“Are you ISO 42001 certified?” — answering honestly when you are not
This is the AI-section question a vendor without the certificate cannot answer with a yes — and answering it well does not require one. ISO/IEC 42001 is the international standard for an AI management system, and it now shows up in enterprise procurement as "preferred" or "required": the SIG 2026 questionnaire maps its AI risk domain to it. The trap is not the honest no. The trap is the two answers that feel safer: the ambiguous yes ("we align with ISO 42001") and the bare no with nothing after it.
What the certificate question is actually testing
The certificate is a proxy. What the buyer actually needs, ahead of 2 August 2026 — when Article 50 of the EU AI Act starts to apply, with penalties for breaches of up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher (for SMEs and startups, Article 99(6) applies the lower of the two) — is evidence that your AI features are governed by something other than enthusiasm. A certificate proves that in one line. In its absence, what you can put in front of the reviewer is the underlying evidence itself — much of which a small vendor can produce without an auditor. That reframing is the whole answer strategy.
The three-part honest answer
- Status, stated plainly. "We are not currently ISO/IEC 42001 certified." No hedging, no "aligned with". An ambiguous yes is a written statement you may be asked to warrant at contract stage.
- Equivalent controls you can evidence today. This is where the deal is saved — the table below maps what the certificate would attest to what you can show without it.
- The roadmap, without invented dates. "We evaluate certification against customer demand" is honest. "Certification expected Q1" is only honest if your company has actually approved it.
What the certificate would attest vs. what you can evidence now
| The certificate would attest | What you can evidence today without it |
|---|---|
| A scoped, audited AI management system | An AI system inventory: each model, its provider, version, purpose, whether it is fine-tuned, and where it is processed |
| Documented governance and accountability | A written AI policy with a named owner, and the risk classification of each system under Regulation (EU) 2024/1689 |
| Managed transparency obligations | Your Article 50 transparency measures, documented (Article 50 applies from 2 August 2026; the Digital Omnibus did not postpone it) |
| Staff competence around AI | Your AI-literacy programme under Article 4 (applicable since 2 February 2025), with records of who completed it and when |
| Operating effectiveness over time | A documented history of these controls actually running — buyers commonly ask for on the order of 90 days of evidence |
One caution on that second row: for a limited-risk system — which is what most B2B SaaS is — the Regulation's obligations are the Article 50 transparency duties, not the Article 14 human-oversight requirements reserved for high-risk systems (Annex III obligations were postponed to 2 December 2027 by the Digital Omnibus). If you run human-review checkpoints, present them as voluntary good practice that supports the buyer's risk management, not as AI Act compliance.
Template — for orientation only. Replace every bracket with facts your company has verified and approved:
"We are not currently ISO/IEC 42001 certified. Our AI governance programme covers the controls the standard addresses: [an AI system inventory covering model, provider, version, purpose and processing region], [transparency measures under Article 50 of Regulation (EU) 2024/1689], [an AI-literacy programme under Article 4 with completion records] and [human-review checkpoints, maintained as voluntary good practice]. These controls have been documented and operating since [date]. We evaluate certification against customer demand; [state only steps the company has approved, with their real status]."
Why "no, with a plan" beats an ambiguous yes
The procurement-tested formula for any gap is: current state + compensating control + what is genuinely in progress + a reasonable target. It works because it gives the reviewer something to verify instead of something to doubt. The ambiguous yes does the opposite: "we align with ISO 42001" invites exactly one follow-up — can you share the certificate? — and there is no good answer to it. The same logic applies across the AI section; it is Step 4 of our method for answering AI questionnaires, and the reason a questionnaire that admits its gaps precisely tends to read as more credible than one that admits none.
Mini-FAQ
Does the EU AI Act require ISO 42001 certification?
No. ISO/IEC 42001 is a voluntary management-system standard that procurement teams increasingly list as preferred or required; it is not an obligation under Regulation (EU) 2024/1689. For most limited-risk B2B SaaS, the applicable duties are Article 50 transparency (from 2 August 2026) and Article 4 AI literacy (since 2 February 2025).
Should we answer "certification in progress" if we have not started?
No. State only what the company has approved. "In progress" for work that has not started is an overstated yes wearing a delay costume, and it collapses the first time the buyer asks for a status update.
Will answering "no" lose the deal?
A bare "no" is a missed opportunity; "not certified" plus evidenced equivalent controls and an honest roadmap is a normal procurement answer. What fails due diligence is a yes the buyer disproves — that takes the whole document's credibility with it.
Related: this question usually arrives inside the SIG 2026 AI domain, next to "Are you compliant with the EU AI Act?". If a questionnaire just landed, start with the first-24-hours playbook; if your product ships AI features under its own brand, run the free Article 50 checker and see who owes what under Article 50. More questions are covered in the answer library.