Skip to content

CONTENTS

WHY ISO/IEC 42001 CERTIFICATION MATTERS
WHAT ISO/IEC 42001 COVERS
ISO 42001 AND THE EU AI ACT
HOW IT WORKS
READY TO START YOUR ISO 42001 JOURNEY?

Why ISO/IEC 42001 Certification Matters

INDEPENDENT VERIFICATION OF AI GOVERNANCE

ISO 42001 certification provides third-party verification that your organisation manages AI systems responsibly. An accredited certification body independently audits your AIMS and awards certification — providing far more credible assurance to clients, partners, and regulators than self-attestation.

REGULATORY PREPARATION — INCLUDING THE EU AI ACT

AI regulation is accelerating globally. The EU AI Act became legally binding in August 2024, with requirements phasing in through 2027 for high-risk AI systems. ISO 42001 implementation supports many of the governance, risk management, documentation, and transparency requirements of the EU AI Act.
However, it is important to understand the relationship accurately: ISO 42001 is not yet formally harmonised under the EU AI Act, meaning certification does not automatically confer presumption of conformity under the Act. Think of ISO 42001 as building the governance foundation — the EU AI Act adds specific legal obligations on top. Organisations operating in the EU should implement ISO 42001 as a foundation and address EU AI Act-specific requirements in parallel.

WHAT ISO/IEC 42001 COVERS

ISO/IEC 42001

is the international standard for an Artificial Intelligence Management System (AIMS). It provides a roadmap for organisations to develop, provide, or use AI systems responsibly and effectively.

ISO 42001 AND THE EU AI ACT

EU AI Act

Sets the mandatory legal requirements, safety standards, and penalties for using AI in the European market

ISO 42001

Provides the global management system (AIMS) that companies use to actually meet those legal requirements.

HOW IT WORKS

1. Discovery Call

We start by understanding your device, your submission timeline, and where you currently stand on cybersecurity documentation. No forms, no discovery questionnaires — just a direct conversation with someone who knows the FDA guidance inside out.

2. Gap Assessment

We map your current position against FDA requirements and produce a clear, prioritised list of what needs to be done. You'll know exactly what's missing and what it will take to fix it.

3. Documentation & Remediation

We get to work. Depending on your needs, this means threat modelling, SBOM development, policy drafting, architecture review, or the full package. We work to your timeline, not ours.

4. Submission Support

We review your final submission documentation, flag any remaining risk, and make sure what goes to the FDA is as strong as it can be. If Q-Sub feedback comes back, we help you respond.

READY TO START YOUR ISO 42001 JOURNEY?

LEGISLATIVE AUTHORITY: SECTION 524B FD&C ACT

If your submission window is approaching, start the conversation now.

FAQ’s

What is the difference between DCC and Cyber Essentials? minus-icon

Conducting a thorough hazard analysis is crucial for ensuring the safety and compliance of medical devices. Hazard analysis identifies potential risks and evaluates their impact on patient safety and device performance. At Periculo, we offer expert hazard analysis services to help you systematically identify, assess, and mitigate risks throughout the product lifecycle. Our approach includes detailed risk assessments, failure mode and effects analysis (FMEA), and the development of robust mitigation strategies. With Periculo’s support, you can ensure that your medical devices meet regulatory standards, enhance patient safety, and maintain high levels of performance and reliability.

Do I need Cyber Essentials Plus for Level 1? plus-icon
What happens if I fail the assessment? plus-icon
How long does a certification last? plus-icon
Would an assessor be able to implement and audit my DCC certification? plus-icon
What happens if I fail the assessment? plus-icon
Does DCC apply to my subcontractors? plus-icon
How does DCC differ from ISO 27001? plus-icon
What is the cost of certification? plus-icon
What is the “Scope” of the certification? plus-icon
How long does the assessment take? plus-icon

Latest Insights

DSPT 2026-27 Is Live: What's Confirmed, and What IT Suppliers Are Still Waiting On...

DSPT 2026-27 Is Live: What's Confirmed, and W...

The Data Security and Protection Toolkit for 2026-27 went live on 4 September 2026. Version 9 is now aligned to the Cybe...

Tailored for Defence: Why Generic AI-Generated Policies Fail DCC Governance

Tailored for Defence: Why Generic AI-Generate...

Ask an AI assistant to write an Acceptable Use Policy, and it will produce something plausible-looking in seconds: don't...

The Rules of Engagement: What Your Certification Body Can and Cannot Do

The Rules of Engagement: What Your Certificat...

Somewhere in every DCC preparation project, a compliance officer asks a reasonable question: "Can our Certification Body...

DCC Level 2/3 Hybrid: The Assessment Process, Step by Step

DCC Level 2/3 Hybrid: The Assessment Process,...

If your contract requires Defence Cyber Certification (DCC) Level 3, there's one thing worth knowing before you go any f...

DCC Level 1: The Assessment Process, Step by Step

DCC Level 1: The Assessment Process, Step by ...

For suppliers in the UK Ministry of Defence (MOD) supply chain, Defence Cyber Certification (DCC) Level 1 is typically t...

How to Manage Operational Technology (OT) Under DCC

How to Manage Operational Technology (OT) Und...

Industrial control systems have traditionally sat outside IT's compliance conversations, too specialised, too fragile, t...

Why Cyber Essentials and DCC Scope Rarely Match

Why Cyber Essentials and DCC Scope Rarely Mat...

CE scope and DCC scope are not the same thing, and treating them as interchangeable is the single most common reason Def...

DCC Penetration Testing Requirements: A Complete Guide to Control 2403

DCC Penetration Testing Requirements: A Compl...

UK defence procurement no longer assesses cybersecurity contract by contract. The Ministry of Defence (MOD) and IASME ha...