ISO/IEC 42001: the certifiable backbone for AI governance
ISO/IEC 42001:2023 is the first international management system standard for artificial intelligence, published in December 2023. It specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system, and it is certifiable: an accredited body can audit an organization against it and issue a certificate. The certificate covers the management system, not any individual AI system, and it creates no presumption of conformity with the EU AI Act.
Status of time-bound facts in this article: 1 August 2026.
What the standard requires
ISO/IEC 42001ISO/IEC 42001The international requirements standard for AI management systems, published in 2023 and certifiable. It defines how an organization establishes, implements, maintains, and continually improves a management system for AI. Certification against ISO/IEC 42001 does not create a legal presumption of conformity with the EU AI Act. See AI management system, harmonized standard.Open full entry → follows the harmonized structure shared by ISO 9001 and ISO/IEC 27001, which is why organizations that already run one of those systems recognize the shape immediately. Clauses 4 through 10 define the management system itself: context of the organization, leadership, planning, support, operation, performance evaluation, and improvement. The AI-specific substance enters through those clauses: understanding the organization's role in the AI life cycleAI life cycleThe looped stages of an AI system: design → data/development → validation → deployment → operation & monitoring → retirement, each with native controls and gated transitions.Open full entry →, an AI policy, AI riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → assessment and treatment, and an AI systemAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → impact assessmentimpact assessmentA structured evaluation, carried out in the plan-and-design stage, of the harms an AI system could cause and the risk those harms carry, before the system is built. The first place the governance chain is run, and the cheapest point in the life cycle to reduce risk. The anchor artifact of the planning stage; under the EU AI Act, a fundamental-rights impact assessment is required for certain high-risk deployers. See harm, risk, life cycle.Open full entry → that considers effects on individuals and societies, not only on the organization.
Annex A supplies the reference set of controlscontrolThe concrete, testable measure that reduces a specific risk, and through that risk protects the principle behind it. Also called a risk management measure, risk response, or risk treatment. Always traceable to the risk it addresses: under EU AI Act Art. 9 every control must map back to a specific risk, and controls recorded separately from their risks is a recognized compliance failure. It works in one of three types: preventive, detective, or corrective. See risk, control types, evidence.Open full entry →: 38 controls organized under nine control objectivescontrol objectiveA statement of the outcome a control must achieve, such as "unauthorized payments must not be technically executable". It says what must be true rather than what must be built, which leaves room for more than one control activity to meet it. Keeping the objective separate from the activity is what keeps a control register testable. See control activity, enforcement point.Open full entry →, numbered A.2 through A.10, covering AI policy, internal organization, resources, impact assessment, the AI system life cyclelife cycleThe span of a single AI system from first intake to retirement, across which it must be governed. The horizontal axis of governance: where the governance chain holds one principle, the life cycle runs one system through time. Commonly drawn as six stages, plan and design, data and develop, verify and validate, deploy, operate and monitor, and retire, each with controls native to it and an anchor artifact. A loop rather than a line, because a system in production feeds new risk back into fresh assessment. See artifact, control, governance chain.Open full entry →, data, information for interested parties, responsible use, and third-party relationships. Annex A is a catalogue, not a checklist. The organization selects applicable controls through a Statement of Applicability, justifies the selection from its risk and impact assessments, and justifies every exclusion. Annex B gives implementation guidance per control; Annexes C and D are informative, with risk sources and cross-sector notes.
Two design choices distinguish the standard from its older siblings. The impact assessment looks outward, at the people and groups an AI system affects, where ISO/IEC 27001 looks inward at the organization's own information. And the standard applies regardless of whether the organization develops, provides, or merely uses AI, which means a deployerdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → with no model of its own can still run and certify an AIMS.
What certification involves
Certification is a third-party conformity assessmentconformity assessmentThe pre-market process demonstrating a high-risk AI system meets the EU AI Act's requirements, leading to CE marking and registration.Open full entry →: an accredited certification body audits the management system against the standard, in an initial audit and then a surveillance cycle. The certificate names a scope, the legal entity, sites, and services covered, and reading that scope statement is the first check anyone relying on the certificate should perform.
