Guide · ISO 42001
ISO/IEC 42001 Explained: The AI Management System Standard
What the first certifiable AI governance standard requires, how it is structured, and how to get from gap analysis to certificate.
ISO/IEC 42001:2023 is the international standard for Artificial Intelligence Management Systems (AIMS). Published in December 2023, it is the first management system standard dedicated to AI: a certifiable framework of requirements for establishing, implementing, maintaining, and continually improving how an organization governs the development and use of AI. Like ISO 27001 for information security, it follows the Plan-Do-Check-Act (PDCA) cycle and can be audited by accredited certification bodies. This guide explains what the standard contains, who needs it, and what the certification journey actually involves.
What is ISO/IEC 42001?
ISO/IEC 42001 defines the requirements for an AI management system: the policies, roles, processes, and documented evidence an organization uses to govern AI responsibly across its lifecycle. It was developed by the joint ISO/IEC subcommittee responsible for AI standardization and is deliberately built on the same harmonized structure used by ISO 27001, ISO 9001, and other management system standards. That shared skeleton is what makes it practical: organizations that already run a certified management system can extend familiar governance machinery to AI rather than inventing a parallel program.
Three properties define the standard:
- It is a management system standard, not a technical checklist. ISO 42001 does not tell you which model architecture to use or which fairness metric to compute. It requires that you have a repeatable, documented process for identifying AI risks, assessing impacts on individuals and society, treating those risks with controls, and proving the process ran.
- It is PDCA-based. The Plan-Do-Check-Act cycle means the AIMS is never "done": you plan controls, operate them, measure their effectiveness through internal audit and management review, and correct what fails. Auditors specifically look for evidence of the full loop, not a one-time documentation exercise.
- It is certifiable. Unlike voluntary frameworks such as the NIST AI RMF, ISO 42001 conformity can be independently certified by an accredited third party, which is why it is rapidly becoming the reference artifact in enterprise AI procurement.
Who needs ISO 42001 certification, and why now?
ISO 42001 applies to any organization that develops, provides, or uses AI systems, in any industry and at any size. In practice, three forces are driving adoption in 2025 and 2026:
EU AI Act alignment
The EU AI Act entered into force in August 2024 with obligations phasing in over the following years. The Act's requirements for providers of high-risk AI systems, such as risk management, data governance, technical documentation, logging, human oversight, and post-market monitoring, presume exactly the kind of systematic governance an AIMS provides. ISO 42001 certification is not proof of AI Act conformity, but it builds the operational substrate: the risk registers, impact assessments, and lifecycle records that AI Act evidence will be drawn from.
Enterprise procurement pressure
AI vendors are now routinely asked in security and vendor-risk questionnaires how their AI governance is structured, whether impact assessments are performed, and whether an independent party has verified any of it. An ISO 42001 certificate answers those questions in one line. For AI-native startups selling into regulated enterprises, it is becoming the AI equivalent of what SOC 2 or ISO 27001 became for cloud security: a de facto entry ticket.
Board-level AI risk accountability
Model incidents, from data leakage through prompts to adversarial manipulation of deployed models, are increasingly treated as enterprise risk. Frameworks such as MITRE ATLAS catalog the adversarial techniques used against AI systems; boards want assurance that someone owns those risks. ISO 42001's leadership clauses put that ownership on record. (For how the standard's control themes intersect with ATLAS threat techniques, see our ISO 42001 vs MITRE ATLAS crosswalk.)
How is ISO 42001 structured?
The standard has two layers: mandatory management system clauses (4 through 10) that every certified organization must satisfy, and an annex of reference controls selected via a risk-based statement of applicability.
Management system clauses 4–10
| Clause | Theme | What it requires |
|---|---|---|
| 4. Context | Scope and stakeholders | Determine internal and external issues, interested parties, and the boundaries of the AIMS, including which AI systems and roles (provider, deployer, user) are in scope. |
| 5. Leadership | Accountability | Top management commitment, an approved AI policy, and clearly assigned roles, responsibilities, and authorities for AI governance. |
| 6. Planning | Risk and objectives | AI risk assessment and risk treatment planning, AI system impact assessment, and measurable AIMS objectives. |
| 7. Support | Resources and records | Competence, awareness, communication, and control of documented information: the evidence layer of the entire system. |
| 8. Operation | Running the controls | Operational planning and control of AI lifecycle processes, executing risk treatments, and performing impact assessments in practice. |
| 9. Performance evaluation | Check | Monitoring and measurement, internal audit of the AIMS, and management review. |
| 10. Improvement | Act | Handling nonconformities, corrective action, and continual improvement of the AIMS. |
Annex A control themes
Annex A provides a library of reference controls, applied through a statement of applicability the way ISO 27001 practitioners will recognize. Rather than memorizing control numbers, it is more useful to understand the themes the controls cover:
- AI policy and internal organization: a documented AI policy, defined roles, and reporting lines for AI decisions.
