Overview
ISO/IEC 42001:2023 is the world’s first international management-system standard written specifically for artificial intelligence. Published in December 2023, it sets out how an organisation should establish, run and keep improving an AI Management System (AIMS) — the governance around how you build, deploy and monitor AI, not the models themselves.
Adoption is real but still small. By the middle of 2026, industry trackers put the number of organisations holding an ISO 42001 certificate worldwide at just over 350, with the count climbing through the year as more accredited bodies build out audit capacity. That is a fraction of the companies building or deploying AI today. In India, Mphasis is reported as the first Indian IT services firm to be certified, audited by TÜV SÜD South Asia under NABCB accreditation; KPMG’s India practice is also reported certified, as part of KPMG International’s wider group certification push. Beyond that, the list of certified Indian companies is short.
That is the honest pitch for certifying now rather than later: this is a differentiation bet, not a compliance deadline. No Indian regulator currently requires ISO 42001, and no major enterprise procurement process treats it as a hard gate the way ISO 27001 already is. What is changing is the question, not the rulebook: enterprise buyers are increasingly asking AI-product vendors and IT-services partners how they govern model risk, data provenance and human oversight, even where no certificate is demanded outright. Being one of the few Indian companies that can point to an accredited certificate, rather than a policy document, is the whole value of moving early.
CapEasy prepares your AI Management System against the ISO/IEC 42001 clauses and gets you ready for a NABCB-accredited certification body’s audit. We do not issue, award or assign the certificate — an accredited certification body does, following its own independent assessment, and that independence is what makes the certificate mean something to a buyer.
Who it’s for
- AI-product companies — SaaS built around a proprietary or fine-tuned model, or an AI feature layered on a foundation model API — whose enterprise buyers are starting to ask governance questions in due diligence
- IT services and consulting firms offering AI or GenAI delivery to enterprise clients, where ISO 42001 signals a mature governance practice alongside an existing ISO 27001 certificate
- Companies already ISO 27001-certified that want to extend their management-system maturity into AI-specific risk: model bias, data provenance, explainability and human oversight
- Founders weighing whether to certify now, for the early-mover position, or wait until buyers demand it — this page is written for that decision, not just the mechanics
- Businesses that deploy third-party AI models in a regulated or high-stakes workflow (credit decisions, hiring, healthcare triage) and want a structured way to demonstrate responsible governance
Eligibility & requirements
- A defined AI Management System scope — which products, models, teams and data flows the AIMS actually covers; a scope that is too broad slows the whole engagement down
- Leadership commitment and an AI policy the organisation actually follows, not a document written for the audit
- An AI risk assessment covering the system’s full lifecycle — data sourcing, training or fine-tuning, deployment, monitoring and retirement — with controls mapped against ISO 42001’s Annex A
- Human oversight mechanisms wherever an AI system’s output affects a person materially, plus a way to demonstrate that oversight actually happens
- Documented processes for data provenance, model performance monitoring and incident response when an AI system behaves unexpectedly
- Internal audit and management review cycles, run before the external audit so nonconformities surface on your own schedule, not the certification body’s
- Use of an NABCB-accredited (or another IAF-MLA-signatory-accredited) certification body — an unaccredited certificate carries no international recognition and will not satisfy a buyer who checks
How CapEasy handles it
- Scoping and gap assessment — define the AIMS boundary and assess current AI governance practice against the ISO/IEC 42001 clauses and Annex A controls
- AI risk assessment — profile each in-scope AI system across its lifecycle and document the risks that matter for that system specifically, not a generic checklist
- Policy and documentation build — AI policy, roles and responsibilities, data governance, human-oversight procedures and the records the standard expects
- Control implementation — put the identified controls into practice: model monitoring, escalation paths, vendor and third-party-model due diligence, incident logging
- Internal audit — a full pass against every clause before anyone external sees the system, so gaps get fixed on your timeline
- Management review — leadership formally reviews the AIMS’s performance and signs off before certification audit
- Stage 1 audit — the certification body reviews your documentation and readiness and flags anything that would stop a Stage 2 audit from succeeding
- Stage 2 audit and certification decision — the certification body audits the AIMS in operation; on a positive outcome, it issues the ISO/IEC 42001 certificate directly, followed by periodic surveillance audits over the certification cycle
Documents you’ll typically need
- An inventory of the AI systems, models and use cases you want in scope, including any third-party or foundation-model APIs you build on
- Existing AI or data-governance policies, model documentation and any risk assessments already done
- Data flow information — where training or inference data comes from, how it is stored, and who can access it
- Details of any human-in-the-loop or oversight mechanisms currently in place for AI-driven decisions
- Your current ISO 27001 documentation, if you hold it — the two management systems share structure and several controls can be reused rather than rebuilt
- Org chart and named owners for AI governance responsibilities, since the audit will ask who is accountable for what
CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.



