vista infosec white

ISO 42001 certification in India

ISO 42001 certification in India

Your clients have started asking how you govern AI, and ISO/IEC 42001 is the answer they accept. India has already adopted it as a national standard. We take you from the first gap assessment through to the certification audit, on a fixed fee agreed before any work starts.

  • Gap assessment, AI risk and impact assessment, full AIMS build
  • Audit support through Stage 1 and Stage 2 with an accredited certification body
  • Run alongside your ISO 27001 or SOC 2 work so you are not paying twice
  • Delivered by working PCI QSA and CREST-accredited assessors
21+ years in compliance audit CERT-In empanelled PCI QSA CREST-accredited ISO 27001 certified ourselves Mumbai & Pune

Talk to a Compliance Expert

    Get your Free ISO 42001 Readiness Checklist

    Our certified ISO 42001 Readiness Checklist will guide you through the entire Certification process. 100% pass rate guaranteed.

    ISO 42001 Certification in India — VISTA Infosec

    Why Indian companies are suddenly being asked for ISO 42001

    Four pressures landed within about eighteen months of each other. Most enquiries we get from India trace back to one of them.

    It is now an Indian Standard

    The Bureau of Indian Standards adopted ISO/IEC 42001:2023 as IS/ISO/IEC 42001:2023, identical and without deviation, through its Artificial Intelligence Sectional Committee (LITD 30). You are no longer explaining a foreign standard to your board.

    MeitY pointed at it

    The India AI Governance Guidelines, released by MeitY on 5 November 2025, set out seven sutras for safe and trusted AI. They are voluntary and principles-based. They also name international standards, ISO 42001 among them, as a route to putting those principles into practice.

    DPDP has a clock on it

    The DPDP Rules were notified in November 2025 and started a phased compliance window running into 2027. If you train or run inference on personal data, consent, purpose limitation and erasure stop being abstract. The data and lifecycle controls in ISO 42001 give that work somewhere to live.

    Your buyers moved first

    If you export software or run a GCC for a US or EU parent, their AI clause reached you well before any Indian regulation did. Sector regulators are moving too. The RBI's FREE-AI committee reported in August 2025 with recommendations for AI use in the financial sector.

    A straight answer on the EU AI Act: ISO 42001 certification does not make you compliant with it. Presumption of conformity comes only from harmonised standards cited in the EU's Official Journal, and ISO 42001 has no such citation. It is strong preparation rather than a legal pass. If a consultant tells you otherwise on a sales call, that tells you something useful about the consultant.

    What ISO 42001 actually asks of you

    ISO/IEC 42001 sets requirements for establishing, implementing, maintaining and continually improving an AI Management System (AIMS). Here’s what that means in practice.

    Clauses 4–10: AIMS Requirements

    Covers organisational context, leadership, AI policy, planning, risk and impact assessment, resources, operational controls, performance evaluation and continual improvement.

    Annex A: 38 AI Controls

    Covers areas including AI policies, internal organisation, resources, AI impact assessment, AI system lifecycle, data, information for interested parties, responsible use and third-party relationships.

    Who ISO 42001 Is For

    Designed for organisations that provide or use AI systems, regardless of size or industry—including organisations using third-party AI technologies as part of their operations.

    Your Path to ISO 42001 Certification

    A structured approach from initial gap assessment and AIMS implementation through certification audit preparation and support..

    Step 1

    ISO 42001 Gap Assessment

    We assess your current AI governance practices against ISO/IEC 42001 requirements, define the AIMS scope and identify gaps that need to be addressed.

    Step 2

    AI risk and impact assessment

    Identify AI-related risks and impacts, evaluate existing controls and determine the actions required to strengthen your AI governance framework.

    Step 3

    AIMS Implementation

    Develop the policies, processes, governance structures and controls required to establish and operate your AI Management System.

    Step 4

    Internal audit and management review

    Evaluate whether your AIMS is operating effectively, identify remaining gaps and prepare your organization for the certification audit.

    Step 5

    Stage 1 and Stage 2 support

    Prepare your team for the certification audit, support you through Stage 1 and Stage 2, and help address identified nonconformities.

    What the first conversation covers

    Thirty minutes with an assessor, free, and not a pitch. Most people come off this call knowing whether to start now or wait two quarters.

    • Your likely AIMS scope, and which of the 38 Annex A controls you can reasonably justify leaving out
    • Your role under the standard. Are you developing AI, providing it, using it, or some combination of the three
    • How much of your existing ISO 27001 or SOC 2 evidence already counts toward this
    • A realistic timeline to Stage 2, plus the three things most likely to delay you
    • Whether the EU AI Act touches your product at all, and where it clearly does not
    • A fee range, and what would move it up or down once we scope the work properly

    Already had ISO 42001 raised in a tender or client questionnaire? Send it across and we will tell you what you can answer today.

