vista infosec white

ISO 42001 Certification Ireland

ISO 42001 Certification Ireland: an AI management system you can put in front of an auditor

Your customers want to know how you govern AI. Security questionnaires now come with an AI section. And since July 2026, Ireland has its own enforcement structure around the EU AI Act. We help you prepare for ISO 42001 certification in Ireland by building an ISO/IEC 42001 Artificial Intelligence Management System (AIMS) that stands up to all three: scoped around the AI you actually build, buy and use, run inside your real workflows, and backed by evidence an independent certification body can test.

  • A gap assessment against the ISO/IEC 42001 clauses and the Annex A controls in your scope
  • AI risk and AI impact assessments your teams can keep up to date
  • Policies, roles and records that match how your organisation really works
  • Internal audit and management review finished before the certification body arrives
  • 21+ years in compliance audit
  • In-house ISO lead auditors
  • ISO 27001 certified ourselves
  • CREST-accredited
  • CERT-In empanelled
  • PCI QSA

See how the readiness process works

Talk to a Compliance Expert

    ISO 42001 Certification Ireland | VISTA Infosec

    Why ISO 42001 is on the agenda for Irish organisations

    A lot of Europe's technology, financial services and life-sciences work is run from Ireland. So Irish teams tend to feel two pressures before most: EU AI rules arriving in stages, and enterprise buyers who want something more concrete than a responsible AI statement on a website. ISO 42001 certification in Ireland has become one of the ways teams answer both.

    Ireland now has its own AI Act enforcement body

    The Regulation of Artificial Intelligence Act 2026 was signed into law on 21 July 2026. It establishes Oifig IS na hÉireann, the AI Office of Ireland, as the central authority coordinating how the EU AI Act is applied here.

    Your sector regulator is part of it

    Ireland chose a distributed model. Fifteen national competent authorities have been designated, including the Central Bank of Ireland, the Data Protection Commission, the HPRA and the CCPC. The body looking at your AI may be the one already supervising your sector.

    Deadlines moved. They didn't disappear.

    The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026. It pushes Annex III high-risk obligations to 2 December 2027 and Annex I (product-embedded AI) to 2 August 2028. Other parts of the AI Act already apply.

    Buyers usually ask first

    In practice, the first hard question tends to come from a customer's procurement or security team, not a regulator. A certificate from an accredited certification body is an answer they already know how to read.

    Key dates for AI governance planning in Ireland

    DateWhat happened or applies
    1 Aug 2024EU AI Act (Regulation (EU) 2024/1689) enters into force
    2 Feb 2025Prohibited AI practices begin to apply
    4 Mar 2025Irish Government approves a distributed model of AI Act implementation
    2 Aug 2025Obligations for general-purpose AI model providers apply
    16 Sep 2025Ireland's list of national competent authorities reaches fifteen
    21 Jul 2026Regulation of Artificial Intelligence Act 2026 signed into law, establishing the AI Office of Ireland
    27 Jul 2026Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force
    2 Dec 2027High-risk obligations apply to Annex III systems (as amended)
    2 Aug 2028High-risk obligations apply to Annex I systems (as amended)

    Dates reflect the position at our last review, shown at the foot of this page. This is general information, not legal advice.

    What an AI management system looks like day to day

    ISO/IEC 42001:2023 won't tell you which model to use or set a fairness threshold for you. What it asks is that you run AI the way a well-governed organisation runs anything that carries risk: decide what's in scope, give each AI system an owner, assess risk and impact, put controls in place, check they work, and fix what doesn't.

    That's easier to see in practice. Here's the difference an AIMS makes to situations most teams will recognise:

    SituationWithout an AIMSWith an AIMS in place
    A team connects a generative AI tool to the CRMFound months later, usually during a customer auditA defined approval route for new AI use, with a risk and data review before it goes live
    A model is retrained and results shiftNobody can say what changed, or whenChange and monitoring records linked to that system in the AI inventory
    A customer asks which features use AI and who oversees themA scramble across product, engineering and legalAn inventory with a named owner and human-oversight arrangements for each in-scope system
    A supplier changes its AI terms or modelNoticed only if someone happens to read the emailThird-party AI reviewed on a defined cycle, with responsibilities agreed
    The board asks how AI risk is being managedAnecdotes and a slideAI objectives, risk treatment status and audit results reported through management review

    Do you need ISO 42001 certification in Ireland?

    Legally, no. As at our last review, no Irish or EU law requires ISO/IEC 42001 certification. It's a voluntary standard.

