What is the best software for ISO 42001?
Key takeaways
- Four criteria decide which software fits ISO 42001: whether it reuses controls, risks, and evidence from an existing ISO 27001 ISMS, whether it covers AI risk assessment and the AI system impact assessment, whether experts or audit partners support the certification, and where the data is hosted.
- Compliance platforms with their own ISO 42001 offering include Drata, Kertos, Scrut, Sprinto, and Vanta, according to their websites. Modulos comes from AI governance and covers ISO 42001 with a dedicated module.
- Kertos maps the ISO 42001 controls to your policies, builds the AI management system in parallel with ISO 27001 and ISO 27701, and has itself been ISO 42001 certified since January 2026.
- An accredited certification body issues the certificate, not a software vendor. Annex A of ISO/IEC 42001:2023 contains 38 controls in nine areas, and the standard is not a harmonized standard under the EU AI Act.
The best software for ISO 42001 is the one that extends the management system you already run instead of building a second one next to it. For most companies, that means a compliance platform that already carries the ISO 27001 ISMS and adds the AI-specific requirements: an AI inventory, AI risk assessment, impact assessment, and the Annex A controls. Drata, Kertos, Scrut, Sprinto, and Vanta offer this as part of their GRC platforms. If your main need is testing and monitoring models at a technical level, you also need an AI governance platform. In every case, an accredited certification body performs the certification itself.
What types of software are there for ISO 42001?
Two categories come up for ISO 42001, and they are often confused. GRC and compliance platforms run the management system: scope, policies, risks, controls, evidence, and internal audit. AI governance platforms work closer to the model: model cards, bias and fairness testing, technical documentation, and monitoring of models in production. The first category is built for ISO 42001 certification. The second produces evidence a management system can use, but it does not replace one.
| Category | Built for | Fits if you | Examples |
|---|---|---|---|
| GRC and compliance platform with an ISO 42001 module | Management system per clauses 4 to 10, Annex A controls, evidence, audit preparation | already run ISO 27001 or are building it in parallel and need a certificate | Drata, Kertos, Scrut, Sprinto, Vanta |
| AI governance platform | Model inventory, model cards, bias and fairness testing, monitoring of models in production | develop many models of your own and must document technical testing | Credo AI, Holistic AI, Modulos |
Which tool category fits your EU AI Act obligations is a separate question. Our comparison of EU AI Act compliance and AI governance tools answers it.
What does the software handle, what does your team handle, and what does the certification body handle?
The software provides the structure and does the evidence work. Your team makes the decisions the standard assigns to top management and implements the controls. The certification body audits independently and issues the certificate. A certification body may not certify a management system it helped build as a consultant.
| Step | Software | Your team | Certification body |
|---|---|---|---|
| Define scope and role (AI provider, deployer, developer) | Template and documentation | Decision | Reviews in stage 1 |
| AI policy and objectives | Templates, approval workflow, versioning | Content and sign-off by management | Reviews |
| AI inventory | Records AI systems and use cases | Completeness | Samples |
| AI risk assessment and impact assessment | Risk library, assessment workflow, links to controls | Assessment and treatment decision | Reviews method and result |
| Statement of Applicability against Annex A | Pre-mapped controls, gap analysis | Justification for every inclusion and exclusion | Reviews |
| Evidence and monitoring | Collects evidence from connected systems, flags gaps | Implements controls | Tests effectiveness |
| Internal audit and management review | Planning and records | Performs them; management decides | Reviews the results |
| Certification audit and certificate | Audit view of evidence | Answers questions, fixes nonconformities | Audits and issues the certificate |
Certified experts, at the software vendor or external, can take on the gap analysis, the impact assessment preparation, and the internal audit. The certification audit stays with the certification body.
Which providers support ISO 42001 certification?
