ISO 42001

ISO 42001:
the AI management system standard, explained.

What ISO/IEC 42001 requires, clause by clause, what the 38 Annex A controls cover, how the impact assessment differs from the risk assessment, and what certification involves. Written for the people who have to build the management system, not buy a badge.

Last updated Published by TryTrustableNot legal advice

01

What is ISO 42001?

ISO 42001, formally ISO/IEC 42001:2023, is the international standard that sets requirements for an artificial intelligence management system (AIMS): the policies, roles, risk and impact assessments, controls and review cycle an organisation uses to develop, provide or use AI responsibly. Published in December 2023, it is certifiable by accredited third-party auditors.

It was prepared by ISO/IEC JTC 1/SC 42, the joint committee on artificial intelligence, and is the first edition (ISO/IEC 42001:2023). It says what a management system must contain and leaves the method, for risk management or data quality, to you.

The phrase to hold onto is management system. ISO 42001 does not certify a model, a product or an AI system. It certifies that an organisation has a working process for governing the AI it builds, sells or uses, and evidence that the process runs.

02

Who is ISO 42001 for?

ISO 42001 applies to any organisation, of any size or sector, that provides or uses products or services involving AI systems. That covers companies building models, companies wrapping a foundation model into a product, and companies buying AI features from suppliers. Certification is voluntary; the usual trigger is a customer asking for evidence of AI governance.

The standard's own scope is broad on purpose: it says it applies regardless of size, type and nature, and it covers using AI as well as developing it. In practice three kinds of organisation pursue it:

  • AI product companies whose customers ask how models are evaluated and changed
  • SaaS companies adding AI features on a third-party foundation model
  • Regulated users of AI (lenders, insurers, hospitals, employers) governing AI they buy rather than build

You define the scope of the AIMS yourself under clause 4.3. A narrow first scope, one product line or one business unit, is common and entirely legitimate, provided the boundary is stated and defensible.

03

What are the ISO/IEC 42001 requirements?

The ISO/IEC 42001 requirements sit in clauses 4 to 10, which follow the same harmonized structure as ISO 27001: context, leadership, planning, support, operation, performance evaluation and improvement. What makes it specific to AI is clause 6, which requires an AI risk assessment, an AI risk treatment plan with a Statement of Applicability, and an AI system impact assessment.

Clauses 1 to 3 are scope, references and definitions. The auditable requirements are clauses 4 to 10, and a certification body will look for evidence against every one.

ClauseWhat it requiresEvidence an auditor will ask for
4 Context of the organisationInternal and external issues, interested parties and their needs, your role with respect to AI, and the scope of the AIMSScope statement; list of AI systems in scope and your role for each
5 LeadershipTop management commitment, an AI policy, and assigned roles, responsibilities and authoritiesApproved AI policy; named owners
6 PlanningAI risk assessment (6.1.2), AI risk treatment and Statement of Applicability (6.1.3), AI system impact assessment (6.1.4), AI objectives, planning of changesRisk methodology and register; Statement of Applicability; impact assessments
7 SupportResources, competence, awareness, communication, and control of documented informationTraining records; document control
8 OperationOperational planning and control, and running the risk assessment, risk treatment and impact assessment at planned intervals or on significant changeDated reassessments; records that controls operated
9 Performance evaluationMonitoring and measurement, an internal audit programme, and management reviewInternal audit report; management review minutes
10 ImprovementContinual improvement, nonconformity and corrective actionCorrective action log with root causes and closure

Clause titles from ISO/IEC 42001:2023. Clauses 4 to 10 use the harmonized structure common to ISO management system standards.

Four annexes follow. Annex A (normative) holds the reference control objectives and controls. Annex B (normative) is implementation guidance for those controls; it is often described as optional reading, but the standard marks it normative. Annex C (informative) lists potential AI-related organisational objectives and risk sources, and Annex D (informative) covers using the AIMS across domains and sectors.

04

How many controls are in ISO 42001 Annex A?

ISO 42001 Annex A lists 38 reference controls grouped into nine areas, numbered A.2 to A.10, from AI policy through to third-party and customer relationships. Annex A is normative but not a checklist: you select the controls your risk treatment needs and justify every inclusion and exclusion in a Statement of Applicability.

