Your clients have started asking how you govern AI, and ISO/IEC 42001 is the answer they accept. India has already adopted it as a national standard. We take you from the first gap assessment through to the certification audit, on a fixed fee agreed before any work starts.
Four pressures landed within about eighteen months of each other. Most enquiries we get from India trace back to one of them.
The Bureau of Indian Standards adopted ISO/IEC 42001:2023 as IS/ISO/IEC 42001:2023, identical and without deviation, through its Artificial Intelligence Sectional Committee (LITD 30). You are no longer explaining a foreign standard to your board.
The India AI Governance Guidelines, released by MeitY on 5 November 2025, set out seven sutras for safe and trusted AI. They are voluntary and principles-based. They also name international standards, ISO 42001 among them, as a route to putting those principles into practice.
The DPDP Rules were notified in November 2025 and started a phased compliance window running into 2027. If you train or run inference on personal data, consent, purpose limitation and erasure stop being abstract. The data and lifecycle controls in ISO 42001 give that work somewhere to live.
If you export software or run a GCC for a US or EU parent, their AI clause reached you well before any Indian regulation did. Sector regulators are moving too. The RBI's FREE-AI committee reported in August 2025 with recommendations for AI use in the financial sector.
A straight answer on the EU AI Act: ISO 42001 certification does not make you compliant with it. Presumption of conformity comes only from harmonised standards cited in the EU's Official Journal, and ISO 42001 has no such citation. It is strong preparation rather than a legal pass. If a consultant tells you otherwise on a sales call, that tells you something useful about the consultant.
Published in December 2023, it is the first AI standard an organisation can be certified against. There are two halves to it, and both are in scope.
Context and scope, leadership and AI policy, planning that includes AI risk and impact assessment, support and competence, operational controls, monitoring and internal audit, then corrective action. It follows the same harmonised structure as ISO 27001, so an existing ISMS already carries much of this.
Nine objectives numbered A.2 to A.10: policies, internal organisation, resources, impact assessment, AI system lifecycle, data, information for interested parties, responsible use, and third-party relationships. You choose what applies through a Statement of Applicability and justify each exclusion in writing.
Any organisation that develops, provides or uses AI systems. That takes in companies calling a foundation model API without training anything of their own. You remain accountable for how the feature is deployed, overseen, disclosed and sourced.
Four to eight months to the Stage 2 audit if you already hold ISO 27001. Nine to twelve if you are building a management system from scratch. We size it after the gap assessment rather than quoting a number to win the call.
We map your AI systems, fix your role under the standard, set the scope boundary and assess you clause by clause. What you get back is a gap register with owners and effort against each item, not a traffic-light chart.
Risk against your business objectives first, then impact on the people your AI affects. This drives the Statement of Applicability, which is why it happens before any documentation gets written.
AI policy, lifecycle procedures, data governance, transparency artefacts, oversight design and supplier controls. We build these into the tools your team already uses so evidence generates itself instead of being assembled the week before an audit.
A system has to run before anyone can audit it. We run the internal audit, close out nonconformities, and take your leadership through a management review with a real agenda.
We prepare your team, sit with you through both audit stages, and manage the corrective action plan afterwards. Certificates run for three years, with annual surveillance audits in between.
Impartiality rules under ISO/IEC 17021-1 and ISO/IEC 42006:2025 stop one firm doing both. Your certificate comes from an accredited certification body, whether that is NABCB, UKAS, ANAB or another accreditation recognised under the IAF arrangement. No consultancy can guarantee a certificate, and we will not pretend otherwise.
Thirty minutes with an assessor, free, and not a pitch. Most people come off this call knowing whether to start now or wait two quarters.
Already had ISO 42001 raised in a tender or client questionnaire? Send it across and we will tell you what you can answer today.
Request a consultationVISTA Infosec is a global cybersecurity and compliance consultancy with over 20 years of experience helping organisations navigate frameworks like GDPR, ISO 27001, SOC 2, DORA, NIS2, and more. We work with clients across the US, UK, EU, India, and Singapore — delivering fixed-fee, audit-ready programmes sized for lean teams.
We hold ISO 27001 certification ourselves, so the management system we ask you to run is one we run. Our assessors work on live PCI DSS, ISO 27001, SOC 2 and GDPR engagements every week. The ISO 42001 advice you get here comes from people who sit on the audit side of the table rather than from a template library.
No. It is voluntary. No Indian law currently requires it, and MeitY's AI Governance Guidelines are advisory rather than binding. What has changed is commercial. Enterprise clients, global parents and tender processes are asking for it, so in practice it behaves more like a condition of doing business than a nice-to-have.
Yes. The Bureau of Indian Standards adopted it as IS/ISO/IEC 42001:2023, an identical adoption under single numbering, through the Artificial Intelligence Sectional Committee LITD 30. Certification is available in India through bodies accredited by NABCB under the Quality Council of India, or through international accreditation bodies recognised under the IAF arrangement.
Four to eight months to Stage 2 for an organisation that already holds ISO 27001. Nine to twelve months building from scratch. The limiting factor is rarely documentation. It is that the management system has to run long enough to produce records an auditor can sample.
It depends on how many distinct AI systems are in scope, whether you train or fine-tune models, how many entities and locations are included, and how much of your ISO 27001 or SOC 2 work can be reused. Our consulting fee is fixed once scope is agreed at the gap assessment. Certification body audit days are quoted separately by that body, so be careful with anyone bundling both into a single headline number.
Less than most people fear. Both standards use the same harmonised structure, so scope, leadership, internal audit and management review carry across. What you are adding is AI-specific: system inventory, role determination, AI risk and impact assessment, lifecycle controls, data provenance, transparency artefacts, and supplier controls covering your model providers. We usually run the two as one integrated programme with a single evidence base.
Yes, and it is the scoping conversation we have most often. The standard covers organisations that develop, provide or use AI systems. Ship a feature built on someone else's model and you are still accountable for how it is deployed, monitored, overseen and disclosed, even though the model itself is closed to you.
Not on its own. They are different instruments. DPDP is law, ISO 42001 is a voluntary management standard. The overlap is genuinely useful though. Data governance, consent handling, purpose limitation and record-keeping work done for DPDP produces evidence that the ISO 42001 data and lifecycle controls ask for. We scope them together where clients want both.
No, and no credible firm can. Impartiality requirements under ISO/IEC 17021-1, supplemented by ISO/IEC 42006:2025 for AI management systems, keep consulting and certification separate. We deliver readiness, implementation and audit support. An accredited certification body issues the certificate after its own audit. That independence is exactly what makes the certificate worth showing a client.
Yes. We deliver across India remotely, with on-site visits where the scope calls for them. We also work with Indian companies whose parent or client base sits in the US, UK, EU and Singapore, where we have offices of our own.
Most teams we speak to are further along than they expect on lifecycle and data, and further behind than they expect on impact assessment and oversight. A short call will tell you which one you are. If certification is not the right move for you yet, we will say so.
Speak to a consultantOr call directly on +91 99872 44769 or write to sales@vistainfosec.com
VISTA InfoSec LLC,347 Fifth Ave,
Suite 1402-526, New York, NY 10016
© Copyright 2026. VISTA InfoSec. All Rights Reserved. | Disclosure Policy | Privacy Policy | Sitemap
Enquire Now
WhatsApp us