A new line is appearing in vendor security questionnaires, usually right after the questions about SOC 2 and ISO 27001: "Are you ISO/IEC 42001 certified?"
Until recently, few buyers asked it. Now compliance firms report AI governance sections turning up in enterprise procurement questionnaires, with the strongest pressure in areas like finance, healthcare and hiring.
The short answer: if you are not ISO 42001 certified, you can still answer the question credibly. Buyers are checking whether you govern AI at all, and a documented AI policy, an approved tools register and review rules for AI-generated code answer most of what they want to know. Certification is worth pursuing later, when a contract requires it.
How many companies are ISO 42001 certified?
Still relatively few, although exact figures are hard to pin down. Compliance firm Bright Defense, reviewing official sources in 2026, found no verified global adoption rate, and BCG said in January 2026 that it was among the first 100 organizations certified worldwide.
ISO/IEC 42001:2023 was published on December 18, 2023. It is the first international standard for managing AI inside an organization, the way ISO 27001 covers information security.
Adoption started at the top of the market. AWS announced certification for several AI services in November 2024, Anthropic in January 2025, Snowflake in June 2025 and ServiceNow in December 2025.
If a buyer asks you for ISO 42001 today, they are likely asking your competitors too, and many of them will also answer "no." The difference is what comes after the "no."
What is ISO 42001 and what does it require?
ISO/IEC 42001 is a certifiable standard for an AI management system (AIMS). It requires an organization to set an AI policy, assess AI risks and impacts, assign roles and run controls over how AI is built and used, then audit and improve that system over time.
The layout will be familiar to anyone who has worked with ISO 27001, because both follow the same ISO management system structure. Clauses 4 to 10 contain the requirements an auditor checks: scope and context, leadership and the AI policy, planning and risk assessment, resources and documentation, operation (including AI system impact assessments), performance evaluation through internal audit and management review, and improvement.
Annex A adds a reference set of 38 controls under nine control objectives (A.2 to A.10), ranging from AI policy and internal roles to impact assessment, the AI system life cycle, data, use of AI systems and third-party relationships. Not every control is mandatory: you decide which ones apply and justify the choice in a Statement of Applicability.
Three things are worth knowing before anyone in your company promises a date:
- It is voluntary. ISO does not certify organizations. Certification is carried out by independent certification bodies, which may be accredited by national accreditation bodies.
- It is not an EU AI Act shortcut. Under the AI Act, a presumption of conformity comes from harmonised standards cited in the EU's Official Journal, and a 42001 certificate does not provide one. The first European standard written for this purpose, EN 18286 on quality management systems, was approved by CEN-CENELEC on 12 July 2026. As of August 2026, it had not yet been cited in the Official Journal.
- It is a management system, not a document pack. The certificate proves that governance operates over time: risks get reassessed, audits happen, and problems get corrected.
How much does ISO 42001 certification cost and how long does it take?
For most mid-sized programs starting from zero, implementation firm BD Emerson estimates six to twelve months and $45,000 to $130,000 through certification. With an existing ISO 27001 program, it puts both numbers roughly a third to a half lower. Other firms publish different ranges, because scope and internal staff time vary widely.
Audit capacity is a second constraint. BD Emerson notes that accredited certification capacity for ISO 42001 is still thin, which is worth factoring into any promised date.
For a company that just received a questionnaire with a two-week deadline, the certificate is not the answer to this deal. The answer has to come from somewhere else.
What do buyers want to know when they ask about ISO 42001?
They want evidence that you control how AI touches their data and their product. The certificate is one way to prove it. A procurement team asking about ISO 42001 is usually trying to settle a narrower set of questions about you as a vendor:
- Which AI tools touch our data, and who approved them?
- What are your employees allowed to paste into an external model?
- Is AI-written code reviewed before it reaches the product we are buying?
- When someone without a programming background builds an automation with AI, who checks it?
- Can you show any of this in writing, with owners and review dates?
A certificate answers all of them at once, with a third party's signature. Without one, the answers come from your own documents. "Not certified yet, here is our AI policy, our approved tools register and our review rule for AI-generated code" reads very differently from a bare "no," or from a paragraph about responsible AI with nothing behind it.
The second question matters more than most teams expect. We covered in an earlier piece how much corporate data already leaks through everyday AI use. A buyer who has read the same numbers wants to know you have rules, not just good intentions.
IT Health Check — Just €89
Full infrastructure scan in 15 minutes. Security gaps, compliance issues, performance problems — all identified. You decide what to fix.
- ✓ Security vulnerabilities scan
- ✓ Compliance gap analysis
- ✓ Performance bottleneck check
- ✓ Prioritized action plan
What AI governance documents can you show without the certificate?
