. This means your AI governance posture can be independently verified by an accredited certification body and demonstrated to customers, regulators, and partners with a globally recognized certificate.

Additional Services

SOC & ATTESTATION

SOC 2

Audit Timeline: 4-8 weeks*

The standard trust report for technology companies. Demonstrates that your security, availability, and data handling controls meet rigorous AICPA standards.

For: SaaS, cloud, and software companies selling to enterprise buyers

ISO Standards

ISO 27001

The internationally recognized information security management standard. Required by enterprise and government buyers globally — and a strong differentiator in competitive deals.

For: Companies operating globally or selling into regulated international markets

ISO Standards

ISO 27017/18

Security controls tailored specifically to cloud service providers and cloud customers — going beyond ISO 27001 to address cloud-unique risks and responsibilities.

For: Cloud providers, IaaS, PaaS, and SaaS platforms

Customer Success Stories

Cryptocurrency Exchange

Bitkub Exchange Becomes Thailand's First Digital Asset Exchange to Achieve SOC 2 Type II

Thailand's leading digital asset exchange became the country's first to earn SOC 2 Type II — validating security across all five Trust Services Criteria.

6 weeks
Biotech Company

Scisco Genetics Secures Data with SOC 2 Compliance

Seattle-based Scisco Genetics Inc. is a leader in genetic analysis, offering fast and accurate high resolution genotyping of complex immune regions.

4.9
Based on 100+ G2 reviews

Don't just take our word for it.

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

Frequently asked questions

Your answer not here? Feel free to contact us for more information.

ISO/IEC 42001:2023 is the world's first international standard for AI Management Systems — the only certifiable AI governance framework with independent third-party verification. It matters now because AI governance has moved from a voluntary ethics discussion to a business and regulatory imperative. The EU AI Act imposes binding obligations on organizations using AI in the EU; enterprise procurement teams are increasingly requiring evidence of AI governance maturity; and investors are scrutinizing AI risk management as part of ESG assessments. ISO 42001 provides the auditable, internationally recognized proof of responsible AI practice that these stakeholders require.

Any organization that develops or uses AI systems and needs to demonstrate responsible AI governance to external stakeholders. This includes AI technology companies and SaaS vendors whose products use AI; enterprises using AI in high-stakes decisions (HR, lending, healthcare, public services); organizations subject to EU AI Act obligations; companies selling AI-enabled products into regulated industries or international markets; and public sector organizations deploying AI in citizen-facing services. You do not need to be an AI company — any organization deploying AI in its operations can and should consider ISO 42001.

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework for AI risk management — it provides structured guidance but is not certifiable and does not result in independent third-party verification. ISO 42001 is a certifiable management system standard — it produces an independently audited certificate from an accredited certification body that provides verifiable, globally recognized proof of your AI governance posture. Many organizations use NIST AI RMF for internal self-assessment and use ISO 42001 as the certifiable standard that provides external assurance. The two frameworks have significant conceptual overlap and can be pursued complementarily.

No — ISO 42001 can be pursued independently of ISO 27001. The two standards address different domains: ISO 27001 governs information security; ISO 42001 governs AI management specifically. However, if you already have ISO 27001, adding ISO 42001 is significantly more efficient — the standards share the same high-level structure (Annex SL), and management system elements like internal audit, management review, and documentation control can be integrated rather than duplicated. ISO 42001 Annex D provides explicit integration guidance for organizations combining it with other ISO management system standards.

ISO 42001 certification provides substantial support for EU AI Act compliance — but it is not a complete substitute for Act compliance on its own. The EU AI Act imposes specific technical, procedural, and registration obligations that vary by risk tier and go beyond what ISO 42001 covers. However, ISO 42001 controls map directly to many EU AI Act requirements — particularly risk assessment (Clause 8 and Annex A.5), technical documentation (Annex A.11), transparency (Annex A.8), human oversight (Annex A.9), and post-market monitoring (Clause 9). Johanson Group designs AIMS programs that address both ISO 42001 and EU AI Act obligations concurrently, eliminating duplicated effort.

ISO 42001 requires documented information supporting the establishment, implementation, operation, monitoring, and continual improvement of the AI Management System (AIMS). This typically includes policies, risk assessments, statements of applicability, internal audit records, management review records, impact assessments, and risk treatment plans.

No. You do not need to build your own AI models to pursue ISO 42001. The standard applies to organizations that act as an AI producer, AI provider, AI user, or a combination of these roles. Organizations using third-party AI services such as Microsoft Copilot, ChatGPT, Claude, Gemini, or industry-specific AI tools may still benefit from implementing an AI Management System (AIMS) to govern AI-related risks, responsibilities, and oversight.

Certified organizations are responsible for notifying Johanson Group of significant changes that may affect their certified management system or certification scope. Examples include:

Changes to the organization's legal name
Changes to the organization's registered or certified address
Addition or closure of locations within the certification scope
Significant changes to the scope of certification
Mergers, acquisitions, or ownership changes
Significant organizational restructuring
Major changes to products, services, or activities covered by the certification
Significant changes affecting the effectiveness of the management system

Organizations should communicate these changes as soon as possible so that Johanson Group can determine whether additional review activities, audits, or updates to certification records are required.

Organizations must notify Johanson Group whenever significant changes occur that could affect the certified management system or the scope of certification. Examples include changes to the organization's name, addresses, locations, scope, ownership, or key business activities.

Early notification allows Johanson Group to assess the impact of the change and determine whether additional review activities, special audits, or certificate updates are necessary. Delaying notification may affect the organization's ability to maintain accurate certification records.