ISO 42001 Explained
- ISO/IEC 42001 is a management system standard for artificial intelligence. It certifies how you govern AI, not whether any individual model is safe.
- It was published in December 2023 and is the first certifiable AI management standard.
- Annex A contains 38 controls across nine objectives. You choose which apply and justify any you exclude.
- Certification runs on a three-year cycle: a two-stage audit, then annual surveillance.
- UKAS granted its first ISO 42001 accreditations in January 2026, so accreditation status is worth checking before choosing a certification body.
What the standard is
ISO/IEC 42001 is a standard for how an organisation manages artificial intelligence. It asks you to build an AI management system, usually shortened to AIMS: a set of policies, roles, risk processes and controls that governs how AI is developed, bought, deployed and monitored across the business.
It does not certify a model. It certifies that you run a system for governing AI, and that the system actually operates. That distinction is the whole point, and it is why buyers have started asking for it: a certificate about your governance travels across every AI system you have, where a claim about one model does not.
Why it exists
By 2023 organisations were deploying AI faster than they could account for it. Nobody could answer basic questions consistently: which systems are in use, who owns them, what data trained them, who reviews their output, what happens when one goes wrong.
ISO/IEC 42001 was published in December 2023 as the first certifiable answer. It follows the same structure as other management system standards, which means an organisation that already holds ISO 27001 will recognise the shape immediately.
What the standard asks for
The main body of the standard, Clauses 4 to 10, sets out the management system requirements.
| Clause | What it requires |
|---|---|
| 4. Context | Understand your organisation, the parties affected by your AI, and define the scope of the system |
| 5. Leadership | An AI policy, assigned roles and responsibilities, and demonstrated commitment from the top |
| 6. Planning | AI risk assessment, AI risk treatment, an AI system impact assessment, a Statement of Applicability, and objectives |
| 7. Support | Resources, competence, awareness, communication and documented information |
| 8. Operation | Running the risk treatment, the impact assessments, and controls over the AI lifecycle including third parties |
| 9. Performance evaluation | Monitoring, measurement, internal audit, and management review |
| 10. Improvement | Nonconformity handling, corrective action, and continual improvement |
Annex A then lists 38 controls grouped into nine objectives, covering areas such as AI policy, internal organisation, resources for AI systems, impact assessment, the AI lifecycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships.
You select the controls relevant to your organisation and record them in a Statement of Applicability, along with a justification for any you exclude. That document is one of the first things an auditor reads.
The impact assessment
The AI system impact assessment is the piece most organisations underestimate. It asks you to consider the consequences of an AI system for individuals, groups and society, not only the risks to your own business.
That is a genuinely different exercise from an information security risk assessment, which looks outward from the organisation. Here you look inward at the organisation from the position of the people affected. Teams that treat it as a form to complete produce something an auditor will push back on.
How certification works
| Step | What happens |
|---|---|
| Gap analysis | Compare your current position against the standard and plan the work. Optional but almost always sensible |
| Implementation | Build the management system: policy, roles, risk process, impact assessments, controls, documentation |
| Internal audit | Required by Clause 9.2 before certification and annually afterwards. Cannot be performed by your certification body |
| Management review | Leadership formally reviews the system and records decisions |
| Stage 1 audit | The certification body reviews your documentation and readiness |
| Stage 2 audit | The certification body tests whether the system operates in practice |
| Certificate | Valid three years, with surveillance audits in years two and three and recertification at the end |
Two rules follow from ISO/IEC 17021, the standard governing certification bodies. Your certification body cannot consult on the system it will certify, and it cannot perform your internal audit. That separation is why implementation and certification are always two different suppliers.
Accreditation is worth checking
The certification market is young. UKAS granted its first ISO 42001 accreditations in January 2026, and equivalents such as ANAB in the United States have been building their schemes over the same period.
Certificates issued before a body held accreditation for this specific standard are not worthless, but they carry less weight in procurement, and a sophisticated buyer will check. Ask any certification body to confirm it holds accreditation for ISO/IEC 42001 specifically, not for management system certification in general. Our existing guide on choosing a certification body covers this in more detail.
Why buyers ask for it
Three reasons, in roughly this order of frequency.
Enterprise procurement teams added AI questions to their security reviews and needed something to check for. A certificate is checkable; a policy document is not.
Organisations preparing for the EU AI Act found that ISO/IEC 42001 builds most of the governance substance the Act's high-risk duties assume, which turns the Act's documentation work into a mapping exercise. See our EU AI Act service page.
Some large buyers now require it contractually from suppliers whose AI touches sensitive uses, which cascades down supply chains quickly.
What it does not do
It does not make a model accurate, fair or safe. It makes the organisation account for those questions in a repeatable way and keep the record.
It does not satisfy the EU AI Act. The Act attaches per-system obligations that a management system certificate does not discharge, although holding one makes them considerably easier to meet.
It does not replace ISO 27001. The two overlap in structure, and Annex D of ISO/IEC 42001 addresses integrating the two, but they answer different questions. See our ISO 27001 service page.
What to do next
Decide first whether you need the certificate or the management system. Some organisations need the governance and not the audit. Most that are asked for it by buyers need both.
Our free readiness diagnostic gives a first view, and the ISO/IEC 42001 service page sets out how a programme runs.
References
FAQ
What is ISO 42001?
A certifiable management system standard for artificial intelligence, published in December 2023. It governs how an organisation develops, buys, deploys and monitors AI.
Does ISO 42001 certify our AI model?
No. It certifies the management system around your AI, which applies across every system you run.
How many controls does it have?
Annex A contains 38 controls across nine objectives. You select which apply and justify exclusions in a Statement of Applicability.
How long is certification valid?
Three years, with surveillance audits in years two and three and a recertification audit at the end of the cycle.
Is it mandatory?
No. It is voluntary. Demand comes from buyers and, increasingly, from contractual requirements imposed by large customers.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We take companies through ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001, from first assessment to certificate, and maintain the position afterwards. We are not a certification body and we do not issue certificates. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.