/

  / ISO 42001 Consulting Cost for Mid-Sized Firms in 2026

ISO 42001 Consulting Cost for Mid-Sized Firms in 2026

Here are real numbers to anchor on: Axipro delivers ISO 42001 readiness for $4,000 if you’re under 50 employees and $5,500 if you’re over, and the GRC platform plus accredited audit adds roughly $4,000 to $7,000 on top. A mid-sized tech firm lands at around $10,000 to $15,000 all-in for year one. A small team comes in under $10,000.

The Average Cost of ISO 42001 Consulting

If you’ve been researching this topic, those figures probably look wrong to you. Published cost guides quote $85,000 to $320,000 for mid-market ISO 42001 certification. This article explains the gap: those guides price a traditional consulting-led engagement, where consultants bill day rates to build everything by hand. Automation-supported delivery, where a GRC platform collects the evidence and a fixed-fee team does the thinking, produces a completely different number. We break down both models phase by phase so you can budget against the delivery model you actually intend to buy.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

What ISO 42001 Consulting Includes for Mid-Sized Tech Firms

ISO/IEC 42001 is the first certifiable international standard for an AI Management System (AIMS). Published in December 2023, it applies the familiar ISO management system structure to AI governance: scoped policies, AI risk and impact assessments, Annex A controls, a Statement of Applicability, internal audits, and a two-stage certification audit by an accredited certification body.

Scope of Consulting Engagements

A typical engagement covers five things: scoping the AIMS and building an AI system inventory, running a gap analysis against the standard, designing and documenting the management system, supporting control rollout, and preparing for the Stage 1 and Stage 2 audits. Under the traditional model, consultants hand-build each phase and bill for the hours. Under the automation-supported model, a fixed-fee readiness package covers the same ground while the platform does the mechanical work.

Typical Deliverables from an ISO 42001 Consultant​

Expect a defined AIMS scope statement, an AI system inventory and risk register, AI impact assessments for in-scope systems, a policy and procedure set mapped to Annex A, a Statement of Applicability, training materials, an internal audit report, and audit-day support. If a proposal can’t name its deliverables this concretely, that tells you something about how well the consultant knows the standard.

How Mid-Sized Tech Firms Differ from Startups and Enterprises

Mid-sized firms sit in an awkward middle. They run more AI systems across more teams than a 15-person startup, so scoping, interviews, and evidence collection all take longer, and fixed-fee providers price them in a higher tier as a result. Unlike enterprises, though, they rarely need multi-site audit sampling or a dedicated AI governance function, so the six-figure quotes written for enterprises don’t apply to them either.

Average Cost of ISO 42001 Consulting

Typical Price Range for Mid-Sized Tech Firms​

Two delivery models, two price ranges.

Automation-supported, fixed-fee delivery: readiness consulting at $4,000 for companies under 50 employees and $5,500 for companies over 50, covering the engagement from gap analysis through certification support. The GRC platform and accredited audit add roughly $4,000 to $5,000, so a mid-sized firm’s first-year total comes to around $10,000 to $12,000.

Traditional consulting-led delivery: $25,000 to $80,000 in consulting fees alone for a mid-sized firm, built on day rates of $1,000 to $1,800 across 15 to 40 consultant days. This is the model behind the $85,000-plus totals in most published guides. It still makes sense in a few situations: on-prem infrastructure the platforms can’t see, heavy regulatory overlays, or a board that wants a named Big Four partner on the engagement.

The market is young enough that quotes for identical scope can differ by a factor of five. ISO 42001 certificates only started appearing in volume in 2024, and plenty of consultants quoting today have never taken a client through a Stage 2 audit.

Insider Note: When a mid-sized firm shows us a $90,000 quote for ISO 42001, the line items usually reveal hand-built work the platform now automates: manual evidence collection, policy drafting from scratch, spreadsheet-based risk registers. What you’re actually paying a consultant for is scoping, impact assessment methodology, and audit judgment. The mechanical work has been commoditized, and pricing that ignores this is pricing from 2023. 

