Live 16 practitioner certifications live · First lesson free on every course Back to main site →
Cybersecurity

ISO/IEC 42001 AI Management System Practitioner Certification

For the Indian CIO, CISO, Head of AI, DPO and General Counsel who has to build, run and pass a first-time ISO/IEC 42001:2023 certification — written the way an advocate teaches a student, not the way an ISO PDF is translated.

₹9,999 incl. 18% GST Intermediate 8.9 hours 8 modules
8
Modules
40
Lessons
40
Exam questions
70%
Pass mark

A citation-anchored, exam-backed practitioner course on ISO/IEC 42001:2023 as it actually runs for an Indian enterprise, IT services company, GCC, SaaS or fintech deploying AI in production and going for first certification by a body accredited under ANAB, UKAS or RvA (with NABCB scheme extension expected). Not a PECB / BSI five-day exam-prep flyover — this course teaches the working AI Management System (AIMS) the way a senior advocate teaches a student: what the clause actually says, what it means in practice, where teams get it wrong, what the auditor will look for, and how the India AI Governance Guidelines (November 2025) + IT Amendment Rules 2026 + SEBI 5-May-2026 AI Advisory + RBI FREE-AI Framework Report (13-Aug-2025) + DPDP Act 2023 + EU AI Act extraterritorial reach sit on top of the standard. Covers all ten clauses of ISO/IEC 42001:2023, all 38 Annex A controls across the 9 groups A.2 through A.10, Annex B implementation guidance, Annex C organisational objectives, and Annex D domain-application guidance. Includes ten downloadable working templates the student can lift straight into a live AIMS build.

Written against primary sources current to 19 September 2026.

