ISO 42001 Explained: AI Management System Guide and Templates
ISO/IEC 42001 is the international standard for an AI management system (AIMS): the policies, roles, risk and impact assessments, controls and reviews that show an organization develops, provides or uses AI responsibly. Published in December 2023, it is the first AI standard a company can be independently certified against.
Key facts about ISO 42001
- Full name: ISO/IEC 42001:2023, the AI management system standard (official ISO page).
- Published: December 2023. It is the first certifiable AI management system standard.
- Who it applies to: any organization, of any size or sector, that develops, provides or uses AI systems.
- Structure: requirements in clauses 4 to 10, plus 38 Annex A controls grouped under 9 objectives (A.2 to A.10).
- Certification: stage 1 and stage 2 audits by an accredited certification body, then a 3-year cycle with annual surveillance audits.
- Companion standards: ISO/IEC 42005:2025 (impact assessment guidance), ISO/IEC 42006:2025 (rules for certification bodies) and ISO/IEC 23894 (AI risk guidance).
- Legal status: voluntary. As of 2026 it is not a harmonized standard under the EU AI Act.
What does ISO 42001 actually require?
ISO 42001 requires you to know what AI you have, decide what could go wrong for your business and for the people affected, choose safeguards, name owners and prove the safeguards work. It does not tell you which model to use or what accuracy to hit.
Think of it as ISO 27001 for AI. You write down how you manage AI, you do what you wrote, and an auditor checks the two match. It uses the same high-level clause structure as ISO 27001 and ISO 9001, so the systems can share audits and reviews.
Who needs ISO 42001, and why now?
Any company that puts AI into its product, or relies on AI for decisions about customers or staff, is being asked to prove it manages that AI. ISO 42001 is the most widely recognized way to show it. Three pressures are driving the timing.
- Customer questionnaires. Security reviews now carry AI sections: which models you use, whether customer data trains them, who approves new AI features and how you handle AI incidents. A working AIMS gives you one consistent set of answers.
- Enterprise procurement. Large buyers want evidence of AI governance from suppliers, and some ask for ISO 42001 certification or a credible roadmap to it.
- EU AI Act timing. Transparency obligations under Article 50 apply from 2 August 2026. The 2026 Digital Omnibus moved most high-risk obligations to 2 December 2027 (Annex III systems) and 2 August 2028 (AI built into regulated products). That is a runway, not a pass. ISO 42001 builds the inventory, risk, documentation and oversight habits the Act expects, although it is not a legal safe harbor. Check the current text for your situation.
Who can wait: a company whose only AI is staff using chat assistants. Start with an acceptable use policy instead.
How is ISO 42001 structured?
ISO 42001 has two layers: clauses 4 to 10 describe how to run the management system, and Annex A lists 38 controls you select from.
Clauses 4 to 10: the management system
- Clause 4, Context: your AI role, who has a stake and what the AIMS covers.
- Clause 5, Leadership: top management owns the system, approves the AI policy (5.2) and assigns roles.
- Clause 6, Planning: AI risk assessment (6.1.2), risk treatment and the Statement of Applicability (6.1.3), AI system impact assessment (6.1.4), AI objectives (6.2) and planned changes (6.3).
- Clause 7, Support: competence, awareness, communication and document control.
- Clause 8, Operation: run the risk assessments, treatments and impact assessments for real as systems change (8.2 to 8.4).
- Clause 9, Performance evaluation: measure results, run internal audits (9.2) and hold management reviews (9.3).
- Clause 10, Improvement: fix problems at the root and keep improving.
Annex A: 38 controls in 9 groups
| Group | Topic | Controls | What it means in plain English |
|---|---|---|---|
| A.2 | Policies related to AI | 3 | Write an AI policy, align it with your other policies and review it. |
| A.3 | Internal organization | 2 | Name who is accountable for AI and give people a safe way to raise concerns. |
| A.4 | Resources for AI systems | 5 | Document the data, tools, computing and people each AI system depends on. |
| A.5 | Assessing impacts of AI systems | 4 | Assess how each system could affect individuals, groups and society, and keep the records. |
| A.6 | AI system life cycle | 9 | Specify, build, test, deploy, monitor and log AI systems in a controlled, documented way. |
| A.7 | Data for AI systems | 5 | Know where data came from, whether you may use it, how good it is and how it was prepared. |
| A.8 | Information for interested parties | 4 | Tell users what the system does and its limits, give them a way to report problems and plan incident communication. |
| A.9 | Use of AI systems | 3 | Use AI responsibly and only for its intended purpose. |
| A.10 | Third-party and customer relationships | 3 | Split responsibilities clearly with suppliers and customers, and vet AI suppliers. |
You do not have to implement every control. You must consider all 38 and record which apply, and why, in a Statement of Applicability. A company that only uses third-party AI usually carries lighter A.6 and A.7 obligations than one training its own models. For each control with example evidence, see ISO 42001 Annex A: all 38 controls explained simply.
Which documents does every AIMS need first?
Start with six documents: a scope statement, an AI policy, an AI system inventory, an AI risk assessment with its register, AI system impact assessments and a Statement of Applicability.
- AIMS scope (clause 4.3). One page naming the products, AI systems, teams and locations covered, and your role: developer, provider or user.
- AI policy (5.2, A.2.2). A short, leadership-signed statement of principles and ownership. The staff acceptable use policy sits beneath it.
- AI system inventory. A register of every AI system in scope: purpose, owner, model or vendor, data used and who is affected. You cannot assess what you have not listed.
- AI risk assessment and register (6.1.2, 6.1.3). A method for scoring risks to your objectives, and the resulting list of risks, owners and treatments.
- AI system impact assessments (6.1.4, A.5). For each system, the likely consequences for people and society: fairness, privacy, safety and transparency.