Hourly vs Project-Based Consulting Rates

Experienced AI governance consultants charge $150 to $300 per hour in the North American and UK markets. Hourly billing works for targeted needs: reviewing an impact assessment methodology, answering auditor questions, validating a control design. For a full implementation it’s a false economy, since open-ended hours remove any incentive to compress the work. Fixed-fee delivery flips that incentive, and that’s a big part of why it prices so much lower.

Fixed-Fee vs Retainer Engagement Models

ModelTypical costBest forWatch out for
Fixed-fee readiness package$4,000 (under 50 employees) / $5,500 (over 50)First certification with defined scopePackages that exclude audit facilitation
Traditional fixed-fee project$25,000 to $80,000Complex scopes, heavy regulatory overlayPaying consulting rates for automatable work
Monthly retainer$2,000 to $8,000/monthSpreading work over 6 to 12 monthsEngagements that drift without a certification date
Hourly / ad hoc$150 to $300/hourTargeted reviews, audit-day supportCosts compounding on open-ended work
Fractional AI governance officer$3,000 to $10,000/monthPost-certification ownership without a hireThin coverage if the fractional lead is overloaded

Fixed-fee is the right default for a first certification. It moves delivery risk to the provider and forces both sides to agree scope upfront. Fractional arrangements earn their keep after certification, once the work shifts from building the AIMS to running it.

Cost Breakdown by Consulting Phase

The figures below show what each phase costs when you buy it separately from a traditional consultancy. Inside a fixed-fee package, all five phases sit within the single $4,000 or $5,500 engagement fee, and that’s exactly why the totals diverge so sharply.

Readiness and Gap Assessment Fees

Standalone price: $2,000 to $15,000, often more than an entire fixed-fee engagement. Either way, this is the highest-value work relative to its cost. The AI system inventory and gap analysis determine everything that follows, including whether you need the rest of the engagement at all.

AIMS Design and Documentation Support

Standalone price: $3,000 to $25,000 for the AI policy, risk methodology, impact assessment templates, lifecycle procedures, supplier controls, and Statement of Applicability. Platform policy templates adapted by a practitioner collapse most of this cost. Documentation written from a blank page is where traditional engagements burn the most billable days.

Implementation and Control Rollout

Standalone price: $4,000 to $20,000. The consultant supports training, model documentation practices, human oversight mechanisms, logging, and third-party AI supplier management. Your internal team does most of the actual work in this phase no matter which model you pick, so the real cost here is employee hours rather than fees.

Internal Audit and Pre-Certification Support

Standalone price: $2,000 to $10,000. ISO 42001 requires an internal audit that’s independent of the people who built the system, and that’s why most mid-sized firms outsource it. Axipro includes the internal audit within its end-to-end plans; bought alone, internal audit support starts from $1,000 for narrow scopes.

Post-Certification Advisory Costs

A few hundred dollars to $3,000 per month, depending on how much you keep in-house. Surveillance audits arrive annually, the AI inventory keeps changing, and impact assessments need refreshing whenever models or use cases change. Maintenance plans that bundle vCISO support and surveillance audit prep sit at the low end of that range. Standalone advisory retainers from traditional firms sit at the top.

Factors That Influence ISO 42001 Consulting Costs for Mid-Sized Tech Firms

Number of AI Systems and Use Cases in Scope

Scope is the single biggest cost driver at any company size. Each in-scope AI system needs an inventory entry, a risk assessment, an impact assessment, and lifecycle evidence. Ten systems cost meaningfully more to certify than three, and that shows up as more internal hours and more audit days even when the readiness fee is fixed.

Pro Tip: Certify a deliberately narrow scope first.

Certify a deliberately narrow scope first. Define the AIMS around your customer-facing AI products rather than every internal tool that touches a model, get certified, then expand scope at the first surveillance audit. Scope discipline is what keeps audit days, and therefore audit fees, at the bottom of the range.

