vista infosec white

ISO 42001 certification in India

ISO 42001 certification in India

Your clients have started asking how you govern AI, and ISO/IEC 42001 is the answer they accept. India has already adopted it as a national standard. We take you from the first gap assessment through to the certification audit, on a fixed fee agreed before any work starts.

  • Gap assessment, AI risk and impact assessment, full AIMS build
  • Audit support through Stage 1 and Stage 2 with an accredited certification body
  • Run alongside your ISO 27001 or SOC 2 work so you are not paying twice
  • Delivered by working PCI QSA and CREST-accredited assessors
21+ years in compliance audit CERT-In empanelled PCI QSA CREST-accredited ISO 27001 certified ourselves Mumbai & Pune

Talk to a Compliance Expert

    ISO 42001 Certification in India — VISTA Infosec

    Why Indian companies are suddenly being asked for ISO 42001

    Four pressures landed within about eighteen months of each other. Most enquiries we get from India trace back to one of them.

    It is now an Indian Standard

    The Bureau of Indian Standards adopted ISO/IEC 42001:2023 as IS/ISO/IEC 42001:2023, identical and without deviation, through its Artificial Intelligence Sectional Committee (LITD 30). You are no longer explaining a foreign standard to your board.

    MeitY pointed at it

    The India AI Governance Guidelines, released by MeitY on 5 November 2025, set out seven sutras for safe and trusted AI. They are voluntary and principles-based. They also name international standards, ISO 42001 among them, as a route to putting those principles into practice.

    DPDP has a clock on it

    The DPDP Rules were notified in November 2025 and started a phased compliance window running into 2027. If you train or run inference on personal data, consent, purpose limitation and erasure stop being abstract. The data and lifecycle controls in ISO 42001 give that work somewhere to live.

    Your buyers moved first

    If you export software or run a GCC for a US or EU parent, their AI clause reached you well before any Indian regulation did. Sector regulators are moving too. The RBI's FREE-AI committee reported in August 2025 with recommendations for AI use in the financial sector.

    A straight answer on the EU AI Act: ISO 42001 certification does not make you compliant with it. Presumption of conformity comes only from harmonised standards cited in the EU's Official Journal, and ISO 42001 has no such citation. It is strong preparation rather than a legal pass. If a consultant tells you otherwise on a sales call, that tells you something useful about the consultant.

    What ISO 42001 actually asks of you

    Published in December 2023, it is the first AI standard an organisation can be certified against. There are two halves to it, and both are in scope.

    Clauses 4 to 10, mandatory

    Context and scope, leadership and AI policy, planning that includes AI risk and impact assessment, support and competence, operational controls, monitoring and internal audit, then corrective action. It follows the same harmonised structure as ISO 27001, so an existing ISMS already carries much of this.

    Annex A, 38 controls

    Nine objectives numbered A.2 to A.10: policies, internal organisation, resources, impact assessment, AI system lifecycle, data, information for interested parties, responsible use, and third-party relationships. You choose what applies through a Statement of Applicability and justify each exclusion in writing.

    Who it covers

    Any organisation that develops, provides or uses AI systems. That takes in companies calling a foundation model API without training anything of their own. You remain accountable for how the feature is deployed, overseen, disclosed and sourced.

    How we take you there

    Four to eight months to the Stage 2 audit if you already hold ISO 27001. Nine to twelve if you are building a management system from scratch. We size it after the gap assessment rather than quoting a number to win the call.

    Step 1

    Gap assessment

    We map your AI systems, fix your role under the standard, set the scope boundary and assess you clause by clause. What you get back is a gap register with owners and effort against each item, not a traffic-light chart.

    Step 2

    AI risk and impact assessment

    Risk against your business objectives first, then impact on the people your AI affects. This drives the Statement of Applicability, which is why it happens before any documentation gets written.

    Step 3

    Build the AIMS

    AI policy, lifecycle procedures, data governance, transparency artefacts, oversight design and supplier controls. We build these into the tools your team already uses so evidence generates itself instead of being assembled the week before an audit.

    Step 4

    Internal audit and management review

    A system has to run before anyone can audit it. We run the internal audit, close out nonconformities, and take your leadership through a management review with a real agenda.

    Step 5

    Stage 1 and Stage 2 support

    We prepare your team, sit with you through both audit stages, and manage the corrective action plan afterwards. Certificates run for three years, with annual surveillance audits in between.

    Important

    We consult, we do not certify

    Impartiality rules under ISO/IEC 17021-1 and ISO/IEC 42006:2025 stop one firm doing both. Your certificate comes from an accredited certification body, whether that is NABCB, UKAS, ANAB or another accreditation recognised under the IAF arrangement. No consultancy can guarantee a certificate, and we will not pretend otherwise.

    What the first conversation covers

    Thirty minutes with an assessor, free, and not a pitch. Most people come off this call knowing whether to start now or wait two quarters.

