Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →ISO/IEC 42001:2023 - Artificial Intelligence Management System
Issued by
International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)
ISO and IEC published ISO/IEC 42001:2023 in December 2023 as the first international AI management system standard. It sets requirements for establishing, maintaining, and improving an AI Management System. Organizations developing or using AI products and services can seek independent certification.
Applies To
Overview
ISO/IEC 42001:2023 follows the familiar Plan-Do-Check-Act structure used in ISO 27001 (information security) and ISO 9001 (quality management), allowing organizations to integrate an AIMS into existing management system programs. The standard applies universally across sectors and organization sizes, covering both AI providers and AI deployers, and addresses the full lifecycle of AI systems from development through deployment and retirement. Key provisions include establishing an AI policy, defining organizational roles and responsibilities, conducting AI-specific risk and impact assessments, and implementing controls drawn from the normative Annex A control set. Annex A contains 38 controls organized across domains including AI system impact assessment, data governance, transparency, and human oversight. Conformity is assessed through accredited third-party certification audits, enabling organizations to obtain an ISO/IEC 42001 certificate that can be presented to regulators, customers, and partners as evidence of systematic AI governance. The standard also provides informative annexes that map its controls to other AI ethics frameworks, helping organizations rationalize compliance across multiple obligations.
Key Requirements
- •Establish a documented AI policy aligned with the organization's strategic context and communicated across the organization.
- •Conduct AI risk assessments and AI system impact assessments for systems in scope, covering potential harms to individuals, groups, and society.
- •Implement controls from Annex A appropriate to identified risks, including controls on data quality, transparency, human oversight, and accountability.
- •Define and assign roles and responsibilities for AI governance, including top management accountability for AIMS performance.
- •Maintain documented information (records and procedures) sufficient to demonstrate conformity and enable third-party certification audits.
- •Continually improve the AIMS through internal audits, management reviews, and corrective action processes on a defined cycle.
What Your Organization Must Do
- →Audit all AI systems currently in use or under development and compile an inventory that will form the scope boundary for AIMS implementation.
- →Conduct a gap analysis against ISO/IEC 42001:2023 clause by clause to identify which management system elements require creation or uplift before pursuing certification.
- →Appoint a senior owner for the AIMS, ensuring top management formally endorses the AI policy and receives periodic performance reports.
- →Develop and operationalize an AI impact assessment procedure covering both pre-deployment evaluation and ongoing monitoring of deployed systems.
- →Update procurement and vendor management processes to flow down AIMS requirements to third-party AI suppliers and assess their conformity posture.
- →Engage an accredited certification body early to understand audit readiness timelines and to align internal audit cycles with external certification schedules.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Governance Controls
Operational controls that implement requirements from this regulation.
Frequently Asked Questions
- Is ISO 42001 certification mandatory or voluntary for organizations deploying AI?
- ISO/IEC 42001 certification is entirely voluntary. No jurisdiction currently mandates it by law, though regulators in the EU and elsewhere are signaling that conformity with recognized standards like ISO 42001 may satisfy certain AI Act compliance obligations, making certification strategically valuable even without a legal requirement.
- How does ISO 42001 differ from the EU AI Act in terms of compliance obligations?
- The EU AI Act is binding law with mandatory requirements, enforcement powers, and penalties for covered organizations. ISO 42001 is a voluntary management system standard that any organization globally can adopt to demonstrate structured AI governance, and conformity with it may serve as partial evidence of due diligence under the AI Act.
- Can an organization integrate ISO 42001 with an existing ISO 27001 or ISO 9001 program?
- Yes. ISO 42001 follows the same Annex SL high-level structure used by ISO 27001 and ISO 9001, so organizations with established management systems can integrate the AI Management System into their existing program rather than building a parallel governance structure from scratch.
- What is covered in ISO 42001 Annex A and how are the controls selected?
- Annex A contains 38 normative controls organized across domains such as AI impact assessment, data governance, transparency, and human oversight. Organizations select applicable controls based on their AI risk assessments, documenting justifications for any controls they exclude, similar to the Statement of Applicability process in ISO 27001.
- Does ISO 42001 apply to organizations that use third-party AI tools but do not develop AI themselves?
- Yes. The standard explicitly covers both AI providers and AI deployers, so organizations using commercially available AI-enabled products or services are within scope. Compliance obligations extend to vendor management, requiring organizations to assess and flow down AIMS requirements to third-party AI suppliers.
- What are the penalties for failing to maintain ISO 42001 certification once obtained?
- ISO 42001 is not a regulatory instrument, so there are no statutory penalties for losing certification. Practical consequences include withdrawal of the certificate by the accredited certification body and potential reputational or contractual impacts where customers or partners require demonstrated conformity as a condition of doing business.