    Commercially, it can be a different story. The requirement usually arrives through a contract clause, a tender scoring criterion, a customer's vendor due diligence, an investor's checklist, or a group policy set by a parent company. When that happens, a certificate from an accredited body is often the quickest credible answer.

    Certification is probably worth it if…

    • Customers or prospects are asking for ISO 42001 by name, or scoring AI governance in tenders
    • AI is part of the product you sell, not just a tool you use internally
    • You already run ISO 27001 and want AI governance under the same audit cycle
    • You operate in a regulated sector and want governance evidence you can show a supervisor
    • Your parent company or investors expect independent assurance

    You may not need it yet if…

    • AI use is limited to a few low-impact productivity tools
    • Nobody outside the business is asking for evidence
    • You'd get more value from a clear AI inventory and AI use policy first
    • What you really need is an AI Act role and risk classification (a different piece of work)

    Even then, a gap assessment is a sensible way to find out where you stand before someone else asks.

    ISO 42001 and the EU AI Act: how they fit together

    They get mentioned in the same breath so often that it's easy to treat them as one thing. They aren't. One is a certifiable management system standard. The other is law.

    ISO/IEC 42001EU AI Act
    What it isA voluntary international standard for an AI management systemAn EU regulation that applies directly in Ireland and every other Member State
    Who it applies toAny organisation that develops, provides or uses AI and chooses to adopt itProviders, deployers, importers and distributors of AI systems in scope, with obligations depending on role and risk category
    What gets looked atYour organisation's management system: policies, processes, controls, recordsIndividual AI systems and general-purpose AI models
    OutcomeA certificate from an accredited certification body, typically on a three-year cycle with surveillance auditsLegal compliance; for high-risk systems, conformity assessment before placing on the market
    Who checksAn independent certification bodyNational competent authorities (in Ireland, coordinated by the AI Office of Ireland) and, for general-purpose AI models, the European AI Office

    Where an AIMS genuinely helps with AI Act work

    A lot of AI Act preparation depends on things an AIMS makes you build anyway: an inventory of AI systems, a repeatable risk process, defined roles, documented human oversight, monitoring, supplier controls and records you can find again. Having that machinery running makes classification, documentation and oversight work far less painful.

    Where it doesn't

    ISO 42001 certification doesn't classify your AI systems under the Act, doesn't replace conformity assessment or CE marking for high-risk systems, and doesn't make you compliant by itself. It isn't a harmonised standard under the AI Act. Providers of high-risk systems also have specific quality management system obligations under Article 17, which CEN-CENELEC has been addressing through separate European standards such as EN 18286.

    If your main question is what the AI Act requires of you specifically, start with our EU AI Act compliance services. Many teams run the two pieces of work side by side so the evidence is only gathered once.

    ISO 42001 gap analysis for Irish organisations

    A gap assessment tells you, clause by clause, how far your current practice is from what ISO/IEC 42001 requires, and what it'll take to close the distance. It's where almost every engagement starts, and it's useful on its own even if certification is a year away.

    What we assess

    • Context and scope: which AI systems, teams, sites and entities belong in the AIMS, and your role as developer, provider or user of AI
    • Leadership and AI policy: top-management commitment, the AI policy, and who is accountable for what
    • Planning: AI risk assessment and treatment, AI impact assessment, AI objectives
    • Support: competence, awareness, communication and documented information
    • Operation: how AI systems are designed, bought, deployed, changed and retired in practice
    • Performance evaluation and improvement: monitoring, internal audit, management review, corrective action
    • Annex A controls relevant to your scope, including data for AI systems and third-party relationships
    • What you can reuse from ISO 27001, ISO 27701, GDPR records and existing risk registers

    What you receive

    • A clause-by-clause and control-level gap report, with each finding rated
    • A prioritised remediation plan with suggested owners and effort
    • A draft AIMS scope statement you can take to leadership
    • A first-pass AI system inventory
    • A reuse map showing what your existing management systems already cover
    • A realistic timeline to certification readiness, in writing

    Most of the work runs remotely through document review and short interviews with AI product owners, engineering, data, security, legal and your DPO.

    ISO 42001 implementation in Ireland: closing the gaps properly

    A gap report is only useful if the gaps get closed in a way that survives an audit. Implementation is where most AIMS projects stall, usually because documents get written that nobody follows. We work the other way round: start with how your teams already build, buy and approve things, then put the ISO 42001 requirements into those routes.

    Policies and procedures

    An AI policy, plus procedures for AI risk, impact assessment, AI system lifecycle, data for AI, supplier management and incident handling. Written to fit your size. A 40-person SaaS company doesn't need a bank's document set.