What you will learn
  • Read the ISO/IEC 42001:2023 standard end-to-end and identify each of the ten clauses (0 through 10) plus the 38 Annex A controls organised across groups A.2 through A.10
  • Explain the difference between an AI Management System (AIMS) — what you build — and the ISO 42001 certificate — what a certification body issues after audit
  • Distinguish ISO 42001 from NIST AI RMF from the EU AI Act from the India AI Governance Guidelines and identify which one your customer, regulator or board is actually asking for
  • Write an AIMS Scope Statement per Clause 4.3 that a certification body will accept at Stage 1
  • Draft an AI Policy per Clause 5.2 and Annex A.2.2 that survives a management review challenge
  • Run an AI risk assessment methodology per ISO/IEC 23894:2023 that produces a defensible risk register and drives control selection
  • Conduct an AI Impact Assessment (AIIA) per Annex A.5 and ISO/IEC 42005:2025 covering fairness, safety, transparency, privacy, security and human oversight
  • Build a Statement of Applicability mapping all 38 Annex A controls (A.2 Policies, A.3 Internal organisation, A.4 Resources, A.5 Impact assessment, A.6 AI lifecycle, A.7 Data, A.8 Information for interested parties, A.9 Use of AI systems, A.10 Third-party and customer relationships) to Include or Exclude with clause-anchored justification
  • Apply the India AI Governance Guidelines seven sutras (Trust, People-first, Innovation, Fairness, Accountability, Understandability by design, Safety) and six pillars as an AIMS overlay
  • Meet Information Technology Amendment Rules 2026 obligations on Synthetically Generated Information (SGI) — visual labels, audio disclosure, metadata embedding, 2-3 hour takedown for deepfake harm
  • Integrate the SEBI 5-May-2026 AI Advisory obligations if your organisation is a SEBI-regulated entity
  • Anticipate RBI FREE-AI directions if your organisation is an RBI-regulated entity
  • Handle the DPDP Act 2023 intersection — automated processing, Significant Data Fiduciary triggers, DPIA thresholds, cross-border transfer for training data
  • Understand the EU AI Act phase timeline through 2 December 2027 for Annex III high-risk and 2 August 2028 for Annex I product-embedded, and know which Indian exporters are caught
  • Design the Internal Audit Programme (Clause 9.2) and Management Review agenda (Clause 9.3) that produce operating-effectiveness evidence for Stage 2 audit
  • Select a certification body from A-LIGN, BSI, Bureau Veritas, DNV, Schellman, SGS, TÜV SÜD or TÜV Nord based on accreditation scope, sector experience and audit-day cost
  • Prepare for and pass Stage 1 (documentation review) and Stage 2 (operating effectiveness) audits
  • Run the three-year certification cycle (surveillance Year 1 + Year 2, recertification Year 3)
  • Cross-reference NIST AI RMF 1.0 (Govern, Map, Measure, Manage) using the official crosswalk published by NIST AIRC
Prerequisites
  • General exposure to an enterprise IT, SaaS or GCC environment — you do not need to be a machine-learning engineer, but you should be comfortable naming the AI features your organisation runs
  • Comfort reading a formal management-system standard with clauses and sub-clauses (ISO 27001 or ISO 9001 background helpful but not required)
  • Familiarity with the concept of a risk register (likelihood x impact scoring, treatment options)
  • Access to a list of the AI systems your organisation currently runs or plans to deploy is helpful for the practical exercises but not required
Who this is for
  • Indian CIOs, CISOs and Heads of Security at IT services companies, SaaS, GCCs, enterprises, BFSI, healthtech, edtech and fintech that are deploying AI in production and now need an AIMS
  • Heads of AI, Heads of Data Science and Chief AI Officers running production ML/LLM pipelines who own the governance question
  • DPOs already running DPDP compliance who have to extend scope to cover AI systems that process personal data
  • General Counsels and Chief Compliance Officers wanting to survive a board question about "our AI risk exposure"
  • ISMS Managers already running ISO 27001 who need to bolt an AIMS on top rather than run two parallel management systems
  • Consultants at cyber and AI advisory boutiques (KPMG, EY, Deloitte, PwC, mid-tier firms, boutique AI governance specialists) building an ISO 42001 practice
  • Product Managers and Solutions Architects at Indian SaaS and services companies whose enterprise buyer questionnaires have started asking for ISO 42001
  • Compliance and Risk Managers at BFSI, healthcare and telecom organisations layering AI governance on top of RBI, SEBI, IRDAI and CERT-In obligations
  • Government affairs and policy leads tracking the India AI Governance Guidelines, IT Amendment Rules 2026 SGI regime, RBI FREE-AI direction and the eventual Digital India Act
  • Sales and Customer Success at Indian SaaS responding to European and American vendor security questionnaires that now include an ISO 42001 line
About the author
dC
AI Management System Design, Certification Readiness and Assurance

The dcomply Cyber Practice authors the cybersecurity and AI assurance track at dcomply Academy. This course is built from the primary text of ISO/IEC 42001:2023 (December 2023 first edition, ten clauses, Annex A with 38 controls across groups A.2 through A.10, Annex B implementation guidance, Annex C organisational objectives, Annex D domain application), companion standards ISO/IEC 23894:2023 (AI risk management guidance), ISO/IEC 23053:2022 (framework for AI systems using ML), ISO/IEC 42005:2025 (AI system impact assessment), ISO/IEC 22989:2022 (AI concepts and terminology), ISO/IEC TR 24028:2020 (trustworthiness in AI), the India AI Governance Guidelines released by MeitY in November 2025 (seven sutras across six pillars, with Annexure 6 recommending ISO/IEC 42001), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 notified 10 February 2026 with effect from 20 February 2026 (introducing Synthetically Generated Information obligations), SEBI Circular dated 5 May 2026 on advanced AI vulnerability detection tools (Cyber-suraksha.ai task force), Report of the RBI Committee on FREE-AI chaired by Professor Pushpak Bhattacharyya of IIT Bombay dated 13 August 2025, DPDP Act 2023 with DPDP Rules 2025 notified November 2025, EU Artificial Intelligence Act Regulation (EU) 2024/1689 phased application from February 2025 through August 2028, NIST AI Risk Management Framework 1.0 with the official crosswalk to ISO/IEC 42001 published at airc.nist.gov, and the BIS adoption as IS/ISO/IEC 42001:2023. Content is written in the voice of a senior advocate teaching a student — direct, warm, patient, in easy Indian English — and every substantive claim is anchored to a primary source. This course is built for working practitioners: Indian CIOs and CISOs adding AI risk management to an existing ISMS, Heads of AI and Data Science leaders running production ML/LLM systems, DPOs extending their DPDP scope to cover AI, General Counsels wanting to survive board questions on AI liability, consultants at cyber and AI advisory boutiques building an ISO 42001 practice, and Product Managers who need to answer the "provide your ISO 42001 certificate" line on the vendor questionnaire from a European or American customer.

