Compliance · Global · AI
ISO/IEC 42001:2023First certifiable AI management standard

ISO 42001

Plain-English definition

ISO 42001, published in December 2023, is the first international standard specifically for an AI Management System (AIMS), and the first in this space that organizations can be formally certified against. It follows the same high-level structure as ISO 27001, but focused on AI-specific risk management, lifecycle governance, and impact assessment across the systems an organization builds or deploys.

Complements, rather than replaces, information security standards: an organization can run ISO 27001 and ISO 42001 as parallel, integrated management systems.

Who needs it

Organizations that develop, deploy, or provide AI systems and want a certifiable, auditable framework for AI governance, whether to satisfy customer due diligence, internal risk management, or emerging regulatory expectations like the EU AI Act.

Key requirements

A documented AI management system scope, AI-specific risk assessment and treatment, AI system impact assessments, lifecycle governance covering development through decommissioning, and management review and continual improvement, following the same PDCA structure as ISO 27001.

Cyber/privacy implications

AI systems introduce risk categories, model behavior, training data provenance, and output reliability, that traditional information security controls don't fully address, requiring governance specific to how AI systems are built, monitored, and retired.

Assessment methodology

AI system inventory and risk-tier classification, gap assessment against ISO 42001's AIMS requirements, impact assessment process build-out, and readiness review ahead of a formal certification audit.

Implementation phases

01
Assess

Inventory AI systems in use or development and assess current governance maturity.

02
Build

Establish the AIMS documentation, risk assessment, and impact assessment processes.

03
Certify

Support through Stage 1 and Stage 2 certification audits with an accredited body.

Evidence & documentation requirements

AI system inventory, AI-specific risk and impact assessments, AIMS policy documentation, and management review records demonstrating ongoing governance rather than a one-time exercise.

Common mistakes

Treating ISO 42001 as a rebrand of existing information security controls instead of building genuinely AI-specific risk and impact assessment processes; scoping the AIMS around only customer-facing AI features while ignoring internal tools with equal or greater risk.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

How does this relate to our AI Governance service?
AI Governance work builds the underlying identity, data classification, and human-approval controls; ISO 42001 readiness formalizes that work into a certifiable management system.
Do we need this if we only use third-party AI tools, not build our own?
Yes, if you deploy AI systems in your operations, ISO 42001's AIMS scope covers deployers as well as developers, though the specific risk profile differs.
Does ISO 42001 certification satisfy EU AI Act obligations?
It can serve as supporting evidence of a conformity management system, but the EU AI Act has its own specific legal requirements that certification alone doesn't automatically satisfy.

Request an AI Governance Readiness Check

See where your AI systems stand before committing to formal AIMS certification.

Request a Readiness Check →