    Controls in real workflows

    Approval steps in procurement for new AI tools. Risk checks in your product and change process. Monitoring tied to the systems that matter. Controls live where the work happens, not in a separate binder.

    Responsibilities

    Named owners for each in-scope AI system, and clear lines between the AI governance lead, product, engineering, security, legal and the DPO. Competence and awareness records to show people know their part.

    Evidence

    A Statement of Applicability that justifies each Annex A control decision, plus the records an auditor samples: risk and impact assessments, approvals, monitoring outputs, supplier reviews, training and meeting minutes.

    You can have us draft most of the documentation with your input, or draft it yourselves and have us review it. Either way, the AIMS has to belong to you. The certification body will want to talk to your people, not ours.

    What we help you build

    Grouped the way ISO/IEC 42001 is structured, on the Plan-Do-Check-Act cycle. Under each item is the thing that should exist when we're done.

    Planset it up

    AIMS scope

    A scope statement that names the AI systems, teams and boundaries in play.

    AI system inventory

    A maintained register of AI you develop, provide or use, with owners.

    AI governance

    An AI policy approved by top management and a clear governance structure.

    AI risk management

    A risk method, risk register and treatment plan specific to AI.

    AI impact assessment

    Assessments of effects on individuals, groups and society for in-scope systems.

    Dorun it

    Policies and procedures

    The documented processes your teams actually follow.

    Roles and accountability

    Named owners, a RACI, and competence records.

    Third-party AI governance

    Supplier assessments, contract expectations and review cycles for AI you buy.

    Documentation

    A controlled document set, including the Statement of Applicability.

    Checkprove it

    Monitoring

    Defined measures for AI system performance, incidents and AIMS objectives.

    Internal audit

    A completed internal audit of the AIMS, with findings logged.

    Management review

    Minutes showing leadership has reviewed AIMS performance and made decisions.

    Actimprove it

    Corrective actions

    A nonconformity and corrective action log, with root causes and closures.

    Continual improvement

    Evidence that lessons from audits, incidents and reviews change how you work.

    ISO 42001 certification readiness process

    Seven steps with us, then a clear handover. We're open about where our role ends, because it matters: the certification audit has to be independent of the people who helped you prepare.

    With VISTA Infosec

    1. Discovery and scope

      We confirm what's driving the project, which AI systems and entities are in play, and your role in relation to each.

    2. Gap assessment

      Clause and control-level review of current practice, with a prioritised plan.

    3. AIMS design

      Scope, policy, governance structure, risk and impact methods agreed with leadership.

    4. Implementation

      Procedures and controls built into your real workflows, with owners assigned.

    5. Documentation and evidence

      Statement of Applicability finalised; records building up as the AIMS operates.

    6. Internal audit and management review

      An independent internal audit, findings closed out, and a management review held.

    7. Certification readiness

      A readiness check against what the certification body will sample, and support preparing for Stage 1.

    With your independent certification body

    We can introduce you to an accredited partner certification body or work alongside the one you choose. We support you during the audits; we don't audit our own work, and we don't issue the certificate.

    • Stage 1 audit

      Reviews your AIMS documentation and readiness, and confirms the audit plan.

    • Stage 2 audit

      Tests whether the AIMS is implemented and working effectively, by sampling evidence and interviewing your people.

    • Certification decision

      Made by the certification body. Nonconformities must be addressed first.

    • Surveillance audits

      Usually annual, through the certificate's typical three-year cycle.

    • Recertification

      A full reassessment before the certificate expires.

    No one can honestly guarantee a certification outcome, and we won't. What we can do is make sure there are no surprises about what the auditor will ask for.

    Already ISO 27001 certified?

    Good news, with a caveat. ISO/IEC 42001 uses the same harmonised management-system structure as ISO/IEC 27001, so a lot of your existing machinery carries straight over. But ISO 27001 certification doesn't satisfy ISO 42001, and an auditor won't accept information security controls as a stand-in for AI governance.

    Usually reusable from your ISMSNew work for the AIMS
    Document control and records managementAI system inventory and AIMS scope
    Internal audit programme and auditor poolAI impact assessment for individuals, groups and society
    Management review and corrective action processAI-specific risk criteria and treatment (bias, transparency, misuse, model drift)
    Risk methodology structure and risk register toolingAI system lifecycle controls, from design through retirement
    Supplier management processData for AI systems: quality, provenance, preparation
    Competence, awareness and training recordsHuman oversight arrangements and AI-specific objectives

    Many certification bodies can run ISO 27001 and ISO 42001 audits together once both systems are mature, which can reduce duplicated effort. Worth raising with your certification body early.

