ISO 42001: the complete guide to AI management system certification

ISO 42001 is the world's first international standard for managing artificial intelligence. It gives organizations a certifiable framework for governing how they build, deploy, and use AI systems responsibly. If your company develops AI features, embeds third-party AI tools, or sells into markets where buyers now ask hard questions about AI risk, the ISO 42001 standard gives you a structured way to answer them.

framework_ISO42001_pillar_en

What is ISO 42001?

ISO/IEC 42001:2023 is the international standard that sets out requirements for establishing, implementing, maintaining, and continually improving an AI management system. It's the first edition of the standard, published in December 2023 and developed by the joint technical committee ISO/IEC JTC 1/SC 42.

The standard defines what a responsible AI governance system needs to include, and it's the only AI-specific ISO standard you can be independently certified against.

The standard also solves a practical problem. AI adoption tends to run ahead of governance: teams roll out models and tools faster than anyone can track the risks around bias, data quality, transparency, and oversight. ISO 42001 gives that sprawl a single operating framework, so responsible AI becomes a system you manage rather than a promise you make.

What is an AI management system (AIMS)?

An AI management system (AIMS) is a structured set of policies, processes, and controls that govern how AI systems are designed, developed, deployed, and used across an organization. It works the same way an information security management system governs security under ISO 27001: it turns good intentions about responsible AI into repeatable, auditable practice.

A typical ISO 42001 AI management system includes:

  • An AI policy signed off by top management
  • An AI risk assessment and impact assessment process
  • Clear roles and responsibilities for AI governance
  • A Statement of Applicability (SoA) that records which controls apply
  • Ongoing monitoring, internal audit, and management review

ISO 42001 vs. other AI-related ISO standards

ISO/IEC SC 42 has published a family of AI standards. Most of them are vocabulary, framework, or guidance documents. Only ISO 42001 is a management system you can certify against.

Standard What it covers Type
ISO/IEC 42001 AI management system requirements Management system (certifiable)
ISO/IEC 22989 AI terminology and concepts Vocabulary
ISO/IEC 23053 Framework for AI systems using machine learning Framework
ISO/IEC 23894 Guidance on AI risk management Guidance
ISO/IEC 42005 AI system impact assessment Guidance

Is ISO 42001 legally required?

No. ISO 42001 is voluntary. It's a certifiable standard, not a legal mandate in any jurisdiction today. No law currently requires an organization to hold ISO 42001 certification.

That said, it lines up closely with where regulation is heading, which is why many organizations adopt it ahead of the EU AI Act. More on that below.

What are the benefits of ISO 42001?

The value of ISO 42001 goes beyond compliance. It gives you a working governance system and a credible way to prove it to the people who matter: customers, partners, regulators, and your own board. The main benefits are:

  • Structured AI risk governance: You move from ad hoc AI use to a documented, monitored system with clear ownership
  • Buyer and procurement trust: Security questionnaires increasingly carry AI-specific sections, and certification answers them before they're asked
  • Early-mover differentiation: The certified population is still small, so certification sets you apart while it's rare
  • Alignment with emerging regulation: The controls map closely to what the EU AI Act asks of high-risk AI systems

Who needs ISO 42001? Industries and use cases

ISO 42001 applies to any organization that develops or uses AI. That includes:

  • AI and machine learning vendors building models and AI products
  • Cloud and SaaS providers embedding AI features into their platforms
  • Any organization deploying third-party AI tools, not only those building them
  • Regulated sectors such as finance, healthcare-adjacent services, and the public sector, where AI now faces specific scrutiny

Here's the point worth clearing up early: ISO 42001 applies to organizations that use AI, not only those that build it. This is the most common misconception about the standard. If your teams rely on third-party AI tools to make or support decisions, the standard is written for you too.

ISO 42001 requirements and structure

ISO 42001 follows the same Harmonized Structure (formerly Annex SL) as ISO 9001 and ISO 27001. That means the same 10-clause skeleton, covering context, leadership, planning, support, operation, performance evaluation, and improvement. If you already run one ISO management system, the shape will feel familiar.

