Guide · ISO/IEC 42001:2023

ISO 42001 certification, explained.

Published in December 2023, ISO/IEC 42001 is the world's first certifiable management-system standard for artificial intelligence. It doesn't grade a model. It certifies that your organisation runs AI responsibly and by design with the policies, controls, and evidence to prove it. Here's what it asks for, and how certification actually works.

Based on ISO/IEC 42001:2023 and published guidance from accredited certification bodies Educational overview, not certification or legal advice
Overview

What the standard actually does.

ISO/IEC 42001 specifies the requirements for an AI management system (AIMS): the set of policies, roles, processes, and controls an organisation uses to develop, provide, or use AI responsibly. Like ISO 27001 for information security or ISO 9001 for quality, it is a management-system standard you can be independently audited and certified against.

It follows ISO's Harmonised Structure (Annex SL), the same backbone as ISO 27001 and ISO 9001, so it slots into management systems you may already run. Requirements sit in Clauses 4–10, and a menu of reference controls lives in Annex A. The whole thing turns on a Plan–Do–Check–Act loop, so governance is a habit that improves over time, not a one-off document.

Crucially, it is technology- and use-case-neutral. Whether you build foundation models, fine-tune them, or simply deploy someone else's AI in your products and operations, the same governance discipline applies, scaled to your context and risk.

2023
First published (Dec) — the first international AI management system standard
7
Requirement clauses (4–10) you're audited against
38
Annex A reference controls across 9 objectives
3yr
Certificate validity, with annual surveillance audits
The Engine

One continuous improvement loop.

The clauses map onto a Plan–Do–Check–Act cycle. Governance is planned, operated, measured, and improved on repeat, so the system gets stronger with every turn.

Plan
P

Set the direction

Define scope and objectives, name accountable owners, assess AI risks and impacts, and decide which controls apply.

Clauses 4 · 5 · 6 · 7
Do
D

Operate the lifecycle

Embed controls into how AI systems are designed, built, tested, deployed, monitored, and retired.

Clause 8
Check
C

Measure what's working

Track performance, gather stakeholder feedback, run internal audits, and hold management reviews.

Clause 9
Act
A

Fix and improve

Correct non-conformities at the root cause and update the AIMS as models, risks, and regulations change.

Clause 10
Clauses 4–10

The requirements, clause by clause.

Clauses 1–3 cover scope, references, and terms. The auditable requirements, the ones you must satisfy to certify, run from 4 to 10.

4
ContextScope the AIMS; understand internal and external issues and what stakeholders expect of your AI.
5
LeadershipTop-management commitment, an AI policy, and clear roles, responsibilities, and authorities.
6
PlanningAI risk assessment and AI system impact assessment; measurable objectives; a Statement of Applicability.
7
SupportResources, competence, awareness, communication, and documented information to run the system.
8
OperationPut the plans into practice across the AI lifecycle; operate the risk treatment and control changes.
9
PerformanceMonitor, measure, and analyse; run internal audits and management reviews of the AIMS.
10
ImprovementHandle non-conformities, take corrective action, and continually improve the system.
Annex A

38 controls, nine objectives.

Annex A is a menu of reference controls grouped under nine objectives (A.2–A.10). You select the ones relevant to your AI systems and justify the choice in your Statement of Applicability.

A.23 controls

Policies related to AI

Establish, align, and regularly review an organisation-wide AI policy that sets the tone for everything else.

A.32 controls

Internal organisation

Define AI roles and responsibilities, and a clear process for raising and reporting AI-related concerns.

A.45 controls

Resources for AI systems

Document the data, tooling, compute, and human resources your AI systems depend on.

A.54 controls

Assessing impacts

Run a process to assess an AI system's potential effects on individuals, groups, and wider society.

A.69 controls

AI system life cycle

Responsible objectives, design, development, verification, deployment, operation, monitoring, and logging.

A.75 controls

Data for AI systems

Govern data acquisition, quality, provenance, and preparation across the model's life.

A.84 controls

Information for interested parties

Give users and stakeholders the documentation, reporting, and incident communication they need.

A.93 controls

Use of AI systems

Set responsible-use objectives and processes, and keep systems working within their intended use.

A.103 controls

Third parties & customers

Manage supply-chain accountability, supplier obligations, and duties toward your own customers.

Annex A is a reference set, not a checklist to tick blindly. Controls are selected on the basis of your risk and impact assessments. Anything you include or exclude has to be justified and recorded in the Statement of Applicability, the document auditors use to test whether your controls match your risks.
Two assessments at the core

What makes 42001 different.

