ClearPenTest

ISO and IEC · ISO/IEC 42001:2023

Does ISO 42001 require a penetration test?

ISO/IEC 42001 is the first certifiable standard for an artificial intelligence management system. It sits alongside ISO 27001 in structure and is starting to appear in enterprise diligence for companies that ship AI features.

Common evidenceAnnex A controls on AI system impact assessment and verification

The short answer

ISO 42001 is a governance standard rather than a technical testing standard, so it does not require a penetration test. Where an AI system is part of a product, the security testing obligation usually arrives through ISO 27001 or SOC 2 instead, and adversarial testing of the AI surface is becoming an expected part of that scope.

Who it applies to

Organizations that develop or deploy AI systems and are being asked how those systems are governed.

In detail

42001 follows the same management system shape as 27001: context, leadership, planning, support, operation, performance evaluation and improvement, with an Annex A of controls. Its controls cover AI policy, roles, impact assessment, data governance and lifecycle management rather than exploitation-level technical testing.

The practical link to testing is the AI attack surface itself. Prompt injection, tool and agent authority, model supply chain and data exposure are security problems that show up in an ordinary application penetration test scope once a product has AI features, whether or not the organization pursues 42001.

What to have in scope

  • The AI surface as part of the application test: prompt handling, tool authority, data boundaries
  • Agent action paths where untrusted input can reach a privileged operation

Questions people ask

Does ISO 42001 require penetration testing?

No. ISO/IEC 42001 is a management system standard covering AI governance, impact assessment and lifecycle. Technical security testing obligations generally come from ISO 27001 or SOC 2, and adversarial testing of AI features is increasingly part of that scope.

This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.

Get a scoped price without a discovery call

Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.