Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

ISO 42001 certification and EU AI Act readiness

The EU AI Act is already in force, and regulated buyers ask for evidence of AI controls. Get full certification support with Hacken so you end up with an AI Management System (AIMS) that meets both the ISO standard and the EU AI Act.

ISO 42001 certified
9
years in blockchain and security
2,168
assessments delivered
16,774
vulnerabilities identified
ISO 27001:2022SOC 2 Type II
Certified
BybitEBSiETH FoundationMetaMaskOKXSuiForgeADGM

For crypto, fintech, and SaaS teams shipping AI

Scope check

AI-system inventory, role and risk-tier map, go/hold decision

~1-2 weeks

Gap assessment

Gap report against ISO clauses and all 38 Annex A controls, plus live technical testing

~3-6 weeks

Full-cycle to certified

Remediation, AIMS build, internal audit, support through the external certification audit.

AI governance is now a deal requirement

AI governance moved out of the policy folder the moment it entered your customers' security questionnaires. Those now include a dedicated AI section: model inventory, training data provenance, human-oversight design, and sign-off before any model change ships. Regulators ask the same questions, with fines attached.

ISO 42001 lets you respond to buyers, regulators, and your own supply chain with a single auditable management system rather than a document set no one has tested.

Dmytro Yasmanovych

Dmytro Yasmanovych

Head of GRC & Security Operations, Hacken

"Most AI governance on the market is a folder of policies no one has attacked. We build the management system, then send the same engineers who red-team AI systems to prove the controls hold. Buyers and regulators can tell the difference."

We'll map your AI systems and tell you where you stand

Why does the EU AI Act set your ISO 42001 timeline?

ISO/IEC 42001:2023 is the first international standard for an AI management system, or AIMS. This standard is a governance framework covering how you assess AI risk, control data, document systems, keep humans in the loop, and monitor models after they ship.

The presumption-of-conformity gap

A certificate does not grant legal "presumption of conformity" with the Act. That effect only attaches to harmonised standards cited in the EU Official Journal, and none is published yet. Building on ISO 42001 now means the eventual delta to that standard is incremental, not a rebuild (see the FAQ).

EU AI Act timeline

1 Aug 2024In force

AI Act enters into force

2 Feb 2025Live

Prohibited practices (Art. 5) + AI literacy (Art. 4)

2 Aug 2025Live

GPAI model obligations (Art. 51–55), governance bodies, notified bodies, penalties

2 Aug 2026Live

General application — most of the Act, deployer transparency (Art. 50), public registration DB (Art. 49)

2 Dec 2026Hard deadline

AI-content watermarking / synthetic-media marking (Art. 50(2)); new Art. 5 ban on NCII/CSAM "nudifiers"

2 Aug 2027Upcoming

National AI regulatory sandboxes must be operational

2 Dec 2027Deferred

High-risk Annex III (stand-alone) systems — recruitment, credit, biometrics, etc. (deferred from Aug 2026)

2 Aug 2028Deferred

High-risk Annex I (AI embedded in regulated products) (deferred from Aug 2027)

Who needs ISO 42001?

Under the AI Act, the same company can be a provider for one model and a deployer for another. That distinction sets your obligations, so we classify every system before we scope anything.

Crypto-native AI

  • AI trading bots and automated execution — provider and deployer at once.
  • AI in custody and wallet operations — deployer of high-impact AI.
  • AI for AML and transaction monitoring — decision-making about people.
  • AI onboarding and KYC — deployer.

Teams building and shipping AI

  • Built or fine-tuned your own model — developer/provider, full lifecycle obligations.
  • "Prompt-to-app" products that generate apps for users — provider.
  • MCP servers and AI agents access client data — a high-risk pattern.
  • AI in payments and authentication — deployer of high-stakes AI.
  • An AI product making security or risk judgments, like an AI auditor.

What is required by the AI Act?

ISO 42001 does not automatically satisfy the AI Act, but its clauses and Annex A controls map cleanly onto the Act's core technical requirements, so one build serves both. Each row pairs the Act's requirement, the ISO 42001 control that supports it, and the tested evidence we hand you.

EU AI Act requirementISO 42001 control that supports itHacken deliverable
Risk management system (Art. 9)
AI risk assessment & treatment (6.1.2 / 8.2)
AI risk register + treatment plan
Data & data governance (Art. 10)
Data for AI systems (A.7)
Data for AI systems (A.7)
Record-keeping (Art. 12)
Event logging (A.6.2.8)
Logging design + evidence review
Transparency & human oversight (Art. 13–14)
Information for users + human oversight (A.8 / A.9)
Oversight controls + user-facing disclosures
Accuracy, robustness, cybersecurity (Art. 15)
Verification & validation (A.6.2.4)
Adversarial testing + robustness results
Technical documentation (Art. 11 / Annex IV)
Technical documentation (A.6.2.7)
Drafted technical file
Fundamental-rights impact assessment (Art. 27)
AI system impact assessment (8.14 / A.5)
Impact and fundamental-rights assessment
Value-chain obligations (distributed, e.g. Art. 25)
Third-party & supplier controls (A.10)
Supplier-control mapping
AI quality management system (Art. 17)
The whole AIMS
Operational AIMS, covering the Art. 17 documentation and post-market-monitoring elements explicitly

Build the controls and evidence needed for ISO 42001 and AI Act readiness

How the engagement works

Scope & classify

We inventory every AI system, determine your role per system (developer / provider / deployer), and classify each against the AI Act's risk tiers. You get: a scope memo, an AI-system risk-tier map, and a go/hold decision.