Most of the standard will feel familiar to anyone who has run an ISO management system. Two requirements are distinctly about AI, and they are where the real work sits.

Clause 6

AI risk assessment

Identify the threats to your AI objectives, reliability, security, privacy, robustness, and decide how to treat them. This drives which Annex A controls you adopt.

Clause 6 · Annex A.5

AI system impact assessment

Go beyond risk to the business and assess the consequences for people and society, fairness, safety, rights, and document the results for interested parties.

Clause 6.1.3

Statement of Applicability

The bridge between risk and control: it lists every Annex A control, whether you apply it, and why. It is the first thing an auditor reads.

The Certification Journey

From gap analysis to certificate.

Certification is granted by an accredited, independent body after a two-stage audit. Most organisations reach it in six to twelve months; the durations below are typical, not guaranteed.

Step 1

Gap analysis

Measure your current practice against every clause and the relevant Annex A controls to build a realistic roadmap.

≈ 2–6 weeks
Step 2

Build the AIMS

Write the AI policy, run the risk and impact assessments, produce the Statement of Applicability, and implement the controls.

≈ 4–12 weeks
Step 3

Operate & collect evidence

Run the system long enough to generate records, logs, monitoring, and management activity that prove it works in practice.

≈ 2–12 weeks
Step 4

Internal audit & management review

Audit yourself first and have leadership formally review the AIMS, fixing gaps before an external auditor sees them.

≈ 2–5 weeks
Step 5 · Stage 1 audit

Documentation review

The certification body checks that your AIMS is designed correctly, your scope, policy, SoA, and assessments, and flags readiness gaps.

Certification body
Step 6 · Stage 2 audit

Effectiveness audit

Auditors test that the AIMS actually operates, sampling Clause 8 operations, risk and impact management, and in-scope controls.

Certification body
Ongoing

Certificate, surveillance & recertification

The certificate is valid for three years, with annual surveillance audits to confirm you're maintaining and improving the system, then a full recertification.

3-year cycle
Where It Fits

42001, the EU AI Act & NIST.

These three are complementary, not competing. One is a law, one is a voluntary framework, and one is a certifiable management system that helps you operationalise both.

Certifiable standard

ISO/IEC 42001

An auditable AI management system you can be certified against, the "how we govern AI, and can prove it" layer that turns principles into repeatable practice.

Law · EU

EU AI Act

Binding, risk-tiered regulation with real obligations and penalties. A 42001 management system is one of the most direct ways to organise the evidence it demands. Read our guide →

Framework · US

NIST AI RMF

A voluntary, US-origin risk-management framework (Govern, Map, Measure, Manage). It pairs naturally with 42001's controls, shared evidence clears both.

~50%control overlap

Analysts estimate roughly half of ISO 42001's application-level controls overlap with EU AI Act articles. Written once, well, a single data-governance control can produce evidence that satisfies ISO 27001, ISO 42001, the EU AI Act, and NIST AI RMF at the same time, so you build the machinery once and reuse it.

Why Certify

What certification buys you.

Beyond the badge, an accredited certificate is independent proof that turns "trust us" into "here's the evidence."

  • Market trust. Independent, third-party assurance that customers, partners, and regulators recognise.
  • Faster procurement. Answer security and AI-governance questionnaires with a certificate instead of a project.
  • Regulatory readiness. A running head start on the EU AI Act and emerging AI regulation worldwide.
  • Real risk reduction. Bias, data, security, and oversight risks are found and treated before they become incidents.
  • Clear accountability. Named owners, defined processes, and an audit trail across the whole AI lifecycle.
  • Continual improvement. The PDCA loop keeps governance current as your models and risks evolve.
References

Sources & further reading.

  1. ISO/IEC 42001:2023 — Information technology · Artificial intelligence · Management system. International Organization for Standardization (the authoritative source).
  2. Schellman — ISO/IEC 42001 requirements explained (clauses 4–10, assessments, Statement of Applicability).
  3. Vanta — ISO 42001 certification process and timeline (six-step journey, typical durations, surveillance and recertification).
  4. Mindset Cyber — ISO 42001 Annex A controls (A.2–A.10), the 38 reference controls across nine objectives.
  5. Cloud Security Alliance — Using ISO/IEC 42001 & NIST AI RMF to help comply with the EU AI Act (framework overlap).

Ready to certify your AI?

We run the gap analysis, stand up your AI management system, and get you audit-ready, so ISO 42001 becomes proof of trustworthy AI rather than a paperwork exercise.