What is ISO/IEC 42001?
- ISO/IEC 42001:2023 was published December 2023 — the first certifiable AI management system standard.
- It certifies the organisation's management system, not any individual AI product.
- It uses the same High-Level Structure as ISO 27001 and ISO 9001, so 27001 holders certify faster.
- Certification is issued only by an accredited certification body (UKAS/ANAB-accredited).
- It is voluntary in law but commercially mandatory in a growing share of enterprise AI RFPs.
- General information, not legal advice. Current as of July 2026.
What the standard is
ISO/IEC 42001 is a management-system standard for artificial intelligence, published by ISO and IEC in December 2023. It is the first standard of its kind: previous ISO work on AI (ISO/IEC 22989, 23894 and others) produced vocabulary and guidance, but not a certifiable specification. ISO 42001 is that specification.
The standard follows ISO's High-Level Structure — the same shape as ISO/IEC 27001 for information security and ISO 9001 for quality. An organisation that already operates a mature ISO 27001 programme will recognise the anatomy: context, leadership, planning, support, operation, performance evaluation, improvement, and an annex of reference controls.
What an AI management system is
An AI management system, or AIMS, is the coordinated set of policies, roles, processes and controls an organisation uses to direct and govern AI across its lifecycle. Rather than governing one model in isolation, an AIMS governs the way the whole organisation decides which AI to build or buy, how it assesses risk and impact, how it oversees systems in operation, and how it improves the practice over time.
The standard does not tell you which AI is acceptable. It tells you what a well-run AI governance function looks like, and what evidence of that function must exist.
What certification actually proves
Certification against ISO/IEC 42001 proves that an accredited third party has audited the organisation's AIMS against the standard and found it conformant. That is a meaningful statement about governance discipline. It is not a statement that any particular AI system is safe, lawful, unbiased, or compliant with any specific regulation.
This distinction matters commercially and legally. A certificate answers the buyer's question 'do you have a functioning AI governance system?'. It does not answer 'is this specific product compliant with the EU AI Act?' — that is a product-level conformity assessment, and it is separate work.
Who ISO 42001 applies to
The standard is written to apply to any organisation providing or using AI, at any scale, in any sector. In practice adoption is concentrated in three groups: AI vendors selling into large enterprises whose procurement teams screen for it; enterprises deploying AI at scale who need one consistent internal governance system; and regulated firms under supervisory pressure to evidence AI oversight.
Why buyers ask for it
Buyers ask for ISO/IEC 42001 because it is the only artefact currently available that answers 'show me your AI governance' with an independent third-party attestation rather than a self-description. As of mid-2026, roughly 40% of EU AI vendor RFPs and 25% of North American ones request it — and the largest AI providers, including Anthropic, AWS, Snowflake, Salesforce, ServiceNow, CrowdStrike and Harvey, have publicly certified. That has moved the market's expectation.
Key terms
- AIMS
- AI management system — the coordinated set of policies, roles and controls used to govern AI across its lifecycle.
- High-Level Structure
- The common clause structure ISO uses across its management-system standards (27001, 9001, 42001, etc.).
- Accredited certification body
- A conformity-assessment body accredited to issue certificates against a given standard; only accredited bodies can certify.