    ISO 42001 services across Ireland

    We support teams across Ireland, including those based in Dublin, Cork, Galway, Limerick and Waterford, and we work just as well with a founder-led SaaS company in Limerick as with the Irish entity of a global group in Dublin. Where your people sit doesn't change the method. Building an AI management system in Ireland does mean thinking about a few local realities, though.

    Remote-first delivery

    Workshops, interviews and evidence reviews run over video and a shared workspace. On-site sessions can be planned where the engagement needs them.

    Same working hours

    Our London team works in the same time zone as Ireland, so calls fit your working day.

    Evidence kept in the EU

    If you need AIMS evidence to stay within the EU, we can process it on EU-region infrastructure.

    Your regulator in view

    We plan the AIMS with your sector supervisor in mind, whether that's the Central Bank of Ireland, the HPRA or the Data Protection Commission.

    On certification, you choose the body. Several certification bodies offer ISO/IEC 42001 certification in Ireland, including the National Standards Authority of Ireland (NSAI). Whichever you pick, check it's accredited for ISO/IEC 42001, and we'll support you through its audits.

    Who we support

    ISO 42001 certification services in Ireland aren't only for AI labs. These are the kinds of organisations we set up to support, and what usually starts the conversation.

    SaaS and platform companies

    Enterprise customers asking how AI features are governed, often inside a security review that already covers ISO 27001 or SOC 2.

    AI technology companies

    Building or fine-tuning models, where buyers expect evidence of lifecycle, data and risk controls from day one.

    Financial services and fintech

    AI in credit, fraud, onboarding or customer service, with the Central Bank of Ireland named as a market surveillance authority for AI in financial services.

    Health technology and medtech

    AI in clinical, diagnostic or device software, where the HPRA and medical device rules sit alongside AI governance.

    Professional services

    Firms using AI to deliver client work, where clients now include AI questions in panel and supplier reviews.

    Organisations deploying third-party AI

    Copilots, chatbots, HR screening or analytics tools bought from vendors. Using AI still brings governance responsibilities, and some uses, such as recruitment, can fall into the AI Act's high-risk categories.

    What you should have before the certification audit

    Auditors sample evidence. They'll want to see that the AIMS has been operating for long enough to produce records, not just that the documents exist. Your certification body will confirm what it expects; this is the evidence set we work towards.

    • Approved AIMS scope statement, signed off by top management, with boundaries and exclusions justified
    • AI policy, approved, communicated, and available to relevant interested parties
    • AI objectives, with measures, owners and progress tracked
    • AI system inventory, current, with owners and lifecycle stage for each system
    • AI risk assessment and treatment plan, with residual risk accepted by the right people
    • AI impact assessments, for in-scope systems, reviewed when systems change
    • Statement of Applicability, every Annex A control included or excluded, with a reason
    • Roles, responsibilities and competence records, including training and awareness evidence
    • Third-party AI records, supplier assessments and agreed responsibilities
    • Operational records, approvals, changes, monitoring outputs and any AI incidents
    • Internal audit report, covering the full AIMS, with findings closed or in progress
    • Management review minutes, showing inputs, decisions and actions
    • Corrective action log, root causes, actions and verification of effectiveness

    Want the fuller version? Our ISO 42001 readiness checklist walks through the questions to ask before you book the audit.

    Why VISTA Infosec

    We're an audit-led compliance firm with more than 21 years behind us. That background shapes how we prepare you: we think about your AIMS the way an auditor will read it.

    Auditors, not just writers

    Our ISO 42001 work is delivered by in-house ISO lead auditors, so readiness is measured against how evidence actually gets sampled.

    We practise what we audit

    VISTA Infosec is ISO 27001 certified itself. We also hold CREST accreditation, CERT-In empanelment and PCI QSA status.

    One programme, shared evidence

    If you run ISO 27001, ISO 27701 or SOC 2 alongside ISO 42001, we plan them together so controls and evidence aren't paid for twice.

    AI Act work under the same roof

    Our EU AI Act services sit in the same team, so AI Act classification and your AIMS can be built from one inventory.

    Fixed fee, agreed up front

    You get a written quote and timeline after scoping, before any work starts.

    International footprint

    Offices in Mumbai, Pune, New York, London, Singapore, Dubai and Tallinn, with the London team working your hours.