inclusive of 18% GST
No account to create. We email you a one-click link.
How we use your personal data DPDP notice
  • What we collect: name, email, IP address (for security logging), and course progress.
  • Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
  • How long: kept until you unsubscribe or request erasure.
  • Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
  • Unsubscribe any time using the link in every email we send you.
Certificate on completion. Pass mark 70%.
Curriculum

Syllabus

8 modules, 40 lessons. Click any module to expand.

Let me start where most Indian CIOs and Heads of AI actually start — with a customer or a regulator asking for a certificate they have never heard of. This free preview module walks what ISO/IEC 42001:2023 actually is, where the standard sits in the ISO family, why it was published in December 2023, how the AI Management System (the thing you build) is different from the certificate (the thing a certification body issues), and why through 2025 and into 2026 it stopped being an optional badge and became a line item on every enterprise procurement questionnaire coming out of Europe and North America. Also covered: where India is in this story — the India AI Governance Guidelines released by MeitY in November 2025 which explicitly recommends ISO 42001 in Annexure 6, the BIS adoption as IS/ISO/IEC 42001:2023, the IT Amendment Rules 2026 on Synthetically Generated Information, and why the SEBI 5 May 2026 AI Advisory and the RBI FREE-AI Committee report of August 2025 mean that regulators are now watching AI risk directly, not through the ISO standard alone.

Free preview.

  1. 1. What ISO/IEC 42001 actually is, and why 2026 turned it into a procurement gate 12 min
  2. 2. The structure of ISO/IEC 42001 and where it sits in the ISO family 13 min
  3. 3. ISO 42001 vs NIST AI RMF vs the EU AI Act — which one is your customer actually asking for? 13 min
  4. 4. What actually happens in a twelve-to-eighteen month ISO 42001 certification 12 min
  5. 5. How the India AI Governance Guidelines sit on top of ISO 42001 12 min

Clauses 4 through 6 of ISO/IEC 42001:2023 set the strategic layer of the AIMS. Clause 4 defines the scope and organisational context — including the AI stakeholder map that includes affected individuals and society, not only paying customers. Clause 5 defines top-management commitment, the AI policy and roles.

Clause 6 defines the AI risk assessment methodology aligned to ISO/IEC 23894:2023, the risk-treatment approach and the AI objectives. This is where certifications are won or lost at the Stage 1 documentation review. Weak scope statements, generic AI policies that could apply to any organisation, and vague risk methodologies that fail to distinguish AI risk from ordinary IT risk produce the majority of Stage 1 nonconformities.

I will walk each clause exactly the way I would walk it with a client in the first two weeks of an implementation engagement.