Six providers describe ISO 42001 support on their own websites, which we read on October 5, 2026. The table lists what each provider states itself, in alphabetical order. Providers whose websites we did not check for ISO 42001, or where we found no product statement, are not listed; that is not a claim that they lack support.
| Provider | What its own website states on ISO 42001 | Strength | Category |
|---|---|---|---|
| Drata | Control library for ISO 42001, AI risks linked directly to controls, owners, and evidence, continuous control monitoring, policies with approval history | Surfaces the related AI risks automatically when a control fails | GRC platform |
| Kertos | Pre-mapped ISO 42001 controls, automated gap analysis, AI risk library aligned with the EU AI Act and ISO/IEC 23894, AI inventory, parallel build with ISO 27001 and ISO 27701, certified experts from onboarding to audit | Platform and expert support from one provider; Kertos is itself ISO 42001 certified | GRC platform with experts |
| Modulos | Automated evidence collection and audit preparation across clauses 4 to 10 and Annex A, AI agents for evidence and control assessment | Deep AI governance focus; cites a CertX product conformity certificate for its own platform | AI governance platform with an ISO 42001 module |
| Scrut | Pre-mapped overlapping controls from ISO 27001, more than 40 predefined templates, support from ISO 42001 specialists | Names the ISO 27001 overlap explicitly as a feature | GRC platform |
| Sprinto | Detects AI tool use in browser extensions, managed devices, integrations, and SSO logins; auditor-reviewed policy templates; a list of audit partners | Finds AI tools nobody reported | GRC platform |
| Vanta | Templates, mapped controls, and AI-specific risk scenarios; define which AI systems and people are in scope; reuse evidence for the EU AI Act and NIST AI RMF; auditors in the platform | Broad mapping to other AI frameworks | GRC platform |
Ask every provider two questions, Kertos included: in which region is your governance data hosted, and what accreditation do the audit partners hold for ISO 42001? Both answers decide whether a European company can use the tool.
What can you reuse from an existing ISO 27001 ISMS?
ISO 42001 and ISO 27001 share the same high-level structure for management system standards, with clauses 4 to 10. That is why the management system processes carry over largely intact: document control, training, internal audit, management review, and corrective action. What is new is the AI-related content of those processes, plus several requirements with no counterpart in ISO 27001, above all the AI system impact assessment. The table shows, per requirement area, what you can reuse.
| ISO 42001 requirement area | Reusable from ISO 27001 | What software takes off your plate | What is new and AI-specific |
|---|---|---|---|
| Clause 4: Context of the organization, scope | Partly: context analysis and interested parties | Templates, link to the existing scope | Your role in relation to AI (provider, deployer, developer) and a separate AIMS scope |
| Clause 5: Leadership, AI policy | Partly: roles, responsibilities, approval process | Approval workflow, versioning | A separate AI policy with principles for developing and using AI |
| Clauses 6.1.2 and 6.1.3: AI risk assessment and treatment | Partly: method, rating scales, risk register | Risk library, links between risks and controls | AI risk sources such as data quality or lack of transparency, a separate Statement of Applicability against Annex A |
| Clause 6.1.4: AI system impact assessment | No | Assessment workflow and documentation | Assess the consequences of an AI system for individuals, groups, and society; ISO 27001 has no equivalent |
| Clause 7: Support (resources, competence, awareness, communication, documented information) | Yes: training and document processes | Training records, document control | AI-related competence as training content |
| Clause 8: Operation | Partly: operational planning and control | Task planning, evidence | Repeat risk assessment, risk treatment, and impact assessment during operation |
| Clauses 9 and 10: Performance evaluation, improvement | Yes: internal audit, management review, corrective action | Audit program, records, action tracking | Extend the audit program and management review to the AIMS |
| Annex A.2 to A.4: Policies, internal organization, resources for AI systems | Partly: policy structure, roles, asset inventory (ISO 27001 Annex A 5.9) | Pre-mapped controls, inventory | Document the resources of an AI system, such as data, tooling, compute, and people |
| Annex A.5: Assessing impacts of AI systems | No | Template, workflow | Entirely new |
| Annex A.6: AI system life cycle | Partly: secure development (ISO 27001 Annex A 8.25 to 8.29) | Evidence from development tools | Requirements, verification, validation, and monitoring across the AI life cycle |
| Annex A.7: Data for AI systems | Partly: classification and protection of information | Data discovery, links to data sources | Provenance, quality, and preparation of training and input data |
| Annex A.8 and A.9: Information for interested parties, use of AI systems | Partly: communication processes from incident management | Documentation, tasks | User information about AI systems and rules for responsible use |
| Annex A.10: Third-party and customer relationships | Partly: supplier management (ISO 27001 Annex A 5.19 to 5.23) | Supplier assessment, contract evidence | Responsibility along the AI supply chain, including toward customers |
"Partly" means the process exists and its content has to be extended to cover AI. You reuse the structure of the management system, not the assessments. A platform that already runs your ISMS can carry controls, roles, and evidence into the AIMS instead of creating them again. One Kertos customer describes the ISMS base this way, in relation to ISO 27001:
"Kertos and its experts help us cover the full range and lifecycle of GDPR and ISO 27001 compliance. It has been substantial support in achieving ISO 27001 certification and, currently, in preparing for the Surveillance Audit."