- AI system impact assessment: assessing consequences of AI systems for individuals, groups, and society, not just for the organization itself.
- AI system lifecycle: documented requirements, design, verification and validation, deployment, operation, and monitoring for each AI system, including technical documentation and event logging.
- Data governance for AI: provenance, quality, and management of data used to build and operate AI systems.
- Resources and asset inventory: knowing which models, datasets, tooling, and compute underpin each AI system. This is where a Machine Learning Bill of Materials (ML-BOM) becomes the natural evidence artifact.
- Third-party and supplier management: managing risk from suppliers of models, data, and AI services, including customers and partners in the AI value chain.
- Information for interested parties and responsible use: transparency to users, incident reporting channels, and defined processes for responsible use of AI.
Supporting annexes provide implementation guidance for the controls, a catalog of AI-related organizational objectives and risk sources to seed risk assessments, and guidance on using the AIMS alongside domain-specific standards.
What does the ISO 42001 certification journey look like?
Certification follows the same arc as other ISO management system standards. Four phases matter:
- Gap analysis. Inventory your AI systems, classify your role for each (provider, deployer, or both), and assess current practices against clauses 4–10 and the Annex A themes. The output is a scoped statement of applicability and a remediation backlog. This is where most organizations discover they have no authoritative inventory of models and datasets at all.
- Implementation. Stand up the AIMS: publish the AI policy, assign roles, build the risk and impact assessment processes, and implement the applicable controls across the AI lifecycle. Integration with an existing ISO 27001 ISMS is common and reduces duplicated effort substantially.
- Evidence generation. Operate the system long enough to produce records: completed risk assessments, impact assessments, lifecycle documentation, supplier reviews, internal audit results, and management review minutes. Auditors certify what you can prove, not what you assert.
- Audit. An accredited certification body performs a stage 1 review of your documentation and readiness, then a stage 2 audit of the AIMS in operation. Certificates are typically maintained on a multi-year cycle with periodic surveillance audits, so evidence collection never stops after the certificate is issued.
Practitioner note
The critical path in almost every ISO 42001 program is phase 3. Policies can be written in weeks; a body of trustworthy, system-linked evidence can only accumulate over months of actual operation. Teams that treat evidence as an automated by-product of their ML pipeline, rather than a quarterly scramble, compress the journey dramatically.
How does ISO 42001 compare to ISO 27001, NIST AI RMF, and the EU AI Act?
These four frameworks are complements, not competitors, but they differ fundamentally in scope and force:
| Framework | What it is | Scope | Certifiable? | Focus |
|---|---|---|---|---|
| ISO/IEC 42001:2023 | Voluntary international management system standard | Governance of AI development and use, any organization | Yes, via accredited certification bodies | Responsible AI governance: risk, impact, lifecycle, suppliers |
| ISO/IEC 27001 | Voluntary international management system standard | Information security management, any organization | Yes, via accredited certification bodies | Confidentiality, integrity, availability of information |
| NIST AI RMF | Voluntary U.S. framework (Govern, Map, Measure, Manage) | AI risk management guidance, any organization | No, guidance only | Trustworthy AI characteristics and risk practices |
| EU AI Act | Binding EU regulation, in force since August 2024 | AI systems placed on or used in the EU market, risk-tiered | No, legal compliance with staged obligations | Prohibited practices, high-risk system requirements, GPAI duties |
A useful mental model: the EU AI Act tells you what you are legally obliged to achieve, NIST AI RMF describes good risk practice, ISO 27001 secures the information underneath, and ISO 42001 is the certifiable operating system that organizes all of it into one auditable management loop.
Why is evidence collection the hard part of ISO 42001?
Nearly every ISO 42001 requirement terminates in the same demand: documented information. A risk assessment that was performed but not recorded, or a control that operates but leaves no trace, does not exist from an auditor's perspective. And AI evidence is uniquely painful to collect manually, for three reasons:
- The subject matter changes constantly. Models are retrained, datasets are refreshed, and pipelines are re-deployed far faster than quarterly compliance reviews can track. Point-in-time spreadsheets are stale before they are reviewed.
- Evidence is scattered across the ML stack. Lineage lives in training pipelines, dependencies in package manifests, deployment facts in infrastructure tooling. No single team owns the full picture of any one AI system.
