Aug 20 2026

The AIMS/ISMS readiness ladder: seven steps from curious to certified

Category: Information Security,ISO 27k,ISO 42001disc7 @ 10:38 am

A practical seven-step path from a 15-minute readiness call to ISO 42001 and ISO 27001 certification — with the prep work that makes each step fast instead of painful.

Most organizations don’t stall on ISO 42001 or ISO 27001 because the standards are hard. They stall because step one is unclear, and the gap between “we should probably do this” and “we’re booking a Stage 1 audit” has no visible rungs. Here are the rungs — and the prep that makes each one fast.

Each step below is designed to be finished, not admired. Each one produces an artifact you keep and reuse at the next step — the AI system register you build for a gap assessment is the same register your certification auditor samples from. Nothing is throwaway.

You can enter at any rung. Most organizations that already have SOC 2 or a mature security program enter at step 3 or 4. Organizations meeting AI governance for the first time should start at step 1.


01 — Book a 15–20 minute readiness discussion

Time: 20 minutes · Cost: free · Output: a scope boundary and a sequencing decision

The purpose of this call is not a sales pitch — it’s to answer two questions that determine everything downstream: what’s actually in scope, and which standard goes first.

How to make it efficient. Come with three answers ready. That’s the whole prep.

  • What triggered this? A customer security questionnaire, an RFP requirement, funding diligence, EU AI Act exposure, or a board ask. The trigger sets the deadline and the evidence bar.
  • Do you build AI, buy AI, or both? Under ISO 42001 this is the provider/user distinction, and it decides which Annex A controls actually bite. “Both” is the common answer and it’s fine — just say so.
  • What’s your real deadline? Certification bodies book out. A date changes the plan more than a budget does.

Schedule the readiness discussion →


02 — Run the free 5-minute risk assessment quiz

Time: 5 minutes · Cost: free · Output: a directional read on your exposure

A fast self-check across your core security and governance posture. It won’t produce audit evidence, and it isn’t meant to — it tells you whether you’re 20% ready or 70% ready before you spend money finding out.

How to make it efficient.

  • Answer as things are, not as they’re written. A policy nobody follows is a “no.” Auditors test operation, not intent, so score yourself the way Stage 2 will.
  • Have two people take it independently — ideally someone in engineering and someone in leadership. The delta between their scores is usually a more useful finding than either score. Disagreement about what’s in place is the governance gap.

Take the 5-minute quiz →


03 — Order the $49 ISO 42001 AIMS gap assessment

Time: ~1 hour of your input · Cost: $49 · Output: clause-by-clause and control-by-control gap table

This assesses you against the mandatory clauses (4–10) and the Annex A controls of ISO/IEC 42001:2023, and returns a status per item with the evidence each one requires and a prioritized remediation order.

How to make it efficient.

  • Build the AI system register first. One spreadsheet row per AI system, with its intended purpose, owner, and whether you built it or bought it. This single artifact accelerates every step after it.
  • Include the AI you forgot you have. Embedded AI features in SaaS tools, coding assistants, AI in your support desk, an LLM API call buried in one microservice. Incomplete registers are the most common finding I write.
  • Don’t pre-clean. Send the messy version. A gap assessment priced at $49 is worthless if it’s assessing a sanitized picture.

Expect the usual suspects to surface: no AI system impact assessment (AISIA), undocumented human oversight, thin data governance, no supplier AI due diligence, and AI objectives written as principles rather than measurable targets.

Get the $49 ISO 42001 gap assessment →


04 — Order the $59 ISO 27001 ISMS gap assessment

Time: ~1–2 hours of your input · Cost: $59 · Output: gap table across clauses 4–10 and the 93 Annex A controls

Same structure, applied to ISO/IEC 27001:2022 — the 93 controls across the four themes, plus the mandatory documented information the standard requires. If a customer is asking for “a security certification,” this is usually the one they mean.

How to make it efficient.

  • Bring your asset and supplier inventories, whatever state they’re in, plus the policy set you already have. Most organizations have more written than they think and less operating than they hope.
  • Reuse your SOC 2 evidence if you have it. The overlap is substantial, and mapping existing evidence is far cheaper than generating new evidence.
  • Work in 2022 only. The 2013 transition window closed in October 2025 — there’s no reason to assess against the retired version.

Doing both assessments together is the efficient move if AI governance and security certification are both on your roadmap: the two standards share the same clause structure, so the overlapping gaps get remediated once rather than twice.

