Most AI governance documents tell you what good looks like. ISO/IEC 42001 is different: it is the first one a third party can audit you against and hand you a certificate for. Published in December 2023 by ISO and IEC, it defines an AI management system, a set of policies, roles, processes, and controls that an organization uses to govern how it builds, buys, and runs AI. If you already know ISO 27001 for information security or ISO 9001 for quality, the shape will feel familiar. This is that same model, pointed at AI.
The reason it matters in 2026 is commercial, not just technical. Certification is starting to appear in RFPs, vendor questionnaires, and enterprise procurement checklists as a way to ask "prove your AI is governed" without writing a bespoke audit each time. This guide walks through what the standard actually contains: its clause structure, the Annex A controls and the Statement of Applicability, the companion standards that sit around it, and what it takes to get certified. It is written for compliance, risk, and AI leads who have to decide whether to pursue it and what the program will cost in effort.
What ISO/IEC 42001 Is, and Why It Matters
A management-system standard for artificial intelligence, structured like ISO 27001, and certifiable by an accredited body. That last word is what makes it different from every framework that came before it.
The full title is ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. It specifies the requirements for establishing, implementing, maintaining, and continually improving an AI management system, usually shortened to AIMS. It is written to apply to any organization, regardless of size or sector, that provides or uses AI, whether you build models yourself, fine-tune someone else's, or simply deploy purchased AI features inside your products and operations.
The word that carries the weight is certifiable. The NIST AI Risk Management Framework is a voluntary method you self-attest to. ISO/IEC 42001 can be independently audited by an accredited certification body, which then issues a certificate your buyers, board, and regulators recognize on sight. That external validation is the point: it converts an internal claim ("we govern our AI responsibly") into a third-party attestation that survives a change of personnel and a hostile procurement review.
The standard is spreading fast because several pressures arrived at once. Enterprise buyers now ask AI vendors the same governance questions security teams have asked for a decade, and a certificate answers many in one line. The EU AI Act's push toward harmonized standards makes a recognized management system a practical way to show diligence. And boards want a defensible answer to "how do we know our AI is under control" that does not rest on one trusted individual.
How It Is Structured: Annex SL and PDCA
If you have ever seen ISO 27001, the skeleton of 42001 is identical. Both use the Annex SL high-level structure, the common template ISO applies to all its management-system standards so they slot together.
Annex SL means the substantive requirements live in seven numbered clauses, 4 through 10. Clauses 1 to 3 cover scope, references, and definitions. The real obligations start at clause 4. If you run an integrated management system, this shared structure is a gift: your existing ISO 27001 leadership, risk, audit, and improvement machinery can be extended to cover AI rather than rebuilt from scratch.
4. Context
Define the scope of the AIMS, the internal and external issues that affect it, and the interested parties (regulators, customers, affected people) whose needs the system must address.
5. Leadership
Top management must own the AI policy, assign roles and accountability, and show the AIMS is resourced and integrated into how the business actually runs.
6. Planning
Identify AI risks and opportunities, set objectives, and plan how to meet them. This is where AI risk assessment and AI system impact assessment are required.
7. Support
Provide the resources, competence, awareness, communication, and documented information the system needs to function and stay auditable.
8. Operation
Run the controls day to day: manage the AI lifecycle, data, third-party relationships, and the operational processes that turn policy into practice.
9. Performance Evaluation
Monitor, measure, and audit the AIMS, and hold management reviews so leadership sees whether the system is working and where it drifts.
10. Improvement
Handle nonconformities, take corrective action, and improve the system continually. Nothing is set once and forgotten.
Those seven clauses are not a checklist you complete once. They map onto the Plan-Do-Check-Act cycle, the continual-improvement loop at the heart of every ISO management system. The whole design assumes AI risk shifts as models, data, and use cases change, so the system has to loop, not terminate.
- Establish context, leadership commitment, and the AI policy (clauses 4 and 5).
- Assess AI risks and impacts, set objectives, and select controls (clause 6).
- Provide resources and competence (clause 7).
- Operate the selected controls across the AI lifecycle (clause 8).
- Monitor and measure performance, and run internal audits (clause 9).
- Hold a management review to judge whether objectives are being met.
- Correct nonconformities and address root causes (clause 10).
