ISO/IEC 42001 readiness, measured against evidence
ISO/IEC 42001 is the international standard for AI management systems, and the first one you can certify against. Increasingly it is what enterprise procurement asks for by name, well before any regulator does.
The gap between a management system and a binder
ISO/IEC 42001 is built on the same management-system structure as ISO 27001, which means an auditor is looking for something operating, not something written. Annex A sets out AI-specific controls across areas including AI policy, internal organization, resources, impact assessment, the system lifecycle, data, information for interested parties, responsible use, and third-party relationships.
Organizations that treat certification as a documentation exercise reach the audit with a complete set of policies and no way to show any of them ran. That is the finding that sends you back for another cycle.
Certification is becoming a condition of sale
The commercial pressure is arriving faster than the regulatory pressure. Enterprise procurement teams and insurers are adding AI management questions to vendor reviews, and a certificate answers in one line what a questionnaire takes six weeks to argue.
If you sell into regulated buyers, the cost of not being able to answer is not a fine. It is the deal you are quietly dropped from, and you rarely find out that is why.
What you get from a METRIS™ score
You get a gap analysis scored against the Annex A control areas, not a checklist you tick. Each control is rated on what your evidence can actually support, so you know before an auditor tells you.
You get your remediation ordered by what the certification body will look at first, which is usually not the order your internal list is in.
You get a measurement layer that keeps running after the certificate is issued. Surveillance audits ask whether the system still operates. Because the score is continuous, you can answer with a record instead of a rehearsal.
Every engagement is conducted by a practitioner holding ISO/IEC 27701 and ISO/IEC 42001 Lead Auditor certification.
What the standard covers
Annex A control areas in ISO/IEC 42001:2023. Structure summarized for orientation. Work from the standard itself when scoping an audit.
Last reviewed 27 July 2026.
Find out where you actually stand against 42001
A scored gap analysis against the Annex A control areas, with your remediation ordered by what the audit looks at first.
The same evidence maps to more than one framework. Proving a control once should not mean proving it three times.