Existing Maturity (ISO 27001, SOC 2, NIST AI RMF)

ISO 42001 shares its management system skeleton with ISO 27001: risk process, document control, internal audit, management review. Firms with a live ISO 27001 program typically cut ISO 42001 implementation effort by 40 to 60 percent, since they’re extending existing machinery instead of building it. SOC 2 helps less but still counts. Prior alignment with the NIST AI Risk Management Framework shortens the AI-specific work too, because the risk thinking is already done.

Company Headcount and Number of Business Units

Fixed-fee providers price on headcount because it’s a fair proxy for effort, and the under-50 and over-50 tiers reflect that. Structure matters more than the raw number, though. A 300-person firm with one product line certifies faster than a 120-person firm with four business units each running its own AI experiments, because every extra unit adds interviews, evidence owners, and coordination overhead.

Geographic Footprint and Multi-Site Operations

Multiple offices raise audit costs. Certification bodies sample sites during Stage 2 and surveillance audits, and controls have to demonstrably operate the same way everywhere. A firm with offices across the US, UK, and the Gulf should expect the audit component to run 15 to 30 percent above single-site equivalents.

Regulatory Exposure (EU AI Act, Sector-Specific Rules)

The EU AI Act’s main obligations entered into application on 2 August 2026, and enforcement now runs at national and EU level, even as the Commission’s Digital Omnibus proposal would tie the high-risk rules to the availability of harmonized standards. If your product qualifies as a high-risk AI system, you face conformity work that overlaps with ISO 42001 but goes beyond it, and providers price that extra work in.

Important: ISO 42001 certification doesn’t equal EU AI Act compliance. The standard is a management system framework; the Act imposes product-level legal requirements on specific systems. A consultant selling certification as an AI Act compliance solution is either confused or overselling, and both should worry you.

In-House GRC Capacity vs Full Outsourcing

A firm with a competent GRC lead who can own evidence collection and policy adaptation needs 30 to 50 percent fewer external hours than a firm outsourcing everything. Under a fixed-fee model this mostly changes how fast the engagement moves rather than what it costs, which is one more point in favor of fixed fees.

Consulting Cost vs Total ISO 42001 Investment

Consulting Fees as a Percentage of Total Certification Budget

Under the traditional model, consulting eats 30 to 50 percent of the total budget. Under the automation-supported model you can see the split in the sticker prices: a $5,500 readiness fee against roughly $4,000 to $5,000 in platform and audit costs, so consulting is about half of a much smaller total.

How Consulting Costs Compare to Audit and GRC Platform Costs

Cost componentAutomation-supported (mid-market)Traditional consulting-led (mid-market)
Consulting / readiness$5,500 ($4,000 under 50 employees)$25,000 to $80,000
GRC platform + accredited audit$4,000 to $5,000 combined$25,000 to $70,000 combined
Internal staff time150 to 400 hours300 to 800 hours
Indicative first-year total~$10,000 to $12,000$60,000 to $150,000

The gap between the columns is real, not padding. Narrow, well-prepared scopes need fewer audit days, and audit days are what certification bodies actually sell. In either model, the certification body must be independent of your consultant. Anyone offering to both implement and certify your AIMS is offering something accreditation rules don’t permit, and a certificate from an unaccredited body carries little weight in enterprise procurement.

Hidden Costs Mid-Sized Firms Often Overlook

Three costs surprise mid-market buyers most often. First, internal time: engineers and product owners spend real hours producing evidence, and that time has a payroll cost even though no invoice arrives. Second, the operating window. The AIMS has to run long enough to generate audit evidence before Stage 2, which stretches the calendar past the point where fees stop. Our breakdown of how long ISO 42001 certification takes covers why that window, not documentation, is usually the long pole. Third, surveillance: annual surveillance audits and program upkeep continue every year the certificate lives.

How Mid-Sized Tech Firms Can Reduce ISO 42001 Consulting Costs

Leveraging Existing ISO 27001 or SOC 2 Programs

Reuse is the biggest lever you have. Extend your existing risk methodology, document control, internal audit program, and management review to cover AI rather than duplicating them. If you’re weighing both frameworks, read our ISO 27001 certification cost breakdown, because bundling the two with one implementation partner and one audit firm commonly saves 20 to 30 percent against running them separately.