    Request a consultation

    Why teams in India work with us

    VISTA Infosec is a global cybersecurity and compliance consultancy with over 20 years of experience helping organisations navigate frameworks like GDPR, ISO 27001, SOC 2, DORA, NIS2, and more. We work with clients across the US, UK, EU, India, and Singapore — delivering fixed-fee, audit-ready programmes sized for lean teams.

    21+years in security assurance and compliance audit
    CERT-Inempanelled information security auditing organisation
    PCI QSAplus PCI Software Security Framework Assessor
    CRESTaccredited for security testing
    7 officesMumbai, Pune, New York, London, Singapore, Dubai, Tallinn

    We hold ISO 27001 certification ourselves, so the management system we ask you to run is one we run. Our assessors work on live PCI DSS, ISO 27001, SOC 2 and GDPR engagements every week. The ISO 42001 advice you get here comes from people who sit on the audit side of the table rather than from a template library.

    ISO 42001 certification in India, common questions

    Is ISO 42001 certification mandatory in India?

    No. It is voluntary. No Indian law currently requires it, and MeitY's AI Governance Guidelines are advisory rather than binding. What has changed is commercial. Enterprise clients, global parents and tender processes are asking for it, so in practice it behaves more like a condition of doing business than a nice-to-have.

    Has India adopted the standard nationally?

    Yes. The Bureau of Indian Standards adopted it as IS/ISO/IEC 42001:2023, an identical adoption under single numbering, through the Artificial Intelligence Sectional Committee LITD 30. Certification is available in India through bodies accredited by NABCB under the Quality Council of India, or through international accreditation bodies recognised under the IAF arrangement.

    How long does ISO 42001 certification take?

    Four to eight months to Stage 2 for an organisation that already holds ISO 27001. Nine to twelve months building from scratch. The limiting factor is rarely documentation. It is that the management system has to run long enough to produce records an auditor can sample.

    What does ISO 42001 certification cost in India?

    It depends on how many distinct AI systems are in scope, whether you train or fine-tune models, how many entities and locations are included, and how much of your ISO 27001 or SOC 2 work can be reused. Our consulting fee is fixed once scope is agreed at the gap assessment. Certification body audit days are quoted separately by that body, so be careful with anyone bundling both into a single headline number.

    We already have ISO 27001. How much extra is this?

    Less than most people fear. Both standards use the same harmonised structure, so scope, leadership, internal audit and management review carry across. What you are adding is AI-specific: system inventory, role determination, AI risk and impact assessment, lifecycle controls, data provenance, transparency artefacts, and supplier controls covering your model providers. We usually run the two as one integrated programme with a single evidence base.

    We only use ChatGPT-style APIs. Does this still apply to us?

    Yes, and it is the scoping conversation we have most often. The standard covers organisations that develop, provide or use AI systems. Ship a feature built on someone else's model and you are still accountable for how it is deployed, monitored, overseen and disclosed, even though the model itself is closed to you.

    Does ISO 42001 cover our DPDP Act obligations?

    Not on its own. They are different instruments. DPDP is law, ISO 42001 is a voluntary management standard. The overlap is genuinely useful though. Data governance, consent handling, purpose limitation and record-keeping work done for DPDP produces evidence that the ISO 42001 data and lifecycle controls ask for. We scope them together where clients want both.

    Can VISTA Infosec certify us as well as consult?

    No, and no credible firm can. Impartiality requirements under ISO/IEC 17021-1, supplemented by ISO/IEC 42006:2025 for AI management systems, keep consulting and certification separate. We deliver readiness, implementation and audit support. An accredited certification body issues the certificate after its own audit. That independence is exactly what makes the certificate worth showing a client.

    Do you work outside Mumbai and Pune?

    Yes. We deliver across India remotely, with on-site visits where the scope calls for them. We also work with Indian companies whose parent or client base sits in the US, UK, EU and Singapore, where we have offices of our own.

    Find out where you actually stand

    Most teams we speak to are further along than they expect on lifecycle and data, and further behind than they expect on impact assessment and oversight. A short call will tell you which one you are. If certification is not the right move for you yet, we will say so.

    Talk to an ISO 42001 Expert

    Or call directly on +91 99872 44769 or write to sales@vistainfosec.com

    Expert Auditors. Faster Certification.

     

    European Operations
    European engagements are delivered through Zulon Audits OÜ, the European practice of VISTA InfoSec.
    Visit Zulon Audits →