ISO/IEC 42001:2023 is the first international standard for an AI management system (AIMS) — the policies, roles, risk processes and controls an organization uses to develop, provide or use AI responsibly. Published in December 2023, it is voluntary, not a law, and no regulator requires it outright. But it is becoming the reference point vendors, regulators and enterprise buyers point to when they ask "how do you govern AI," and organizations can be independently certified against it. It does not replace the EU AI Act, and certification does not automatically satisfy it — the two are related but distinct.
What is ISO/IEC 42001?
ISO/IEC 42001:2023, formally titled Information technology — Artificial intelligence — Management system, is the first international standard specifying requirements for an AI management system. It was published in December 2023 by ISO/IEC JTC 1/SC 42, the joint technical committee that develops AI standards for ISO and the International Electrotechnical Commission.
An AI management system, in the standard's own terms, is the set of policies, roles, processes, controls and documented evidence an organization uses to govern how it develops, provides or uses AI. ISO 42001 follows the same Harmonized Structure as other well-known ISO management-system standards — ISO 27001 for information security, ISO 9001 for quality — with clauses 4 through 10 covering context, leadership, planning, support, operation, performance evaluation and improvement. Organizations that already hold ISO 27001 typically find the management-system clauses familiar; the delta is Annex A's AI-specific controls and the AI impact-assessment process the standard requires.
The standard applies across sectors and AI system types — predictive machine learning, generative AI, agentic systems — and to organizations that provide AI products, deploy AI systems in their own business processes, or use AI systems supplied by someone else.
Is ISO 42001 mandatory?
No. ISO 42001 is a voluntary international standard. No government requires certification against it by law, and it is not itself a regulation.
What is changing is the practical pressure to have one anyway. Enterprise buyers increasingly ask vendors for it in due-diligence questionnaires and RFPs, the way ISO 27001 became a de facto requirement for enterprise software procurement. Regulators and courts are starting to treat a certified AIMS as evidence of a documented, auditable governance process — useful, though not sufficient, if an organization has to demonstrate it took AI risk seriously. And it is explicitly designed to be complementary to binding regulation rather than a substitute for it: the EU AI Act, which reached its main compliance deadline for high-risk AI system obligations on August 2, 2026, does not treat ISO 42001 certification as automatic proof of compliance. An organization can be ISO 42001 certified and still have EU AI Act obligations to satisfy separately, and vice versa.
Who needs it?
The standard is written broadly enough to cover three different relationships to AI, and most organizations doing anything serious with AI fall into at least one.
- Providers — organizations that build and sell AI products or models. Certification is a market signal: it says a buyer's due-diligence team doesn't have to take the vendor's governance claims on faith.
- Deployers — organizations that build AI into their own products or internal workflows. Certification here demonstrates the organization governs what it builds, not just what it buys.
- Users — organizations that consume AI systems supplied by others inside their operations, without building anything themselves. A lighter-weight AIMS still applies: vendor oversight, use-case risk assessment, and monitoring are all in scope.
In practice, the sectors moving first are the ones already used to management-system certification and carrying the most regulatory or reputational exposure from AI going wrong: financial services, healthcare, defense and public-sector technology, and any B2B software vendor selling into those sectors.
What's inside the standard
Two parts do the work: the management-system clauses that set up the system itself, and Annex A, the AI-specific control catalogue you draw from — not a checklist you implement top to bottom.
The management-system clauses (4–10)
Context of the organization, leadership and AI policy, planning and risk assessment, support (resources, competence, awareness), operation (including the AI impact assessment), performance evaluation, and continual improvement. This is the same skeleton ISO 27001 and ISO 9001 use, which is why it integrates cleanly into an organization that already runs one of those systems.
Annex A — 38 controls, 9 objectives
| Ref | Control objective | What it covers |
|---|---|---|
| A.2 | AI policy | A documented, leadership-approved policy for how the organization develops, provides or uses AI |
| A.3 | Internal organization | Roles, responsibilities and reporting lines for AI governance |
| A.4 | Resources | The people, tools and data resources the AIMS needs to actually function |
| A.5 | Impact assessment | Assessing the impact an AI system could have on individuals, groups and society before and during deployment |
| A.6 | AI system life cycle | Requirements spanning design, development, verification, deployment, operation and retirement |
| A.7 | Data for AI systems | Data quality, provenance, and governance specific to training and operating AI systems |
| A.8 | Information for interested parties | Transparency: what users, regulators and other stakeholders are told about the AI system |
| A.9 | Use of AI systems | Governance of how the organization actually uses AI systems in its operations |
| A.10 | Third-party and customer relationships | Managing AI-related risk introduced by vendors, suppliers and customers |
Which controls apply to a given organization is documented in a Statement of Applicability, justified by that organization's own AI risk and impact assessments — not every control applies to every organization equally.
Can companies be certified against ISO 42001?
Yes. Certification is performed by accredited, independent certification bodies, the same model used for ISO 27001 and ISO 9001 — not by ISO itself.
