Written, reviewed and corrected by humans. · Expert support after purchase Our corrections →
⚠  Microsoft SSPA: ISO 42001 is mandatory for Sensitive Use AI suppliers  ·  See the mapping →
ISO/IEC 42001:2023 · AI Management Systems

Build a certifiable AI Management System in weeks, not quarters.

The complete ISO/IEC 42001:2023 documentation toolkit, built for Microsoft SSPA DPR v12 (live 30 March 2026, ISO 42001 mandatory for Sensitive Use AI suppliers) and EU AI Act Article 73 readiness (Annex III obligations now apply from 2 December 2027 under the Digital Omnibus, adopted by Parliament 16 June 2026). Drop-in DOCX templates you own forever.

Human-written, human-reviewed 24 months of free updates Instant DOCX download 7-day money-back guarantee
→ Free · 2 minutes · No signup to start
How ready are you for ISO 42001? Find out in 2 minutes.

Answer 18 questions and see exactly which of the 23 required documents you have, which you are missing, and which gaps an auditor checks first. Free, instant, no signup to begin. Also exposed to the EU AI Act?

Score my documentation →
38Annex A Controls
23Core documents (Starter)
64Gap-analysis formulas (Pro)
3Regulatory hooks covered
24 moFree updates included

Built with auditor feedback, and improved in the open

These documents are shaped by the people who actually run ISO 42001 audits. When a customer, a director at a DACH consultancy, flagged that our risk treatment plan referenced actions by ID but never described them, he was right. We investigated, found two more issues he hadn't spotted, corrected all three, and shipped the fix free to every existing customer.

We publish every correction openly, with the control IDs, so you can check the work yourself. That is the standard we hold: not a green dashboard, but documentation an auditor accepts, and a team that fixes what's wrong in public rather than hiding it.

Read the full changelog, with control IDs →
Three reasons this is urgent

ISO 42001 is now a legal, procurement, and regulatory asset, not just a badge.

Three distinct regulatory frameworks converge around ISO 42001 in 2026. If any of these apply to your organisation, this toolkit is directly relevant.

Procurement baseline

Enterprise procurement & US state AI laws

Enterprise customers increasingly require AI-governance evidence in vendor questionnaires, and US state AI laws are taking shape. Colorado repealed its original AI Act and replaced it with SB 189, a transparency framework effective 1 January 2027. ISO 42001 is the recognised way to demonstrate AI-governance maturity across them.

What changed in Colorado
Live 30 March 2026

Microsoft SSPA DPR v12, ISO 42001 mandatory for Sensitive Use AI

Microsoft DPR v12 has 63 requirements; Section K (AI Systems) has 18 with 15 updated. For general AI services, ISO 42001 is accepted in lieu of independent assessment. For "Sensitive Use" AI (hiring, credit, healthcare, biometrics, etc.), ISO 42001 is required, no alternative. And v12 is enforced: suppliers who can't show evidence are placed in Red Status, a hard block on new Microsoft purchase orders until resolved.

See the SSPA mapping
Applies from 2 December 2027

EU AI Act Article 73, tiered incident reporting

High-risk AI providers must report serious incidents within 2 days (critical-infrastructure disruption / widespread infringement), 10 days (death), or 15 days (general). Under the Digital Omnibus (adopted by Parliament 16 June 2026, Council adoption 29 June 2026), the date moved from 2 August 2026 to 2 December 2027. AIMS-22 operationalises this.

Article 73 readiness guide
Who this is for

You've been told you need ISO 42001. Now what?

Whatever brought you here, the hard part is the same: turning the standard into documents an auditor accepts. Find your situation:

🏢

A customer or enterprise buyer is asking for it

Microsoft SSPA, a Fortune 500 procurement team, or an EU client won't sign until you can show an AI Management System. You need the documents fast, and they have to hold up.

⚖️

The EU AI Act applies to you

You put AI in front of EU users, and enforcement is coming. ISO 42001 is the recognised way to show you govern it responsibly, with the Annex IV file and Article 27 FRIA to prove it.

🚀

You're getting ahead of it

You'd rather certify now, as a trust signal and a sales advantage, than scramble when a deal or a regulator forces it. Smart. The whole set is ready today.

🎓

You advise, train, or certify others

Consultancies, law firms building an AI practice, and certification bodies training auditors use these documents as the raw material behind client deliverables. It is why our buyers so far are a Tokyo IP firm, a European consultancy, and a certification body. Ask us about licensing.

Why buy the toolkit

Three ways to get certifiable documentation. Only one is fast and affordable.

ISO 42001 requires the same 23 documents no matter how you produce them. Here's what each path actually costs you:

Path 1

Hire a consultant

$15,000–$40,000

Weeks of meetings, their timeline, their availability. You get good documents, at a price that stops most teams before they start.

Path 2

Write it yourself from scratch

4–8 weeks + audit risk

Free, if your time is free. The catch: the three areas auditors fail most, risk traceability, data controls, and validation, are exactly the ones first-timers get wrong.

Path 3 · recommended

Buy the toolkit

$199–$1,497 · ready today

All 23 documents, editable and yours forever, built from auditor feedback and corrected in the open. Skip the weeks and the five-figure invoice. Full refund within 7 days if it is not right for you, no reason needed.

See the 3 tiers →
Three tiers · priced to fit your stage

Pick your path to a certifiable AIMS.

Each tier builds cumulatively on the one below it. Buying a higher tier gives you everything in the lower tiers plus the additional artefacts for that tier. All tiers include 24 months of free updates.

1
You payStripe checkout, about 40 seconds
2
Files land instantlyEditable DOCX and XLSX, no waiting
3
A human answersStuck on scope? Email us, we reply
4
Start the same dayFirst Week Checklist maps your first 7 days
Starter

Documentation Pack

$199 one-time

The 23 core documents ISO 42001 implementations typically require, plus a Master Index and a 7-day onboarding plan.

  • 23 mandatory AIMS documents (AIMS-01 through AIMS-22, including AIMS-06a)
  • Master Index + First Week Checklist
  • All 38 Annex A controls in the Statement of Applicability
  • 20 pre-seeded example risks
  • EU AI Act Article 73 tiered incident reporting built in
  • 24 months of free updates
Buy Starter, $199 →

Instant DOCX download · Stripe checkout

Audit-Ready

Certification Launch Pack

$1,497 one-time

Everything in Professional plus 5 certification-launch artefacts and a 30-min email Q&A with the HumanAudit team.

  • Everything in Professional (52 files)
  • Pre-Audit Self-Assessment (100+ items)
  • Stage 1 Evidence Binder template
  • Stage 2 Evidence Binder template
  • Auditor Briefing Pack
  • Post-Certification Marketing Kit
  • 30-minute email Q&A with HumanAudit team
  • 24 months of free updates
Buy Audit-Ready, $1,497 →

58 files total · for cert-bound orgs

Built on verified data from organisations certified to ISO/IEC 42001

KPMG Australia (first globally, Oct 2024) AWS (Nov 2024) Anthropic Google Microsoft IBM Red Hat SAP CrowdStrike Cohere Workday Autodesk ibex Zendesk Synthesia

Selected examples of public ISO 42001 certifications (non-exhaustive). HumanAudit Inc. is not affiliated with these organisations.

How teams use the toolkit

Three representative scenarios.

Common paths our buyers take through the toolkit, based on typical organisational starting points and regulatory exposures.

Scenario 1 · Compliance Lead at a US SaaS company

"A customer’s vendor-security questionnaire asked how we govern AI in our hiring-recommendation feature, and we needed an answer fast. The Starter tier gave us the policy, scope, and risk documentation in a weekend. Upgraded to Professional when the Microsoft SSPA question came up from procurement."