Whether the certificate carries weight depends on a second standard. ISO/IEC 42006:2025 specifies what a certification body must be capable of before it audits and certifies against ISO/IEC 42001, supplementing ISO/IEC 17021-1 with AI-specific competence requirements, audit time rules, and impartiality provisions. Accreditation against it is still being put in place. Certification by a body without that accreditation is not void, but it carries less independent weight, and the question to ask is always the same: accredited by whom, under which standard, with which published scope.
What the certificate does and does not prove
The certificate states that an independent body found the management system to conform, at the audit moment, within the stated scope. External audits sample both design and operation, in a window, against that scope.
It does not state that any individual AI system is safe, fair, or lawful. It creates no presumption of conformity with the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry →: that presumption attaches only to harmonized European standards after citation in the Official Journal, and ISO/IEC 42001 is an international standard outside that mechanism. The first European candidate, EN 18286 on quality management systems, reached publication in July 2026 but had not been cited as of that month. And the certificate does not relieve a deployer of its own obligations: a supplier's ISO/IEC 42001 certificate says something about that supplier's governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry →, nothing about yours.
The standard's real value sits elsewhere. It forces the questions that ad hoc AI governanceAI governanceGovernance extended for AI: the same organizational steering at the highest level, widened to cover what makes AI different (it works in probabilities rather than fixed rules, learns from data, and can act at a speed and scale no human reviewer can match). It inherits the existing governance structure and brings AI inside the disciplines the organization already runs, rather than creating a parallel system in a silo. It operates on two levels, design and execution. See governance, governance design, execution level, responsible AI.Open full entry → skips: who is accountable, which systems exist, what impact they have on people outside the organization, which controls apply and why, and what evidenceevidenceThe concrete proof that a control is designed, implemented, and working: a test report, an audit trail, an impact assessment, a monitoring log. Each link in the governance chain produces an artifact, and together they are what an organization hands to its own board, a regulator, a customer, or an affected person to show, not say, that a system is governed. Its absence is itself the failure: a risk register without test results, or a mitigation claimed without validation, is a governance gap, not a paperwork one. The closing link of the governance chain. See control, governance.Open full entry → shows they operate. An organization that answers those questions honestly is most of the way to demonstrable control, with or without the certificate on the wall.
Where it fits in the stack
The EU AI Act is the law and defines what you must do. ISO/IEC 42001 is the certifiable management system standard that gives your governance an auditable backbone. The NIST AI RMFNIST AI RMFThe AI Risk Management Framework of the US National Institute of Standards and Technology, published as version 1.0 in 2023. It is a voluntary framework built around four functions: govern, map, measure, and manage. In a layered setup, it serves as the risk method inside a management system such as ISO/IEC 42001. See ISO/IEC 42001, ISO/IEC 23894.Open full entry → is the risk method that runs inside it. Complementary and layered, not a choice of one.
For organizations subject to the Act, the practical sequence is to build the AIMS as the operating structure, run the risk method inside it, and maintain the Act's specific obligations, technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry →, conformity assessment, post-market monitoringpost-market monitoringProvider-side duty to systematically collect and act on experience from systems in use, the product-regulation half of continuous monitoring.Open full entry →, as outputs the system produces rather than as separate projects.
Continue reading
Frequently asked questions
- Does ISO/IEC 42001 certification make an organization EU AI Act compliant?
- No. The certificate covers the management system, and the standard sits outside the EU harmonization mechanism, so it creates no presumption of conformity. Compliance with the Act is demonstrated against the regulation text and, in time, against harmonized European standards.
- Who can be certified?
- Any organization that develops, provides, or uses AI systems. The standard applies regardless of size or sector, and a pure deployer can certify its AIMS.
- How many controls does the standard contain?
- Annex A lists 38 controls under nine control objectives, A.2 through A.10. They are a reference set: the organization selects and justifies applicable controls through a Statement of Applicability.
- What is the difference between ISO/IEC 42001 and ISO/IEC 42006?
- ISO/IEC 42001 sets requirements for the organization's AI management system. ISO/IEC 42006 sets requirements for the certification bodies that audit and certify against it. One governs the audited, the other the auditor.
- How does the standard relate to ISO/IEC 27001?
- Same harmonized structure, different object. ISO/IEC 27001 manages information security risk to the organization; ISO/IEC 42001 manages AI risk including impacts on individuals and societies outside it. Organizations commonly run both, and integrated audits are possible.