  1. 1. Clauses 4.1 and 4.2: understanding your context and identifying interested parties 12 min
  2. 2. Clause 4.3: writing an AIMS Scope Statement that a certification body will accept 11 min
  3. 3. Clause 5: Leadership, AI Policy and Roles — where an AIMS becomes real 12 min
  4. 4. Clause 6.1: the AI risk assessment methodology — the beating heart of the AIMS 14 min
  5. 5. Clauses 6.2 and 6.3: AI objectives and planning of changes 10 min

Clauses 7 through 10 of ISO/IEC 42001:2023 set the operating layer. Clause 7 covers resources, competence, awareness, communication and the documented information the auditor will ask to see. Clause 8 executes the AI risk assessment methodology and produces the AI Risk Treatment Plan plus the results of the AI Impact Assessment referenced by Annex A.5.

Clause 9 monitors, measures, runs internal audits and management reviews. Clause 10 handles nonconformity, corrective action and continual improvement. The Stage 2 audit tests operating effectiveness of these clauses; internal-audit-programme quality and management-review discipline are the two most common Stage 2 findings across ISO 42001 audits reported through 2026.

I will walk each clause with the operating cadences and artefacts that actually satisfy Stage 2 — not the textbook version, the version I have seen pass and fail.

  1. 1. Clauses 7.1 to 7.4: Resources, Competence, Awareness, Communication 11 min
  2. 2. Clause 7.5: Documented information — what must be in writing, and how it is controlled 10 min
  3. 3. Clause 8: Operation — executing the risk methodology and running the AIIA 12 min
  4. 4. Clause 9: Performance evaluation — monitoring, internal audit, management review 13 min
  5. 5. Clause 10: Continual improvement, nonconformity and the CAPA process 10 min

ISO/IEC 42001:2023 Annex A organises 38 controls across nine control groups from A.2 to A.10. This module walks the first four groups: A.2 Policies related to AI, A.3 Internal organisation (including the reporting line for AI concerns which is a specific control the auditor will test), A.4 Resources for AI systems (data resources, tooling resources, human resources — competence again but on the resource side), and A.5 Assessing impacts of AI systems on individuals or groups and societies. Group A.5 is what the AI ethics literature and the India AI Governance Guidelines actually asks for: the AI Impact Assessment (AIIA).

ISO/IEC 42005:2025 is the companion standard for AIIA and this module walks how to run one that satisfies both the ISO auditor and the India AI Governance Guidelines expectation. Closes with the Statement of Applicability entries for A.2 through A.5.

  1. 1. Annex A.2 — Policies related to AI: three controls that anchor the AIMS 11 min
  2. 2. Annex A.3 — Internal organisation: AI roles and the concerns-reporting channel 10 min
  3. 3. Annex A.4 Part 1 — Data and tooling resources (A.4.2 and A.4.3) 11 min
  4. 4. Annex A.4 Part 2 — Compute, human and financial resources (A.4.4 to A.4.6) 10 min
  5. 5. Annex A.5 — AI Impact Assessment: the four controls that decide whether an AIMS is real 12 min

Groups A.6 through A.10 of Annex A contain the engineering-heavy controls most Heads of AI and ML platform teams recognise. A.6 AI system lifecycle covers requirements, design, development, verification and validation, deployment, operation and monitoring, and decommissioning — nine controls describing the working AI lifecycle. A.7 Data for AI systems covers data for development and enhancement, quality of data, data provenance, data preparation.

A.8 Information for interested parties covers system documentation, information for users and external reporting. A.9 Use of AI systems covers processes for responsible use, objectives, intended use. A.10 Third-party and customer relationships covers allocation of responsibilities, suppliers and customers.

Closes with the AIMS Control Ownership Matrix — who inside the organisation owns each control, who provides the evidence, and how does the auditor test it.

  1. 1. Annex A.6 Part 1 — AI lifecycle: requirements, design and development 11 min
  2. 2. Annex A.6 Part 2 — Verification, deployment, operation, monitoring and event logs 12 min
  3. 3. Annex A.7 — Data for AI systems: five controls with the DPDP overlay 11 min
  4. 4. Annex A.8 — Information for interested parties: where the IT Rules 2026 SGI obligations land 10 min
  5. 5. Annex A.9 and A.10 — Responsible use of AI systems and third-party relationships 11 min

This module puts the pieces together. Start with the AI system inventory — deciding what counts as an AI system in your organisation is harder than it sounds, especially for teams that have wrapped LLM APIs into every feature. Move to the AI Impact Assessment methodology (AIIA) using ISO/IEC 42005:2025 as the companion standard.

