ISO/IEC 42001: key requirements

, ISO/IEC 42001 is the first international standard for Artificial Intelligence Management Systems (AIMS). Think of it as the AI equivalent of ISO 27001 for information security.

ISO/IEC 42001: key requirements

Most companies now use AI in some form. Fewer than one in four have a governance framework that actually works. The gap matters. Without structured oversight, AI systems can produce biased outputs that discriminate against customers, make consequential decisions with no audit trail, leak sensitive data through poorly governed model inputs, or simply fail in ways nobody anticipated and nobody owns.

Regulatory exposure is real — the EU AI Act imposes fines of up to 3% of global annual turnover for governance failures, and that number climbs higher for prohibited practices. Reputational damage tends to arrive faster than any fine. A single high-profile incident — a hiring tool that screens out protected groups, a credit model that cannot explain its decisions — can undo years of trust-building overnight. ISO/IEC 42001 is the standard that changes that.

Published in December 2023, ISO/IEC 42001 is the first international standard for Artificial Intelligence Management Systems (AIMS). Think of it as the AI equivalent of ISO 27001 for information security, or ISO 9001 for quality. It gives organisations a structured, auditable way to govern how AI systems are developed, deployed, and operated — across the entire lifecycle.

It applies to every organisation that develops AI products, provides AI-powered services, or simply uses AI tools as part of their operations. That means it is not just for software companies. It covers financial institutions, healthcare providers, manufacturers, professional services firms, and public authorities.


What ISO 42001 actually is

ISO 42001 defines requirements for an AI Management System: a structured set of policies, processes, and controls that govern how an organisation handles AI. The standard does not certify specific AI products or algorithms. It certifies the management system — the framework your organisation uses to make decisions about AI responsibly and consistently.

At its core, an AIMS built on ISO 42001 should help an organisation:

  • Identify and manage AI-related risks, including bias, model drift, opacity, and misuse
  • Define accountability — who owns AI decisions and outcomes
  • Maintain transparency with customers, regulators, and partners
  • Embed ethical principles — fairness, privacy, human oversight — into AI operations
  • Continuously improve as AI systems and regulations evolve

Crucially, it follows the same Harmonised Structure used by other ISO standards. If your organisation already holds ISO 27001 or ISO 9001, the clause layout — context, leadership, planning, support, operations, evaluation, improvement — will be immediately familiar. That makes integration significantly less painful than starting from scratch.


Why get certified

Certification is voluntary. You can implement the standard without going through a formal audit. But there are strong commercial and strategic reasons to pursue the certificate.

Regulatory alignment

The EU AI Act is now in force. ISO 42001 maps directly to its requirements around risk classification, documentation, and post-market monitoring. Certification does not confer automatic compliance, but it creates a documented management framework that simplifies the process considerably. Organisations operating in regulated sectors — financial services, healthcare, critical infrastructure — will feel this benefit most acutely.

Market differentiation

The number of ISO-certified organisations grew 20% globally in 2024 compared to the previous year. ISO 42001 is still early enough that certification signals genuine commitment rather than checkbox compliance. That changes as adoption accelerates, which makes now the right time to move. Major enterprises — Microsoft among them — have already certified, and procurement teams are beginning to ask for it from vendors and partners.

Stakeholder trust

Customers, investors, and employees increasingly want evidence that AI is being used responsibly. A third-party-validated certificate is a much stronger signal than a self-declared policy page. It demonstrates that an independent body has assessed your governance framework and found it meets an internationally recognised standard.

Operational discipline

The process of building an AIMS forces clarity that most organisations lack. Who owns AI risk? Where are the documented impact assessments? How are third-party AI components evaluated? Answering these questions systematically reduces the likelihood of costly incidents — and makes it easier to onboard new AI capabilities responsibly as they emerge.

Competitive access

As enterprise procurement requirements evolve, ISO 42001 is likely to become a condition of doing business in some sectors, just as ISO 27001 did for information security. Getting ahead of that curve avoids the scramble later.


Key requirements

The standard runs from Clause 1 to 10, plus four annexes. Clauses 1 through 3 cover scope, normative references, and terms and definitions. The seven operative clauses (4 through 10) set the actual requirements, and are what certification audits assess. Here is what each requires in practice.

Clause 4 — Context

Map the internal and external factors that affect how your organisation uses AI. This includes regulatory requirements, stakeholder expectations, and the specific scope of AI activities you are governing. You need to understand not just what AI you use, but why, and what constraints apply.

Clause 5 — Leadership

Top management must demonstrate visible commitment. This means establishing an AI policy, assigning clear roles and responsibilities for AI governance, and ensuring that AI objectives are integrated into the organisation's strategic direction. Leadership accountability is non-negotiable — governance frameworks that sit below the executive level tend not to hold.