Choosing Modular vs Full-Service Consulting

When full-service delivery costs $4,000 to $5,500, the case for buying phases piecemeal mostly disappears. A standalone gap assessment from a traditional firm can cost more than an entire fixed-fee engagement. Modular buying still makes sense if you only need one independent piece, typically the internal audit. If you want to understand what each phase involves before committing either way, our step-by-step ISO 42001 implementation guide maps the full sequence.

Combining Consulting with GRC Automation Platforms

This stopped being a cost-reduction tactic a while ago. It’s the baseline now. GRC platforms such as Drata and Vanta ship ISO 42001 frameworks with automated evidence collection and pre-built policy templates, and the pricing difference between the two columns in the table above is mostly this. The platform handles evidence and monitoring; the consultant handles scoping, impact assessments, and audit judgment. Paying consulting day rates for work the platform automates is the single most common budgeting mistake in this market.

Training Internal Staff to Reduce Consultant Hours

Sending one person through an ISO 42001 lead implementer or lead auditor course costs $800 to $2,500. At traditional day rates that training pays back within the first engagement. Under a fixed-fee model its value shows up afterward, in keeping the AIMS running between audits and shrinking the post-certification support you need.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

When Hiring an ISO 42001 Consultant Is Worth the Cost

Speed to Certification vs DIY Approaches

A supported mid-market engagement typically reaches certification readiness in 6 to 12 weeks of active work, with the full calendar to certificate running 4 to 8 months once you count the evidence window and audit scheduling. DIY efforts routinely take 9 to 15 months, mostly lost to scoping mistakes, rewritten documentation, and evidence gaps discovered at Stage 1. At a $4,000 to $5,500 readiness fee, the support pays for itself in calendar time alone if a deal is waiting on the certificate.

Reducing Audit Failure Risk

The expensive failure mode isn’t a failed audit. It’s a delayed one. Major nonconformities at Stage 2 trigger remediation, re-audit fees, and a slipped certificate date. Experienced implementers know where auditors probe and build the evidence trail accordingly, and a provider that’s confident in its process can put a certification guarantee behind the engagement.

Worth Knowing: Stage 1 Finding

The most common Stage 1 finding we see on AI management systems is an AI impact assessment that’s really an information security risk assessment with the word AI inserted. Auditors check whether the assessment considers affected individuals and societal impact, not just organizational risk, and a copied-over ISO 27001 methodology fails that test.

ROI for Sales, Procurement, and Enterprise Deals

ISO 42001 requests now show up in security questionnaires and RFPs that never mentioned AI before 2025, particularly from EU and regulated-industry buyers. When total certification cost sits around $10,000 to $12,000, a single unblocked enterprise deal covers it many times over. That arithmetic, not regulatory fear, is what drives most of the mid-market certifications we see.

How to Choose the Right ISO 42001 Consultant for a Mid-Sized Tech Firm

Qualifications and AI Governance Experience

Look for three things together: management system implementation experience (ISO 27001 pedigree counts), genuine AI literacy (can they discuss model lifecycle risks for your specific stack, not generically), and at least one completed ISO 42001 certification. Two of three is workable if the price reflects it. One of three means you’re funding their training.

Questions to Ask Before Signing an Engagement

Ask how many ISO 42001 certifications they’ve delivered end to end, which certification bodies they’ve worked with, whether the platform subscription and audit facilitation sit inside or outside the quoted fee, who actually does the work (partner or junior staff), and how they handle scope changes mid-engagement. Ask for a reference from a certified client of similar size.

Red Flags in Consulting Proposals

Walk away from proposals that certify through an affiliated certification body, quote a price without asking about your AI inventory, or bundle vague “AI Act compliance” into scope without naming which obligations. And judge cheap quotes by their deliverables rather than their price tag. A $4,000 fixed fee backed by a named deliverables list, a platform, and completed certifications is a delivery model. A $4,000 quote with none of those is a template dump, and auditors have learned to spot them.

