In 18 months, a new generation of audit opinions will start landing in mid-market boardrooms. The standard those opinions will be written against is already published. Most companies haven't read it. The ones writing about it usually haven't either.
The standard is ISO 42001 — an international management standard for AI systems, published in December 2023. Schellman became the first accredited certification body. Coalfire, A-LIGN, and BARR Advisory have AI assurance practices being stood up right now. The first wave of mid-market certifications hits in 2027.
I read the standard end-to-end. Here's the plain-English version — what it requires, what it deliberately doesn't, and what's likely to be the gap between requirement and reality.
ISO 42001 is shorter than most companies expect. The Annex A controls list is under forty entries. The normative text runs under forty pages. It's not a long document. A handful of those entries are going to break the way mid-market companies actually operate.
The shape of the standard
ISO 42001 is built on the same harmonized backbone as ISO 27001. If you've been through a 27001 audit, the bones are familiar. Management system clauses — context, leadership, planning, support, operation, evaluation, improvement — set the program-level requirements. Annex A holds the controls: about 38 of them, grouped into nine categories. Among the categories: AI policies, internal organization for AI, resources, impact assessment, AI system lifecycle, data for AI, information for interested parties, responsible use of AI, and third-party relationships.
If that list reads like a procurement checklist, it isn't. It's a structure for an AI program — not a list of technical mitigations.
What it requires
What makes the standard interesting is the requirements that go beyond ordinary security audit territory.
The standard demands an AI management system. That phrase does a lot of work. It means a formal program — with policy, ownership, defined processes, and records — that governs how AI is developed, deployed, operated, and retired across your organization. Not just the deployment moment. The full lifecycle.
It requires two distinct assessments that most companies conflate. There's an AI risk assessment (clause 6.1.2) — the familiar exercise of what could go wrong and how badly. There's also an AI system impact assessment, in Annex A — the less-familiar exercise of what your AI does to the people, groups, and society it affects.
The standard treats these as separate work, with separate records.
It requires lifecycle controls. Not "we tested the model before deployment." Records that demonstrate decisions, approvals, and changes across design, development, deployment, operation, and decommissioning. The audits will sample at lifecycle stages most companies don't currently document — the change request that swapped a model version, the evaluation that justified deploying it, the monitoring that confirmed it kept working.
It requires information for affected parties. If your AI makes a decision that touches a customer or an employee, the standard requires you to be able to tell that person what's happening and why. Not at a vague policy level. At a specific, retrievable level. The plumbing for that requirement is non-trivial.
It requires third-party governance. If you embed an external model into your product — Claude, GPT, Gemini, an open-source model running on your own infrastructure — you own the assurance question for that model. The standard does not let you offload the answer to OpenAI, Anthropic, or Google. You can use their representations, but you have to evaluate them and keep records of having done so.
What it deliberately doesn't say
Now the part most write-ups skip.
The standard says almost nothing about specific technical controls. There is no list of "use these encryption settings, this red-team protocol, this benchmark." That work is left to other frameworks. NIST AI RMF — the voluntary US framework, with a function-based control catalog. The OWASP LLM Top 10 — the vulnerability classes specific to language-model applications. MITRE ATLAS — the adversarial-technique catalog for ML systems. Databricks' DASF — twelve AI system components mapped to 62 risks and 64 controls, with cross-references to most of the major standards. ISO 42001 sits above all of them. It requires that your management system addresses risks. It does not name the risks or the controls.
The standard also says very little about evidence format. It requires "documented information" — ISO-speak for records an auditor can examine. It does not specify what those records look like for AI specifically. The first wave of audits is going to be where evidence norms get set. The firms standing up practices right now are the ones who set them.
It doesn't tell you which AI use cases to allow or prohibit. It doesn't tell you what level of accuracy is enough. It doesn't name bias thresholds. Those decisions stay with your organization. The standard requires you to make them — and to record how.
The tension worth holding
The standard is short on technical prescription and long on operational proof. It tells you the management system must address risk, impact, lifecycle, third parties, and affected parties. It does not tell you how to prove any of it works. That gap — between requirement and evidence — is where the next 18 months get hard.
If you've already done ISO 27001, the management system discipline transfers. The lifecycle, impact-assessment, and third-party requirements will be the new work. If you haven't done 27001, the standard will feel heavier than it actually is — most of the weight is in the management system bones, not the AI-specific parts.
What to do this quarter
Three things worth doing while the standard is still new and the audit norms aren't fixed.
Read the standard yourself
Or have someone on your team who is going to own the program read it. The full text is under forty pages and reads in an afternoon. Secondary write-ups — this one included — are a starting point, not a substitute.
Map your AI inventory against the standard's lifecycle stages
Not "do we have AI?" but "for each AI use case in production, what records do we hold for design, deployment, operation, and change?" The gaps are usually obvious in 30 minutes.
Pick a framework partner for the technical layer
ISO 42001 doesn't fight with NIST AI RMF or DASF — it sits above them. Pick one technical framework to operationalize the controls layer, and document the mapping. The audit firms will be looking for that mapping.
If an auditor asked you tomorrow to show them the records of every AI decision that touched a customer this quarter — not the policy, the records — what would your team actually be able to produce?
For the firms doing these audits
This piece is for the mid-market companies that will sit through the 2027 audits. For the firms doing the auditing — how to scope and price ISO 42001 engagements, what evidence to sample, how the 2027-2030 market will differentiate — there's a separate four-part series written for that audience:
- Part 2: Scoping and Pricing ISO 42001 Audits — why "ISO 27001 plus 30%" mispricing fails by 50% or more, and what defensible pricing looks like.
- Part 3: An Evidence Field Guide — what to sample by clause and control category, and how to handle agentic AI traces specifically.
- Part 4: The 2027-2030 AI Audit Market — how firms will differentiate, the talent pipeline, and the pricing trajectory.
And a companion piece on the regulatory anchor that converts AI assurance from a voluntary standard into a binding compliance obligation: EU AI Act Article 12: AI Logging Requirements for Audit Firms and Their Clients.
Get ahead of the 2027 audits
ISO 42001 audits are coming, and the companies that will pass them are the ones building the evidence layer now — not in 2026 when the auditors are already at the door. vCISO Lite is the integrated platform mid-market companies run their security and compliance program on — purpose-built for the cross-framework evidence collection ISO 42001 will require.
If you're scoping ISO 42001 readiness for 2027, or building the AI governance layer your auditors will sample first, visit vcisolite.com to learn more and get started.
Where this matters next
Platform: APRI (AI-Powered Risk Intelligence) — the platform's Risk Intelligence MCP — how AI-decision provenance actually gets logged for a 42001 audit.
APRI: AI-Powered Risk Intelligence — the AI compliance-analyst surface designed to pass the 42001 provenance + oversight tests.