ISO/IEC 42001: what the AI management system standard requires, and who is being asked for it.
ISO/IEC 42001:2023, published in December 2023, is the first certifiable international standard for an Artificial Intelligence Management System, abbreviated AIMS. It is to an organization's use of AI what ISO/IEC 27001 is to its information security: a management system standard that turns intentions into documented, auditable, sustained practice. This page explains what the standard contains, how it parallels ISO 27001, who is asking organizations for it, and what readiness work involves.
ISO/IEC 42001:2023
- Published December 2023 by ISO/IEC JTC 1/SC 42
- Certifiable requirements in Clauses 4 through 10
- 38 reference controls in 9 Annex A objectives
- AI system impact assessment required
- Statement of Applicability documents control selection
- Structured to integrate with ISO/IEC 27001
What ISO/IEC 42001 is and what certification actually attests.
ISO/IEC 42001 defines the requirements for establishing, implementing, maintaining, and continually improving an AI management system. A management system, in the ISO sense, is the organizational machinery around a subject: the scope decisions, policies, assigned responsibilities, risk processes, operating procedures, records, internal audits, and management reviews through which an organization directs and controls that subject over time. ISO 9001 applies this machinery to quality. ISO/IEC 27001 applies it to information security. ISO/IEC 42001 applies it to the development and use of artificial intelligence.
This makes the standard fundamentally different from a technical AI specification. It does not certify that a model is accurate, unbiased, or safe. It certifies that the organization operates a governed, auditable system for managing its AI activities and their risks: that AI use is inventoried, that impacts on people are assessed, that responsibilities are assigned, that suppliers are examined, and that the whole arrangement is documented, measured, and reviewed. The distinction matters when reading vendor claims. An ISO 42001 certificate speaks to how an organization manages AI, not to the performance of any particular AI system.
The standard is written for organizations in any role with respect to AI. A company that develops models, a company that integrates AI into products, and a company that simply uses AI tools and AI-enabled services all fall within its intended audience, with the applicable controls tailored to the role. For most small and midsize organizations, the relevant role is deployer and user, which shapes a lighter but still substantive management system centered on inventory, policy, impact assessment, and supplier oversight.
Seven certifiable clauses and four annexes.
The certifiable requirements sit in Clauses 4 through 10, which follow the harmonized structure shared by modern ISO management system standards and trace the Plan, Do, Check, Act cycle. The annexes supply the controls and the guidance for implementing them.
| Element | Subject | What It Requires |
|---|---|---|
| Clause 4 | Context of the organization | Determine internal and external issues, interested parties, the organization's role with respect to AI, and the scope of the AI management system. |
| Clause 5 | Leadership | Top management commitment, an AI policy, and assigned roles, responsibilities, and authorities for the management system. |
| Clause 6 | Planning | AI risk assessment and risk treatment, the AI system impact assessment process established at 6.1.4, measurable AI objectives, and planning of changes. |
| Clause 7 | Support | Resources, competence, awareness, communication, and control of documented information. |
| Clause 8 | Operation | Operational planning and control, performance of the AI risk assessments and the AI system impact assessment defined in planning, and treatment implementation. |
| Clause 9 | Performance evaluation | Monitoring and measurement, internal audit, and management review of the AI management system. |
| Clause 10 | Improvement | Nonconformity handling, corrective action, and continual improvement. |
| Annex A | Reference controls | 38 controls organized into 9 control objectives, selected and justified through a Statement of Applicability. |
| Annex B | Implementation guidance | Guidance for implementing each Annex A control. |
| Annex C | Objectives and risk sources | Potential AI-related organizational objectives and risk sources to consider during risk assessment. |
| Annex D | Domain and sector standards | Guidance on using the AI management system across domains and alongside sector-specific standards. |
Two elements deserve particular attention because they generate most of the real work. The first is the AI system impact assessment, established in planning at Clause 6.1.4 and performed in operation at Clause 8.4. It requires the organization to assess the consequences of its AI systems for individuals, groups, and society, and it has no equivalent in ISO 27001, which means even a mature ISMS organization builds this process new. The second is the Statement of Applicability, the document that records which Annex A controls apply, which do not, and why. The Statement of Applicability is where an auditor starts, and it is where a poorly scoped program is exposed first.
The nine control objectives.
Annex A organizes its 38 controls into nine objectives, each addressing one domain of AI-specific risk. The controls are principle-based rather than prescriptive: they state what must be achieved, and the organization determines how, proportionate to its role and the risks its impact assessments identify.
Policies related to AI
Management direction for AI through an AI policy that is documented, aligned with other organizational policies, and reviewed.
Internal organization
Assigned roles, responsibilities, and reporting lines for AI, including the process for raising concerns about AI systems.
Resources for AI systems
Documentation of the data, tooling, system, computing, and human resources each AI system depends on across its life cycle.
Assessing impacts of AI systems
The impact assessment process itself: evaluating consequences for individuals, groups, and society, and documenting the results.
AI system life cycle
Objectives, requirements, design, verification, deployment, operation, and monitoring managed as defined life cycle stages with records.
Data for AI systems
Management of data used in AI systems, including provenance, quality, preparation, and the controls appropriate to its sensitivity.
Information for interested parties
What users, customers, and other parties are told about AI systems, including reporting channels and required disclosures.
Use of AI systems
Responsible use processes, defined intended use, and operation of AI systems within their documented purposes.
Third-party and customer relationships
Allocation of responsibility among the organization, its suppliers, and its customers, and oversight of AI obtained from third parties.
