ISO/IEC 42001 readiness, without the compliance department.

ISO/IEC 42001:2023 is the management-system standard for AI — and increasingly what enterprise customers ask their vendors for. RiskWoven takes a small or mid-size organisation from "we should look at this" to a documented position you can take into a certification process: assessment, gap analysis, tailored policies, and a readiness report you can hand to an auditor.

What ISO/IEC 42001 actually asks of you

In plain terms, the standard expects an organisation to know its AI systems (inventory), decide who is accountable (policy and leadership), assess the risks and impacts of each system, run lifecycle controls — data quality, human oversight, incident handling — and keep the whole thing reviewed and improving. It is a management system, not a technology checklist: the work is mostly documents, decisions and evidence.

That is precisely the work RiskWoven generates and organises. We reference the standard's clauses and control themes in our own words — the standard's text is licensed by ISO, and if you pursue certification you'll need your own copy, which we'll tell you plainly rather than quietly quote.

The path, concretely

  1. Free scan — 12 questions, immediate score, no account. Establishes whether 42001 readiness is a this-quarter problem or a this-year one.
  2. Full assessment ($299) — every AI system inventoried and analysed, discrepancies between what you declared and what your data flows imply disclosed rather than smoothed over, gaps mapped clause by clause.
  3. Readiness Bundle ($899) — the tailored document set: AI policy, oversight procedures and supporting standards, plus the certification-readiness report. Every document passes an independent review stage that rejects invented citations.

Why teams pick this over the alternatives

Versus compliance platforms

Platforms like Vanta, Drata and Secureframe are excellent — and start around $7,500–$15,000 a year behind a sales call, with AI governance as an added module. RiskWoven is AI-governance-native and sells the outcome one-time, from $299, with the price on the page.

Versus a consultant

A good consultant brings judgment; so does a bad one, and you can't tell from the proposal. Our output is public — judge the actual work product before spending anything. Many consultants use RiskWoven themselves via our partner plan.

Versus ChatGPT and a template

The real competitor. What it can't give you: a framework library pinned to current versions, an independent reviewer that catches fabricated clause citations, disclosed discrepancies, and a system that remembers your organisation between documents.

Straight answers

Can RiskWoven certify us?

No — certification is issued by accredited certification bodies after their own audit. RiskWoven gets you ready: the documents, the register, the evidence structure, and a readiness report that says honestly what is in place and what is missing. It does not predict the outcome of an audit, and it carries no standing with a certification body.

How long does readiness take?

Depends on your starting point. Organisations with basic security hygiene but no AI-specific governance typically need 3–6 months of part-time effort. The assessment gives you a dated roadmap rather than a guess.

Does this help with the EU AI Act too?

Partly. The intake asks about your role under the EU AI Act, prohibited practices and risk tier, and the same inventory, oversight and documentation work serves all three. The documents and the control mapping are grounded in ISO 42001, ISO 27001 and NIST AI RMF, not in the Act's own articles. Transparency duties for customer-facing AI have applied since August 2026; high-risk system obligations land in December 2027.

Do we need to buy the standard?

For certification, yes — ISO licenses the text and every organisation needs its own copy. RiskWoven references the standard in its own words and never reproduces the licensed text, which also means our documents are safe for you to distribute.