The honest summary: ISO 42001 doesn’t have one average cost. It has two. Traditional consulting-led delivery runs $25,000 to $80,000 in fees for a mid-sized tech firm, with first-year totals of $60,000 to $150,000. Automation-supported fixed-fee delivery runs $4,000 for companies under 50 employees and $5,500 over 50, with the platform and accredited audit adding $4,000 to $5,000, for a total around $10,000 to $12,000. Which number applies to you comes down to scope discipline, existing ISO 27001 maturity, and whether you insist on paying day rates for automatable work. If you want a scoped quote rather than a range, Axipro’s ISO 42001 consulting and implementation services run from standalone readiness assessments to end-to-end delivery with guaranteed certification on the Achievement Plan.

Frequently Asked Questions

What is the average hourly rate for an ISO 42001 consultant?

Experienced AI governance consultants charge $150 to $300 per hour in the US and UK markets in 2026. Most certification work has moved to fixed-fee packages, which start at $4,000 for companies under 50 employees and $5,500 above that, so hourly billing is now mainly for targeted reviews and audit-day support rather than full implementations.

Six to twelve weeks of active implementation work, inside a 4 to 8 month calendar from kickoff to certificate. The constraint is rarely the consulting itself. The AIMS has to operate long enough to generate the evidence auditors need at Stage 2, and firms with an existing ISO 27001 program land at the short end.

Yes, and you usually should. The standards share the same management system structure, so one partner can integrate the two programs, reuse documentation, and coordinate combined audits. Bundling both frameworks commonly saves 20 to 30 percent against separate engagements.

Implementation is one-time, but the certificate creates recurring costs: annual surveillance audits, recertification every three years, and program upkeep. Many mid-sized firms cover this with a light monthly maintenance plan rather than staffing AI governance internally, at a fraction of the original implementation fee per year.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

