Hael
Book a meeting
ISO/IEC 42001 · United States

US ISO 42001 consultants

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Microsoft's SSPA programme requires ISO 42001 certification where service delivery includes Sensitive Use AI, and accepts it in lieu of independent assessment against Section K otherwise.
  • DPR version 12 defines two supplier types, Publishers and Deployers, and independent assurance applies to both.
  • ANAB accredits US certification bodies. Confirm the body holds accreditation for ISO/IEC 42001 specifically.
  • Colorado's repeal removed the ISO 42001 affirmative defence its original AI Act offered. Pages still citing it are out of date.
  • Certification body fees commonly run $7,500 to $25,000 for a smaller organisation, with implementation separate.

The Microsoft supplier requirement

US companies certify to ISO 42001 for procurement reasons rather than legal ones. There is no federal AI statute requiring it. What has changed is that large buyers began asking for AI governance evidence, and a certificate is the only thing in that conversation a procurement team can verify without a bespoke assessment.

A US ISO 42001 consultant builds the management system and prepares you for audit. Certification comes from an accredited certification body, which cannot be the same organisation under ISO/IEC 17021.

This is the sharpest driver in the US market and the one most often misunderstood.

Microsoft's Supplier Security and Privacy Assurance programme delivers its Data Protection Requirements to suppliers handling personal data, Microsoft confidential data or AI systems. Version 12 of those requirements went live on 30 March 2026, reducing the total requirement count from 67 to 63 and refining the AI obligations in Section K.

Two positions follow.

Where the service delivery includes Sensitive Use AI, an ISO 42001 certification is required.

For other AI services, an ISO 42001 certificate may be submitted in place of an independent assessment against Section K.

Version 12 also defines two categories of AI supplier: Publishers, who develop or own the AI system, and Deployers, who use a third-party AI system to deliver their services. Independent assurance requirements apply to both, which catches companies that assumed buying AI rather than building it kept them outside the scope.

Suppliers who cannot show the required evidence face restrictions in Microsoft's supplier portal, which affects new work rather than being a paperwork inconvenience.

Accreditation in the US

ANAB, the ANSI National Accreditation Board, accredits US certification bodies under the ISO/IEC 17021 scheme. As with UKAS in the UK, accreditation for ISO/IEC 42001 specifically is a separate scope entry from general management system accreditation.

Ask any body to confirm it holds ISO/IEC 42001 in its accreditation scope, and ask to see it. In a market this young, that question separates providers quickly.

State AI laws, and one correction

There is no federal AI statute. Binding duties sit in state law, and the position moved this year.

Texas TRAIGA took effect on 1 January 2026 and gives substantial compliance with the NIST AI Risk Management Framework an enforcement safe harbour. California SB 53 and AB 2013 took effect on the same date, alongside the CCPA automated decision-making regulations. Illinois HB 3773 amended the Human Rights Act for AI in employment from 1 January 2026. Utah's AI Policy Act has applied since 2024, and New York City Local Law 144 since 2023.

The correction worth carrying: Colorado repealed its 2024 AI Act and replaced it with SB 26-189, signed in May 2026, with core duties starting on 1 January 2027. The original act never took effect, and the affirmative defence it offered for organisations following ISO 42001 or the NIST AI Risk Management Framework did not survive into the successor. Any adviser still describing that defence as available has not updated since the spring.

ISO 42001 remains valuable in the US. The reason is procurement and demonstrable governance, not a statutory safe harbour.

Cost

ComponentTypical range
Gap analysis$7,000 to $20,000
Implementation$20,000 to $65,000
Certification body, initial cycle, smaller organisation$7,500 to $25,000
Certification body, enterprise or multi-site$25,000 to $100,000 and above
Annual surveillance auditRoughly 20% to 40% of the initial audit fee
Annual internal audit, outsourced$5,000 to $15,000

Fees run above the ISO 27001 equivalent because accredited capacity is limited. Book early: availability affects your date more than price does.

What a US-facing consultant should cover

They should establish whether Microsoft SSPA applies to you and, if so, whether you are a Publisher or a Deployer, because the assurance route differs.

They should be current on the Colorado position rather than repeating the affirmative defence.

They should build the management system so the same evidence answers enterprise security questionnaires, since for most US companies that is where the certificate earns its return. Our buyer assurance and security reviews service covers that.

They should raise the internal audit requirement early. Clause 9.2 requires one before certification and annually after, your certification body cannot perform it, and most US companies under a few hundred people have nobody independent. This is covered in ISO 42001 - Internal Audit Consultants.

Where SOC 2 and ISO 27001 help

Most US companies pursuing ISO 42001 already hold SOC 2, and many hold ISO 27001. The security controls, change management and supplier oversight transfer. The genuinely new work is the AI system inventory, the AI system impact assessment, data governance for AI, and lifecycle controls over models.

Where you hold ISO 27001, Annex D of ISO/IEC 42001 supports running one integrated management system, which is cheaper than two. See our ISO 27001 and SOC 2 service pages.

What to do next

Check whether Microsoft SSPA applies to you and which supplier category you fall in. If it does and Sensitive Use is involved, the certificate is a requirement rather than a differentiator, and the timeline matters.

Our free readiness diagnostic gives a first view, and the ISO/IEC 42001 service page sets out how we run the programme.

References

FAQ

Does Microsoft require ISO 42001?

Where service delivery includes Sensitive Use AI, yes. For other AI services, an ISO 42001 certificate may be submitted instead of an independent assessment against Section K of the Data Protection Requirements.

Does ISO 42001 give us a legal safe harbour in the US?

Not currently. Colorado's original AI Act offered an affirmative defence, but it was repealed in May 2026 and the defence did not survive into the replacement statute.

Who accredits US certification bodies?

ANAB, under the ISO/IEC 17021 scheme. Confirm the body holds ISO/IEC 42001 in its accreditation scope specifically.

What does ISO 42001 cost in the US?

Certification body fees commonly $7,500 to $25,000 for a smaller organisation, with implementation of $20,000 to $65,000 separate.

Does SOC 2 reduce the work?

Some of it. Security and change controls transfer. The AI inventory, impact assessment and model lifecycle controls are new work.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We take companies through ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001, building one management system that answers multiple procurement and regulatory demands rather than several parallel ones. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO/IEC 42001, free.

Answer a short set of questions and see what ISO/IEC 42001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO/IEC 42001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO/IEC 42001.

Or speak to us about your deadline. Book a meeting.