Get the $59 ISO 27001 gap assessment →


Why the ladder compounds. ISO 42001 and ISO 27001 both follow the ISO High Level Structure. That means one scope statement, one risk methodology, one internal audit programme, one management review, and one corrective action log can satisfy both standards. Organizations that run them sequentially pay for the management system twice. Run them as a single integrated system and the second certification costs a fraction of the first.


05 — Run the 7–10 day AIMS/ISMS Quick-Start

Time: 7–10 calendar days · Output: the mandatory document set, drafted and ready to sign

The Quick-Start converts your gap assessment into the documents the standard actually requires: scope, top-management-signed policy, risk assessment and treatment plan, AI system impact assessment, Statement of Applicability, measurable objectives, an internal audit programme, and a management review agenda.

How to make it efficient.

  • Name one owner with signing authority before day one. The single biggest cause of a 10-day engagement becoming a 10-week one is documents waiting on an approver who was never identified.
  • Batch the input. Two or three 90-minute working sessions beat three weeks of asynchronous questions.
  • Don’t write policy for controls you don’t operate. Every unearned claim in a policy becomes a nonconformity at Stage 2. Where a control isn’t running yet, the honest answer is a dated plan, and auditors accept that.

Start the 7–10 day Quick-Start →


06 — Implement the AIMS/ISMS

Time: typically 8–16 weeks · Output: a management system with operating history

Documents don’t certify — evidence does. Implementation is where the risk assessments get executed, impact assessments get completed per AI system, training gets delivered and logged, supplier assessments get run, and incidents get recorded through the process you wrote.

How to make it efficient.

  • Instrument the evidence at the source. If access reviews, training completions, and change approvals generate records automatically in tools you already use, evidence collection stops being a project.
  • Accumulate operating history deliberately. Stage 2 samples records over a period. Two to three months of a control genuinely running beats a perfect binder assembled the week before.
  • Log the boring events. An incident log with zero incidents proves nothing. A log showing minor events triaged and closed proves the process works — which is exactly what the auditor is testing.

Discuss implementation support →


07 — Certify

Time: Stage 1 and Stage 2, typically 4–8 weeks apart · Output: an accredited certificate

An accredited certification body audits in two stages: Stage 1 reviews your documented management system, Stage 2 verifies it operates. Then annual surveillance audits, with recertification every three years.

How to make it efficient.

  • Book the certification body early. Scheduling — not readiness — is the most common reason certification dates slip. Get on the calendar while you’re still implementing.
  • Complete your internal audit and management review before Stage 1, not between the stages. Both are mandatory, both take real calendar time, and squeezing them into the gap is where teams lose their date.
  • Rehearse the interviews. Stage 2 auditors talk to control owners, not just the compliance lead. Thirty minutes of prep with each owner — what they do, where the record lives — converts a stressful audit into a routine one.

This is the path I ran with ShareVault, a virtual data room platform serving M&A and financial services clients, through ISO 42001 Stage 2 certification on the first attempt — as implementer and internal auditor. Financial data rooms are the hard mode of compliance, and the ladder held.

Talk about certification →


Pick your rung

If you don’t know where you sit, start at the top of this list — the call is 20 minutes and it will tell you which step is actually yours.

  1. Schedule a 15–20 minute AIMS/ISMS readiness discussion — free, 20 min
  2. Free 5-minute risk assessment quiz — free, 5 min
  3. Paid AIMS ISO 42001 gap assessment — $49
  4. Paid ISMS ISO 27001 gap assessment — $59
  5. 7–10 day AIMS/ISMS Quick-Start — fixed scope
  6. ISO 42001/27001 AIMS/ISMS implementation — 8–16 weeks
  7. ISO 42001/27001 AIMS/ISMS certification — Stage 1 + Stage 2

DISC InfoSec — Deura Information Security Consulting LLC · Petaluma, CA info@deurainfosec.com · (707) 998-5164 · calendly.com/hd-deurainfosec

A practical seven-step path from a 15-minute readiness call to ISO 42001 and ISO 27001 certification — with the prep work that makes each step fast instead of painful.

Download the AI Governance & Cybersecurity pdf file

AI Attack Surface ScoreCard 

MachineLearning & Artificial Intelligence

AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do

Your Shadow AI Problem Has a Name-And Now It Has a Score

Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

AIMS and Data Governance – Managing data responsibly isn’t just good practice—it’s a legal and ethical imperative

Schedule a consultation: info@deurainfosec.com

InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Securit

DISC InfoSec blog | DISC InfoSec Site 

Tags: AIMS, isms, iso 27001, ISO 42001

Leave a Reply

You must be logged in to post a comment. Login now.