What Is ISO 42001? The AI Management Standard in Plain English
ISO Cloud Consulting editorial team
ISO 42001 (formally ISO/IEC 42001:2023) is the international standard for an AI management system: a repeatable way for an organization to decide how it builds, buys and uses AI, manage the risks to people and the business, and prove it. It is voluntary, it applies to any size of company, and you can be certified against it.
Key facts
- Published: December 2023 by ISO and IEC. It is the first certifiable AI management system standard.
- Applies to: any organization that develops, provides or uses AI systems.
- Contents: requirements in clauses 4 to 10, plus 38 Annex A controls grouped under 9 objectives.
- Certification: two-stage audit by an accredited certification body, then a 3-year cycle with annual surveillance audits.
- Law: voluntary, and not a harmonized standard under the EU AI Act as of 2026.
What does "AI management system" mean?
An AI management system (AIMS) is the set of rules, roles and routines an organization uses to keep its AI under control. It is not software, and it is not a single policy. It is how decisions about AI get made, recorded and checked.
A restaurant kitchen is a useful comparison. Food safety is not the recipes. It is who checks fridge temperatures, how often, where the readings are written down and what happens when a reading is wrong. ISO 42001 does the same for AI. It does not tell you which model to pick or what accuracy to hit. It makes sure someone asked the right questions, wrote down the answers and keeps checking them.
Why does AI need its own standard?
AI fails differently from ordinary software. Traditional code does what it was written to do, every time. AI systems learn behavior from data, so they can be confidently wrong, unfair to some groups, or quietly degrade after launch.
Anyone who has shipped a machine learning model has seen this. A model that tested well can drift as customer behavior changes. A vendor can update the model behind an API without telling you. A tool built to summarize tickets ends up used to rank staff performance. None of these is a classic security breach, so an information security program alone will not catch them. ISO 42001 adds the missing questions: what is this system for, who could it affect, what data shaped it, and who is watching it now.
Who is ISO 42001 for?
ISO 42001 is for any organization whose products, services or decisions rely on AI, whether it builds the AI or buys it. How much of the standard you use depends on your role.
| Your situation | Does ISO 42001 fit? | Where to start |
|---|---|---|
| You build or fine-tune models for your product | Strong fit; most controls will apply | AI system inventory, risk and impact assessments, life cycle controls |
| You sell software with AI features built on a vendor's model | Strong fit, especially if enterprise customers ask about AI | Supplier controls, user information, incident communication |
| You use AI tools to make decisions about customers or staff | Good fit; impact assessment is central | Intended use, human oversight, impact on individuals |
| Your staff only use chat assistants for drafting | Probably premature for certification | An AI acceptable use policy and a simple tools list |
Company size is not the test. A 30-person software firm whose product scores loan applications has more reason to adopt ISO 42001 than a 3,000-person manufacturer whose only AI is an email assistant. What matters is how much your AI can affect customers, staff and the public, and how often outsiders ask you to prove you have it under control.
What does ISO 42001 require you to do?
At its core, ISO 42001 asks you to do five things and keep evidence that you did them. Everything in the standard supports one of these.
- Know your AI. Define the scope and list every AI system in it, with its purpose, owner, data and vendor.
- Set direction. Leadership approves an AI policy, sets AI objectives and assigns clear roles.
- Assess risk and impact. Score what could go wrong for the organization (AI risk assessment) and for people and society (AI system impact assessment), then decide treatments.
- Apply controls. Choose from the 38 Annex A controls, record your choices and reasons in a Statement of Applicability, and put them into practice.
- Check and improve. Monitor results, run internal audits, hold management reviews and fix what you find.
A Statement of Applicability sounds formal, but it is simply a list of every Annex A control with a yes or no, a reason, and how you meet it. For a control-by-control walkthrough, read ISO 42001 Annex A: all 38 controls explained simply.
How is ISO 42001 different from ISO 27001?
ISO 27001 protects information; ISO 42001 governs how AI systems behave and affect people. They share the same management-system skeleton, so they work well together, but neither replaces the other.
| Question | ISO 27001 | ISO 42001 |
|---|---|---|
| What is being managed? | Information security | The development, provision and use of AI |
| Main risk lens | Confidentiality, integrity and availability of information | Risk to the organization plus impact on individuals, groups and society |
| Distinctive requirement | Information security risk assessment | AI system impact assessment (clause 6.1.4) |
| Typical evidence | Access reviews, backups, security incident logs | Model testing results, data provenance, intended-use statements, human oversight records |
| Shared parts | Clause structure, internal audit, management review, document control, corrective action | |
If you already hold ISO 27001, you have a head start: the management-system machinery exists and needs extending, not building.
What are the common misconceptions about ISO 42001?
The most common misconception is that ISO 42001 is a technical standard for model quality. It is a management standard: it checks that you make and record good decisions about AI, not that your model hits a benchmark.
- "It certifies our AI product." It certifies the management system around your AI, within a stated scope. Say "our AI management system is certified to ISO 42001", not "our AI is ISO certified".
- "We have to implement all 38 controls." You must consider all 38, but you apply the ones relevant to your risks and justify the rest. A company that never trains models will treat data-preparation controls very differently from one that does.
- "It makes us compliant with the EU AI Act." It does not, on its own. It builds many of the habits the Act expects, such as inventories, risk management, documentation and oversight, but legal obligations depend on your role and the system's risk category.
- "It is a one-off project." Certification runs on a three-year cycle with yearly audits. The system has to keep working after the consultants leave.
- "It needs a large compliance team." Small companies run it with one accountable owner, a few hours from each system owner, and leadership time for reviews.
Is ISO 42001 certification worth it?
Certification is worth it when customers, investors or regulators need independent proof that you manage AI well. If nobody is asking yet, implementing the core of the standard without certifying is a sensible middle path.
Signs it is worth pursuing now: enterprise prospects send AI questionnaires, AI sits inside your product, you make decisions about people with AI, or you plan to sell into the EU where the AI Act will apply. Signs it can wait: AI use is limited to staff productivity tools, and nobody outside the company has asked. Either way, the inventory, policy and assessments are worth doing, because you will need them to answer questions whatever you decide about certification.
How do you get started with ISO 42001?
Start small and concrete: name an owner, list your AI, and check yourself against the standard before writing anything long.
- Name an owner. One person accountable for the AIMS, with a senior sponsor.
- Build the inventory. Ask every team which AI tools and features they use, including AI inside existing software.
- Check readiness. Use the free ISO 42001 Readiness Checklist to see where the gaps are.
- Draft the core documents. Scope, AI policy, risk and impact assessments and the Statement of Applicability. The ISO 42001 Starter Bundle ($129) covers the inventory and risk register, impact assessment and gap assessment workbook.
- Run it, then audit it. Operate the processes for a few weeks, then do an internal audit and management review.
For the bigger picture, including certification steps, a 90-day plan and which template fits each stage, see our ISO 42001 guide and templates hub. The official summary is on the ISO website.
Last reviewed: 29 September 2026