ISO 42001 certification and EU AI Act readiness
The EU AI Act is already in force, and regulated buyers ask for evidence of AI controls. Get full certification support with Hacken so you end up with an AI Management System (AIMS) that meets both the ISO standard and the EU AI Act.

- 9
- years in blockchain and security
- 2,109
- assessments delivered
- 15,975
- vulnerabilities identified
- ISO 27001:2022SOC 2 Type II
- Certified








For crypto, fintech, and SaaS teams shipping AI
Scope check
AI-system inventory, role and risk-tier map, go/hold decision
~1-2 weeksGap assessment
Gap report against ISO clauses and all 38 Annex A controls, plus live technical testing
~3-6 weeksFull-cycle to certified
Remediation, AIMS build, internal audit, support through the external certification audit.
AI governance is now a deal requirement
AI governance moved out of the policy folder the moment it entered your customers' security questionnaires. Those now include a dedicated AI section: model inventory, training data provenance, human-oversight design, and sign-off before any model change ships. Regulators ask the same questions, with fines attached.
ISO 42001 lets you respond to buyers, regulators, and your own supply chain with a single auditable management system rather than a document set no one has tested.

"Most AI governance on the market is a folder of policies no one has attacked. We build the management system, then send the same engineers who red-team AI systems to prove the controls hold. Buyers and regulators can tell the difference."
Why does the EU AI Act set your ISO 42001 timeline?
ISO/IEC 42001:2023 is the first international standard for an AI management system, or AIMS. This standard is a governance framework covering how you assess AI risk, control data, document systems, keep humans in the loop, and monitor models after they ship.
The presumption-of-conformity gap
A certificate does not grant legal "presumption of conformity" with the Act. That effect only attaches to harmonised standards cited in the EU Official Journal, and none is published yet. Building on ISO 42001 now means the eventual delta to that standard is incremental, not a rebuild (see the FAQ).
EU AI Act timeline
AI Act enters into force
Prohibited practices (Art. 5) + AI literacy (Art. 4)
GPAI model obligations (Art. 51–55), governance bodies, notified bodies, penalties
General application — most of the Act, deployer transparency (Art. 50), public registration DB (Art. 49)
AI-content watermarking / synthetic-media marking (Art. 50(2)); new Art. 5 ban on NCII/CSAM "nudifiers"
National AI regulatory sandboxes must be operational
High-risk Annex III (stand-alone) systems — recruitment, credit, biometrics, etc. (deferred from Aug 2026)
High-risk Annex I (AI embedded in regulated products) (deferred from Aug 2027)
Who needs ISO 42001?
Under the AI Act, the same company can be a provider for one model and a deployer for another. That distinction sets your obligations, so we classify every system before we scope anything.
Crypto-native AI
AI trading bots and automated execution — provider and deployer at once.
AI in custody and wallet operations — deployer of high-impact AI.
AI for AML and transaction monitoring — decision-making about people.
AI onboarding and KYC — deployer.
Teams building and shipping AI
Built or fine-tuned your own model — developer/provider, full lifecycle obligations.
"Prompt-to-app" products that generate apps for users — provider.
MCP servers and AI agents access client data — a high-risk pattern.
AI in payments and authentication — deployer of high-stakes AI.
An AI product making security or risk judgments, like an AI auditor.
What is required by the AI Act?
ISO 42001 does not automatically satisfy the AI Act, but its clauses and Annex A controls map cleanly onto the Act's core technical requirements, so one build serves both. Each row pairs the Act's requirement, the ISO 42001 control that supports it, and the tested evidence we hand you.
How the engagement works
Scope & classify
We inventory every AI system, determine your role per system (developer / provider / deployer), and classify each against the AI Act's risk tiers. You get: a scope memo, an AI-system risk-tier map, and a go/hold decision.
Gap & risk
We run a full gap analysis against the ISO 42001 clauses, all 38 Annex A controls, and the mapped AI Act articles, including technical testing of the actual systems, not a document review. You get: a prioritized gap report, a remediation roadmap, an AI risk register, and a drafted Statement of Applicability.
Remediate & implement
We close gaps, build tailored AIMS documentation that reflects your real stack, and stand up the controls. You get: an operational AIMS and evidence that the controls work.
Test, audit & certify
AI red teaming, adversarial testing, and secure machine-learning development review, then an internal audit and support through the external certification audit. You get: an ISO 42001 certificate with AI Act alignment already in place.
Then sustain: After certification, an AIMS has to keep running. Many teams keep us on through a virtual CISO engagement to own ongoing governance, monitoring, and the next audit cycle.
ISO 42001 deliverables

Where to start?
Scope Check
Is your organisation in scope? Fixed-fee. AI inventory, per-system role determination, AI Act risk-tier classification, ISO 42001 applicability and Statement of Applicability scoping.
For: teams that need a go/hold decision before committing budget.
Gap Assessment
Full ISO 42001 and EU AI Act gap analysis against the clauses, all 38 Annex A controls, and mapped AI Act articles, plus technical testing of your actual systems. In the end, you will know your compliance gaps and roadmap for remediating them.
For: teams committed to certifying that need a costed, prioritized plan.
Full-Cycle Project
"Take us all the way to certified. This full-cycle project guides your organization through the compliance process to achieve certification. The flow goes as follows: Gap analysis and → remediation → tailored documentation → AIMS implementation → technical testing → internal audit → support through the external certification audit, with AI Act readiness (technical files, impact assessments, conformity prep) built in.
For: teams that want one partner from scoping to certificate. Duration and pricing scoped to your AI inventory and target certificate
Standalone AI red teaming and adversarial testing
for teams that already run an AIMS and need control evidence.
Why companies choose Hacken
Auditors and offensive engineers under one roof
The team that writes your controls is the team that attacks them: adversarial testing, prompt injection, model robustness, and agent/MCP exfiltration.
60+ security engineers in-house
Including CCSS Lead Auditors and the offensive specialists who run AI red teams - so your controls are built and tested by one bench, not a subcontracted chain.
Built for digital-asset-native compliance
We already certify against CCSS, MiCA, DORA, and VARA, so AI governance maps onto obligations you already carry rather than running as a parallel program.
Documentation built from the systems you actually run
Statement of Applicability, technical file, and risk register mapped to your real model inventory and data flows.
End to end
We stay through remediation, implementation, internal audit, and the external certification audit rather than stopping at a gap report.
Want to see where you stand?
Request a scoping call → and we'll size the work against your actual AI inventory.



