Reference · ISO/IEC 42001:2023
The management system standard for organisations that develop, provide or use AI: what it asks, how it is built, and how it is certified.
Written for people who need the structure before the detail. It follows the clauses of the standard, lists the Annex A controls, and shows where it meets the EU AI Act and the GDPR.
Last reviewed: 2 October 2026
01 · Logic
ISO/IEC 42001 does not certify an AI system. It certifies that an organisation manages its AI in a controlled, documented and improving way.
02 · Structure
Clauses 4 to 10 are the requirements, each a "shall". Annex A lists the reference controls; Annex B explains how to implement them.
| Part | Content | Status |
|---|---|---|
| Clauses 1–3 | Scope, normative references, terms (with ISO/IEC 22989 for AI vocabulary) | Context |
| Clauses 4–10 | Requirements of the AI management system (AIMS) | Requirements |
| Annex A | Reference control objectives and controls: 38 controls in 9 areas | Normative |
| Annex B | Implementation guidance for each Annex A control | Normative |
| Annex C | Potential AI-related organisational objectives and risk sources | Informative |
| Annex D | Use of the AIMS across domains and sectors | Informative |
03 · Clauses 4–10
The clauses follow the improvement cycle. Three items in clause 6 carry most of the AI-specific weight: risk assessment, risk treatment with the Statement of Applicability, and the AI system impact assessment.
04 · Annex A
Annex A is a reference list, not a checklist. Each control is applied or excluded on the basis of the risk assessment, and the choice is justified in the Statement of Applicability.
| Area | What it covers | Controls |
|---|---|---|
| A.2 Policies related to AI | The AI policy, its alignment with other policies, its review | 3 |
| A.3 Internal organisation | Roles and responsibilities; reporting of concerns | 2 |
| A.4 Resources for AI systems | Documentation of data, tooling, computing and human resources | 5 |
| A.5 Assessing impacts of AI systems | Impact assessment process and documentation; impacts on individuals, groups and society | 4 |
| A.6 AI system life cycle | Objectives and processes for responsible development; requirements, design, verification and validation, deployment, operation and monitoring, technical documentation, event logs | 9 |
| A.7 Data for AI systems | Data for development, acquisition, quality, provenance, preparation | 5 |
| A.8 Information for interested parties | Information for users, external reporting, communication of incidents | 4 |
| A.9 Use of AI systems | Processes and objectives for responsible use; intended use | 3 |
| A.10 Third-party and customer relationships | Allocation of responsibilities; suppliers; customers | 3 |
The organisation may add controls of its own, or take them from other standards. What it may not do is leave an Annex A control out without saying why.
05 · Documented information
A management system is judged on evidence. These are the artefacts the clauses require, before any control-specific record.
06 · Certification
Certification is done by an accredited certification body. Since 2025, ISO/IEC 42006 sets the extra requirements for bodies that audit AI management systems, including the competence of their auditors.
07 · Related standards
ISO/IEC 42001 sets the requirements. A set of companion standards from ISO/IEC JTC 1/SC 42 gives the vocabulary and the methods.
| Standard | Role |
|---|---|
| ISO/IEC 22989 | AI concepts and terminology, referenced by 42001 |
| ISO/IEC 23894 | Guidance on AI risk management, building on ISO 31000 |
| ISO/IEC 42005 | AI system impact assessment — the method behind clause 6.1.4 and A.5 |
| ISO/IEC 42006 | Requirements for bodies that audit and certify AI management systems |
| ISO/IEC 38507 | Governance implications of AI for boards |
| ISO/IEC 5338 | AI system life cycle processes |
| ISO/IEC 27001 | Information security management — same structure, often integrated |
08 · EU AI Act and GDPR
ISO/IEC 42001 is not a harmonised standard under the EU AI Act and gives no presumption of conformity. It does build much of the evidence the Act asks for, and organises it.
| ISO/IEC 42001 | EU AI Act | GDPR |
|---|---|---|
| Roles in context 4.1 | Provider, deployer Art. 3, 25 | Controller, processor Arts. 24, 28 |
| Competence, awareness 7.2, 7.3 | AI literacy Art. 4 | — |
| Risk assessment and treatment 6.1.2, 6.1.3 | Risk management system Art. 9 | Risk-based accountability Art. 24 |
| Impact assessment 6.1.4, A.5 | Fundamental rights impact assessment Art. 27 | Data protection impact assessment Art. 35 |
| Data for AI systems A.7 | Data and data governance Art. 10 | Principles, special categories Arts. 5, 9 |
| Life cycle, documentation, logs A.6 | Technical documentation, logging Arts. 11, 12 | Privacy by design Art. 25 |
| Information for interested parties A.8 | Transparency, instructions Arts. 13, 50 | Information to data subjects Arts. 13–14 |
| Use of AI systems A.9 | Deployer obligations, human oversight Arts. 14, 26 | Automated decisions Art. 22 |
| Whole management system 4–10 | Quality management system Art. 17 | — |
The AI Act also requires things 42001 does not cover on its own: conformity assessment, CE marking, registration, serious-incident reporting to authorities. A dedicated European standard on quality management for the AI Act is in preparation at CEN-CENELEC.
09 · Pitfalls
Most problems are not about missing documents. They come from treating the standard as a form to fill in.
10 · Test yourself
Short cases that come up in practice. Open each one to see the answer.
No. 42001 certifies the management system, not a product, and it is not a harmonised standard under the AI Act. It supports Arts. 9 and 17 and much of the evidence, but conformity assessment, CE marking and registration remain separate.
Yes, if the risk assessment shows they are not needed. Every exclusion is justified in the Statement of Applicability 6.1.3.
Yes. Its role is user rather than provider 4.1; A.9 (use of AI systems) and A.10 (suppliers) become central, and the impact assessment still applies.
6.1.2 assesses risks to the organisation and its AI objectives. 6.1.4 assesses the consequences of an AI system for individuals, groups and society. ISO/IEC 42005 gives the method for the second.
A running system with evidence: completed risk and impact assessments, the Statement of Applicability, operational records, at least one internal audit 9.2 and one management review 9.3.
38 controls in nine areas, A.2 to A.10. The largest is A.6, the AI system life cycle, with nine controls.
Questions
Scope, roles and the first risk assessment are where most of the work starts. If you want to talk it through, write to me.
This page is a study reference based on the published structure of ISO/IEC 42001:2023; it does not reproduce the standard and is not a substitute for it. The text of the standard is available from ISO and national standards bodies.