The process runs a Stage 1 audit (documentation review — is the AIMS designed correctly) followed by a Stage 2 audit (does it actually operate this way in practice), and a certificate, once issued, is valid for three years with annual surveillance audits to keep it current. Typical timelines run four to nine months, shorter for organizations that already hold ISO 27001, since the management-system clauses carry over directly. Cost varies by organization size and scope but commonly falls in the tens of thousands of dollars once audit fees and the internal effort to build the AIMS are counted.
One detail that changed the market more than most implementation teams noticed: ISO/IEC 42006:2025, published in July 2025, governs the certification bodies themselves. Before it existed, AIMS audits ran under the generic rules for management-system certification bodies, with no AI-specific competence requirement for auditors. ISO 42006 adds a competence floor for the people conducting AIMS audits and rules for how certification bodies document and stand behind the certificate — worth checking when you pick a certification body, since not every accredited body was necessarily built for AI-specific audits before 2025.
Who should own implementation?
ISO 42001 gets misfiled more often than almost any other standard on this list. It reads like a compliance document, so it often lands with legal, information security, or a quality-management team already running ISO 27001 — and each of those owners misses something the standard actually requires.
Legal and compliance understand regulatory exposure but rarely have visibility into how a model actually behaves in production. Information security teams understand controls and audits but not AI risk assessment or model impact specifically. A pure quality-management owner treats it as paperwork rather than as a live governance system tied to actual AI initiatives. The AI policy, the impact assessments, and the life-cycle controls in Annex A all require someone who understands both the organization's AI portfolio and its risk exposure — which is precisely the Chief AI Officer's mandate, sitting across the initiatives that make the standard's requirements concrete rather than abstract. Where no CAIO exists yet, ownership should sit with whoever chairs AI governance cross-functionally, with legal, security and engineering as named contributors, not the sole owner.
How ISO 42001 relates to AI governance more broadly
ISO 42001 is one piece of a wider AI governance landscape, not the whole of it. It is the certifiable management-system standard; the others below are either binding law, a voluntary framework, or supporting technical standards it draws on.
| What it is | Certifiable? | |
|---|---|---|
| ISO/IEC 42001 | Voluntary international AI management-system standard | Yes |
| EU AI Act | Binding EU law, risk-tiered obligations for AI systems placed on the EU market | No — legal compliance, not a certificate |
| NIST AI RMF | Voluntary US framework built around four functions: Govern, Map, Measure, Manage | No |
| ISO/IEC 23894 | Guidance on AI-specific risk management, extending ISO 31000 | No — informative |
| ISO/IEC 22989 | Shared AI vocabulary and concepts the other standards rely on | No — informative |
NIST's four functions map onto ISO 42001's requirements closely enough that work done for one framework carries into an audit for the other — they are complementary, not competing. The practical read for an executive: ISO 42001 gives you the auditable governance structure; the EU AI Act and any other binding regulation you're subject to are still separate legal obligations layered on top of it.
Getting started
- Inventory what you already have. If you hold ISO 27001, most of clauses 4–10 are already in place; the gap is Annex A and the AI impact-assessment process.
- Name an owner. A CAIO or cross-functional AI governance lead, not a compliance team working alone.
- Run the AI impact assessment on your actual AI initiatives — this is what turns the standard from paperwork into a live governance system.
- Draft the Statement of Applicability against the 38 Annex A controls, justified by that impact assessment.
- Choose a certification body accredited under ISO/IEC 42006, and budget four to nine months for the Stage 1 and Stage 2 audits.
A certificate on the wall does not govern anything. The AI impact assessment, run against real initiatives, is what makes ISO 42001 a working system instead of a binder.
Building the AIMS correctly the first time — the policy, the impact-assessment process, the Statement of Applicability, and the evidence a certification body will actually accept — is exactly the kind of governed-initiative work covered in World AI University's Certified AI Consultant program, which applies a full AI transformation methodology, including governance and risk design, to a real client initiative under expert review.
Seven weeks; one real client initiative, including governance and risk design; reviewed by the World AI Council.
Explore the Certified AI Consultant ProgramExecutives building this into their organization's AI portfolio from the inside — rather than advising on it from the outside — should see the Chief AI Officer Program, which covers governance and risk design as one module of a broader initiative methodology.
Frequently asked questions
Does ISO 42001 certification satisfy the EU AI Act?
No. Certification does not grant automatic presumption of conformity under the EU AI Act. It builds much of the governance infrastructure the Act expects, but the Act's own obligations still have to be satisfied separately.
How is ISO 42001 different from ISO 27001?
ISO 27001 governs information security broadly, with 93 Annex A controls across four themes. ISO 42001 uses the same management-system skeleton but is scoped specifically to AI, with 38 controls focused on AI policy, impact assessment, the AI life cycle and AI-specific data governance.
How long does certification take?
Typically four to nine months from a standing start, shorter for organizations that already hold ISO 27001, since the management-system clauses carry over.
Do we need to implement all 38 Annex A controls?
No. Annex A is a reference catalogue. Which controls apply is determined by your own AI risk and impact assessments and recorded in a Statement of Applicability, with any exclusions justified.
