45 Ivan Allen Jr Blvd NW
Atlanta, GA 30308
+1 (888) 808-7330
General: [email protected]
Sales: [email protected]
Support: [email protected]
On 2 August 2026, the EU AI Act's transparency obligations took effect. Four days later, most of the security leaders reading this are in the same position they were in a month ago: holding a customer questionnaire that asks whether their organization is ISO/IEC 42001 certified, with no clear sense of what answering "yes" would actually require — or prove.
That question has become one of the fastest-moving items in enterprise procurement. It is also one of the most poorly understood, because it collapses two different standards, two different purposes, and two different kinds of evidence into a single yes/no box.
This piece separates them.
ISO/IEC 23894:2023, published in February 2023 by ISO/IEC JTC 1/SC 42, is Information technology — Artificial intelligence — Guidance on risk management. It is 26 pages of guidance. There is no certification path, no auditor, no certificate.
Structurally, 23894 is an AI-specific extension of ISO 31000:2018, the general enterprise risk management standard. It inherits ISO 31000's three-layer architecture — principles, framework, process — and populates each layer with AI-specific content. Where ISO 31000 says "identify risk sources," 23894 tells you which risk sources are characteristic of AI systems. Its informative annexes catalog common AI-related organizational objectives and risk sources, and map risk management activities onto an AI system life cycle.
The important consequence: if your team has not internalized ISO 31000, 23894 will read as a list of concerns rather than a method. It is a translation layer, not a standalone document.
ISO/IEC 42001:2023, published in December 2023 by the same committee, is Information technology — Artificial intelligence — Management system. It is the first certifiable international standard for an Artificial Intelligence Management System (AIMS), and it follows the Harmonized Structure (formerly Annex SL) shared by ISO 27001, ISO 9001, and every other modern ISO management system standard.
Clauses 4 through 10 define the management system itself: organizational context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A supplies 38 reference controls across nine control objectives (A.2 to A.10), spanning AI policy, internal organization, resources, impact assessment, the AI system life cycle, data, information for interested parties, responsible use, and third-party and customer relationships. Annex B provides implementation guidance for those controls. Annexes C and D are informative — potential organizational objectives and risk sources, and notes on applying the AIMS across sectors.
So: 23894 is the method. 42001 is the system that runs the method and can be audited. They were designed to operate together, and 42001 directly references 23894.
The buying signal comes from procurement, and procurement asks for certificates. So the typical sequence is: a customer questionnaire arrives, a certification body is engaged, a gap assessment is run, and somewhere in month three, someone asks the question that should have come first — what are our actual AI risks, and how did we decide?
This matters more in 42001 than in most management system standards, because of a structural feature that is widely misread. Annex A is a reference set, not a checklist. Clause 6.1.3 explicitly states that the 38 controls are not exhaustive and that organizations may need to design additional controls or draw on them from other sources. You select controls through a Statement of Applicability, and you justify both inclusions and exclusions in writing, to an auditor.
That justification has to come from somewhere. In a well-built AIMS, it comes from a documented AI risk assessment, which is precisely what 23894 provides the methodology for, and what ISO/IEC 42005:2025 (AI system impact assessment, also guidance, also non-certifiable) provides the impact-assessment methodology for. 42005 includes an annex mapping its process onto 42001 clauses and another explaining its relationship to 23894.
Organizations that skip the risk work and go straight to control implementation end up with a Statement of Applicability that is essentially reverse-engineered from Annex A. It will often pass an audit. It will not survive contact with an incident, a regulator, or a sophisticated customer's technical due diligence — because the controls were never selected against anything.
The most consequential misconception in the current market is that ISO/IEC 42001 certification confers regulatory cover under the EU AI Act. It does not, and the reasons are worth stating precisely.
Under Article 40 of the AI Act, the presumption of conformity attaches only to harmonized standards whose references have been published in the Official Journal of the European Union. As of mid-2026, none of the CEN-CENELEC JTC 21 deliverables had been cited in the OJEU. The most advanced of them, prEN 18286 on AI quality management systems, was at the approval stage.
More pointedly, JTC 21 developed prEN 18286 as a bespoke European standard rather than adopting ISO/IEC 42001 directly, on the grounds that 42001's objectives and definitions were not aligned with the AI Act's quality management requirements. Similar work is underway on risk management (with 23894 as one input alongside a separate European work item), datasets, bias, logging, transparency, and human oversight.
The regulatory calendar has also moved. The Digital Omnibus on AI — Regulation (EU) 2026/1744 — was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It defers high-risk obligations for stand-alone Annex III systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations were not deferred and applied from 2 August 2026, with Article 50(2) reaching legacy systems and a set of new prohibited practices on 2 December 2026.
