Why ISO 42001 Is About to Become Table Stakes
Rick Orloff is a Fortune 1000 CISO and Strategic Advisor at A-LIGN, with over 20 years of experience at companies including Apple and eBay.
Four out of five organizations now field direct customer inquiries about their AI risk management practices, according to the 2026 Compliance Benchmark Report. That’s how a certification stops being a differentiator and starts being a filter.
SOC 2 Type 2 and ISO 27001 followed that arc. ISO 42001 is following it now, and the compressed timeline is what makes this one worth paying attention to. I believe that ISO 42001 will become table stakes within the next two years. Companies that wait will find themselves reacting to lost deals rather than getting ahead of them.
What’s driving the shift
Sellers are the leading indicator here. Sales teams are fielding AI-related questions from prospects with growing frequency, and the pattern is showing up across the industry. When sales starts feeling the pull consistently, the certification conversation is already moving from optional to expected, even if the market hasn’t fully caught up to that fact yet.
The EU AI Act’s high-risk system obligations take effect in 2026. The EU Cyber Resilience Act carries a September 2026 first deadline and a full-teeth deadline in 2027. Buyers may be on the hook if their vendors handle AI badly, and their vendor risk questions reflect that new compliance posture. A certification like ISO 42001 provides a defensible response that generic assurances can’t match.
The “on our roadmap” answer works, until it doesn’t
Some teams are currently telling prospects some version of: “we have an AI risk program, we’re running third-party risk management on our AI vendors, and ISO 42001 is on our roadmap.” Prospects are accepting that answer today with the expectation these are committed projects. It’s best to scope these properly and do the work well rather than rushing it.
I would not accept that if a vendor provided the answer two years in a row without showing meaningful progress.
Buyer patience for roadmap answers has a shelf life, and the shelf life on AI-related certifications is going to be shorter than it was for SOC 2 Type 2. Boards are pushing on AI risk, legal teams are updating their vendor language, and procurement is starting to add filter criteria. The pieces that turned SOC 2 Type 2 into a de-facto requirement are all in motion now for ISO 42001, and they’re moving faster than they did a decade ago because the industry has already been through this exercise once.
The companies that will be caught flat-footed are the ones that treat “on our roadmap” as a durable answer. It’s a bridge, and the bridge is finite.
Applying the CRO test to ISO 42001
In an earlier article, I argued that every compliance certification is a revenue decision and that the Chief Revenue Officer is the deciding voice. The question I’d ask a CRO on 42001 specifically: “How many deals in the last two quarters have surfaced AI-related questions, and how many of those did we win?” If the answer includes even a handful of losses attributable to a “we don’t have that yet” moment, the case for pursuing 42001 has velocity behind it.
Most compliance certifications produce offensive ROI. They unlock new markets, open regulated verticals, or let you compete for deals you couldn’t have chased before. ISO 42001 is likely to be one of the first certifications where the ROI is primarily defensive: don’t lose the deals you already have, don’t get filtered out of shortlists you would have made a year ago, don’t leave your sales team without a good answer when the AI question comes up on a call.
That’s a different conversation to have with your CRO, but it’s still a revenue conversation. The dollar impact is real. It’s just measured in deals-you-would-have-otherwise-lost rather than net-new pipeline.
What ISO 42001 covers and what it doesn’t
ISO 42001 is a management-system standard. It provides the vocabulary, the governance structure, the risk assessment methodology, and the documentation discipline for an AI risk program, much the way ISO 27001 does for information security. If implemented well, you’ll have a defensible AI management system that a buyer’s procurement team can evaluate confidently. That’s genuine value, and it’s why the framework is going to become table stakes.
What ISO 42001 does not do is solve the hardest AI risk problems on its own. It does not detect when an AI agent starts talking to systems it wasn’t approved to talk to. It does not address how to detect a SaaS vendor that quietly swaps out their underlying language model for a cheaper version that is on the “do not allow” list as part of your governance structure. Those are detection problems, not governance problems, and they need their own investments in tooling, monitoring, and operational discipline.
Pursuing ISO 42001 is likely a good move for most organizations, but do not confuse compliance certifications with real-world security driving intended outcomes. I’m honest with myself that the ISO 42001 framework doesn’t address every concern I have about AI risk. Getting certified is table stakes for the buyer conversation. It is not the same thing as a complete AI security program. Confusing the two is how organizations end up with a clean certificate and a real problem hiding underneath it.
How to get started
For companies already running SOC 2 and ISO 27001, the foundational overlap with ISO 42001 is significant. That head start helps with structure and discipline, but the AI-specific policies and procedures ISO 42001 requires still need to be written net new, whether or not you already have ISO 27001 in place. A gap analysis through a common controls framework will show you where that foundation helps and where you’re starting from scratch: model inventory, AI impact assessments, and ongoing monitoring of AI-specific risks.
If you’ve already rationalized your audit portfolio the way I described in an earlier article, there’s a further advantage: you may be able to self-fund the 42001 pursuit through consolidation savings rather than adding a new line to your budget. That was the model I used in a prior role for other certifications, and it turns the “we can’t afford it right now” objection into a self-funded sales enablement conversation.
To get started, run a gap analysis this quarter, socialize the findings with your CRO to get the pipeline case documented, and target a readiness assessment against ISO 42001 within the next two audit cycles. That timeline gets you certified before “on our roadmap” stops working as an answer, which is the whole point.
The takeaway
Table stakes always feel premature until suddenly they don’t. The certification that looks like a differentiator this year is the one that’s expected next year, and by the year after that, its absence is the reason you didn’t make the shortlist. ISO 42001 is running that same play, on a faster clock than the frameworks that came before it.
If you’re waiting for the market to force your hand, you’ve already waited too long.
Ready to start your ISO 42001 journey?
Start with a readiness assessment and a common-controls gap analysis — that combination will tell you exactly where the work is. A-LIGN’s ISO 42001 services are designed to help organizations move from “on our roadmap” to fully certified before the buyer market runs out of patience.



