Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: AI Governance

ISO/IEC 42001

Also known as: ISO/IEC 42001:2023, AI Management System standard, AIMS standard
Simply put

ISO/IEC 42001 is an international standard that sets out how an organization can set up and run a management system for artificial intelligence. It is aimed at organizations that develop, provide, or use AI, and it describes practices for establishing, maintaining, and continually improving that system. As a voluntary standard rather than a law, it does not carry legal force on its own, though organizations may adopt it to demonstrate responsible AI practices or pursue certification against it.

Formal definition

ISO/IEC 42001:2023 is an international management-system standard, published jointly by ISO and IEC, that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS). It provides both requirements and guidance for organizations that develop, provide, or use AI-based products or services. It is a voluntary, certifiable standard rather than a regulation; conformity is typically demonstrated through third-party certification or internal conformity assessment, and adoption becomes binding only where incorporated by contract or referenced by applicable law. It should be distinguished from AI-specific legislation such as the EU AI Act, which imposes legal obligations within its jurisdictional scope, whereas ISO/IEC 42001 confers no legal force by itself. Readers should verify the current version and status against the official ISO/IEC text, as standards are periodically revised and certification scheme details may change.

Why it matters

As organizations increasingly develop, provide, and use AI-based products and services, they face pressure from customers, regulators, and internal stakeholders to demonstrate that these systems are governed responsibly. ISO/IEC 42001 addresses this need by offering a recognized, certifiable framework for an Artificial Intelligence Management System (AIMS), giving organizations a structured way to establish, maintain, and continually improve their AI governance practices. Because it is described as the first certifiable international standard dedicated to AI management systems, it provides a common reference point that can support consistency across organizations and jurisdictions.

The standard matters most in contexts where AI accountability must be evidenced rather than merely asserted. Adopting ISO/IEC 42001 and, where appropriate, pursuing third-party certification can help an organization show customers, partners, or oversight bodies that it has implemented a systematic approach to managing AI-related risks and responsibilities. This can be relevant in procurement, contractual negotiations, and stakeholder assurance, where demonstrable governance practices carry weight.

It is important to keep the standard's role in proportion. ISO/IEC 42001 is a voluntary standard and does not carry legal force on its own; it is not a substitute for compliance with AI-specific legislation such as the EU AI Act, which imposes binding obligations within its jurisdictional scope. Conformity with the standard may support an organization's broader compliance and governance posture, but it does not by itself satisfy statutory requirements unless incorporated by contract or referenced by applicable law. Readers should verify the current version and certification scheme details against the official ISO/IEC text, as standards are periodically revised.

Who it's relevant to

Organizations developing or providing AI
Companies that build or supply AI-based products or services may adopt ISO/IEC 42001 to structure their internal governance and to demonstrate responsible AI practices to customers and partners. Certification can serve as evidence of a systematic management approach, though it does not by itself establish compliance with any applicable AI legislation.
Organizations using AI systems
Enterprises that deploy AI provided by others also fall within the standard's intended audience, as it addresses organizations that use AI, not only those that develop it. Such organizations may use the AIMS framework to manage AI-related risks arising from their use of these systems.
Compliance and governance professionals
Compliance officers, risk managers, and governance teams may use ISO/IEC 42001 as a structured reference for building AI governance programs. They should treat it as a voluntary standard that can support, but does not replace, obligations under applicable regulations such as the EU AI Act within its jurisdictional scope.
Auditors and certification bodies
Internal auditors performing conformity assessments and external certification bodies evaluating an organization's AIMS rely on the standard's requirements as the basis for their work. They should confirm they are working against the current version, as standards are periodically revised and certification scheme details may change.

Inside ISO/IEC 42001

AI Management System (AIMS)
The core construct of the standard: a structured set of policies, processes, and controls an organization establishes to govern the development, provision, and use of AI systems. As with other ISO management system standards, it follows a plan-do-check-act cycle and is designed to be integrated with existing management systems.
Risk and impact assessment
Provisions directing organizations to identify and evaluate risks arising from AI systems, including impacts on individuals and groups, and to address them through appropriate controls. The specific methodology is left to the organization, informed by its context and risk appetite.
AI-specific controls and objectives
Annex-style control guidance addressing considerations distinctive to AI, such as data quality and management, transparency, human oversight, and lifecycle governance. These operate as reference controls that organizations select and justify based on applicability.
Governance and organizational roles
Requirements around leadership commitment, assignment of responsibilities, competence, and accountability for AI outcomes. The standard frames governance as an ongoing organizational function rather than a one-time exercise.
Continual improvement and monitoring
Mechanisms for performance evaluation, internal audit of the management system, management review, and corrective action, consistent with the harmonized structure common to ISO management system standards.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 42001.