Used: Starter → Professional ($199 → $697)

Scenario 2 · AIMS Owner at a FinTech

"We already had ISO 27001. The Four-Way Crosswalk in the Professional tier showed us exactly which existing controls we could reuse, cutting new documentation work roughly in half. The FinTech-variant Impact Assessment with SR 11-7 and PRA references saved us a week of tailoring."

Used: Professional ($697)

Scenario 3 · Certifying a GenAI product

"Three weeks out from our Stage 1 audit, we needed evidence binders, a pre-audit self-assessment, and an auditor briefing pack that signalled maturity. The Audit-Ready tier delivered all four. The 30-minute email Q&A handled the remaining scope questions."

Used: Audit-Ready ($1,497)

Representative scenarios illustrating typical use cases, not direct quotations from named clients.

Common questions

ISO 42001 toolkit, FAQ

Is ISO/IEC 42001 certification mandatory?

No, ISO 42001 certification is voluntary. However, it is increasingly being treated as a de facto requirement by enterprise procurement teams and by Microsoft, which accepts it in lieu of an independent assessment for SSPA Section K AI requirements and requires it outright for "Sensitive Use" AI suppliers.

Does this toolkit guarantee ISO 42001 certification?

No. Certification outcomes depend on your implementation quality, your evidence, your organisational maturity, and the independent judgement of your ISO-accredited certification body. This toolkit provides the documentation foundations that every ISO 42001 implementation requires, but customisation to your organisation and sound operational practice are your responsibility.

Does this help with the Colorado AI Act?

Colorado's original AI Act (SB 24-205), which granted that affirmative defense, was repealed in May 2026 and replaced by SB 189, a transparency-focused law effective 1 January 2027 that no longer includes the ISO 42001 / NIST AI RMF affirmative defense or the risk-assessment and impact-assessment mandates. ISO 42001 is therefore no longer a Colorado affirmative defense, but the Starter tier still gives you the AI-governance documentation that supports SB 189's disclosure expectations and broader procurement and EU AI Act readiness.

We're a Microsoft supplier, does this satisfy SSPA Section K?

Microsoft accepts an ISO/IEC 42001 certification in lieu of an independent assessment for AI-specific requirements in DPR Section K. Our Professional tier includes a dedicated Microsoft SSPA Section K mapping (updated for DPR v12, released 30 March 2026) that shows how ISO 42001 evidence maps to Section K intent.

How is this different from ISMS.online, Advisera, or similar?

We're templates, not software. If you need live control tracking and automation, a SaaS GRC platform is probably right for you. If you want professional-grade DOCX documents you own forever, at 10–50× lower cost than consulting engagements and with multi-framework crosswalks (ISO 27001, NIST AI RMF, EU AI Act) included, this toolkit is built for that.

What does "24 months of free updates" mean?

When ISO publishes a revision or erratum to 42001, when related standards change materially (ISO 27001, NIST AI RMF 2.0), or when regulatory guidance shifts (EU AI Act Article 73 final guidance, Microsoft SSPA DPR revisions, Colorado SB 189 rulemaking), we regenerate the affected artefacts and send updates to buyers within the 24-month window. Updates arrive as versioned replacement files with a changelog.

See all FAQs →

Ready to build your AIMS?

Start with the Starter at $199, the 23 documents ISO 42001 implementations typically require, plus a First Week Checklist that takes you from purchase to signed AI Policy in 7 days.

Buy Starter, $199 → Compare all tiers

Version 2.3 · 9 July 2026

A customer found a defect in our toolkit. Here's what we did about it.

He was reading AIMS-06 and noticed it referenced treatment actions by identifier, TRT-001 through TRT-016, without ever describing what any of them were. He was right.

So we audited the whole set and found two more defects he hadn't spotted. Four risks with no treatment action at all, one of them marked "in treatment" with nothing treating it. And two control back-links in the Statement of Applicability that didn't reconcile with the treatment plan. An auditor tracing controls would have found both, as a finding against his AI management system, not against our toolkit.

We rebuilt the documents, wrote a new one, and shipped v2.3 free to every existing customer with a written explanation of exactly what had been wrong.

Read the full account, with the control IDs →