The honest framing for a security or compliance leader is therefore:
Because certification demand outran audit capacity, a second-order problem emerged: not all ISO 42001 certificates were issued under equivalent scrutiny.
ISO/IEC 42006:2025, published on 7 July 2025, addresses this. It supplements ISO/IEC 17021-1 with additional requirements for bodies performing AIMS audit and certification — competence requirements for certification personnel, audit time calculation, impartiality and liability provisions, and requirements governing certification documents and access to the audited organization's documentation. Before it was published, accreditation bodies were working from the draft.
This gives buyers and vendors a concrete diligence question that is more useful than "Are you certified?":
Which certification body issued the certificate, which accreditation body accredited them, and is that accreditation scoped to ISO/IEC 42001 under ISO/IEC 42006:2025?
Recognized accreditation bodies include ANAB, UKAS, DAkkS, JAS-ANZ, SCC, and others. A certificate from an unaccredited body is not fraudulent, but it carries meaningfully less assurance, and increasingly sophisticated procurement teams have begun to ask questions.
On the adoption scale, treat the numbers with care. There is no official global register — the ISO Survey does not yet report ISO/IEC 42001 — so published counts are compiled from certification bodies' statements and companies' press releases. Industry compilations put the worldwide total at roughly 350 organizations by mid-2026, heavily skewed toward cloud platforms, AI vendors, and IT service providers, with professional services, healthcare, and financial services forming a visible second wave. For scale comparison, the number of ISO 9001 certificates is in the millions. This is still an early market.
Here is where a cybersecurity reading of these standards diverges from a compliance reading.
Neither 23894 nor 42001 is a security standard. 42001 addresses AI-specific governance concerns that ISO 27001 does not cover — bias, transparency, impact assessment, responsible use, and life-cycle accountability. ISO 27001 addresses the confidentiality, integrity, and availability of the systems and data on which AI runs. Both share the Harmonized Structure, which makes an integrated AIMS/ISMS genuinely economical: one risk assessment cadence, one internal audit program, one management review, one documentation control regime.
What sits between them — the adversarial layer — is largely not covered by either.
ISO/IEC 27090, Cybersecurity — Artificial intelligence — Guidance for addressing security threats and failures in artificial intelligence systems, is the document intended to fill that space. It reached the FDIS stage in March 2026, with publication anticipated in the second half of 2026. It is guidance, not a requirements standard, and carries no certification path. Its substance is a threat taxonomy across the AI system life cycle — data poisoning, evasion, model extraction, membership inference, and prompt injection — with mitigations mapped against the ISO 27000 family.
Until it publishes, organizations building an AIMS rely on 42001's supplier and life cycle controls, plus external frameworks such as the OWASP AI Exchange and NIST AI 100-2 to address adversarial risk. That is a workable position, but it should be a deliberate one, documented in the risk assessment, rather than an unnoticed gap.
The related point —and the one most often missed —is that Annex A.10—third-party and customer relationships—is where the AI supply chain lives. Model providers, fine-tuning vendors, inference APIs, and embedded AI features inside the SaaS you already bought. For most organizations, the majority of AI risk is not in the models they built. It is in models they procured, often without a procurement event.
Vendor-neutral, and roughly in order:
Expect three to nine months from a standing start for organizations with existing ISO 27001 maturity, followed by a two-stage initial audit and a three-year cycle with annual surveillance.
ISO/IEC 42001 is a real standard that produces real governance improvements, and it is currently the most credible signal available in an AI procurement conversation. It is also, in a non-trivial number of cases, being bought as a logo rather than built as a system, with a Statement of Applicability assembled backward from Annex A and a risk assessment that exists to satisfy the audit rather than to inform the controls.
The distinction between those two outcomes is not visible on the certificate. It is visible in the risk assessment underneath it, which is why ISO/IEC 23894 — the non-certifiable, unglamorous, 26-page guidance document nobody puts in a press release — is the one that determines whether the certificate means anything.
Why Organizations Choose Zaxtron
Organizations face increasingly sophisticated ransomware campaigns that exploit unpatched systems, stolen credentials, exposed remote access, and third-party weaknesses. To stay protected, they need actionable intelligence, not just alerts, to identify and reduce cyber risks before disruption occurs. Zaxtron provides Cybersecurity Risk Management, AI Risk Management, and Cyber Threat Intelligence services that deliver continuous visibility and risk-based insights. By combining attack surface intelligence, vulnerability data, threat and breach intelligence, and third-party risk analysis, Zaxtron offers a complete view of cyber exposure. This helps security leaders respond to threats, improve vendor security, and make informed decisions. Contact Zaxtron to strengthen cyber resilience today.
Cookie preferences