Phase 1

Gap & risk

We run a full gap analysis against the ISO 42001 clauses, all 38 Annex A controls, and the mapped AI Act articles, including technical testing of the actual systems, not a document review. You get: a prioritized gap report, a remediation roadmap, an AI risk register, and a drafted Statement of Applicability.

Phase 2

Remediate & implement

We close gaps, build tailored AIMS documentation that reflects your real stack, and stand up the controls. You get: an operational AIMS and evidence that the controls work.

Phase 3

Test, audit & certify

AI red teaming, adversarial testing, and secure machine-learning development review, then an internal audit and support through the external certification audit. You get: an ISO 42001 certificate with AI Act alignment already in place.

Phase 4

Then sustain: After certification, an AIMS has to keep running. Many teams keep us on through a virtual CISO engagement to own ongoing governance, monitoring, and the next audit cycle.

ISO 42001 deliverables

circle check iconAI Act risk-tier classification map
circle check iconISO 42001 applicability scope and a drafted Statement of Applicability
circle check iconPrioritized gap report against ISO clauses, the 38 Annex A controls, and mapped AI Act articles
circle check iconRemediation roadmap and AI risk register
circle check iconAdversarial-testing and AI red-team results as control evidence
circle check iconTailored AIMS documentation and a drafted technical file
circle check iconImpact and fundamental-rights assessment
circle check iconInternal audit report and support through the external certification audit
circle check iconAI inventory across your stack, with role determination.

Where to start?

Scope Check

Is your organisation in scope? Fixed-fee. AI inventory, per-system role determination, AI Act risk-tier classification, ISO 42001 applicability and Statement of Applicability scoping.

For: teams that need a go/hold decision before committing budget.

~1–2 weeksFixed-feeStarting from $5,000
Most popular

Gap Assessment

Full ISO 42001 and EU AI Act gap analysis against the clauses, all 38 Annex A controls, and mapped AI Act articles, plus technical testing of your actual systems. In the end, you will know your compliance gaps and roadmap for remediating them.

For: teams committed to certifying that need a costed, prioritized plan.

~3–6 weeksPricing scoped per engagementStarting from $15,000

Full-Cycle Project

"Take us all the way to certified. This full-cycle project guides your organization through the compliance process to achieve certification. The flow goes as follows: Gap analysis and → remediation → tailored documentation → AIMS implementation → technical testing → internal audit → support through the external certification audit, with AI Act readiness (technical files, impact assessments, conformity prep) built in.

For: teams that want one partner from scoping to certificate. Duration and pricing scoped to your AI inventory and target certificate

Starting from $30,000
Also available

Standalone AI red teaming and adversarial testing

for teams that already run an AIMS and need control evidence.

Why companies choose Hacken

Auditors and offensive engineers under one roof

The team that writes your controls is the team that attacks them: adversarial testing, prompt injection, model robustness, and agent/MCP exfiltration.

60+ security engineers in-house

Including CCSS Lead Auditors and the offensive specialists who run AI red teams - so your controls are built and tested by one bench, not a subcontracted chain.

Built for digital-asset-native compliance

We already certify against CCSS, MiCA, DORA, and VARA, so AI governance maps onto obligations you already carry rather than running as a parallel program.

Documentation built from the systems you actually run

Statement of Applicability, technical file, and risk register mapped to your real model inventory and data flows.

End to end

We stay through remediation, implementation, internal audit, and the external certification audit rather than stopping at a gap report.

Want to see where you stand?

Request a scoping call → and we'll size the work against your actual AI inventory.

FAQ

Usually yes, as a deployer. Using someone else's model to make or support decisions about people — onboarding, monitoring, credit, custody — carries deployer obligations under the AI Act, even though you did not build the model. Your role depends on how you use the system, not who trained it. A scope check settles this per system in about one to two weeks.
A scope check runs ~1–2 weeks on a fixed fee. A gap assessment runs ~3–6 weeks. A full-cycle project to certificate is scoped to your AI inventory and target certificate, so timeline and price depend on how many systems you run and how far off you start. There is no honest flat number before we see your stack.
Both, and that is the point. A document review confirms the paperwork exists; it does not prove the controls hold. We send the same engineers who red-team AI systems to test yours — adversarial inputs, prompt injection, model robustness, agent/MCP exfiltration — so your evidence is proof the controls hold under attack, not a binder of untested policy.
No standard automatically makes you AI Act compliant. ISO 42001 gives you the AI management system the Act assumes: risk management, data governance, documentation, human oversight, and post-market monitoring. Its controls map onto the Act's core technical articles — see the requirement-by-requirement table above. You still handle the Act's specific obligations for your role and risk tier. We scope both together so one build serves both.
Presumption of conformity only attaches to harmonised standards cited in the EU Official Journal, and none is published yet. The first candidate, prEN 18286 (a quality-management standard for Art. 17, written by CEN-CENELEC JTC 21), reached public enquiry stage in October 2025 and is designed to build directly on the AIMS structure defined in ISO 42001. It is still a draft. Certify to ISO 42001 now, and conformity to that standard later becomes an incremental delta, not a rebuild.
They cover different things. ISO 27001 governs information security; ISO 42001 governs AI-specific risk: model behaviour, the data used to train and run AI, human oversight, and post-market monitoring. If you handle sensitive data and ship AI, you likely want both, and they share management-system structure so the second build reuses much of the first. We run ISO 27001 and ISO 42001 with the same team.