Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

ISO 42001 certification and EU AI Act readiness

The EU AI Act is already in force, and regulated buyers ask for evidence of AI controls. Get full certification support with Hacken so you end up with an AI Management System (AIMS) that meets both the ISO standard and the EU AI Act.

ISO 42001 certified
9
years in blockchain and security
2,109
assessments delivered
15,975
vulnerabilities identified
ISO 27001:2022SOC 2 Type II
Certified
BybitEBSiETH FoundationMetaMaskOKXSuiForgeADGM

For crypto, fintech, and SaaS teams shipping AI

Scope check

AI-system inventory, role and risk-tier map, go/hold decision

~1-2 weeks

Gap assessment

Gap report against ISO clauses and all 38 Annex A controls, plus live technical testing

~3-6 weeks

Full-cycle to certified

Remediation, AIMS build, internal audit, support through the external certification audit.

AI governance is now a deal requirement

AI governance moved out of the policy folder the moment it entered your customers' security questionnaires. Those now include a dedicated AI section: model inventory, training data provenance, human-oversight design, and sign-off before any model change ships. Regulators ask the same questions, with fines attached.

ISO 42001 lets you respond to buyers, regulators, and your own supply chain with a single auditable management system rather than a document set no one has tested.

Dmytro Yasmanovych

Dmytro Yasmanovych

Head of GRC & Security Operations, Hacken

"Most AI governance on the market is a folder of policies no one has attacked. We build the management system, then send the same engineers who red-team AI systems to prove the controls hold. Buyers and regulators can tell the difference."

We'll map your AI systems and tell you where you stand

Why does the EU AI Act set your ISO 42001 timeline?

ISO/IEC 42001:2023 is the first international standard for an AI management system, or AIMS. This standard is a governance framework covering how you assess AI risk, control data, document systems, keep humans in the loop, and monitor models after they ship.

The presumption-of-conformity gap

A certificate does not grant legal "presumption of conformity" with the Act. That effect only attaches to harmonised standards cited in the EU Official Journal, and none is published yet. Building on ISO 42001 now means the eventual delta to that standard is incremental, not a rebuild (see the FAQ).

EU AI Act timeline

1 Aug 2024In force

AI Act enters into force

2 Feb 2025Live

Prohibited practices (Art. 5) + AI literacy (Art. 4)

2 Aug 2025Live

GPAI model obligations (Art. 51–55), governance bodies, notified bodies, penalties

2 Aug 2026Live

General application — most of the Act, deployer transparency (Art. 50), public registration DB (Art. 49)

2 Dec 2026Hard deadline

AI-content watermarking / synthetic-media marking (Art. 50(2)); new Art. 5 ban on NCII/CSAM "nudifiers"

2 Aug 2027Upcoming

National AI regulatory sandboxes must be operational

2 Dec 2027Deferred

High-risk Annex III (stand-alone) systems — recruitment, credit, biometrics, etc. (deferred from Aug 2026)

2 Aug 2028Deferred

High-risk Annex I (AI embedded in regulated products) (deferred from Aug 2027)

Who needs ISO 42001?

Under the AI Act, the same company can be a provider for one model and a deployer for another. That distinction sets your obligations, so we classify every system before we scope anything.

Crypto-native AI

  • AI trading bots and automated execution — provider and deployer at once.
  • AI in custody and wallet operations — deployer of high-impact AI.
  • AI for AML and transaction monitoring — decision-making about people.
  • AI onboarding and KYC — deployer.

Teams building and shipping AI

  • Built or fine-tuned your own model — developer/provider, full lifecycle obligations.
  • "Prompt-to-app" products that generate apps for users — provider.
  • MCP servers and AI agents access client data — a high-risk pattern.
  • AI in payments and authentication — deployer of high-stakes AI.
  • An AI product making security or risk judgments, like an AI auditor.

What is required by the AI Act?

ISO 42001 does not automatically satisfy the AI Act, but its clauses and Annex A controls map cleanly onto the Act's core technical requirements, so one build serves both. Each row pairs the Act's requirement, the ISO 42001 control that supports it, and the tested evidence we hand you.