Leadership sits at the center. The standard expects top management to own the AI policy, set objectives, allocate resources, and review how well the system performs. AI governance can't be delegated to a single engineer or buried in a policy no one reads.

At its core sits the Plan-Do-Check-Act (PDCA) cycle:

  • Plan: Set your AI policy, objectives, and risk assessment
  • Do: Implement the controls and run your AI systems under them
  • Check: Monitor performance, audit internally, and review results
  • Act: Correct nonconformities and improve the system

The standard also includes Annex A: 38 controls grouped under 9 objectives. You don't apply all of them by default. A Statement of Applicability (SoA) records which controls are in scope and why, exactly as it works in ISO 27001.

ISO 42001 Annex A controls (overview)

Annex A organizes its 38 controls into 9 objectives (A.2 to A.10). Each objective covers a domain of AI-specific risk.

Control group What it covers
A.2 Policies related to AI Establishing and reviewing an overarching AI policy
A.3 Internal organization AI roles, responsibilities, and channels to raise concerns
A.4 Resources for AI systems Documenting data, tooling, computing, and human resources
A.5 Assessing impacts of AI systems Impact assessments on individuals, groups, and society
A.6 AI system life cycle Responsible design, development, deployment, and retirement
A.7 Data for AI systems Data quality, provenance, and governance
A.8 Information for interested parties Transparency for users and affected parties
A.9 Use of AI systems Intended use, human oversight, and monitoring of deployed AI
A.10 Third-party and customer relationships Due diligence across suppliers, customers, and partners

Not all 38 controls apply to every organization. Your SoA determines which are in scope, based on your risk assessment.

What documentation does ISO 42001 require?

Auditors want evidence the system works. The core documentation includes:

  • An AI policy
  • An AIMS scope statement
  • Risk assessment and impact assessment records
  • A Statement of Applicability
  • Competence and training records
  • Incident and nonconformity logs

How to get ISO 42001 certified: step-by-step

Certification follows the same proven route as ISO 27001 and ISO 9001. An overview of a typical path is:

  1. Run a gap analysis against the standard
  2. Define your AIMS scope, reviewing the entities, products, and AI systems it covers
  3. Complete an AI risk and impact assessment
  4. Build your Statement of Applicability
  5. Implement the applicable controls
  6. Run an internal audit and management review
  7. Pass the Stage 1 audit, which is a documentation review by your certification body
  8. Pass the Stage 2 audit, which is an assessment of how the system works in practice
  9. Receive your certificate, valid for three years with annual surveillance audits

Most organizations reach certification in a few months. The timeline depends mainly on how mature your AI governance already is. If you already hold ISO 27001, you'll move faster, because the management-system clauses overlap.

ISO 42001 certification cost

ISO 42001 certification costs can vary, depending on several factors.

Cost driver What affects it
Organization size More people and sites mean more audit effort
Number of AI systems in scope Each use case adds risk assessment and control work
Complexity of risk assessment Higher-risk AI raises the bar for evidence
Consultant support vs. in-house External help speeds delivery at added cost
Certification body fees Charged separately from any consulting
Annual surveillance Ongoing audits maintain the certificate

The biggest single lever is scope. A tightly defined AIMS covering one or two AI systems costs far less to certify than a broad scope spanning every product and internal tool. Many organizations start small, certify, and extend the scope at recertification.

Another factor to consider is that the market is young. Certification bodies are still calibrating their pricing to this relatively new standard, so costs vary more than for mature standards like ISO 9001 or ISO 27001. Best practice is to treat any ranges you see as directional and not fixed.

ISO 42001 audits explained

Internal audits

Before a certification body ever visits, organizations should run their own internal audit. This way they have the chance to check the full AIMS scope against the standard.

However, an internal audit must be carried out by someone independent of the work being audited. Findings feed into your management review, where leadership formally examines the results and decides what to fix. Both steps are mandatory, and rushed execution is a common cause of certification findings in the external audit later on.

External certification audits (Stage 1 and Stage 2)

An accredited certification body runs the external audit in two stages.