Verified User in Computer Software, G2
Which requirements are new in ISO 42001?
Compared with ISO 27001, four requirements are new. First, the AI system impact assessment (clause 6.1.4, Annex A.5): it assesses how an AI system can affect individuals, groups, and society, and it is separate from the risk assessment for your own company. Second, a dedicated AI policy (clause 5.2, Annex A.2). Third, the Annex A controls: 38 controls in nine areas from A.2 to A.10, with a focus on data, life cycle, and use of AI systems. Fourth, your company's role: whether you provide, deploy, or develop AI determines which controls apply.
| Area | Topic | Controls |
|---|---|---|
| A.2 | Policies related to AI | 3 |
| A.3 | Internal organization | 2 |
| A.4 | Resources for AI systems | 5 |
| A.5 | Assessing impacts of AI systems | 4 |
| A.6 | AI system life cycle | 9 |
| A.7 | Data for AI systems | 5 |
| A.8 | Information for interested parties | 4 |
| A.9 | Use of AI systems | 3 |
| A.10 | Third-party and customer relationships | 3 |
Annexes B to D are informative: Annex B gives implementation guidance for the controls, Annex C lists potential objectives and risk sources, and Annex D covers use across sectors. ISO/IEC 42001:2023 is the first and current edition, published on December 18, 2023 (ISO, checked October 5, 2026).
Does ISO 42001 help with EU AI Act obligations?
ISO 42001 helps you organize the work, but it does not discharge any EU AI Act obligation and does not create a presumption of conformity. Under Article 40 of Regulation (EU) 2024/1689, that presumption comes only from harmonized standards whose references are published in the Official Journal of the EU. ISO/IEC 42001 is not one of them. The European Commission states that the goals and definitions of ISO/IEC 42001 are not aligned with the quality management system the AI Act requires (Commission FAQ on standardization, as of March 10, 2026).
For AI Act quality management, CEN and CENELEC developed EN 18286 in Joint Technical Committee 21. CEN-CENELEC reports it as published (CEN-CENELEC, July 31, 2026). As of its August 3, 2026 update, the Commission's standardization page did not yet list an Official Journal reference (European Commission).
An AIMS still pays off in practice: the AI inventory, risk assessment, documentation, and supplier management are work you need for the AI Act anyway. Under Regulation (EU) 2026/1744, the high-risk obligations apply from December 2, 2027 for standalone systems under Annex III and from August 2, 2028 for systems embedded in products under Annex I (EUR-Lex, checked October 5, 2026). Whether ISO 42001 certification is mandatory, and which tools fit the AI Act, is covered in our comparison of EU AI Act compliance tools.
How much does ISO 42001 certification cost, and how long does it take?
We found no independent, reliable cost source for ISO 42001. DataGuard states on its own ISO 42001 page that no uniform market prices have formed yet. The only itemized figures come from software vendors and refer to the US market in US dollars. Treat the ranges as orientation and get quotes for the audit from two certification bodies. ISO 27001 figures do not transfer directly, because the impact assessment and Annex A add audit content.
| Item | Figure | Source |
|---|---|---|
| Gap analysis | $3,000 to $10,000+ | Vanta, ISO 42001 cost guide |
| Implementation and internal resources | $10,000 to $40,000+ | Vanta, ISO 42001 cost guide |
| Certification audit | $7,000 to $20,000; surveillance audits $3,500 to $9,000 | Vanta, ISO 42001 cost guide |
| Ongoing maintenance | $3,000 to $10,000 per year | Vanta, ISO 42001 cost guide |
| Duration | 6 to 12 months manually, 3 to 6 months with automation | Vanta, ISO 42001 cost guide |
| Duration | 6 to 9 months with an existing ISO 27001 ISMS, 9 to 15 months without | Modulos, ISO/IEC 42001 guide |
| Time to compliance | Under 6 weeks | Scrut, ISO 42001 page (vendor claim about its own product) |
These ranges are self-reported by vendors that sell ISO 42001 software, as of October 5, 2026. The cost of the Kertos platform depends on your scope; you get a quote after a demo. For the cost structure of ISO 27001 certification, which many companies already know, see our overview of ISO 27001 certification costs.