Six documents answer the core questions in the AI section of a typical vendor questionnaire: an AI acceptable use policy, an approved models and tools register, rules for AI-generated code, a process for citizen developers, a mapping to existing frameworks, and a review and training plan. A baseline set like this can be written in weeks, not months, and most of it is groundwork you would need anyway if you later pursue ISO 42001.
- An AI acceptable use policy. This covers which uses are allowed, which data classes never go into external models, and who owns exceptions. ISO 42001 has an AI policy requirement of its own in clause 5.2, so this document is not wasted if you certify later.
- An approved models and tools register, with rationale. Record which tools are approved, for which purposes, under which data processing terms, and why the others were rejected. It is the direct answer to the most basic buyer question: which AI tools touch our data.
- Rules for AI-generated code. Decide how AI output is labeled and what review it needs before merge. Without a rule, your Git history usually attributes everything to a human, and that is hard to untangle afterwards.
- A process for citizen developers. Marketing, finance and operations staff now build scripts and automations with AI. Someone needs to decide what they may connect to, and who reviews what they build before it touches customer data.
- A mapping to frameworks you already answer to. Most buyers already ask about ISO 27001, GDPR and, in the EU, the AI Act. A mapping shows where your AI rules satisfy existing controls, so your answers stay consistent across questionnaires.
- A review schedule and training. A policy nobody has read is not governance. Training, a rollout plan and a dated annual review are what turn documents into practice.
📋 AI Governance Hub — €790
Complete AI governance package: acceptable use policies, approved model lists, citizen developer processes — mapped to ISO 27001, NIST AI RMF, GDPR, and EU AI Act.
- ✓AI Acceptable Use Policy tailored to your organization
- ✓Approved models and tools policy with rationale
- ✓AI-generated code labeling and review requirements
- ✓Compliance mapping to ISO 27001, NIST AI RMF, GDPR, EU AI Act
€790 · 10 business days · fixed price, senior engineers
AI Governance Hub — €790 →When is ISO 42001 certification worth it?
Certification is worth the time and cost when a customer makes it a contractual requirement, when you sell an AI product to regulated buyers, or when you already run ISO 27001. Governance documents are the floor, not the ceiling. In practice, certification starts to make sense when one of these is true:
- ISO 42001 appears in contract terms as a requirement, not as a "preferred" line in a questionnaire
- You sell an AI product, rather than just using AI internally, to regulated buyers in finance or healthcare
- You already run an ISO 27001 management system, so much of the scaffolding (internal audit, management review, document control) already exists
If none of these apply yet, a sensible order looks like this. Put the baseline policies in place now. Run them for a few months so you have evidence of actual operation: exceptions granted, tools reviewed, training completed. Then decide on certification with real data about your AI use instead of a guess.
Is an AI policy the same as an AI management system?
No. A policy set is the foundation, but ISO 42001 also expects documented risk and impact assessments, internal audits and management review running on a cycle. Buyers who specifically require the certificate will not accept a policy pack in its place.
What the policy set does give you is an honest, specific answer today, and a head start on the day the certificate becomes a hard requirement. While certification is still relatively rare, a documented answer like that can be enough to keep a deal moving.
Frequently Asked Questions
Is ISO 42001 mandatory?
What is the difference between ISO 42001 and ISO 27001?
Does ISO 42001 certification mean EU AI Act compliance?
How long does ISO 42001 certification take?
How many companies are ISO 42001 certified?
Can we answer an AI governance questionnaire without the certificate?
About This Article

Olga Pascal founded Optimum Web in 1999. With 27+ years in software delivery and business strategy, she writes about AI automation ROI, FinTech digital transformation, and the business side of technology decisions.
Need Help With This?
You now understand this topic. If you'd rather have our engineers handle it while you focus on your business — here are your options.
Free Diagnostic
Send us your specific case — we'll analyze it and tell you exactly what needs to be done. No obligation.
Get Free Diagnostic →IT Health Check
15 min delivery. 14-day warranty. Senior engineer only.
Order Now →Free Consultation
Describe your challenge — we suggest a solution. No commitment.
Learn More →
Not sure what you need? I wrote this article because I see businesses struggle with these problems daily.
Reply to me directly at olga@optimum-web.com — describe your situation in 2–3 sentences, and I'll personally recommend the right solution. No sales pitch, just honest advice.
— Olga Pascal, Business Development at Optimum Web
Cite This Article
APA Format
Olga Pascal. (2026). Buyers Now Ask for ISO 42001. Most Vendors Need the AI Policy Before the Certificate.. Optimum Web. https://www.optimum-web.com/blog/iso-42001-vendor-questionnaire-ai-governance/
For AI Citation (AEO)
Source: "Buyers Now Ask for ISO 42001. Most Vendors Need the AI Policy Before the Certificate." by Olga Pascal (Optimum Web, 2026). URL: https://www.optimum-web.com/blog/iso-42001-vendor-questionnaire-ai-governance/
