ISO 42001 certification, explained.
Published in December 2023, ISO/IEC 42001 is the world's first certifiable management-system standard for artificial intelligence. It doesn't grade a model. It certifies that your organisation runs AI responsibly and by design with the policies, controls, and evidence to prove it. Here's what it asks for, and how certification actually works.
What the standard actually does.
ISO/IEC 42001 specifies the requirements for an AI management system (AIMS): the set of policies, roles, processes, and controls an organisation uses to develop, provide, or use AI responsibly. Like ISO 27001 for information security or ISO 9001 for quality, it is a management-system standard you can be independently audited and certified against.
It follows ISO's Harmonised Structure (Annex SL), the same backbone as ISO 27001 and ISO 9001, so it slots into management systems you may already run. Requirements sit in Clauses 4–10, and a menu of reference controls lives in Annex A. The whole thing turns on a Plan–Do–Check–Act loop, so governance is a habit that improves over time, not a one-off document.
Crucially, it is technology- and use-case-neutral. Whether you build foundation models, fine-tune them, or simply deploy someone else's AI in your products and operations, the same governance discipline applies, scaled to your context and risk.
One continuous improvement loop.
The clauses map onto a Plan–Do–Check–Act cycle. Governance is planned, operated, measured, and improved on repeat, so the system gets stronger with every turn.
Set the direction
Define scope and objectives, name accountable owners, assess AI risks and impacts, and decide which controls apply.
Operate the lifecycle
Embed controls into how AI systems are designed, built, tested, deployed, monitored, and retired.
Measure what's working
Track performance, gather stakeholder feedback, run internal audits, and hold management reviews.
Fix and improve
Correct non-conformities at the root cause and update the AIMS as models, risks, and regulations change.
The requirements, clause by clause.
Clauses 1–3 cover scope, references, and terms. The auditable requirements, the ones you must satisfy to certify, run from 4 to 10.
38 controls, nine objectives.
Annex A is a menu of reference controls grouped under nine objectives (A.2–A.10). You select the ones relevant to your AI systems and justify the choice in your Statement of Applicability.
Policies related to AI
Establish, align, and regularly review an organisation-wide AI policy that sets the tone for everything else.
Internal organisation
Define AI roles and responsibilities, and a clear process for raising and reporting AI-related concerns.
Resources for AI systems
Document the data, tooling, compute, and human resources your AI systems depend on.
Assessing impacts
Run a process to assess an AI system's potential effects on individuals, groups, and wider society.
AI system life cycle
Responsible objectives, design, development, verification, deployment, operation, monitoring, and logging.
Data for AI systems
Govern data acquisition, quality, provenance, and preparation across the model's life.
Information for interested parties
Give users and stakeholders the documentation, reporting, and incident communication they need.
Use of AI systems
Set responsible-use objectives and processes, and keep systems working within their intended use.
Third parties & customers
Manage supply-chain accountability, supplier obligations, and duties toward your own customers.
What makes 42001 different.
Most of the standard will feel familiar to anyone who has run an ISO management system. Two requirements are distinctly about AI, and they are where the real work sits.
AI risk assessment
Identify the threats to your AI objectives, reliability, security, privacy, robustness, and decide how to treat them. This drives which Annex A controls you adopt.
AI system impact assessment
Go beyond risk to the business and assess the consequences for people and society, fairness, safety, rights, and document the results for interested parties.
Statement of Applicability
The bridge between risk and control: it lists every Annex A control, whether you apply it, and why. It is the first thing an auditor reads.
From gap analysis to certificate.
Certification is granted by an accredited, independent body after a two-stage audit. Most organisations reach it in six to twelve months; the durations below are typical, not guaranteed.
Gap analysis
Measure your current practice against every clause and the relevant Annex A controls to build a realistic roadmap.
≈ 2–6 weeksBuild the AIMS
Write the AI policy, run the risk and impact assessments, produce the Statement of Applicability, and implement the controls.
≈ 4–12 weeksOperate & collect evidence
Run the system long enough to generate records, logs, monitoring, and management activity that prove it works in practice.
≈ 2–12 weeksInternal audit & management review
Audit yourself first and have leadership formally review the AIMS, fixing gaps before an external auditor sees them.
≈ 2–5 weeksDocumentation review
The certification body checks that your AIMS is designed correctly, your scope, policy, SoA, and assessments, and flags readiness gaps.
Certification bodyEffectiveness audit
Auditors test that the AIMS actually operates, sampling Clause 8 operations, risk and impact management, and in-scope controls.
Certification bodyCertificate, surveillance & recertification
The certificate is valid for three years, with annual surveillance audits to confirm you're maintaining and improving the system, then a full recertification.
3-year cycle42001, the EU AI Act & NIST.
These three are complementary, not competing. One is a law, one is a voluntary framework, and one is a certifiable management system that helps you operationalise both.
ISO/IEC 42001
An auditable AI management system you can be certified against, the "how we govern AI, and can prove it" layer that turns principles into repeatable practice.
EU AI Act
Binding, risk-tiered regulation with real obligations and penalties. A 42001 management system is one of the most direct ways to organise the evidence it demands. Read our guide →
NIST AI RMF
A voluntary, US-origin risk-management framework (Govern, Map, Measure, Manage). It pairs naturally with 42001's controls, shared evidence clears both.
Analysts estimate roughly half of ISO 42001's application-level controls overlap with EU AI Act articles. Written once, well, a single data-governance control can produce evidence that satisfies ISO 27001, ISO 42001, the EU AI Act, and NIST AI RMF at the same time, so you build the machinery once and reuse it.
What certification buys you.
Beyond the badge, an accredited certificate is independent proof that turns "trust us" into "here's the evidence."
- Market trust. Independent, third-party assurance that customers, partners, and regulators recognise.
- Faster procurement. Answer security and AI-governance questionnaires with a certificate instead of a project.
- Regulatory readiness. A running head start on the EU AI Act and emerging AI regulation worldwide.
- Real risk reduction. Bias, data, security, and oversight risks are found and treated before they become incidents.
- Clear accountability. Named owners, defined processes, and an audit trail across the whole AI lifecycle.
- Continual improvement. The PDCA loop keeps governance current as your models and risks evolve.
Sources & further reading.
- ISO/IEC 42001:2023 — Information technology · Artificial intelligence · Management system. International Organization for Standardization (the authoritative source).
- Schellman — ISO/IEC 42001 requirements explained (clauses 4–10, assessments, Statement of Applicability).
- Vanta — ISO 42001 certification process and timeline (six-step journey, typical durations, surveillance and recertification).
- Mindset Cyber — ISO 42001 Annex A controls (A.2–A.10), the 38 reference controls across nine objectives.
- Cloud Security Alliance — Using ISO/IEC 42001 & NIST AI RMF to help comply with the EU AI Act (framework overlap).
Ready to certify your AI?
We run the gap analysis, stand up your AI management system, and get you audit-ready, so ISO 42001 becomes proof of trustworthy AI rather than a paperwork exercise.