When is Kertos not the right choice for ISO 42001?
Kertos runs the management system: controls, policies, AI inventory, AI risk assessment, and evidence. The Kertos product pages do not describe technical model testing such as bias and fairness measurement, model cards, or monitoring of model performance in production. If you develop many models of your own and need that technical evidence, an AI governance platform such as Credo AI, Holistic AI, or Modulos is the better choice, possibly alongside a GRC platform.
Customers also name areas where the platform is still developing. One G2 reviewer wrote:
"The software is still evolving and has improved in many areas since we started using it (1.5 years ago). However, there are still some areas with further development potential. For example, the Trust Center functionality was added recently, but it is not yet at the level we would need."
Verified User in Computer Software, G2
If you only need a certificate for a single, clearly scoped AI system and already run your ISMS in another tool, check first whether that tool has an ISO 42001 module. Switching tools rarely pays off in that case.
How does Kertos support ISO 42001 certification?
Kertos maps the ISO 42001 controls to your policies and builds the AI management system on the same foundation as your ISO 27001 ISMS and your ISO 27701 privacy management system. The platform provides pre-mapped ISO 42001 controls and an automated gap analysis with remediation planning. For AI risk assessment, it uses a risk library aligned with the EU AI Act and ISO/IEC 23894, with customizable risk models and a guided assessment workflow. In the AI inventory, you record your AI systems and use cases and link them to data sources and assets. Evidence comes in through more than 100 integrations. Certified Kertos experts support you from onboarding to audit.
Kertos has itself been ISO 42001 certified since January 2026 (Kertos achieves ISO 42001 certification). Across all frameworks, Kertos customers have passed 100% of their audits on the first attempt so far, and G2 users rate Kertos 4.8 out of 5 stars (as of October 5, 2026). For the features in detail, see ISO 42001 with Kertos and AI risk assessment. In a demo, we check against your AI systems and your existing ISMS whether Kertos fits your project.
Frequently asked questions
Who can certify against ISO 42001?
A certification body accredited for ISO/IEC 42001 can certify. ISO/IEC 42006:2025, published in July 2025 as a supplement to ISO/IEC 17021-1, sets the requirements for such bodies (ISO). Some certifiers active in Germany have so far obtained their ISO 42001 accreditation through foreign accreditation bodies: TÜV NORD through UKAS and the Dutch RvA (February 2026), and DQS through the US-based ANAB (March 2026). We found no DAkkS accreditation for ISO 42001 in DAkkS's public announcements up to October 5, 2026. Before you engage a body, ask for its accreditation certificate and check that ISO/IEC 42001 is in its scope. Kertos is not a certification body; it prepares you for the audit.
Is there an ISO 42001 checklist?
ISO does not publish an official checklist. In practice, the Statement of Applicability serves as one: it lists the 38 Annex A controls and records for each whether it applies, why, and how it is implemented. Add the mandatory requirements from clauses 4 to 10, including the AI policy, risk assessment, impact assessment, internal audit, and management review. You can buy the standard itself from ISO or your national standards body. On the Kertos platform, the automated gap analysis shows which of these requirements are still open for you.
Do you need ISO 27001 before implementing ISO 42001?
No. ISO 42001 can be certified on its own and does not require ISO 27001 certification. An existing ISMS shortens the path, because clauses 4 to 10 share the same structure and processes such as internal audit and management review carry over. Modulos cites 6 to 9 months with an existing ISO 27001 ISMS and 9 to 15 months without one. Many companies build both management systems in parallel, which the Kertos platform supports.
As of October 5, 2026. Next content review of this page: November 30, 2026.
Discover our Resources
Find useful whitepapers, videos, and practical tools to help you efficiently achieve your compliance goals.


