Reference · ISO/IEC 42001:2023

ISO/IEC 42001, in one page

The management system standard for organisations that develop, provide or use AI: what it asks, how it is built, and how it is certified.

Written for people who need the structure before the detail. It follows the clauses of the standard, lists the Annex A controls, and shows where it meets the EU AI Act and the GDPR.

Last reviewed: 2 October 2026

01 · Logic

A management system, not a product test

ISO/IEC 42001 does not certify an AI system. It certifies that an organisation manages its AI in a controlled, documented and improving way.

  • Published in December 2023, it is the first certifiable management system standard for AI.
  • Voluntary. No law requires it; customers, procurement and regulators increasingly ask for it.
  • For any organisation that develops, provides or uses AI systems, of any size and sector. The organisation decides the scope.
  • Risk-based. The controls to apply come from the organisation's own risk assessment, not from a fixed list.
  • Same structure as ISO 9001 and ISO/IEC 27001 (the ISO harmonized structure), so it can be integrated into an existing system.
Anyone who has run a quality system under ISO 13485 or an ISMS under ISO/IEC 27001 knows the mechanics: policy, objectives, risk assessment, documented information, internal audit, management review, corrective action. ISO/IEC 42001 applies them to AI, and adds what is specific to it: impact on people, data, the AI life cycle, and the use of AI.

02 · Structure

Ten clauses and four annexes

Clauses 4 to 10 are the requirements, each a "shall". Annex A lists the reference controls; Annex B explains how to implement them.

PartContentStatus
Clauses 1–3Scope, normative references, terms (with ISO/IEC 22989 for AI vocabulary)Context
Clauses 4–10Requirements of the AI management system (AIMS)Requirements
Annex AReference control objectives and controls: 38 controls in 9 areasNormative
Annex BImplementation guidance for each Annex A controlNormative
Annex CPotential AI-related organisational objectives and risk sourcesInformative
Annex DUse of the AIMS across domains and sectorsInformative

03 · Clauses 4–10

Plan, do, check, act

The clauses follow the improvement cycle. Three items in clause 6 carry most of the AI-specific weight: risk assessment, risk treatment with the Statement of Applicability, and the AI system impact assessment.

Plan

  • 4 Context: internal and external issues, interested parties, scope, and the organisation's roles with respect to AI (provider, producer, user, partner…).
  • 5 Leadership: top-management commitment, the AI policy, roles and responsibilities.
  • 6.1.2 AI risk assessment — identify, analyse and evaluate risks to the organisation's AI objectives.
  • 6.1.3 AI risk treatment — choose controls, compare them with Annex A, produce the Statement of Applicability.
  • 6.1.4 AI system impact assessment — consequences for individuals, groups and society.
  • 6.2–6.3 AI objectives and planning of changes.

Do, check, act

  • 7 Support: resources, competence, awareness, communication, documented information.
  • 8 Operation: run the processes, and perform the risk assessment, risk treatment and impact assessment at planned intervals and when things change.
  • 9 Performance evaluation: monitoring and measurement, internal audit, management review.
  • 10 Improvement: continual improvement, nonconformity and corrective action.
Risk assessment and impact assessment are different things. The first looks at risks to the organisation and its objectives. The second looks at what the AI system can do to people and society. The standard asks for both.

04 · Annex A

38 controls in nine areas

Annex A is a reference list, not a checklist. Each control is applied or excluded on the basis of the risk assessment, and the choice is justified in the Statement of Applicability.

AreaWhat it coversControls
A.2 Policies related to AIThe AI policy, its alignment with other policies, its review3
A.3 Internal organisationRoles and responsibilities; reporting of concerns2
A.4 Resources for AI systemsDocumentation of data, tooling, computing and human resources5
A.5 Assessing impacts of AI systemsImpact assessment process and documentation; impacts on individuals, groups and society4
A.6 AI system life cycleObjectives and processes for responsible development; requirements, design, verification and validation, deployment, operation and monitoring, technical documentation, event logs9
A.7 Data for AI systemsData for development, acquisition, quality, provenance, preparation5
A.8 Information for interested partiesInformation for users, external reporting, communication of incidents4
A.9 Use of AI systemsProcesses and objectives for responsible use; intended use3
A.10 Third-party and customer relationshipsAllocation of responsibilities; suppliers; customers3

The organisation may add controls of its own, or take them from other standards. What it may not do is leave an Annex A control out without saying why.

05 · Documented information

What an auditor will ask to see

A management system is judged on evidence. These are the artefacts the clauses require, before any control-specific record.

Defined once, kept current

  • Scope of the AIMS 4.3
  • AI policy 5.2
  • Risk assessment and treatment processes 6.1.2, 6.1.3
  • Statement of Applicability 6.1.3
  • AI system impact assessment process 6.1.4
  • AI objectives 6.2

Produced as the system runs

  • Evidence of competence 7.2
  • Results of risk assessments, risk treatment and impact assessments 8.2–8.4
  • Monitoring and measurement results 9.1
  • Internal audit programme and results 9.2
  • Management review results 9.3
  • Nonconformities and corrective actions 10.2

06 · Certification

How a certificate is obtained

Certification is done by an accredited certification body. Since 2025, ISO/IEC 42006 sets the extra requirements for bodies that audit AI management systems, including the competence of their auditors.