One management system, extended, rather than two programs.
ISO/IEC 42001 was written on the same harmonized structure as ISO/IEC 27001. The clause numbers and their subjects match deliberately: context is Clause 4 in both standards, leadership is Clause 5, planning is Clause 6, and so on through improvement at Clause 10. This is not a stylistic convenience. It means an organization already operating an ISO 27001 information security management system can extend the management system it has, using the same document control, the same internal audit program, the same management review cadence, and in most cases the same personnel, rather than standing up a parallel bureaucracy for AI.
The genuine additions are two. The Annex A control set is AI-specific, so the organization performs a new control selection and writes a new Statement of Applicability for the AIMS scope. And the AI system impact assessment is a new process with no ISMS counterpart, because information security asks what could happen to the organization's information while the impact assessment asks what the organization's AI could do to people. Everything else, risk methodology, competence records, corrective action handling, audit discipline, transfers.
I approach ISO/IEC 42001 from that management system side. I hold ISO/IEC 27001 certifications as an auditor and in implementation, and the readiness work described below treats 42001 as an extension of management system discipline the organization may already have, rather than as a novel AI specialty detached from it. Integrated audits covering both standards are becoming the norm among certification bodies for exactly this reason.
Nobody mandates ISO/IEC 42001. Several parties are asking for it anyway.
No statute requires ISO/IEC 42001 certification. The demand arrives commercially, through the same channels that made ISO 27001 a de facto requirement long before any law named it. The standard has begun appearing in public procurement tender requirements in Europe, and alignment with it is becoming a baseline expectation for vendors selling AI-enabled products to enterprises. Customer due diligence questionnaires increasingly ask whether an AI governance framework or management system is in place, and an AIMS is the most defensible answer available. Large certification bodies opened ISO/IEC 42001 programs through 2024 and 2025, and accredited certificates are now being issued, which converts the standard from an aspiration into something a counterparty can verify.
For a US organization, the practical calculation usually runs as follows. Certification is worth pursuing when customers or markets will ask for the certificate itself, which today is most common for technology vendors, AI-enabled service providers, and organizations selling into large enterprises or European buyers. Alignment without certification is the sensible position for most other organizations: build the inventory, the policy, the impact assessment process, and the supplier oversight the standard describes, hold the records, and be in a position to certify later if the market demands it. The management system is the durable asset; the certificate is a claim about it that can be added when it earns its cost. This mirrors the framework-based approach described on the AI governance overview, where stable frameworks outlast the churn of individual statutes.
What ISO/IEC 42001 readiness involves.
Readiness work prepares an organization to either operate in alignment with the standard or proceed to certification with an accredited body, and it follows the structure used across this practice. It begins with scope: the organization's role with respect to AI, the systems and tools in scope, and the boundary of the intended management system. A gap analysis then compares current practice to Clauses 4 through 10 and the applicable Annex A controls, drawing on the AI use inventory work described on the AI governance overview. From the gaps comes the build: the AI policy, the impact assessment process, the Statement of Applicability, supplier oversight, and the records that make the system auditable. For organizations with an existing ISO 27001 ISMS, the work is planned as an extension of that system from the outset.
This is independent advisory work. I do not certify, and readiness is kept deliberately separate from any certification audit the organization later purchases from an accredited certification body, which is the same independence discipline this practice applies in its CMMC work. The deliverable is an organization that knows where it stands against the standard, holds the records to demonstrate it, and can decide about certification from an informed position rather than a sales conversation.
ISO/IEC 42001, answered briefly.
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the first certifiable international standard for an Artificial Intelligence Management System. Published in December 2023, it defines management system requirements in Clauses 4 through 10 and a reference set of 38 controls in Annex A through which an organization governs its development and use of AI.
Is certification mandatory?
No. The standard is voluntary. The pressure to adopt it comes from customers, procurement requirements, and due diligence questionnaires rather than from law. Many organizations build alignment without pursuing the certificate, and certify later only if their market asks for it.
How does it relate to ISO/IEC 27001?
The two standards share the same harmonized clause structure by design, so an organization with an ISO 27001 ISMS extends its existing management system rather than building a second one. The material additions in 42001 are the AI-specific Annex A controls and the AI system impact assessment, which has no 27001 equivalent.
Does it apply if we only use AI rather than develop it?
Yes. The standard addresses organizations in any AI role, including those that deploy and use AI built by others. For most small and midsize companies the deployer and user role applies, which centers the management system on inventory, policy, impact assessment, and supplier oversight rather than on model development controls.
How does ISO/IEC 42001 relate to the NIST AI RMF?
They answer different questions. The NIST AI Risk Management Framework is a voluntary framework for identifying and managing AI risk; ISO/IEC 42001 is a certifiable management system that institutionalizes governance. Organizations commonly use the NIST framework to structure risk thinking and the ISO standard to make the program auditable, and the two map to each other well. The AI governance overview places both in the wider framework landscape.
Discuss ISO/IEC 42001 Readiness
Inquiries may involve an ISO/IEC 42001 gap analysis, extending an existing ISO 27001 management system to cover AI, building the impact assessment process, or deciding whether certification is worth its cost for your organization. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.
Discuss an Assessment
Whether the question is where your organization stands against ISO/IEC 42001, how to extend an existing ISO 27001 program to cover AI, or whether certification makes commercial sense for your situation, the first conversation carries no commitment and no pitch.
Discuss an Assessment →