AI Compliance Vendors
Voluntary standardVoluntary standardGlobal

ISO/IEC 42001:2023 AI Management System

ISO/IEC 42001:2023 is the first international management-system standard for artificial intelligence, published in December 2023 jointly by ISO and IEC. It specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system (AIMS) within an organisation. The standard follows the harmonised high-level structure used by ISO 27001 and ISO 9001, making integration with existing management systems straightforward. ISO 42001 is voluntary but is the most credible signal a vendor or operator can provide that AI risk is governed at the management-system level. Certification is granted by accredited third-party certification bodies (the ISO/IEC body itself does not issue certificates) and follows a typical 3-year cycle with annual surveillance audits.

Jurisdiction

Global

Enforcement

December 18, 2023

Maximum penalty

Certification standard; no statutory penalties

Key obligations

  • 01Define the scope of the AI management system, including the AI systems, organisational units, and lifecycle stages it covers.
  • 02Establish an AI policy, objectives, and roles & responsibilities approved by top management.
  • 03Conduct AI risk assessments and AI impact assessments addressing fairness, transparency, safety, security, privacy, accountability, and societal impact.
  • 04Implement Annex A controls (organisational, lifecycle, data, system, third-party, customer/end-user, and use-case controls) selected via a Statement of Applicability.
  • 05Maintain documented information for AI system lifecycle (data, design, verification, deployment, operation, retirement) sufficient for an external auditor.
  • 06Operate continual-improvement processes: internal audits, management review, corrective actions, and incident handling for AI-related events.
  • 07For certification: pass a Stage 1 (documentation) and Stage 2 (implementation) audit by an accredited certification body, then complete annual surveillance audits.

Vendors that support ISO/IEC 42001

Sorted by coverage level. Full coverage shown first.

24 vendors

VendorHQFoundedSizePricingCoverageLast verified
LatticeFlow AIZurich, Switzerland202011-50No public pricing. Enterprise platform sold via direct sales. Contact sales for demo and pricing.FullApr 22, 2026
Prompt SecurityTel Aviv, Israel202311-50Now part of SentinelOne Singularity Platform. Continues as a standalone product. Enterprise pricing only; contact sales or SentinelOne.FullApr 22, 2026
EnzaiBelfast, United Kingdom20212-10SaaS platform, enterprise subscription. No public pricing listed. Contact sales via enz.ai.FullApr 22, 2026
Fairly AIKitchener, Canada202011-50On-premises or private-cloud deployments; quote-based.FullApr 21, 2026
Collibra AI GovernanceNew York, United States20081000+Enterprise subscription; contact sales for custom quote based on users, assets, modules.FullApr 23, 2026
TrustibleArlington, United States202311-50Contact sales for enterprise pricing; no public plans listedFullApr 23, 2026
ModelOpChicago, United States201811-50No public pricing listed; contact sales for enterprise quotes.FullApr 23, 2026
Modulos AI GovernanceZurich, Switzerland201811-50Contact for pricingComprehensiveApr 24, 2026
Scrut AutomationPalo Alto, US202151-200Contact for pricingComprehensiveApr 24, 2026
BABL AIIowa City, US201811-50Contact for pricingComprehensiveApr 24, 2026
DrataSan Francisco, US2020501-1000Contact for pricingComprehensiveApr 24, 2026
NaaiaLouveciennes, FR202111-50No public pricing tiers; demo and quote requested via website.ComprehensiveApr 27, 2026
SaidotHelsinki, Finland201811-50No public pricing listed; contact sales implied via demos and sign-ups.PartialApr 23, 2026
HiddenLayerAustin, United States202251-200Enterprise-only, contact sales for pricing. No public pricing listed on website.PartialApr 22, 2026
OneTrust AI GovernanceAtlanta, United States20161000+Enterprise platform; contact sales for quote, no public pricing listedPartialApr 23, 2026
VantaSan Francisco, USA2018500-1000Contact for pricingPartialApr 26, 2026
IBM watsonx.governanceArmonk, USA1000+Contact for pricingPartialApr 26, 2026
Credo AIPalo Alto, US202051-200Contact sales for enterprise subscription quote. Credo AI homepagePartialApr 26, 2026
Holistic AILondon, UK202051-200Enterprise platform; contact sales for quote.PartialApr 26, 2026
FairNowMcLean, US202311-50Contact sales for quote; no public pricing listedPartialApr 26, 2026
Lasso SecurityTel Aviv, IL202311-50Enterprise pricing only. Not publicly listed.PartialApr 27, 2026
CraniumShort Hills, US202351-200Contact for pricingPartialApr 27, 2026
CitrusˣTel Aviv, IL202111-50Enterprise pricing not publicly listed; demo available upon request.PartialApr 27, 2026
2021.AICopenhagen, DK201651-200Contact for pricingPartialApr 27, 2026

Buyer’s guide

Independent ranking with documented criteria.

See our top picks for ISO/IEC 42001

Frequently asked

In-depth answers about ISO/IEC 42001.

Looking for an audit firm?

Compare 12 independent ISO/IEC 42001 audit firms by accreditation, region, and services.

See all ISO 42001 audit firms

Compare across industries

See which vendors support ISO/IEC 42001 in your sector.

Last verified April 28, 2026. Informational summary only — not legal advice. Consult qualified counsel for specific obligations.