  1. Stage 1 audit — documentation and readiness: scope, policy, risk and impact assessment, Statement of Applicability.
  2. Stage 2 audit — implementation and effectiveness: the system has been running, with evidence of internal audit and management review.
  3. Certificate valid for three years, with surveillance audits in years one and two and a recertification audit in year three.
What a certificate says, and what it does not. It says the organisation operates an AI management system that meets the standard within the declared scope. It does not say that a given AI system is safe, fair or compliant with the AI Act.

07 · Related standards

The family around 42001

ISO/IEC 42001 sets the requirements. A set of companion standards from ISO/IEC JTC 1/SC 42 gives the vocabulary and the methods.

StandardRole
ISO/IEC 22989AI concepts and terminology, referenced by 42001
ISO/IEC 23894Guidance on AI risk management, building on ISO 31000
ISO/IEC 42005AI system impact assessment — the method behind clause 6.1.4 and A.5
ISO/IEC 42006Requirements for bodies that audit and certify AI management systems
ISO/IEC 38507Governance implications of AI for boards
ISO/IEC 5338AI system life cycle processes
ISO/IEC 27001Information security management — same structure, often integrated

08 · EU AI Act and GDPR

Useful for the AI Act, not a pass

ISO/IEC 42001 is not a harmonised standard under the EU AI Act and gives no presumption of conformity. It does build much of the evidence the Act asks for, and organises it.

ISO/IEC 42001EU AI ActGDPR
Roles in context 4.1Provider, deployer Art. 3, 25Controller, processor Arts. 24, 28
Competence, awareness 7.2, 7.3AI literacy Art. 4—
Risk assessment and treatment 6.1.2, 6.1.3Risk management system Art. 9Risk-based accountability Art. 24
Impact assessment 6.1.4, A.5Fundamental rights impact assessment Art. 27Data protection impact assessment Art. 35
Data for AI systems A.7Data and data governance Art. 10Principles, special categories Arts. 5, 9
Life cycle, documentation, logs A.6Technical documentation, logging Arts. 11, 12Privacy by design Art. 25
Information for interested parties A.8Transparency, instructions Arts. 13, 50Information to data subjects Arts. 13–14
Use of AI systems A.9Deployer obligations, human oversight Arts. 14, 26Automated decisions Art. 22
Whole management system 4–10Quality management system Art. 17—

The AI Act also requires things 42001 does not cover on its own: conformity assessment, CE marking, registration, serious-incident reporting to authorities. A dedicated European standard on quality management for the AI Act is in preparation at CEN-CENELEC.

09 · Pitfalls

Where implementations go wrong

Most problems are not about missing documents. They come from treating the standard as a form to fill in.

  • Annex A used as a checklist. Controls picked before the risk assessment, so the Statement of Applicability justifies nothing.
  • Scope drawn to avoid the hard systems. Auditors look at what is left out and why.
  • Impact assessment merged into risk assessment. The effect on people disappears behind business risk.
  • ISO/IEC 27001 documents relabelled. Security is part of it; data quality, life cycle and use of AI are not covered.
  • A system on paper only. No internal audit, no management review, no corrective action: stage 2 fails.
  • Roles left implicit. The same organisation can be provider for one system and user of another; each changes what applies.

10 · Test yourself

Six questions

Short cases that come up in practice. Open each one to see the answer.

Does an ISO/IEC 42001 certificate make an AI system compliant with the EU AI Act?

No. 42001 certifies the management system, not a product, and it is not a harmonised standard under the AI Act. It supports Arts. 9 and 17 and much of the evidence, but conformity assessment, CE marking and registration remain separate.

Can an organisation exclude Annex A controls?

Yes, if the risk assessment shows they are not needed. Every exclusion is justified in the Statement of Applicability 6.1.3.

A company only uses AI tools from suppliers. Is 42001 relevant?

Yes. Its role is user rather than provider 4.1; A.9 (use of AI systems) and A.10 (suppliers) become central, and the impact assessment still applies.

What is the difference between clause 6.1.2 and 6.1.4?

6.1.2 assesses risks to the organisation and its AI objectives. 6.1.4 assesses the consequences of an AI system for individuals, groups and society. ISO/IEC 42005 gives the method for the second.

What must exist before a stage 2 audit?

A running system with evidence: completed risk and impact assessments, the Statement of Applicability, operational records, at least one internal audit 9.2 and one management review 9.3.

How many controls does Annex A contain, and in how many areas?

38 controls in nine areas, A.2 to A.10. The largest is A.6, the AI system life cycle, with nine controls.

Questions

Starting an AI management system?

Scope, roles and the first risk assessment are where most of the work starts. If you want to talk it through, write to me.

This page is a study reference based on the published structure of ISO/IEC 42001:2023; it does not reproduce the standard and is not a substitute for it. The text of the standard is available from ISO and national standards bodies.