ISO 42001:2023 Implementation Guide for Indian Enterprises
ISO 42001:2023 is the world's first AI management system standard — the ISO 27001 of the AI era. Here's a practical implementation guide for Indian enterprises, including what auditors look for and the 10 most common mistakes.
In this guide
- 1What is ISO 42001:2023?
- 2Why ISO 42001 matters for Indian enterprises
- 3The 8 domains of ISO 42001
- 4AI inventory: the foundation of everything
- 5Evidence requirements: what auditors actually check
- 6Certification timeline and cost
- 7The 10 most common implementation mistakes
What is ISO 42001:2023?
ISO 42001:2023 is the first international standard for Artificial Intelligence Management Systems (AIMS). Published in December 2023 by the International Organization for Standardization, it provides a structured framework for organisations to responsibly develop, provide, or use AI systems. Think of it as ISO 27001 — the gold standard for information security management — but purpose-built for the governance, risk, and ethics challenges specific to AI. Unlike prescriptive regulations that mandate specific technical controls, ISO 42001 is a management system standard. It requires you to establish policy, assign accountability, assess risks, implement controls, and continuously improve — then demonstrate this through documented evidence and internal audits. Certification is granted by accredited third-party certification bodies after a two-stage audit.
Why ISO 42001 matters for Indian enterprises
Indian enterprises are increasingly required to demonstrate ISO 42001 compliance by enterprise customers, investors, and regulators. Several large Indian IT services companies and BFSI institutions have begun requiring ISO 42001 as a vendor qualification criterion. The Reserve Bank of India's FREE-AI framework and the EU AI Act both align philosophically with ISO 42001's principles, making compliance with the standard a strong foundation for multi-regulatory compliance. For Indian AI SaaS companies selling to enterprise customers in Europe or the US, ISO 42001 certification can replace months of security questionnaire cycles — your Trust Passport can reference the certification and buyers can verify it in one click.
The 8 domains of ISO 42001
ISO 42001 follows the Annex SL high-level structure shared by ISO 27001, ISO 9001, and other management system standards. This makes it easier to integrate with existing management systems. The 8 clauses of the standard map to a Plan-Do-Check-Act cycle that drives continuous improvement. Clauses 1–3 are definitional (scope, normative references, terms). Clauses 4–10 are the operative requirements.
- Clause 4 — Context of the Organisation: Understand internal/external issues, stakeholder needs, and define scope of your AIMS
- Clause 5 — Leadership: Top management must demonstrate commitment, establish AI policy, and assign roles and responsibilities
- Clause 6 — Planning: AI risk assessment, AI objectives, and planning for change
- Clause 7 — Support: Resources, competence, awareness, communication, and documented information
- Clause 8 — Operation: AI system lifecycle controls, impact assessments, and supplier management
- Clause 9 — Performance Evaluation: Monitoring, internal audit, and management review
- Clause 10 — Improvement: Nonconformity, corrective action, and continual improvement
- Annex A — AI-specific controls: 38 controls across 9 control domains (similar to ISO 27001's Annex A)
Ready to automate your compliance?
Anverith AI covers ISO 42001, EU AI Act, DPDP, and 6 other frameworks — all in one platform.
AI inventory: the foundation of everything
Before you can assess risk, establish controls, or generate evidence, you need a complete inventory of your AI systems. This is the most foundational requirement of ISO 42001 and the most commonly underestimated step. Your AI inventory should capture: the system name and description, the AI technique used (supervised learning, LLM, computer vision, etc.), the data inputs and outputs, the intended use and context of deployment, the EU AI Act risk tier (if applicable), the business owner, and the current governance status. Auditors expect this inventory to be maintained in real time — not a spreadsheet updated once a year. Anverith's AI Discovery module automatically populates and maintains this inventory by scanning your cloud environments.
Evidence requirements: what auditors actually check
ISO 42001 certification requires documented evidence across all 8 clauses. Many organisations underestimate the volume and specificity of evidence required. A common mistake is treating ISO 42001 like a checklist — answering 'yes, we do this' without providing proof. Auditors need to see the actual policy documents, meeting minutes showing management review, completed risk assessments for each AI system, records of employee competence and training, and documented results of internal audits. The Annex A controls require technical evidence: model cards, bias evaluation reports, explainability documentation, and supplier AI governance assessments.
- AI policy — signed by top management, communicated to all staff
- AI risk assessment — documented per system, reviewed annually or after significant changes
- AI impact assessment — for high-risk systems, documented assessment of societal and ethical impact
- Model cards — structured documentation for each AI system in scope
- Internal audit records — at least one full internal audit before certification
- Management review minutes — evidence that leadership reviews AIMS performance
- Competence records — training completed by staff involved in AI development or deployment
- Supplier assessments — evidence that AI-related suppliers are evaluated for governance practices
Certification timeline and cost
For most Indian organisations with 5–20 AI systems in scope, the ISO 42001 certification journey takes 6–9 months from kickoff to certificate. Stage 1 audit (document review, typically remote) is followed by Stage 2 audit (on-site or hybrid, detailed evidence review) 4–6 weeks later. Certification bodies active in India include BSI, Bureau Veritas, TÜV SÜD, and DNV. Certification costs depend on scope: expect ₹8–15 lakh for Stage 1 + Stage 2 audits for a mid-sized organisation. Add internal implementation costs: consultant fees, tool costs, and staff time. Using Anverith reduces implementation time by 60% by automating evidence collection, AI inventory management, and control mapping.
The 10 most common implementation mistakes
After working with dozens of AI governance implementations, these are the mistakes that most commonly delay certification or result in audit findings.
- Treating it like a checklist instead of a management system — ISO 42001 requires ongoing operation, not a one-time exercise
- Incomplete AI inventory — missing shadow AI, third-party models, or AI embedded in SaaS tools
- No documented AI policy — or a policy that doesn't reflect actual practice
- Risk assessments done by IT security without AI/ML expertise — leads to surface-level assessments
- No AI impact assessments for high-risk systems — commonly skipped because teams don't know how
- Evidence stored in inaccessible places — auditors need to retrieve documents during the audit
- No internal audit before the certification audit — Stage 2 finds too many nonconformities
- Supplier AI governance not assessed — many organisations forget to evaluate AI vendors and cloud providers
- Training records missing — competence requirements are often treated as HR's problem
- No continual improvement process — AIMS must demonstrate learning and improvement over time
About this guide
Written by the Anverith AI Compliance Team. Published June 10, 2026 · 11 min read. Anverith AI is India's AI Trust Platform — automating compliance across ISO 42001, DPDP 2023, RBI FREE-AI, EU AI Act, and 5 other frameworks.
Get compliant faster with Anverith AI
Automate ISO 42001, DPDP 2023, RBI FREE-AI, and EU AI Act compliance. First score in 48 hours. Trust Passport in days.