What Is the ISO/IEC 42001 Standard?

Also called: ISO 42001, ISO/IEC 42001

Related problems: Customers asking whether our AI practices follow a recognized standard; Need a structured way to manage AI risk that auditors will accept; Unsure whether an AI vendor's certificate covers the product we use; Already certified to ISO 27001 and wondering what AI adds

ISO/IEC 42001 is the international standard that sets requirements for an artificial intelligence management system: the policies, roles, risk processes and controls an organization uses to develop, provide, deploy, operate or use AI responsibly and keep improving how it does so. Published jointly by the international standards bodies ISO and IEC and first released in 2023, it follows the same management-system approach as ISO/IEC 27001, and organizations can be independently certified against it.

At a glance

  • It defines what an AI management system must include; it doesn’t prescribe specific technology.
  • It applies to organizations that build AI and to those that use it, of any size.
  • Certification is performed by an independent certification body, which may be accredited, and covers a defined scope you should check.
  • Its structure mirrors ISO/IEC 27001, so many organizations run the two together.

What problem it solves

AI is moving into products and business processes faster than most organizations’ controls. Customers, boards and regulators want to know who is accountable for AI use, how risks such as bias, data misuse, security weaknesses and unreliable output are assessed, and what happens when something goes wrong. Without a common reference, each answer is a custom narrative, and each customer questionnaire asks it differently.

ISO/IEC 42001 provides that reference. It turns AI governance from a set of good intentions into a managed system with documented policies, assigned roles, repeatable risk and impact assessments, and regular review. A certificate gives customers and partners an outside opinion that the system exists and operates, much as ISO/IEC 27001 does for information security.

How it works

Context and scope. The organization defines which AI systems, activities and locations the management system covers. For each in-scope AI system, it determines how it develops, provides, deploys, operates or uses that system, and assigns responsibilities to match.

Leadership and policy. Top management sets an AI policy, assigns responsibilities and provides resources.

Risk and impact assessment. The organization identifies AI risks and assesses the potential impact of AI systems on individuals, groups and society, then chooses controls to treat them. Data quality and integrity, including threats such as data poisoning, are part of this work.

Controls. An annex lists reference controls covering areas such as AI policy, data management, the AI system life cycle, transparency to users and relationships with third parties. As with ISO/IEC 27001, the organization documents which controls apply and justifies any exclusions.

Operation, audit and improvement. The system runs day to day, is checked through internal audits and management reviews, and is corrected and improved over time.

Certification. Certification is performed by an independent certification body, which may be accredited. The body audits the system against the standard. Buyers should check the certificate’s scope and, where their procurement policy cares about it, the body’s accreditation status and the scope of that accreditation. Certification typically follows a multi-year cycle with periodic surveillance audits, similar to other ISO management system standards.

When it matters for buyers

  • When buying AI-enabled products or services. A vendor’s certificate is useful evidence for third-party risk management (TPRM), but check that its scope covers the product you use.
  • When customers ask how you govern AI. Enterprise and international customers increasingly include AI questions in due diligence.
  • When preparing for AI regulation. In the EU, the AI Act sets legal obligations; a management system aligned with ISO/IEC 42001 can help organize the work, but how far it supports compliance depends on your role and the rules that apply. Check with counsel.
  • When you already hold ISO/IEC 27001. Extending an existing management system is usually less work than starting from scratch.

Our governance, risk and compliance advisors can help you scope certification work and find assessors.

Questions to ask vendors

  • Are you certified to ISO/IEC 42001, which certification body issued the certificate, and is that body accredited for this standard?
  • What does the certificate’s scope cover, and does it include the product and locations we use?
  • When was your last surveillance audit, and when does the certificate expire?
  • Which parts of this AI system’s life cycle do you handle, such as development, provision, deployment, operation and use, and how are responsibilities for each assigned between you, your suppliers and us?
  • How do you assess and monitor the AI models and data you get from your own suppliers?
  • How does your AI management system connect to your information security program?

How it differs from the NIST AI RMF

The NIST AI Risk Management Framework (AI RMF) is voluntary guidance from the US National Institute of Standards and Technology. It describes outcomes and practices for managing AI risk but sets no formal requirements and offers no certification. ISO/IEC 42001 is an international standard with auditable requirements for a management system, and certification is available. They complement each other: many organizations use the NIST framework to shape the risk-management activities that an ISO/IEC 42001 system then governs, documents and audits.

Frequently Asked Questions

Is ISO 42001 the same as ISO/IEC 42001?
Yes. Like ISO/IEC 27001, it is published jointly by ISO and IEC, so its full designation is ISO/IEC 42001. ISO 42001 is the common shorthand.
Who is ISO/IEC 42001 for?
Organizations that develop, provide, deploy, operate or use AI systems. It is written to apply regardless of size or sector, so a company using third-party AI tools can adopt it as well as one building models.
Is ISO/IEC 42001 mandatory?
No law we know of requires it in general. It is voluntary, but customers may ask for it in contracts, and it can support compliance with rules such as the EU AI Act. Certification against it doesn't by itself prove compliance with any law; check with counsel.
How does ISO/IEC 42001 relate to ISO/IEC 27001?
They share the common structure used by ISO management system standards, so policies, risk processes, internal audit and management review can be run together. ISO/IEC 27001 covers information security; ISO/IEC 42001 covers the responsible development and use of AI. Many organizations add one to the other.
How is it different from the NIST AI RMF?
The NIST AI Risk Management Framework is voluntary US guidance with no certification. ISO/IEC 42001 is an international standard with formal requirements that independent certification bodies, which may be accredited, can audit and certify against. Organizations often use the NIST framework to inform the risk work inside an ISO/IEC 42001 system.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.