Clause 6 — Planning

Conduct AI-specific risk assessments covering technical and ethical dimensions: bias, model drift, explainability failures, misuse, privacy risks. Set measurable objectives tied to your AI policy — for example, reducing demographic bias in a decision-support tool, or improving human-override rates for high-stakes outputs. The standard requires you to compare your chosen controls against the 38 AI-specific controls in Annex A, and justify any you have excluded.

Clause 7 — Support

Ensure you have adequate resources, documented competences, and training programmes. Staff involved in AI development and deployment need to understand responsible AI practices, not just the technical mechanics. This clause also covers documentation and communication — what information needs to be maintained, and who needs to know what.

Clause 8 — Operation

The operational backbone of the standard. This clause governs the AI system lifecycle — from conception through retirement. Requirements include: conducting AI impact assessments before deployment; controlling each lifecycle stage with defined processes; managing third-party AI components with appropriate due diligence; and maintaining operational controls that address data quality, human oversight, and incident response.

Clause 9 — Performance Evaluation

Monitor, measure, and audit. Organisations must track whether their AIMS is achieving its objectives, conduct internal audits, and carry out management reviews. This clause ensures that governance does not decay after the initial implementation push.

Clause 10 — Improvement

Respond to nonconformities, address root causes, and continuously improve the AIMS. AI environments change fast — new models, new use cases, new regulations. The standard requires a structured approach to keeping governance current, not just compliant at the point of certification.

Annex A — AI Controls

The standard includes 38 AI-specific controls across nine control objectives. These cover areas including data governance and quality, AI system transparency, bias and fairness, human oversight mechanisms, incident response, and supply chain controls for third-party AI. During certification, auditors verify that your selected controls are justified and that your reasoning is documented in a Statement of Applicability equivalent.


Who should pursue it now

ISO 42001 is most immediately valuable for organisations that:

  • Develop or sell AI-powered products and services
  • Operate in regulated sectors where AI touches consequential decisions
  • Process personal data using AI systems
  • Work with enterprise customers who are building out their own AI governance requirements
  • Already hold ISO 27001 or ISO 9001 and want to extend their management system coverage

For SMEs, the standard is scalable. The framework adapts to organisational size and risk profile — a ten-person AI startup has different obligations than a healthcare network deploying clinical decision support. The structure is the same; the depth of implementation is proportionate.


Getting started

The path to certification follows a familiar pattern: gap assessment, implementation, internal audit, then Stage 1 and Stage 2 audits by an accredited certification body. BSI, DNV, SGS, and TÜV SÜD (sorry for the German) all offer accredited certification. In the UK, UKAS-accredited bodies are the benchmark.

Before engaging a certification body, the practical first steps are: scoping the AIMS, building an AI policy, conducting an initial risk assessment against your current AI use, and mapping your existing controls to Annex A. Organisations already running ISO 27001 have a structural head start — the clause architecture is familiar, and many controls overlap.

AI governance is moving from voluntary best practice to commercial prerequisite. ISO 42001 is the framework that makes it auditable. The organisations that build it properly now will be significantly better positioned as regulation tightens and customer expectations rise.

✓  TL;DR
What we learned about ISO/IEC 42001
Most companies use AI without a working governance framework. Fewer than one in four have one that actually functions, leaving room for biased outputs, undocumented decisions, and data leaks nobody catches until something breaks.
ISO 42001 certifies the management system, not the AI product itself. It's the AI equivalent of ISO 27001 for information security — a structured, auditable set of policies and controls governing how AI is developed, deployed, and operated, applicable to any organisation using AI, not just software companies.
Familiar structure lowers the barrier for existing ISO holders. It follows the same Harmonised Structure as ISO 27001 and ISO 9001, so organisations already certified elsewhere find the clause layout immediately recognisable rather than starting from scratch.
Seven operative clauses cover the full lifecycle. Context and leadership set the foundation, planning requires risk assessment against 38 Annex A controls, operation governs the AI system from conception to retirement, and performance evaluation plus improvement ensure governance doesn't decay after the initial push.
Certification is voluntary but increasingly a commercial signal. It maps directly to EU AI Act requirements around risk classification and documentation, and major enterprises are already certifying — procurement teams are starting to expect it from vendors, much as ISO 27001 became for information security.
The framework scales to organisation size. A ten-person AI startup and a healthcare network deploying clinical decision support follow the same structure, just at proportionate depth — making it viable for SMEs, not just large enterprises.
Coming in future chapters
The practical first steps toward certification: scoping the AIMS, building an AI policy, running an initial risk assessment, and mapping existing controls to Annex A before engaging an accredited certification body.