ISO 42001 for AI Vendors: The Pen Test Evidence NHS Customers Will Ask For

ISO 42001 for AI Vendors: The Pen Test Evidence NHS Customers Will Ask For

By EJN Labs · 16 Sep 2026 · 7 min read

ISO 42001 certification shows an AI vendor runs formal governance over its AI system; it does not include a penetration test. NHS buyers, largely through the Digital Technology Assessment Criteria, separately expect a recent independent test of the APIs, model endpoints and data pipeline behind the product, alongside your ISO 42001 scope statement.

Why do NHS buyers ask AI vendors about ISO 42001 pen test evidence?

NHS buyers ask because ISO 42001 assesses how you govern an AI system, not whether it resists attack. A management-system audit typically checks your risk register and documented controls; it does not touch your live API, your model infrastructure or the database holding training data.

That gap is why the two certifications keep turning up in the same procurement pack alongside your other third-party assurance requirements. A DTAC submission or an NHS security review wants both: proof that AI risk is managed as a process, and proof that the software itself was tested by someone trying to break it. ISO 42001 answers the first question. Penetration testing answers the second, and buyers increasingly ask for it by name rather than assuming a management-system certificate covers it.

What does ISO 42001 actually require of an AI vendor?

ISO 42001 is the international standard for building and running an AI management system: a risk assessment for each use case, an AI impact assessment, and controls across the system’s lifecycle. It does not name penetration testing, vulnerability scanning or any other technical test as part of that scope.

That is a deliberate design choice, not an oversight. Management-system standards set out what an organisation must decide and document, leaving the choice of technical control to the organisation’s own risk treatment, in the same way ISO 27001 clause 6.1.3 leaves penetration testing out of its mandatory core and relies on a risk-based Statement of Applicability instead. Certification bodies typically audit your AIMS documentation and your evidence of following it; they do not run exploit code against your endpoints. If you sell AI outside the NHS market too, our companion piece on ISO 42001 and penetration testing for AI SaaS companies covers the same gap for commercial buyers.

What penetration test evidence do NHS buyers expect alongside it?

Most NHS buyers ask through the Digital Technology Assessment Criteria, whose technical security section expects proof that penetration testing has happened, typically an annual external test against the OWASP Top 10, a report from the last 12 months, plus a fix plan for what it found.

The Data Security and Protection Toolkit sits alongside DTAC and asks a related but separate question, since it covers your organisation’s wider security posture rather than one product. Where your platform handles patient data, NHS buyers typically also expect Cyber Essentials certification. None of these substitute for each other; a DTAC submission with no current pen test report attached is one of the most common reasons a technology assessment stalls before it reaches clinical safety review.

Where does the test need to reach on an AI product?

A pen test needs to reach every component that touches user data or model behaviour: the web application, the API layer serving the model, authentication and admin interfaces, and the cloud infrastructure hosting the model and its training data. A test scoped only to the marketing site misses what a buyer cares about.

Worth separating two things buyers sometimes conflate. A penetration test examines whether the infrastructure around your model can be compromised: broken authentication, an API returning another tenant’s data, a misconfigured storage bucket holding training data. Testing the model’s own behaviour, prompt injection resistance or output safety, sits in a different discipline again, and our wider guide to AI penetration testing covers that model-layer question in more depth. A DTAC submission should not present one as covering the other.

How do you get DTAC-compatible reporting ready before an NHS bid?

DTAC-compatible reporting starts with mapping your DTAC form against what a tester needs to see: the API list, the cloud accounts in scope, and a data flow diagram showing where training and inference data lives. Vendors who send this at kick-off typically get a scoped proposal back within two to three working days.

From there, testing itself typically runs one to three weeks depending on how many services are in scope, with the report structured to sit inside your DTAC evidence pack rather than as a generic technical document. Building in time for a retest after remediation, rather than submitting findings unresolved, is what turns the report from a red flag into evidence. Our full walkthrough of DTAC’s technical security expectations covers the paperwork end to end.

What does this typically cost in the UK market?

In the UK market, CREST-accredited testing typically prices at £1,100 to £1,400 per day. Testing the web application and APIs behind an AI product typically takes 5 to 8 days, so £5,500 to £11,200; adding a cloud configuration review takes it to 8 to 12 days, or £8,800 to £16,800.

ScopeTypical effortTypical UK cost
Web application and API testing for the AI product5 to 8 days£5,500 to £11,200
Adding cloud configuration review (model hosting, storage, data pipeline)8 to 12 days£8,800 to £16,800
Retest after remediation1 to 2 days£1,100 to £2,800

Two things drive the range beyond day count: how many separate services call the model, since a single API is quicker to cover than five microservices, and whether the training and inference data stores need their own cloud review. For a wider view of how these figures are built up across engagement types, see our guide to penetration testing costs in the UK. A scoping call gets you an exact, fixed figure rather than a range.

How EJN Labs approaches ISO 42001 pen test evidence for AI vendors

EJN Labs is a UK-based, CREST-accredited penetration testing firm, certified to ISO 27001 and ISO 9001, and holding Cyber Essentials and Cyber Essentials Plus ourselves. When an AI vendor comes to us ahead of an NHS bid, we start from the DTAC form and your architecture diagram together, so the days we quote map onto the sections a reviewer will actually read.

Every engagement covers the components that carry risk for your buyer: the web application, the API layer in front of the model, authentication, and the cloud configuration holding training and inference data. The report is structured so your team can lift findings straight into the DTAC evidence pack, with CVSS-scored findings, a remediation plan and, where you need it, a retest before your deadline. If ISO 42001 certification is still in progress, we can usually sequence the technical test to land first, since our experience is that it is the piece most NHS reviews stall on. Our API penetration testing and cloud penetration testing services cover the components this evidence needs, delivered by UK-based testers throughout.

Frequently Asked Questions

Does ISO 42001 require a penetration test?

No. ISO 42001 sets out how to build and run an AI management system, including risk assessment and lifecycle controls, but it does not name penetration testing as part of that scope. Certification confirms your AI governance process, not whether your APIs or endpoints would withstand a real attack.

What penetration test evidence do NHS buyers ask AI vendors for?

Most ask through the Digital Technology Assessment Criteria, whose technical security section expects a recent penetration test report dated within 12 months, covering the OWASP Top 10, stating whether testing was internal or third-party. Buyers handling patient data also typically expect Cyber Essentials.

What does penetration testing for an AI product typically cover?

Typically the web application, the API layer serving the model, authentication and admin interfaces, and the cloud configuration hosting training and inference data. It checks whether that infrastructure can be compromised, not whether the model resists prompt injection, which is a separate discipline.

How much does penetration testing for an AI vendor’s platform cost in the UK?

Web application and API testing for an AI product typically takes 5 to 8 days at £1,100 to £1,400 per day, so £5,500 to £11,200. Adding a cloud configuration review takes it to 8 to 12 days, or £8,800 to £16,800. The exact figure depends on how many services call the model, and comes from scoping via the quote form.

How long does it take to get pen test evidence ready for an NHS bid?

Scoping typically takes two to three working days once you send the API list and a data flow diagram. Testing itself runs one to three weeks depending on scope; in our experience, evidence with open high-severity findings rarely satisfies a DTAC review.

Get your ISO 42001 evidence gap covered before your next NHS bid

If a DTAC submission or an NHS security review is asking for penetration test evidence your ISO 42001 certificate doesn’t cover, we can scope a test around your API, model hosting and data pipeline. Get a CREST pentesting quote and we will set out a fixed scope and price for your product.

Leave a Reply

Your email address will not be published. Required fields are marked *