Then the AI risk assessment methodology using ISO/IEC 23894:2023. Then the Statement of Applicability across all 38 Annex A controls. Then the GRC tooling landscape — Vanta, Drata, Sprinto (Bengaluru), Secureframe, AuditBoard, TrustCloud and the newer AI-specific tooling from Credo AI, Fairly AI and Modulos that specifically pitch ISO 42001.

Score each on ISO 42001 module maturity, India presence, DPDP workflow support and cost band.

  1. 1. Building the AI system inventory — the foundation everything else hangs on 11 min
  2. 2. Running an AI Impact Assessment per ISO/IEC 42005:2025 — the operational template 13 min
  3. 3. Running the AI risk assessment methodology per ISO/IEC 23894:2023 12 min
  4. 4. Building the Statement of Applicability — the single most-audited document 11 min
  5. 5. GRC tooling landscape — buy versus build for an AIMS 10 min

You cannot self-certify ISO 42001. This module walks the accreditation chain — from ISO / IEC publishing the standard, through IAF and its Multilateral Recognition Arrangement, through national accreditation bodies (ANAB in the US, UKAS in the UK, RvA in the Netherlands, and NABCB in India whose scheme extension for ISO 42001 is pending as of September 2026), through the certification bodies (A-LIGN, BSI, Bureau Veritas, DNV, Schellman, SGS, TÜV SÜD, TÜV Nord). Then the CB RFP process — what to score them on.

Then Stage 1 (documentation review): what the auditor tests, common findings, remediation window. Then Stage 2 (operating effectiveness): sample sizes, control walkthroughs, evidence review, interview technique. Then major and minor nonconformities through the CAPA (Corrective Action Preventive Action) process.

Then certificate issuance and publication on your customer trust portal.

  1. 1. The accreditation chain — why the certificate means anything, and where NABCB stands on ISO 42001 10 min
  2. 2. CB selection — the RFP process, scoring criteria and negotiation 11 min
  3. 3. Stage 1 — the documentation review: what the auditor tests and how to pass first time 12 min
  4. 4. Stage 2 — the operating-effectiveness audit: sampling, interviews, evidence 13 min
  5. 5. The three-year sustain cycle — surveillance, recertification and living with the certificate 11 min

The ISO 42001 certificate is the baseline. Real Indian AI governance runs on top of it. This module walks the India regulatory overlay in the order it will actually hit your organisation.

First, the India AI Governance Guidelines released by MeitY in November 2025 — the seven sutras, the six pillars, and Annexure 6's ISO 42001 recommendation. Second, the IT Amendment Rules 2026 (notified 10 February 2026, effective 20 February 2026) which brought Synthetically Generated Information under intermediary due diligence — visual labelling, audio disclosure, metadata embedding, 2-3 hour takedown for deepfake harm. Third, SEBI Circular 5 May 2026 and the Cyber-suraksha.ai task force for market-regulated entities.

Fourth, the RBI FREE-AI Framework Report of 13 August 2025 for BFSI entities — non-binding today but sets RBI's direction for future master directions. Fifth, the DPDP Act 2023 intersection — no GDPR Article 22 equivalent, no right to explanation, but Significant Data Fiduciary status and DPIA requirements catch material AI use. Sixth, EU AI Act extraterritorial reach through 2 December 2027 Annex III high-risk deadline for Indian exporters.

Seventh, NIST AI RMF crosswalk. And a scan of the next five years — Digital India Act, likely RBI master direction based on FREE-AI, likely SEBI regulation converting the advisory into rules.