A consultant-grade ISO 42001 gap analysis checklist has 38 Annex A controls, roughly 80 clause-level “shall” statements, and one question attached to every line: where is the evidence, and would a certification body accept it? That last question is what separates the checklists consultants use from the free self-assessment spreadsheets that rank for the same search. This article lays out the checklist itself: what a consultant checks before the engagement starts, the clause-by-clause and control-by-control checkpoints, how evidence gets sampled, how gaps get scored, what the deliverables look like, and what fails most often. Use it to run your own assessment, or to check whether the consultant you’re about to hire is doing the job properly. What Makes a Consultant-Grade ISO 42001 Gap Analysis Checklist Different​ Depth of Evidence Review vs. Self-Assessment Tools A self-assessment tool asks whether you have an AI policy. A consultant asks to see it, checks the approval date and version, reads clause 5.2 against it, and then asks three people in engineering whether they’ve read it. The checklist item is the same. The evidence standard is not. Consultants score every item on three levels: documented, implemented, and effective. A policy that exists but nobody follows scores as “ad hoc,” not “defined.” A control that runs but produces no record scores as unverifiable, which for audit purposes is the same as absent. Self-assessment tools collapse those three levels into a single yes/no, which is why companies that score 85% on a free tool routinely receive major nonconformities at Stage 2. Alignment with Certification Body Expectations Certification bodies auditing against ISO/IEC 42001:2023 now work under ISO/IEC 42006:2025, which sets competence, audit-time, and impartiality requirements for AIMS auditors and builds on ISO/IEC 17021-1. A consultant-grade checklist is written with 42006 in mind: it organizes findings by clause and control identifier, because that’s how the auditor works, and it records evidence locations, because that’s what the auditor will sample. The practical difference shows up in the report. A gap register that says “AI governance needs improvement” is useless in front of an auditor. One that says “A.5.2 not conformant: no documented impact assessment process; two of four in-scope systems have no assessment on file” maps directly to the audit plan. Risk-Weighted Scoring Methodology Self-assessments count gaps. Consultants weight them. A missing AI policy under clause 5.2 and an incomplete competence matrix under 7.2 are both gaps, but the first will block certification and the second will earn you a minor finding. A consultant-grade checklist carries two scores per line: a maturity rating (how far the control is from working) and a certification criticality (what happens at audit if it stays this way). Effort estimates live in the remediation plan, never in the gap score, because mixing them produces a roadmap that fixes easy things first rather than important ones. Insider Note: The fastest tell that a checklist is consultant-grade rather than a marketing download is whether it has a column for evidence location. Auditors don’t accept “yes” as evidence. If the checklist has nowhere to record where the proof lives, it wasn’t built by someone who has sat through a Stage 2. Pre-Engagement Preparation Consultants Complete Before the Gap Analysis Client AI Inventory and Use Case Cataloging Nothing in the checklist works without a complete AI inventory, and it’s the input clients get wrong most often. The inventory records every AI system in use: purpose, the role you play (developer, provider, deployer, or user), data consumed, outputs produced, whether a human sits between the output and the decision, and which third-party model or API it depends on. Consultants push hard on shadow AI here: SaaS tools that added AI features, agents running under employee credentials, and internal scripts calling model APIs. Every one of those is in scope until you document why it isn’t. Defining AIMS Scope Boundaries Clause 4.3 requires a scope statement naming which AI systems, business units, locations, and lifecycle stages the AIMS covers. Consultants draft this from the inventory, not before it. Scope discipline matters commercially too: certification bodies price audits by audit days, and audit days scale with scope. A narrow, well-justified first scope (the customer-facing AI product, say, rather than every internal tool) is usually the right call for a first certification. Stakeholder Interview Planning The checklist needs answers from people who don’t write policies. A typical interview plan covers the executive sponsor (clause 5), the AI or product lead (clauses 6 and 8), data engineering (A.7), procurement or vendor management (A.10), legal or privacy (A.5, A.8), and at least one front-line user of the AI system (A.9). Consultants interview the doers separately from the document owners, because the distance from what the procedure says to what actually happens is the finding. Document Request List (DRL) Consultants Send Clients The DRL goes out one to two weeks before fieldwork. A standard ISO 42001 DRL asks for the AI inventory; existing AI, security, and data policies; org chart with AI governance roles; any AI risk assessments or impact assessments; model documentation (model cards, system cards, or whatever exists); training-data provenance and data quality records; supplier contracts for third-party models; incident and change logs; training records; any ISO 27001 ISMS documentation; and the last internal audit and management review minutes if they exist. Missing items become findings rather than delays. Pro Tip: Return an Honest DRL Return the DRL with a column that says “does not exist” wherever that’s true. Consultants would rather know on day one than discover it in a workshop. An honest DRL shortens fieldwork by days and makes the maturity scores more accurate, which makes the remediation plan cheaper. Clause-by-Clause Checklist Consultants Use (ISO 42001 Clauses 4 to 10) ISO 42001 follows the Harmonized Structure shared with ISO 27001 and ISO 9001, so clauses 4 to 10 will look familiar to anyone who has run an ISMS. What’s different is the content each clause demands. Clause 4 – Context of the Organization Checkpoints Consultants check for a documented analysis of

Scigeniq, a UAE life sciences software vendor, completed SOC 2 Type 2 and ISO 27001 in one three-month engagement with Axipro and Vamu.

