ISO 42001
The international standard for AI management systems
Reviewed 10 August 2026by Julian Russell, Managing Director
Overview
What is ISO 42001?
ISO 42001 is the international standard for artificial intelligence management systems. It sets out how an organisation governs the AI it builds or uses, including the risks that AI poses to the people affected by it.
ISO 42001 was published in December 2023 and is the first international management system standard for artificial intelligence. It applies to any organisation that develops, provides or uses AI systems, which now includes a great many organisations that would not describe themselves as AI companies.
If you use AI to screen job applicants, score credit, route customer enquiries, monitor productivity or generate content that reaches customers, you are in scope.
Why it matters now
Three things are converging.
Customers are asking. AI governance questions have started appearing in procurement questionnaires and supplier due diligence, in much the same way information security questions did a decade ago.
Regulation is arriving. The EU AI Act is being phased in through 2025 to 2027, and the UK is developing its own approach. ISO 42001 does not make you compliant with either, but it builds the governance structure that compliance work will sit on.
Organisations have deployed AI faster than they have governed it. Tools have often arrived through individual teams rather than a central decision. Many organisations cannot answer, with confidence, which AI systems they are using and what those systems do with their data.
What makes ISO 42001 different
The standard follows the common structure shared across ISO management system standards, so if you hold ISO 9001 or ISO 27001 the shape will be familiar. Two things set it apart.
AI impact assessment. Alongside risk assessment, which considers risk to the organisation, ISO 42001 requires assessment of the impact of AI systems on individuals and society. That is a genuinely different question: a system can present little risk to you while presenting considerable risk to the people it makes decisions about.
The full lifecycle. The standard covers the whole life of an AI system: design, data acquisition, development, verification, deployment, operation, monitoring and retirement. Data quality, provenance and bias are explicit concerns rather than technical footnotes.
Annex A controls
Like ISO 27001, ISO 42001 comes with a set of reference controls in Annex A, covering areas including AI policy, internal organisation, resources for AI systems, impact assessment, the AI system lifecycle, data for AI systems, information for interested parties, use of AI systems, and third party relationships.
As with ISO 27001, you decide which controls apply and record the reasoning. The third party clause is worth particular attention: most organisations consume AI through vendors rather than building it, so supplier governance carries much of the weight.
ISO 42001 and the EU AI Act
These are related but distinct, and it is worth being precise.
The EU AI Act is legislation. It classifies AI systems by risk and imposes obligations, with penalties for non-compliance. It applies to organisations placing AI systems on the EU market or whose systems affect people in the EU, which catches many UK organisations.
ISO 42001 is a voluntary management system standard. Certification does not make you compliant with the Act.
What it does do is establish the inventory, impact assessment, documentation and governance that Act compliance requires you to have. Organisations with a functioning AI management system are considerably better placed than those starting from nothing.
Who is in scope
Wider than most people assume. You are in scope if you develop AI systems, if you provide them to others, or if you use them in your operations.
The last category catches the most organisations. Recruitment screening, customer service automation, fraud detection, content generation, forecasting and productivity monitoring are all AI uses, whether the tool was built in-house or bought.
The first step is usually an inventory, because most organisations discover they are using more AI than they thought.
What certification involves
Certification comes from an independent certification body accredited by UKAS, not from a consultancy. Assessment runs in two stages, with Stage 1 covering documentation and readiness and Stage 2 covering implementation and effectiveness.
Being an early adopter has a practical implication worth knowing: fewer certification bodies hold accreditation for ISO 42001 than for the established standards, so check availability and cost before committing to a timeline. A gap analysis is the usual starting point, and implementation support covers the build.
Combining with ISO 27001
ISO 42001 and ISO 27001 overlap substantially and are often implemented together as an integrated management system. The asset inventory, risk assessment, supplier controls and documentation discipline built for information security transfer directly.
If you hold ISO 27001, adding ISO 42001 is a considerably smaller project than starting from nothing, and the two make a coherent story to a customer asking how you handle their data and how you use AI on it.
Why get certified
Key Benefits of ISO 42001
Responsible AI
Demonstrate ethical and responsible use of AI technologies.
Risk Management
Systematically identify and manage AI-specific risks including bias and transparency.
Regulatory Readiness
Prepare for emerging AI regulations including the EU AI Act.
Competitive Advantage
Be among the first to demonstrate certified AI governance.
How we work
Our Certification Process
AI inventory
Establishing which AI systems you develop, provide or use, including tools adopted by individual teams. Most organisations find more than they expected.
Scope definition
Deciding which systems and activities the management system covers, which shapes cost, effort and commercial usefulness.
Risk and AI impact assessment
Assessing risk to the organisation, and separately the impact of AI systems on individuals and society, which is a distinct question.
Controls and Statement of Applicability
Reconciling your treatment decisions against the Annex A controls and recording which apply, which do not, and why.
Lifecycle and data governance
Controls across design, data acquisition, development, deployment, monitoring and retirement, including data quality, provenance and bias.
Internal audit and management review
Both required before certification, with the audit needing enough technical understanding to test whether controls operate.
Stage 1 and Stage 2 audits
Documentation and readiness review, then the full implementation audit, with Equas in attendance.
Common questions
Frequently Asked Questions
Yes. The standard covers organisations that develop, provide or use AI systems, and the last category catches the most organisations. Recruitment screening, customer service automation, fraud detection, content generation and productivity monitoring all count, whether built in-house or bought.
Ready for ISO 42001 Certification?
Get a free, no-obligation quote from our expert consultants. Backed by the Equas Guarantee.