- Feed improvements back into the next planning cycle.
Annex A: The AI Controls and the SoA
The clauses tell you to manage AI risk. Annex A tells you what specifically to manage. It lists 38 reference controls grouped under 9 control objectives, and Annex B explains how to implement each one.
These controls are AI-specific in a way generic security controls are not. They target what makes AI hard to govern: opacity, data dependence, the lifecycle from design to retirement, and reliance on external providers whose models you cannot see inside. You do not implement all 38 blindly. You select the controls that fit the risks and impacts identified in clause 6, and record every inclusion and exclusion, with justification, in a Statement of Applicability (SoA). The SoA is the bridge between your risk assessment and your controls, and one of the first documents an auditor reads.
| Annex A objective | What it covers |
|---|---|
| A.2 Policies related to AI | An AI policy set by leadership, reviewed on a schedule and aligned to business objectives and other policies. |
| A.3 Internal organization | Roles, responsibilities, and reporting lines for AI, including how concerns get raised and escalated. |
| A.4 Resources for AI systems | Documenting and managing the data, tooling, compute, and human resources AI systems depend on. |
| A.5 Assessing impacts of AI systems | Processes for AI system impact assessment: effects on individuals, groups, and society across the lifecycle. |
| A.6 AI system life cycle | Responsible design, development, verification, deployment, and operation, with requirements defined at each stage. |
| A.7 Data for AI systems | Data quality, provenance, and management across acquisition, preparation, and use in training and operation. |
| A.8 Information for interested parties | What you tell users and affected people about the AI system, its capabilities, and its limitations. |
| A.9 Use of AI systems | Responsible use: defined objectives, intended use, and controls against misuse once systems are live. |
| A.10 Third-party and customer relationships | Allocating responsibilities across suppliers, partners, and customers, since most AI now involves external providers. |
The SoA is where audits get real. Excluding a control is allowed, but every exclusion has to be justified against your risk assessment. "We do not train our own models" can justify narrowing some data controls, but "it seemed like a lot of work" will not survive Stage 2. Write the SoA so the reasoning holds up when an auditor pushes.
The Companion Standards: 23894, 42005, 42006
42001 does not stand alone. ISO and IEC built a family of AI standards around it, and three of them do the heavy lifting that the main standard references but does not spell out in full.
The practical takeaway: use 23894 to run the risk assessment, use 42005 to run impact assessments, and check that whoever certifies you is accredited against 42006. Reaching for the companion standards early saves you from inventing processes that ISO has already specified.
How to Get Certified, and What It Costs
Certification is a two-stage external audit, but the work that precedes it is where most of the effort sits. Plan for the program, not just the audit week.
-
Gap assessmentCompare what you do today against the clauses and Annex A controls to find where you fall short.
- Inventory the AI systems already in use, including shadow AI nobody registered.
- Map existing ISO 27001 or governance processes you can reuse.
- Produce a prioritized gap list and a scope for the AIMS.
-
Build the AIMSStand up the management system: AI policy, roles, and the documented processes clauses 4 to 8 require.
- Get genuine leadership ownership, not a delegated signature.
- Define scope, objectives, and the interested parties you serve.
-
Run risk and impact assessmentsUse 23894 for AI risk and 42005 for impact assessment to produce the evidence clause 6 expects.
- Tie each identified risk to a treatment and a control.
- Keep the assessments live: they are inputs to the SoA, not one-off documents.
-
Implement controls and write the SoASelect the Annex A controls that fit your risks, implement them, and justify inclusions and exclusions in the Statement of Applicability.
- Start capturing evidence and audit trails as controls go live, not at audit time.
-
Internal audit and management reviewAudit the AIMS yourself first, then hold a documented management review so leadership signs off before an external auditor arrives.
- Fix nonconformities now; they are far cheaper to close before Stage 2.
-
Stage 1, Stage 2, and surveillanceAn accredited body runs a Stage 1 documentation review, then a Stage 2 audit of the system in operation, and issues the certificate.
- Stage 1: is the system designed and documented correctly?
- Stage 2: is it actually working, with evidence?
- Then annual surveillance audits and full recertification at year three.
Gap assessment, scope the AIMS, secure leadership sponsorship and budget.