- Statement of Applicability (6.1.3). All 38 Annex A controls, each with a yes or no, a reason and its status. Auditors usually read this first.
How does ISO 42001 certification work?
Certification takes two audits by an accredited certification body. Stage 1 checks your design and readiness; stage 2 checks that the system actually runs. Pass both and you hold a certificate on a 3-year cycle.
- Choose a certification body. Ask each candidate about its accreditation for ISO 42001 specifically.
- Stage 1. The auditor reviews your scope, policy, methods and Statement of Applicability.
- Stage 2. The auditor samples interviews and records, often tracing one real AI system from inventory to monitoring.
- Keep it running. Surveillance audits follow in each of the next two years, then a recertification audit in year three.
Certification bodies generally expect at least one internal audit and one management review to be complete before stage 2, so plan for them early.
What does a realistic 90-day path look like?
A small, focused team can build a working AIMS and be ready for a stage 1 audit in about 90 days, if leadership commits time and the scope is sensible. Treat this as a plan, not a promise.
| Weeks | Focus | Outputs |
|---|---|---|
| 1 to 2 | Appoint an owner, agree scope, list every AI system | Scope statement, AI system inventory |
| 3 to 4 | Approve the AI policy and staff acceptable use policy, assign roles | AI policy, acceptable use policy, responsibility chart |
| 5 to 7 | Assess risk and impact for each in-scope system | Risk register, impact assessments, treatment plan |
| 8 to 9 | Gap-assess against Annex A, close quick wins | Statement of Applicability, gap action plan |
| 10 to 11 | Run the processes, brief staff, collect records | Training records, monitoring evidence |
| 12 to 13 | Internal audit and management review, fix findings | Audit report, review minutes, corrective actions |
What drives the cost and effort of ISO 42001?
Cost is driven mainly by how many AI systems are in scope, whether you build models or only use them, and how much management-system discipline you already have. Certification fees depend on audit days, which the certification body sets from your scope and size, so get written quotes rather than relying on published averages.
- Scope size: how many AI systems, teams and sites are covered.
- Your AI role: training or fine-tuning models brings the A.6 life cycle and A.7 data controls fully into play; using vendor AI is lighter.
- Existing systems: ISO 27001 or ISO 9001 lets you reuse document control, audits and reviews.
- Evidence maturity: if you already monitor models, test releases and log changes, evidence is cheap. If not, you build the processes first.
What are the most common ISO 42001 mistakes?
Most weak first attempts come from writing documents before understanding the AI estate, or from paperwork that does not match how engineers really work.
- Starting with controls instead of the inventory. Controls need something to protect.
- Treating the AI policy and the acceptable use policy as one document. One sets direction for the company; the other gives staff daily rules.
- Merging risk and impact assessment. Risk looks at harm to the organization; impact looks at consequences for people and society.
- A Statement of Applicability with every control marked "yes" and no reasons.
- Forgetting shadow AI. Software that quietly added AI features, and staff on personal accounts, belong in the inventory.
- Paper that does not match practice. If engineers describe a different release process from your procedure, expect a finding.
Which ISO 42001 template fits which stage?
Check readiness for free, set staff AI rules with the policy pack, then build the assessments and Statement of Applicability with the bundle or full toolkit.
| Where you are | Template | Price |
|---|---|---|
| Deciding whether to start | Free ISO 42001 Readiness Checklist | Free |
| Staff use ChatGPT or Copilot with no rules | AI Policy & Acceptable Use Policy Pack | $39 |
| Need to list your AI and its risks | AI System Inventory & AI Risk Register | $49 |
| Assessing effects on people | AI System Impact Assessment Template | $49 |
| Mapping yourself against Annex A | Gap Assessment & Statement of Applicability Workbook | $59 |
| Building the core assessments together | ISO 42001 Starter Bundle | $129 (was $157) |
| Building the full AIMS toward certification | ISO 42001 AIMS Implementation Toolkit | $249 |
All templates are editable Office files, licensed for one organization and downloaded instantly. Templates help you prepare; certification depends on your auditor and on the system you actually run.
Last reviewed: 29 September 2026
Frequently asked questions
Is ISO 42001 mandatory?
No law requires ISO 42001 certification. It is a voluntary standard. In practice it can become a commercial requirement when a large customer writes it into a contract or a security questionnaire. It is also not a harmonized standard under the EU AI Act as of 2026, so it helps you build evidence but does not by itself prove legal compliance.
Do we need ISO 27001 before we start ISO 42001?
No. The two standards are independent, and you can certify to ISO 42001 alone. If you already hold ISO 27001, you are ahead: document control, internal audit, management review and corrective action can be shared, and many certification bodies can audit both systems together. Security controls you already run also support several AI controls.
Does ISO 42001 apply if we only use AI tools such as ChatGPT or Copilot?
Yes. The standard covers organizations that use AI, not only those that build it. The real question is whether a full management system is worth it yet. If your only AI is staff using assistants, start with an acceptable use policy and an inventory, then decide on certification once AI reaches your product or customer decisions.
How long is an ISO 42001 certificate valid?
Certification runs on a three-year cycle. After the initial stage 1 and stage 2 audits, the certification body returns for a surveillance audit in each of the next two years, then carries out a recertification audit before the certificate expires. The system has to keep running between audits, because auditors sample records from the whole period.
Can we self-declare ISO 42001 conformity instead of getting certified?
You can assess yourself against the standard and say you are aligned with it, and that is a sensible first step. You cannot call yourself certified unless an accredited certification body has audited you. Customers who ask for certification usually want to see the certificate and the scope statement printed on it.
Not ready to buy? Start with the free ISO 42001 readiness checklist
25 plain-English questions that show how ready you are for an ISO/IEC 42001 AI management system.