Aspect Stage 1 Stage 2
Focus Documentation and readiness review Implementation and operating effectiveness
What’s checked Policies, scope, Statement of Applicability, risk records, audit reports Interviews, evidence sampling, control operation
Typical outcome Findings to clear before Stage 2 Certification decision

Auditors classify findings as nonconformities. A major nonconformity means a control is missing or failing and must be fixed before certification. A minor nonconformity is a smaller gap you can correct within an agreed timeframe.

ISO 42001 audit checklist

Use these sample points to gauge readiness before an audit:

  • Is the AI policy in force and signed by top management?
  • Is the Statement of Applicability complete and justified?
  • Are risk and impact assessments current?
  • Is the incident and nonconformity log maintained?
  • Have you done due diligence on third-party AI vendors?
  • Are competence and training records in place?

ISO 42001 training and courses

Training helps teams build and audit an AIMS with confidence. Three course types cover most needs.

Course Audience Duration Outcome
Foundation / Awareness Anyone involved in AI governance 1–2 days Understand the standard and core concepts
Lead Implementer Those building the AIMS 3–5 days Skills to implement and manage the system
Lead Auditor Those auditing the AIMS 5+ days Skills to plan and run audits

ISO 42001 vs. ISO 27001 (and other standards)

ISO 42001 is rarely the only standard you'd be considering. It's designed to sit alongside the information security and quality standards many organizations already hold.

Aspect ISO 42001 ISO 27001 ISO 9001
Focus AI governance Information security Quality management
Manages AI risks: bias, transparency, oversight Confidentiality, integrity, availability of information Consistent products and services
Annex A controls 38 93 N/A
Certifiable Yes Yes Yes

ISO 42001 and the EU AI Act

This is where precision matters. ISO 42001 is not a harmonized standard under the EU AI Act (Regulation (EU) 2024/1689) and certification alone doesn't grant a legal presumption of conformity with the Act. That status is reserved for European harmonized standards, which are still being finalized.

What ISO 42001 does do is give you a ready-made governance structure. Its requirements for risk management, documentation, human oversight, and monitoring overlap operationally with much of what the AI Act asks of high-risk AI systems. So while certification isn't a legal free pass, it's the strongest preparation available today, and it puts most of the controls in place before the harmonized standards land.

In practice, that makes ISO 42001 a sensible first move rather than a wait-and-see one. The governance work you do now—mapping AI systems, running impact assessments, and documenting oversight—carries directly into AI Act readiness. When the harmonized standards are published, you'll be adapting an existing system rather than starting from zero.

Frequently asked questions

Is ISO 42001 free?

Is ISO 42001 legally required?

How long does ISO 42001 certification take?

Does ISO 42001 satisfy EU AI Act requirements?

Can a company hold both ISO 42001 and ISO 27001?

🏢 Organization Schema Preview (Development Only)
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "www.dataguard.com#organization",
      "name": "DataGuard",
      "legalName": "DataCo GmbH",
      "description": "DataGuard, the European leader in security and compliance software, is trusted by more than 4,000 organizations across 50+ countries. We help you identify and manage your security and compliance risks and fast-track your certifications and compliance by combining expert consultancy with AI-powered automation. Our purpose-built, all-in-one platform is developed with the experience of over 1.5 million total hours by a team of certified security and compliance experts.",
      "foundingDate": "2018",
      "taxID": "DE315880213",
      "logo": "https://7759810.fs1.hubspotusercontent-na1.net/hubfs/7759810/DataGuardLogo.svg",
      "url": "www.dataguard.com",
      "email": "info@dataguard.de",
      "telephone": "+49 89 452459 900",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "Sandstrasse 33",
        "addressLocality": "Munich",
        "addressRegion": "Bavaria",
        "postalCode": "80335",
        "addressCountry": "Germany"
      },
      "sameAs": [
        "https://www.linkedin.com/company/dataguard1/",
        "https://www.youtube.com/channel/UCEQzPZ6sCBCj9cAoBvaLL6w",
        "https://x.com/i/flow/login?redirect_after_login=%2FDataGuard_dg"
      ]
    }
  ]
}

✅ Organization schema markup for "DataGuard" has been injected into the document head.