Build the system, run risk and impact assessments, implement controls, draft the SoA.
Internal audit, management review, corrective actions, evidence accumulating.
Stage 1 and Stage 2 certification audits, certificate issued.
Annual surveillance audits; full recertification at the end of year three.
A realistic figure for a first-time program with a moderate AI footprint is six to twelve months from kickoff to certificate. Organizations with a mature ISO 27001 system move faster because leadership, risk, audit, and document control already exist. The heaviest cost is rarely the auditor's fee; it is the internal time to build processes and, above all, to produce and maintain evidence. Certificates last three years, but the annual surveillance audits mean the system has to keep running, not go quiet after the celebration.
ISO 42001 vs the EU AI Act vs NIST
These three get compared constantly, and the comparison is slightly wrong-headed, because they answer different questions. One is a law, one is a method, and one is a management system you can be certified against.
The useful mental model: the EU AI Act tells you what you must do, NIST tells you how to think about the risk, and 42001 tells you how to run the program that proves both. They stack rather than compete. A 42001-certified AIMS is a practical vehicle for demonstrating the governance, risk management, documentation, and post-market monitoring the EU AI Act expects. It is not automatic compliance with the Act, and no standard yet is, but a working management system is exactly the kind of diligence regulators and enterprise buyers look for. The operational challenge is running one control set that answers to all three at once instead of building three parallel programs that never reconcile.
One control set, many frameworks. The mature move is to map a single library of controls to 42001, the EU AI Act, and NIST together, backed by a live inventory of every AI system and agent, continuous monitoring for drift, and audit-ready evidence captured as work happens rather than reconstructed before an audit.
Key Takeaways
- ISO/IEC 42001:2023 is the first certifiable AI management system standard: it certifies how you govern AI, not whether one model is safe.
- It uses the Annex SL structure (clauses 4-10) and the Plan-Do-Check-Act cycle, so it integrates cleanly with ISO 27001.
- Annex A defines 38 controls under 9 objectives; you select and justify them through a Statement of Applicability tied to your risk assessment.
- Lean on the companion standards: 23894 for AI risk, 42005 for impact assessment, and 42006 for what makes a certification body credible.
- Budget six to twelve months for a first certification; the real cost is internal process and evidence work, not the audit fee.
- 42001 does not replace the EU AI Act or NIST. It is the proof layer that helps demonstrate diligence against both.
From policy to practice. Spreadsheets and ticket queues rarely keep up with how fast AI spreads across an enterprise, which is what makes an auditable AIMS hard to sustain by hand. Dedicated AI governance platforms give governance teams one place to discover, assess, monitor, and evidence every model and agent against frameworks like the EU AI Act, NIST AI RMF, and ISO 42001.
Frequently Asked Questions
No. It is a voluntary standard. No law requires certification. What is happening in practice is that customers, partners, and procurement teams increasingly ask for it in contracts and vendor questionnaires, so it is becoming a commercial expectation even though it is not a legal one.
Plan for six to twelve months from kickoff to certificate for a first-time program with a moderate AI footprint. Organizations that already run ISO 27001 move faster because leadership, risk, audit, and document control processes exist. The certificate is valid for three years, with annual surveillance audits in between.
Not automatically. The EU AI Act is binding law and 42001 is a voluntary standard, so certification is not the same as legal compliance. That said, a certified AI management system is strong evidence of the governance, risk management, documentation, and monitoring the Act expects, and it is a practical way to demonstrate diligence to regulators and buyers.
They share the same Annex SL structure and PDCA cycle, so the machinery is nearly identical. ISO 27001 governs information security; ISO 42001 governs AI, with AI-specific controls for the lifecycle, data, impact assessment, transparency, and third-party AI providers. If you hold 27001, you can extend it to cover AI rather than build a second system from scratch.
The SoA is the document that records which Annex A controls you apply, which you exclude, and why, all justified against your AI risk assessment. It is the link between the risks you identified and the controls you implemented, and it is one of the first things a certification auditor reviews.
An accredited certification body, one whose competence and impartiality meet ISO/IEC 42006 and ISO/IEC 17021-1. Accreditation is what makes the certificate credible to third parties. A self-declared or unaccredited "certificate" carries little weight in procurement, so confirm the body's accreditation before you engage.