  1. 1. The India AI Governance Guidelines in operational depth — the seven sutras and six pillars, clause by clause 12 min
  2. 2. IT Amendment Rules 2026 SGI obligations in operational depth — the first binding AI law in India 11 min
  3. 3. Sector-specific overlays — SEBI 5-May-2026, RBI FREE-AI, and the wider sectoral picture 12 min
  4. 4. DPDP intersection with AI, and EU AI Act extraterritorial reach on Indian exporters 12 min
  5. 5. NIST AI RMF crosswalk and the next five years — closing the course 11 min
Frequently Asked

Everything a buyer usually asks

Who is this course for?
Indian CIOs, CISOs and Heads of Security at IT services companies, SaaS, GCCs, enterprises, BFSI, healthtech, edtech and fintech that are deploying AI in production and now need an AIMS Full audience list is on the course page below.
Is there a free preview?
Yes. Module 1 is a free preview: read every lesson in it without payment and without an account.
What do I get when I enrol?
Access to all 8 modules covering 40 lessons, the full citation register, the final exam (40 question bank with unlimited retakes at 70% pass mark), and a verifiable certificate with a public verify URL on completion.
Is there a certificate on completion?
Yes. Pass the final exam and you receive a certificate with a public verify URL that recruiters can validate in one click. LinkedIn-shareable.
How much does the course cost?
₹9,999 (inclusive of 18% GST). Lifetime access. One-time payment. Lifetime access including future updates.
How long do I have to complete the course?
Lifetime access. Self-paced. You can start, pause, and resume any time from any device.
Can I retake the final exam?
Yes, unlimited retakes. Options are shuffled per attempt and questions are drawn from a larger question bank, so each attempt is a fresh test of judgement.
How do you keep the course current when the law changes?
Every course carries a Legal Basis Version listing the exact instruments it teaches to. When a material instrument is amended or superseded, we update the affected lessons and email all enrolled learners.
Is this course legal advice?
No. This is an educational and awareness training programme. Nothing in the course creates a lawyer-client relationship. For specific compliance decisions, consult a qualified advocate or a regulator-empanelled auditor.
Educational content, not legal advice.

This course is a paid practitioner training programme aimed at working Indian CIOs, CISOs, Heads of AI and Data Science, DPOs, General Counsels, ISMS Managers, and consultants at cyber and AI advisory boutiques. Every substantive claim is anchored to a primary source: ISO clause number (e.g. Clause 6.1.2 AI risk assessment, Clause 7.5 Documented information, Annex A.5.2 AI impact assessment), India AI Governance Guidelines section number, IT Amendment Rules 2026 rule number, SEBI circular reference, RBI FREE-AI report page reference, DPDP Act section number, EU AI Act article number, or NIST AI RMF function-and-category ID. Items flagged as UNVERIFIED in the lesson prose are pending re-verification against the current primary source and must be checked before the student acts on them in a live certification engagement.

The course maintains a 15-item verification checklist covering ISO 42001 edition currency, BIS adoption identity to ISO text, India AI Governance Guidelines Annexure 6 language, IT Amendment Rules 2026 SGI obligations, SEBI 5-May-2026 Advisory scope, RBI FREE-AI conversion into binding master directions, DPDP automated-decision-making stance, EU AI Act phase dates, NIST AI RMF crosswalk currency, NABCB scheme extension, and vendor pricing benchmarks. This is not legal, tax, audit, or accounting advice and does not create a professional-client or advocate-client relationship. This course does not confer PECB, BSI or any other body's personal Lead Implementer or Lead Auditor certification. Those are separate personal-certification schemes governed by ISO/IEC 17024 requiring examination and CPD maintenance directly with the issuing body.

For certification of an organisation to ISO/IEC 42001:2023, engage a certification body accredited by an IAF MLA signatory (ANAB, UKAS, RvA, or NABCB once its scheme extension covers ISO 42001) directly.