ISO/IEC 42001:2023 asks for three assessments, and most teams try to squeeze them into one spreadsheet: a gap analysis against clauses 4 to 10 and Annex A, an AI risk assessment under clause 6.1.2, and an AI system impact assessment under clause 6.1.4. Treat them as one exercise and the auditor pulls them apart for you at Stage 2. Treat them as three unrelated projects and you triple the workshops, the registers, and the remediation lists. What works is a single methodology with distinct outputs that share inputs, share a traceability matrix, and feed one remediation plan. This article lays out that methodology end to end: how gap analysis and risk assessment fit together under ISO 42001, how to prepare, the step-by-step process for each, how to merge the outputs into one risk treatment plan, the registers and templates you’ll need, and what a certification body expects to see when you’re done. Why Gap Analysis and Risk Assessment Must Work Together Under ISO 42001 A gap analysis measures distance from the standard. A risk assessment measures exposure from your AI systems. They answer different questions, and ISO 42001 makes them depend on each other in a way ISO 27001 only implies. Clause 6.1.3 requires you to compare the controls you select through risk treatment against Annex A, and to justify any Annex A control you leave out in the Statement of Applicability (SoA). So your Annex A gap analysis has no defensible baseline until the risk assessment tells you which controls you need. Run the gap analysis on its own, and you end up scoring yourself against all 38 controls, including ones your risk profile never called for. Run the risk assessment on its own, and you pick treatments with no idea what already exists to deliver them. The methodology below interleaves the two. A clause-level gap review sets the scope and evidence base, the risk and impact assessments decide which controls are required, and a control-level gap review then scores only what matters. How AI-specific risks shape the methodology Traditional information security risk works from confidentiality, integrity, and availability. AI risk adds categories that don’t map neatly onto any of those: model drift, bias in training data, outputs nobody can explain, automation bias in the humans doing the reviewing, and dependence on third-party foundation models whose behavior changes without warning. ISO/IEC 23894, the companion guidance on AI risk management, adapts the ISO 31000 cycle (establish context, identify, analyze, evaluate, treat) to these sources rather than inventing a new one. That’s why the methodology here keeps the familiar ISO 31000 shape and changes the inputs, not the process. Regulatory and business drivers for a formal methodology The commercial driver is procurement. Enterprise security questionnaires now ask whether you ran an AI impact assessment, whether a human reviews high-stakes outputs, and which third-party models touch customer data. A documented methodology answers those questions with evidence instead of assurances. The regulatory driver is the EU AI Act, and its timeline moved in July. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on July 27, 2026, and pushed the high-risk obligations for standalone Annex III systems from August 2, 2026 to December 2, 2027. Annex I embedded systems moved to August 2, 2028. The Article 50 transparency obligations still kicked in on August 2, 2026, as originally planned. Article 9 of the AI Act text on EUR-Lex requires a risk management system for high-risk AI that runs continuously across the system lifecycle, which is exactly what an ISO 42001 methodology gives you. Sixteen extra months is time to build it properly, not a reason to shelve it. Core Principles of an ISO 42001 Gap Analysis and Risk Assessment Methodology Four principles keep the methodology defensible in front of a certification body. Alignment with clauses 4 to 10 and Annex A. Every finding in the gap register cites a clause or an Annex A control identifier. Auditors work clause by clause, so a gap register organized any other way forces a translation step during the audit that nobody enjoys. Integration with the AI system impact assessment. Clause 6.1.4 is what separates ISO 42001 from every other Annex SL standard. The impact assessment looks outward at individuals, groups, and society. The risk assessment under 6.1.2 looks inward at the organization. The standard wants both as separate documented outputs, and the consequences you find in the impact assessment have to feed back into the risk assessment. So the methodology runs the impact assessment as a scheduled input to risk analysis, not something bolted on the week before the audit. Risk-based thinking applied to the AIMS itself. Clause 6.1.1 also asks you to consider risks and opportunities to the management system: someone leaving the AI governance function, a vendor retiring a model, a regulator changing its classification rules. These go in the same register with a different category tag. Defined inputs, outputs, and success criteria. Inputs are the AI system inventory, the scope statement, existing policies, data flow diagrams, model documentation, and your risk criteria. Outputs are the gap register, the AI risk register, impact assessment reports, the SoA, and the risk treatment plan. Success means each output traces to the others, every gap and risk has an owner, and an internal auditor could repeat the process and land somewhere similar. Insider Note: Impact assessments are where certification auditors probe hardest, because they’re the most distinctive part of ISO 42001 compared with ISO 27001. A recycled security risk register with “AI” pasted into the risk titles gets picked apart in Stage 2. Build the impact assessment methodology properly the first time. It’s far cheaper than rebuilding it under a nonconformity deadline. Preparing for the Gap Analysis and Risk Assessment Preparation is where most of the calendar time goes, and where most later problems start. Define scope, boundaries, and the AI system inventory. Scope under clause 4.3 has to name which AI systems, business units, and lifecycle stages the AIMS covers. You can’t write