Can Small AI Startups Achieve ISO 42001?
How ISO 42001 can work for small and scaling startups.

ISO 42001 is built around AI management systems, focusing on how your business implements and governs AI systems. So it can apply whether you're a five-, 10-, or 100-person startup.
Size isn't a qualifier for anything in the standard. Rather, what ISO 42001 cares about is your organization's relationship with AI. Whether you build it, deploy it, or operate models built by other companies. The goal is just to show you have a working system and working plans and policies to manage the risks that come with it.
What exactly is ISO 42001?
ISO 42001 is the first international, certifiable standard for an AI management system (AIMS), offering organizations a structured way to govern how they develop, deploy, and monitor AI responsibly.
ISO 42001 applies to "any organization, regardless of size, type, or nature" that provides or uses AI systems. It's a voluntary, risk-based standard. So it doesn't give you a list of technical controls you must implement. Instead, its Annex A gives you 38 reference controls across nine categories and it's up to your organization to decide which apply to you through the Statement of Applicability — you just have to justify what's included and what's left out.
The standard is designed to work for businesses at any stage, with any team size.
What Does a Startup Need to Get ISO 42001 Certified?
The AI management system (AIMS) is at the core of ISO 42001. Your AIMS needs to include documentation about how you govern AI, and evidence that you actually follow through in practice.
Your auditor will be looking for a handful of things to exist and function:
- AI policies detailing how you use AI across the organization and in your product(s)
- Clear ownership and accountability around AI usage
- Documented AI risk assessment policies and clear guidelines on how you govern the AI products you use
- Incident response plans
- Evidence your policies are being followed
You don't need enterprise scale or multiple full-time security hires to achieve this. ISO 42001 is achievable for a startup of almost any size, but you'll need discipline to put the right policies in place and evidence that your team follows them.
How Does ISO 42001 Scale Down for a Small Team?
Whether you're a 12-person AI startup or a 2,000-person enterprise, ISO 42001 holds those teams to the same standards. But the implementation will look different.
For example, at an enterprise business, you might stand up an AI governance board to oversee AI across the whole organization. For a 10-person startup, one person could own the process. Both can satisfy ISO 42001's requirements.
That same logic can be used throughout the standard:
- Keep the scope tight: You're allowed to define your AIMS scope, only include the processes and products that matter.
- Keep governance lightweight: As you're small, determine one owner and repeatable processes, over a committee.
- Build process into your existing routines: A recurring AI check during each sprint or release can work, you don't need to reinvent the wheel to govern AI effectively. Your existing workflows will often cover at least some of the evidence required for ISO 42001.
- Select controls proportionate to risk: You don't have to include all 38 Annex A controls, only the ones that fit your context.
- Keep a running list of AI tooling: As you add new tools or suppliers (like OpenAI or Anthropic) keep them on a list and explain how and where they're used across the business and your products.
If you already have SOC 2 or ISO 27001 in place you can also re-use some of your existing policies and controls for ISO 42001. Things like access control, change management, and incident response all carry over to ISO 42001.
But there will be some new policies you'll need to produce for ISO 42001. These include an AI policy, risk methodology, and acceptable-use rules.
Don't Treat ISO 42001 Like a Binder Exercise
Size is rarely, if ever, a blocker for ISO 42001. The biggest challenge is often ensuring that your documentation and policies reflect the reality of how your team operates.
Auditors will probe for evidence that AI risks are being reviewed and managed. They'll expect to see dated risk reviews, incident records, and data to back up that every policy and procedure you say is in place is working.
The goal should be a simple, straightforward program that everyone on your team can understand and follow, not an elaborate plan that fails to materialize in the day-to-day reality of operating a startup. That's also a great reason to start while you're small — the program can begin lightweight, tied to how you actually work, and scale with the company.
Small AI Startups Can Achieve ISO 42001 (And We're Here to Help)
AI startups of any size can achieve ISO 42001. The standard measures your AI management system and your role with AI, and the work scales down to lightweight, evidenced controls that live inside how you already ship.
The hard part was never your size. It's proving disciplined AI risk management without turning it into theater, and that's a bar a focused startup can generally clear more easily than a large enterprise.
If you're weighing whether it's realistic — or looking into the business case for ISO 42001 — we're here to help.
At Workstreet, we've helped startups like Clay implement ISO 42001, and we can help with every aspect of the standard: deciding what goes inside your AIMS boundary, choosing which controls to include, producing the evidence, and figuring out whether ISO 42001 is the right next step in the first place.
If you're exploring ISO 42001 and want to see what a right-sized version looks like for your company specifically, talk to our team.

