Article 50 applies 2 Aug 2026 EU AI Act transparency rules were not deferred by the Omnibus, and are not limited to high-risk systems. What it requires →
Common questions · updated April 2026

FAQ, ISO 42001 Toolkit

Straight answers to the questions buyers ask before purchase, about the standard, about the toolkit, about pricing, and about the regulatory hooks.

About the standard

Is ISO/IEC 42001 certification mandatory?

No, ISO 42001 certification is voluntary. However, it is increasingly being treated as a de facto requirement in several contexts: by Microsoft's SSPA DPR v12 (accepted in lieu of independent AI assessment, and mandatory for Sensitive Use AI), by EU AI Act compliance pathways, and by enterprise procurement teams requesting AI-governance evidence.

Does this toolkit guarantee ISO 42001 certification?

No. Certification outcomes depend on your implementation quality, your evidence, your organisational maturity, and the independent judgement of your certification body. The toolkit provides the documentation foundations every implementation requires, but customisation to your organisation and sound operational practice are your responsibility.

What's the difference between ISO 42001, ISO 42005, and ISO 42006?

ISO/IEC 42001:2023 is the certifiable AI management system standard that organisations implement. ISO/IEC 42005 is an impact-assessment standard (companion guidance). ISO/IEC 42006 specifies how certification bodies audit and certify against 42001, it's aimed at the certifying bodies themselves, not at organisations implementing. Our toolkit focuses on 42001 with references to 42005 where relevant.

How does ISO 42001 interact with ISO 27001?

Both standards share the Harmonised Structure. Organisations with ISO 27001 in place typically save 30–50% of ISO 42001 implementation effort because the management-system infrastructure (internal audit, management review, document control, corrective action) is already running. Our Professional tier includes a Four-Way Crosswalk that maps every ISO 42001 requirement to its ISO 27001 equivalent.

How does ISO 42001 interact with NIST AI RMF?

NIST AI RMF is a voluntary US framework, not a certifiable standard. ISO 42001 is a certifiable international management-system standard. They cover similar ground, risk management, governance, impact assessment, but ISO 42001 is structured for audit, while NIST AI RMF is structured for practical guidance. Many organisations implement both.

About the toolkit

What file formats do I get?

All documents are Microsoft Word (.docx) format. Workbooks (Gap Analysis, 90-Day Roadmap) in the Professional and Audit-Ready tiers are Microsoft Excel (.xlsx) with auto-calculating formulas. The root package includes Markdown (.md) files for the Master Guide, Master Index, First Week Checklist, and CHANGELOG. Files open in Microsoft 365, Google Docs/Sheets, LibreOffice, and most other modern office suites.

What does "24 months of free updates" mean?

When ISO publishes a revision or erratum to 42001, or when material regulatory guidance shifts (EU AI Act Article 73 final guidance, Microsoft SSPA DPR revisions, Colorado SB 189 rulemaking), we regenerate the affected artefacts and email updates to buyers during the 24-month window. Updates arrive as versioned replacement files with a changelog. After 24 months you keep the version(s) you received; further updates are available through a renewal.

Can I use this toolkit for multiple organisations or for clients?

All three tiers include a single-organisation licence. You can use the documents within your organisation and its controlled affiliates for internal implementation and certification. Consultancies serving multiple clients should contact us at hello@iso42001toolkit.com, we have consultancy-friendly options and can discuss bespoke arrangements.

Does the content contain "Not legal advice" disclaimers?

Yes. Every DOCX artefact carries a prominent "Educational use only, not legal advice" notice and a third-party trademark acknowledgement on page 1. These are deliberate, persistent disclaimers, the toolkit is educational reference material, not legal advice, and should be reviewed by qualified counsel before use for regulatory, contractual, or certification purposes.

How long does the toolkit stay relevant?

ISO/IEC 42001:2023 is a stable, published standard. The regulatory frameworks layered on top (EU AI Act, Colorado AI Act, Microsoft SSPA) are evolving. We track these and push updates to the toolkit within the 24-month window. Post-24-months, the core documentation remains aligned to the 42001 standard itself; peripheral regulatory content may drift.

About purchasing

How do I pay?

Checkout runs through Stripe. We accept all major credit cards and most country-specific payment methods that Stripe supports. Invoicing and bank transfers can be arranged for tier purchases above $1,000, email hello@iso42001toolkit.com.

When do I get the download?

Immediately after payment. You are redirected to a thank-you page with a download button for the ZIP file. You also receive an email with the download link within 24 hours as a backup, save this email as your permanent access.

Do you offer refunds?

See our full Refund Policy. In short: because these are digital downloads, refunds after the content has been accessed are limited to specific circumstances (failed delivery, wrong product, material misdescription, verified factual defect). EU/UK consumers have additional statutory rights under Directive 2011/83/EU. Contact us within 30 days of purchase if you have any concern, we work to resolve issues fairly before refund discussion.

Can I upgrade from Starter to Professional later?

Yes. Email us at hello@iso42001toolkit.com with your original order reference and we credit your previous purchase against the next tier's price. So Starter → Professional costs $498 ($697 − $199); Professional → Audit-Ready costs $800 ($1,497 − $697). Upgrade credit is valid for 24 months from the original purchase.

Who is HumanAudit Inc.?

HumanAudit Inc. is a Delaware C-Corporation. We also operate euaiactchecklist.com (EU AI Act compliance resources). Contact: hello@iso42001toolkit.com.

About the regulatory hooks

Does this help with the Colorado AI Act?

Colorado's original AI Act (SB 24-205), which granted that affirmative defense, was repealed in May 2026 and replaced by SB 189, a transparency law effective 1 January 2027 with no ISO 42001 / NIST AI RMF affirmative defense. ISO 42001 is no longer a Colorado statutory defense, but it still supports SB 189's documentation expectations and the live drivers (Microsoft SSPA, EU AI Act, procurement). Our Colorado AI Act page has the detail.

We're a Microsoft supplier, does this satisfy SSPA Section K?

Microsoft SSPA DPR v12 (live 30 March 2026) accepts an ISO/IEC 42001 certification in lieu of an independent assessment for AI-specific requirements in Section K for general AI services. For suppliers delivering "Sensitive Use" AI, defined as AI affecting an individual's legal position, life opportunities, physical/psychological well-being, or human rights (examples: hiring, credit, healthcare, biometrics), Microsoft requires ISO 42001 certification, with no independent-assessment alternative. Our Professional tier includes a dedicated Microsoft SSPA Section K mapping (updated for DPR v12; 63 requirements, Section K = 18 with 15 updated) showing exactly how ISO 42001 evidence satisfies Section K. See our SSPA page.

Does this cover EU AI Act Article 73 serious-incident reporting?

Yes. AIMS-22 (Incident Response Procedure) in the Starter tier implements the tiered reporting structure directly, 2 days for critical-infrastructure disruption / widespread infringement, 10 days where a death may be caused, 15 days for other serious incidents. The Professional tier's PRO-AnnexA-08 extends with detailed workflows, the Commission's September 2025 draft-guidance highlights, and a sample serious-incident report aligned to the draft template. See our EU AI Act page.