    ISO 42001 certification cost in Ireland

    We don't publish a price list, because two ISO 42001 projects rarely look alike. What we can do is explain where the money goes, so you can budget sensibly and compare quotes fairly.

    There are usually two separate costs. The first is readiness and implementation support, which is what we provide. The second is the certification audit itself, charged by your certification body for Stage 1, Stage 2 and the surveillance audits that follow. Then there's your own team's time, which is easy to forget and often the largest of the three.

    Cost factorWhy it matters
    Number and type of AI systems in scopeMore systems means more risk and impact assessments, and more evidence to sample
    Your role: developer, provider or user of AIBuilding and selling AI brings lifecycle and data controls that pure users may not need
    Entities, sites and headcount in scopeDrives how many audit days a certification body calculates
    Existing ISO 27001 or similar systemReusable processes can shorten implementation noticeably
    Documentation maturityStarting from scratch takes longer than refining what exists
    How much drafting you want us to doFull drafting and review-only support are priced differently
    Sector and regulatory exposureFinancial services and health technology often need deeper risk and oversight evidence

    You'll get a fixed quote after a short scoping call. If you're comparing providers, check whether each quote includes the internal audit and management review support; those are often where cheaper quotes cut corners.

    Frequently asked questions

    What is ISO 42001?

    ISO/IEC 42001:2023 is the international standard for an Artificial Intelligence Management System (AIMS). Published by ISO and IEC in December 2023, it sets requirements for establishing, implementing, maintaining and continually improving how an organisation governs the AI it develops, provides or uses. It's certifiable, which means an accredited certification body can audit you against it.

    Is ISO 42001 mandatory in Ireland?

    No. As at our last review, no Irish or EU law makes ISO/IEC 42001 certification mandatory. It can become a requirement through contracts, tenders, customer due diligence or group policy, and it can support your wider AI governance, but it's a voluntary standard.

    Who needs ISO 42001 certification in Ireland?

    Nobody needs it by law. It tends to make most sense for SaaS and AI product companies selling to enterprise customers, financial services and health technology firms using AI in regulated activities, and organisations whose customers or parent companies ask for independent assurance on AI governance.

    How long can ISO 42001 implementation take?

    It depends on scope, the number of AI systems, and whether you already run ISO 27001. A focused scope building on an existing ISMS often reaches certification readiness in roughly four to six months; a standing start or a broad multi-entity scope takes longer. The AIMS also needs to run long enough to produce records before the audit. We give you a written timeline after the gap assessment.

    How much does ISO 42001 certification cost in Ireland?

    There are two parts: readiness and implementation support, and the certification body's audit fees. Both depend mainly on the number of AI systems in scope, your role as developer or user, headcount and sites, and how much existing management-system work you can reuse. We provide a fixed quote after scoping.

    Does ISO 42001 make us EU AI Act compliant?

    No. ISO/IEC 42001 certification doesn't by itself make you compliant with the EU AI Act, and it isn't a harmonised standard under the Act. It can give you governance structures that support AI Act work, such as an AI inventory, risk processes, human oversight and records. Your AI Act obligations depend on your role and the risk category of each system and have to be assessed separately.

    Can ISO 42001 integrate with ISO 27001?

    Yes. Both follow the same harmonised management-system structure, so document control, internal audit, management review, corrective action and supplier processes can usually be shared. The AI-specific parts, including impact assessment, AI lifecycle controls, data for AI systems and human oversight, still have to be built. Some certification bodies can audit both together.

    What happens during an ISO 42001 gap assessment?

    We agree the likely scope, review your existing documents, and hold short interviews with the people who own, build, buy and oversee AI. We then assess your practice against each clause and the relevant Annex A controls. You receive a rated gap report, a prioritised remediation plan, a draft scope statement, a first-pass AI inventory and a timeline to readiness.

    Who issues an ISO 42001 certificate?

    An independent, accredited certification body issues it after Stage 1 and Stage 2 audits. VISTA Infosec doesn't issue ISO 42001 certificates. We prepare you and support you through the audit, and can introduce you to an accredited partner certification body. It's worth checking that any body you use is accredited for ISO/IEC 42001, whether through INAB in Ireland or another IAF member accreditation body.

    Can VISTA support organisations across Dublin, Cork, Galway, Limerick and Waterford?

    Yes. Our delivery is remote-first, so we can support teams anywhere in Ireland, including Dublin, Cork, Galway, Limerick and Waterford. On-site sessions can be arranged where an engagement needs them, and our London team works in the same time zone.

    Expert Auditors. Faster Certification.