Is ISO/IEC 42001 a legal requirement for organizations deploying AI?
No. ISO/IEC 42001 is a voluntary international management system standard, not legislation. It carries no legal force in itself. Obligations may arise where a contract requires it, or where a regulator or law references it, but the standard does not impose binding requirements on its own. It is distinct from statutory regimes such as the EU AI Act, which is binding law within its jurisdictional scope. Organizations should verify their actual legal obligations against the applicable regulatory texts rather than assuming that adopting this standard satisfies them.
Does certification to ISO/IEC 42001 demonstrate that an organization is compliant with AI regulations?
Not necessarily. Certification and regulatory compliance are separate concepts. Certification indicates that an accredited body has assessed conformity of an organization's AI management system against the standard's requirements; it does not by itself establish compliance with any specific law. A management system standard addresses governance processes rather than the substantive legal obligations of a given jurisdiction. Certification may support a compliance program as evidence of governance maturity, but organizations should not treat it as a substitute for demonstrating that they meet applicable legal requirements, which requires separate analysis.
How does ISO/IEC 42001 relate to an organization's existing ISO/IEC 27001 information security management system?
ISO/IEC 42001 follows the harmonized high-level structure common to modern ISO management system standards, which is intended to allow integration with existing systems such as an ISO/IEC 27001 information security management system. In many cases organizations can align shared elements such as leadership commitment, risk treatment processes, internal audit, and management review rather than building an entirely separate system. That said, the two standards address different subject matter, so an existing information security management system does not cover AI-specific governance concerns. Readers should confirm the current requirements and structure against the latest published versions of both standards.
What internal roles are typically involved in establishing an AI management system under this standard?
Implementation generally involves coordination across several functions rather than a single owner. Top management is typically responsible for establishing the policy and providing resources; risk, compliance, and legal functions often address applicable obligations and risk criteria; technical and data science teams contribute to controls over AI system development and operation; and internal audit or an equivalent function evaluates conformity. The specific allocation depends on organizational size and structure, and the standard does not prescribe a fixed organizational chart. Roles should be defined based on your own context and documented accordingly.
What is the difference between an internal assessment and a certification audit in the context of this standard?
An internal assessment, such as an internal audit or a gap analysis, is conducted by or on behalf of the organization to evaluate its own management system and identify areas for improvement; it is a self-directed exercise. A certification audit is performed by an independent accredited certification body to determine whether the management system conforms to the standard for the purpose of issuing certification. The two serve different purposes and are not interchangeable. Certification scheme details, including auditor accreditation and audit cycles, are set by the relevant certification and accreditation bodies and can change, so verify current arrangements with the applicable body.
How should an organization decide the scope of its AI management system under this standard?
Scope generally reflects the AI systems, activities, and organizational units the management system is intended to cover, defined in light of the organization's context, its interested parties, and the risks associated with its AI use. Some organizations begin with a defined subset of AI systems and expand over time. The standard requires that scope be determined and documented, but it leaves the boundaries to the organization to justify based on its circumstances. Because scope decisions affect both governance coverage and any subsequent certification, they warrant careful documentation and professional judgment applied to your specific situation; this entry is informational and not a substitute for such analysis.

Common misconceptions

Certification to ISO/IEC 42001 makes an organization compliant with AI regulations such as the EU AI Act.
ISO/IEC 42001 is a voluntary management system standard, not a law. Conformity may support and provide evidence toward demonstrating good governance, but it does not by itself establish compliance with any binding regulation. Legal obligations depend on the applicable jurisdiction and must be assessed against the relevant official texts. Readers should verify how, if at all, the standard is referenced by regulators in their jurisdiction.
ISO/IEC 42001 certifies that an organization's individual AI systems are safe or trustworthy.
The standard addresses the management system used to govern AI, not the technical certification of specific AI products or models. It concerns whether appropriate governance processes exist and operate, which is distinct from validating the behavior, accuracy, or safety of any particular system.
Implementing ISO/IEC 42001 is a one-time project that ends at certification.
Like other ISO management system standards, it is built around continual improvement, monitoring, and periodic review. Maintaining conformity requires ongoing operation of the system, and certification schemes and standard versions are themselves periodically updated, so status should be reverified over time.

Best practices

Treat the standard as a governance framework and separately maintain a mapping to the binding legal obligations that apply in each jurisdiction where you operate, rather than assuming the standard covers them.
Integrate the AI management system with existing management systems (such as those for information security or quality) to leverage the common harmonized structure and avoid duplicative controls.
Document the rationale for which reference controls you apply or exclude, so that scope and applicability decisions are defensible during internal audit or external assessment.
Establish and record risk and impact assessments as living artifacts, updating them across the AI lifecycle rather than treating them as a one-time deliverable.
Assign clear roles, accountability, and competence requirements for AI governance, and ensure leadership review is scheduled on a recurring basis.
Verify the current version of the standard and the specifics of any certification scheme against authoritative sources before relying on them, since standards and schemes are periodically revised.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide