A buyer just asked about ISO 42001 in your security questionnaire. Here's what to do.
AI-governance questions are landing in vendor security reviews — and a blank or hand-wavy answer can stall or lose the deal. You don't need a certificate today. You need a credible AI Management System you can point to. This is the fast path to one.
What they're actually asking
“Are you ISO 42001 compliant?” is shorthand for a handful of concrete questions. Enterprise security and procurement teams want evidence that the AI you ship is governed:
Your three options
Leave it blank
Silence reads as “no governance.” The review stalls, security escalates, and the deal slips — or dies.
Hand-wave it
“We take AI seriously” with nothing behind it invites follow-ups you can't answer, and erodes trust with the exact team gatekeeping the deal.
Stand up an AIMS
Point to a real ISO/IEC 42001-aligned AI Management System — policy, risk and impact assessments, a Statement of Applicability. One credible answer that you reuse on every future questionnaire, and that maps to the EU AI Act too.
What to put in your response — even before you're certified
Certification is a journey; a credible answer isn't. If you have an AIMS in progress, this is a strong, honest response you can give today:
“We operate an AI Management System aligned to ISO/IEC 42001. We maintain an AI policy, perform AI risk and impact assessments on our AI systems, keep a Statement of Applicability against Annex A controls, assign clear ownership for AI governance, and review it on a defined cadence. Certification is on our roadmap; our current controls and evidence are available on request.”
The catch: every clause of that sentence has to be true and backed by evidence. That's exactly what DoAIRight builds for you.
Get a credible answer in days, not months
Assess
Run the free 5-minute readiness check to see exactly where you stand across the standard.
Generate
Stand up a starter AIMS in one click — policy set, Statement of Applicability, and an AI risk register — then tailor it with the assistant.
Prove it
Produce the impact assessments, controls and one-click audit pack you can reference in any questionnaire — and reuse for the EU AI Act, SOC 2 and ISO 27001.
Questions vendors ask us
Why is ISO 42001 showing up in security questionnaires?
Enterprises are being held accountable for the AI in their supply chain — by regulators (the EU AI Act), their own boards, and their customers. The fastest way to push that accountability to vendors is to add AI-governance questions to the security review they already run. ISO/IEC 42001, the AI Management System standard, is the natural benchmark, so it's increasingly named directly.
Do I need to be ISO 42001 certified to answer these questions?
No. Certification helps, but most questionnaires ask whether you have an AI Management System (AIMS), do AI risk and impact assessments, and keep humans in the loop — not whether you hold a certificate. A well-run AIMS lets you answer credibly today and pursue certification when it's worth it.
How do I answer "Do you have an AI management system?"
Answer with specifics, not a yes/no: name your AI policy, your AI risk and impact assessment process, your Statement of Applicability against ISO/IEC 42001 Annex A, who owns AI governance, and how you review it. If you don't have those yet, the honest short-term answer is that you're implementing an ISO 42001-aligned AIMS — which is far stronger than silence.
What if I have ISO 27001 already?
You have a head start. ISO 27001 and ISO 42001 share the same management-system structure, so much of your governance, risk and review machinery carries over. ISO 42001 adds the AI-specific layer: fairness, transparency, human oversight, and impacts on individuals and society.
How fast can I have a credible answer?
With DoAIRight you can run a free readiness check in five minutes and stand up a starter AIMS — policy set, Statement of Applicability, and an AI risk register — in one click, then tailor it. That gives you defensible artifacts to reference in a questionnaire in days, not months.