- Evidence integrity is itself in question. An evidence file that anyone can silently edit is weak proof. Auditors, and increasingly regulators, want to know records were not altered after the fact.
This is the problem AI compliance automation exists to solve, and it is the specific problem SecureGRC is being built for. SecureGRC is an early-stage, purpose-built platform rather than a broad legacy GRC suite, and it approaches ISO 42001 evidence in four opinionated ways:
- A sequential, auditable pipeline. The TCCE Engine runs threat assessment, control mapping, compliance evaluation, and evidence linking as discrete stages, so every conclusion in a compliance report can be traced back through the exact stage that produced it.
- An ISO 42001 control library with gap analysis. AI systems are assessed against ISO/IEC 42001 control themes, producing a compliance posture report and a concrete gap list, the phase-1 artifact of the certification journey described above.
- Metadata-only analysis. Model weights, training data, and proprietary IP never enter the platform; all analysis runs on extracted metadata, which also keeps the compliance tool itself out of your AI risk surface. The reasoning behind this architecture is covered in our metadata-only compliance deep dive.
- Tamper-evident, post-quantum evidence. Every artifact is signed with CRYSTALS-Dilithium (NIST FIPS 204, finalized in August 2024), hashed with SHA-3, and anchored in a Merkle tree, so an auditor can verify integrity using only public keys. How that works, and why quantum-safe signatures matter for long-lived audit records, is explained in our quantum-safe compliance guide.
SecureGRC also generates ML-BOMs aligned with CycloneDX and SPDX to serve as the asset-inventory evidence Annex A themes call for, and maps threat profiles to MITRE ATLAS so risk assessments are grounded in a recognized adversarial-threat knowledge base. Incumbent platforms cover ISO 42001 as one module among hundreds of regulations; a comparison of the purpose-built versus breadth-first approach is in SecureGRC vs OneTrust. For everything else, our FAQ covers the platform in detail.
Frequently asked questions
Is ISO 42001 certification mandatory?
No. ISO/IEC 42001 is a voluntary standard, and certification is optional. However, it is increasingly requested in enterprise procurement questionnaires and vendor risk assessments, and it provides a structured way to demonstrate responsible AI governance to regulators, customers, and partners. For organizations facing EU AI Act obligations, an ISO 42001 AI management system supplies much of the governance scaffolding those obligations assume, even though certification itself is not a legal requirement.
How long does ISO 42001 certification take?
Most organizations should plan for roughly six to eighteen months from initial gap analysis to certificate, depending on the maturity of their existing governance. Companies that already operate an ISO 27001 information security management system typically move faster because the management clauses share the same harmonized structure. The longest phase is usually evidence generation: the AIMS must produce records of risk assessments, impact assessments, and lifecycle documentation over time before an auditor can verify it is genuinely operating.
Does ISO 42001 replace ISO 27001?
No. ISO/IEC 27001 governs information security management, while ISO/IEC 42001 governs the responsible development and use of AI systems. They are complementary: both follow the same harmonized management system structure, so clauses covering context, leadership, planning, support, operation, performance evaluation, and improvement can share processes. Many organizations integrate the two into a single management system, extending existing ISO 27001 governance with AI-specific risk assessment, impact assessment, and lifecycle controls.
Does ISO 42001 certification prove EU AI Act compliance?
No. The EU AI Act is a binding regulation with its own risk classification and legal obligations, and certification against ISO 42001 does not by itself demonstrate conformity with the Act. What ISO 42001 does provide is the management infrastructure the Act presumes: documented risk management, data governance, human oversight arrangements, logging, and post-market monitoring processes. Organizations that operate a certified AIMS are generally far better positioned to evidence AI Act obligations than those starting from scratch.
Can startups and small companies get ISO 42001 certified?
Yes. Like other ISO management system standards, ISO/IEC 42001 scales the required effort to the size, complexity, and risk profile of the organization and its AI systems. A small team with a narrow AIMS scope can certify with proportionally lighter documentation. The practical constraint for small teams is bandwidth: manually assembling risk assessments, control mappings, and audit evidence is time-consuming, which is why automation of evidence collection matters most for smaller organizations.
What evidence do auditors ask for in an ISO 42001 audit?
Auditors look for documented information proving the AIMS operates as described: the AI policy and statement of applicability, AI risk assessments and risk treatment plans, AI system impact assessments, lifecycle documentation for in-scope systems, data governance records, supplier and third-party assessments, incident and nonconformity records, internal audit results, and management review minutes. Crucially, evidence must be traceable to specific AI systems and controls, and must show the process ran repeatedly over time, not just once before the audit.