    • Your likely AIMS scope, and which of the 38 Annex A controls you can reasonably justify leaving out
    • Your role under the standard. Are you developing AI, providing it, using it, or some combination of the three
    • How much of your existing ISO 27001 or SOC 2 evidence already counts toward this
    • A realistic timeline to Stage 2, plus the three things most likely to delay you
    • Whether the EU AI Act touches your product at all, and where it clearly does not
    • A fee range, and what would move it up or down once we scope the work properly

    Already had ISO 42001 raised in a tender or client questionnaire? Send it across and we will tell you what you can answer today.

    Request a consultation

    Why teams in India work with us

    VISTA Infosec is a global cybersecurity and compliance consultancy with over 20 years of experience helping organisations navigate frameworks like GDPR, ISO 27001, SOC 2, DORA, NIS2, and more. We work with clients across the US, UK, EU, India, and Singapore — delivering fixed-fee, audit-ready programmes sized for lean teams.

    21+years in security assurance and compliance audit
    CERT-Inempanelled information security auditing organisation
    PCI QSAplus PCI Software Security Framework Assessor
    CRESTaccredited for security testing
    7 officesMumbai, Pune, New York, London, Singapore, Dubai, Tallinn

    We hold ISO 27001 certification ourselves, so the management system we ask you to run is one we run. Our assessors work on live PCI DSS, ISO 27001, SOC 2 and GDPR engagements every week. The ISO 42001 advice you get here comes from people who sit on the audit side of the table rather than from a template library.

    ISO 42001 certification in India, common questions

    Is ISO 42001 certification mandatory in India?

    No. It is voluntary. No Indian law currently requires it, and MeitY's AI Governance Guidelines are advisory rather than binding. What has changed is commercial. Enterprise clients, global parents and tender processes are asking for it, so in practice it behaves more like a condition of doing business than a nice-to-have.

    Has India adopted the standard nationally?

    Yes. The Bureau of Indian Standards adopted it as IS/ISO/IEC 42001:2023, an identical adoption under single numbering, through the Artificial Intelligence Sectional Committee LITD 30. Certification is available in India through bodies accredited by NABCB under the Quality Council of India, or through international accreditation bodies recognised under the IAF arrangement.

    How long does ISO 42001 certification take?

    Four to eight months to Stage 2 for an organisation that already holds ISO 27001. Nine to twelve months building from scratch. The limiting factor is rarely documentation. It is that the management system has to run long enough to produce records an auditor can sample.

    What does ISO 42001 certification cost in India?

    It depends on how many distinct AI systems are in scope, whether you train or fine-tune models, how many entities and locations are included, and how much of your ISO 27001 or SOC 2 work can be reused. Our consulting fee is fixed once scope is agreed at the gap assessment. Certification body audit days are quoted separately by that body, so be careful with anyone bundling both into a single headline number.

    We already have ISO 27001. How much extra is this?

    Less than most people fear. Both standards use the same harmonised structure, so scope, leadership, internal audit and management review carry across. What you are adding is AI-specific: system inventory, role determination, AI risk and impact assessment, lifecycle controls, data provenance, transparency artefacts, and supplier controls covering your model providers. We usually run the two as one integrated programme with a single evidence base.

    We only use ChatGPT-style APIs. Does this still apply to us?

    Yes, and it is the scoping conversation we have most often. The standard covers organisations that develop, provide or use AI systems. Ship a feature built on someone else's model and you are still accountable for how it is deployed, monitored, overseen and disclosed, even though the model itself is closed to you.

    Does ISO 42001 cover our DPDP Act obligations?

    Not on its own. They are different instruments. DPDP is law, ISO 42001 is a voluntary management standard. The overlap is genuinely useful though. Data governance, consent handling, purpose limitation and record-keeping work done for DPDP produces evidence that the ISO 42001 data and lifecycle controls ask for. We scope them together where clients want both.

    Can VISTA Infosec certify us as well as consult?

    No, and no credible firm can. Impartiality requirements under ISO/IEC 17021-1, supplemented by ISO/IEC 42006:2025 for AI management systems, keep consulting and certification separate. We deliver readiness, implementation and audit support. An accredited certification body issues the certificate after its own audit. That independence is exactly what makes the certificate worth showing a client.

    Do you work outside Mumbai and Pune?

    Yes. We deliver across India remotely, with on-site visits where the scope calls for them. We also work with Indian companies whose parent or client base sits in the US, UK, EU and Singapore, where we have offices of our own.

    Find out where you actually stand

    Most teams we speak to are further along than they expect on lifecycle and data, and further behind than they expect on impact assessment and oversight. A short call will tell you which one you are. If certification is not the right move for you yet, we will say so.

    Speak to a consultant

    Or call directly on +91 99872 44769 or write to sales@vistainfosec.com

    Expert Auditors. Faster Certification.