EU AI Act requirementISO 42001 control that supports itHacken deliverable
Risk management system (Art. 9)
AI risk assessment & treatment (6.1.2 / 8.2)
AI risk register + treatment plan
Data & data governance (Art. 10)
Data for AI systems (A.7)
Data for AI systems (A.7)
Record-keeping (Art. 12)
Event logging (A.6.2.8)
Logging design + evidence review
Transparency & human oversight (Art. 13–14)
Information for users + human oversight (A.8 / A.9)
Oversight controls + user-facing disclosures
Accuracy, robustness, cybersecurity (Art. 15)
Verification & validation (A.6.2.4)
Adversarial testing + robustness results
Technical documentation (Art. 11 / Annex IV)
Technical documentation (A.6.2.7)
Drafted technical file
Fundamental-rights impact assessment (Art. 27)
AI system impact assessment (8.14 / A.5)
Impact and fundamental-rights assessment
Value-chain obligations (distributed, e.g. Art. 25)
Third-party & supplier controls (A.10)
Supplier-control mapping
AI quality management system (Art. 17)
The whole AIMS
Operational AIMS, covering the Art. 17 documentation and post-market-monitoring elements explicitly

Build the controls and evidence needed for ISO 42001 and AI Act readiness

How the engagement works

Scope & classify

We inventory every AI system, determine your role per system (developer / provider / deployer), and classify each against the AI Act's risk tiers. You get: a scope memo, an AI-system risk-tier map, and a go/hold decision.

Phase 1

Gap & risk

We run a full gap analysis against the ISO 42001 clauses, all 38 Annex A controls, and the mapped AI Act articles, including technical testing of the actual systems, not a document review. You get: a prioritized gap report, a remediation roadmap, an AI risk register, and a drafted Statement of Applicability.

Phase 2

Remediate & implement

We close gaps, build tailored AIMS documentation that reflects your real stack, and stand up the controls. You get: an operational AIMS and evidence that the controls work.

Phase 3

Test, audit & certify

AI red teaming, adversarial testing, and secure machine-learning development review, then an internal audit and support through the external certification audit. You get: an ISO 42001 certificate with AI Act alignment already in place.

Phase 4

Then sustain: After certification, an AIMS has to keep running. Many teams keep us on through a virtual CISO engagement to own ongoing governance, monitoring, and the next audit cycle.

ISO 42001 deliverables

circle check iconAI Act risk-tier classification map
circle check iconISO 42001 applicability scope and a drafted Statement of Applicability
circle check iconPrioritized gap report against ISO clauses, the 38 Annex A controls, and mapped AI Act articles
circle check iconRemediation roadmap and AI risk register
circle check iconAdversarial-testing and AI red-team results as control evidence
circle check iconTailored AIMS documentation and a drafted technical file
circle check iconImpact and fundamental-rights assessment
circle check iconInternal audit report and support through the external certification audit
circle check iconAI inventory across your stack, with role determination.

Where to start?

Scope Check

Is your organisation in scope? Fixed-fee. AI inventory, per-system role determination, AI Act risk-tier classification, ISO 42001 applicability and Statement of Applicability scoping.

For: teams that need a go/hold decision before committing budget.

~1–2 weeksFixed-feeStarting from $5,000
Most popular

Gap Assessment

Full ISO 42001 and EU AI Act gap analysis against the clauses, all 38 Annex A controls, and mapped AI Act articles, plus technical testing of your actual systems. In the end, you will know your compliance gaps and roadmap for remediating them.

For: teams committed to certifying that need a costed, prioritized plan.

~3–6 weeksPricing scoped per engagementStarting from $15,000

Full-Cycle Project

"Take us all the way to certified. This full-cycle project guides your organization through the compliance process to achieve certification. The flow goes as follows: Gap analysis and → remediation → tailored documentation → AIMS implementation → technical testing → internal audit → support through the external certification audit, with AI Act readiness (technical files, impact assessments, conformity prep) built in.

For: teams that want one partner from scoping to certificate. Duration and pricing scoped to your AI inventory and target certificate

Starting from $30,000
Also available

Standalone AI red teaming and adversarial testing

for teams that already run an AIMS and need control evidence.

Why companies choose Hacken

Auditors and offensive engineers under one roof

The team that writes your controls is the team that attacks them: adversarial testing, prompt injection, model robustness, and agent/MCP exfiltration.

60+ security engineers in-house

Including CCSS Lead Auditors and the offensive specialists who run AI red teams - so your controls are built and tested by one bench, not a subcontracted chain.

Built for digital-asset-native compliance

We already certify against CCSS, MiCA, DORA, and VARA, so AI governance maps onto obligations you already carry rather than running as a parallel program.

Documentation built from the systems you actually run

Statement of Applicability, technical file, and risk register mapped to your real model inventory and data flows.

End to end

We stay through remediation, implementation, internal audit, and the external certification audit rather than stopping at a gap report.

Want to see where you stand?

Request a scoping call → and we'll size the work against your actual AI inventory.

FAQ