The areas and their control counts, taken from the control list in Annex A:

AreaWhat it coversControls
A.2 Policies related to AIThe AI policy, its alignment with other policies, and its review3
A.3 Internal organisationAI roles and responsibilities; reporting of concerns2
A.4 Resources for AI systemsDocumenting data, tooling, computing and human resources5
A.5 Assessing impacts of AI systemsThe impact assessment process, its documentation, and impacts on individuals, groups and society4
A.6 AI system life cycleResponsible development objectives, requirements, design documentation, verification and validation, deployment, operation and monitoring, technical documentation, event logs9
A.7 Data for AI systemsData for development, acquisition, quality, provenance and preparation5
A.8 Information for interested partiesUser documentation, external reporting, communication of incidents4
A.9 Use of AI systemsProcesses and objectives for responsible use; intended use3
A.10 Third-party and customer relationshipsAllocating responsibilities, suppliers, customers3
Total38

Area titles paraphrased from Annex A. A.1 is the annex's general introduction and holds no controls.

The Statement of Applicability ties the annex to your risks: clause 6.1.3 requires it to list the necessary controls and justify each inclusion and exclusion. Auditors sample from both.

05

What is the difference between an AI risk assessment and an AI system impact assessment?

An AI risk assessment, under clause 6.1.2, looks at risks to the organisation meeting its AI objectives. An AI system impact assessment, under clause 6.1.4, looks outward at the consequences an AI system can have for individuals, groups of individuals and societies. ISO 42001 requires both, and the results of the impact assessment feed the risk assessment.

Teams often collapse the two into one spreadsheet. Keep them apart.

  • AI risk assessment (6.1.2, operated under 8.2). Identify, analyse and evaluate risks that could stop the organisation meeting its AI objectives. Annex C lists risk sources worth considering, such as the complexity of the environment, a lack of transparency and explainability, and the level of automation
  • AI risk treatment (6.1.3, operated under 8.3). Choose treatment options, select controls, compare them against Annex A so nothing necessary is missed, and produce the Statement of Applicability
  • AI system impact assessment (6.1.4, operated under 8.4). Assess the potential consequences of deploying and using an AI system for individuals, groups and societies, across its intended use and foreseeable misuse. Controls A.5.2 to A.5.5 set out how the process is run and documented

All three are repeated at planned intervals and on significant change: a retrained model, a new data source or a new intended purpose should appear as a dated reassessment. For personal data, the impact assessment sits alongside a data protection impact assessment rather than replacing it; the DPIA guide covers that one.

06

How does ISO 42001 certification work?

ISO 42001 certification is an audit by an accredited certification body in two stages: stage 1 reviews your documentation and readiness, stage 2 tests whether the management system actually operates. A certificate lasts three years, with surveillance audits at least annually in between and a recertification audit before it expires.

Certification bodies are themselves accredited against ISO/IEC 17021-1, the general standard for bodies certifying management systems, and ISO/IEC 42006:2025, which adds AI-specific requirements such as auditor competence in AI and how audit time is calculated. Checking that a certificate is issued under accreditation, and not merely by a company that sells certificates, is the buyer's first due-diligence step.

StepWhat happensWhat to have ready
ReadinessGap assessment against clauses 4 to 10 and Annex A; scope decided; AIMS operated for long enough to produce recordsAt least one internal audit and one management review completed
Stage 1 auditDocumentation and readiness review: scope, policy, risk and impact methodology, Statement of ApplicabilityDocumented information, with gaps closed or planned
Stage 2 auditEffectiveness audit: interviews and samples to confirm the AIMS actually operates as documentedRecords that controls ran, dated before the audit
Certification decisionNonconformities corrected; certificate issued for three yearsCorrective action evidence
Surveillance auditsAt least once a year in years one and two, sampling part of the systemEvidence the system kept running between audits
RecertificationFull audit before the certificate expires in year threeThree years of records, not three weeks
07

Is ISO 42001 the same as ISO 27001?

No. ISO 27001 manages information security risk; ISO 42001 manages the risks and impacts of AI systems. They share the harmonized clause structure, so policies, internal audit, management review and corrective action can run as one integrated management system, but each has its own Annex A controls and its own certificate.

The shared structure is the practical benefit. Because both standards use the same clause numbers and titles for 4 to 10, an organisation holding ISO 27001 already has the machinery ISO 42001 reuses: document control, internal audit, management review, corrective action and competence records. The genuinely new work is the AI inventory, the AI risk and impact assessments, the AI-specific Annex A controls and the life-cycle evidence for each system. The ISO 27001 solution page covers the security side.

Neither standard is a prerequisite for the other, and the two can be audited together.

08

How ISO 42001 relates to the EU AI Act and the NIST AI RMF

ISO 42001 is not a route to EU AI Act compliance on its own. The Act regulates individual systems as products and the standard certifies an organisation's process; ISO/IEC 42001 has not been cited as a harmonised standard, and the Commission has said it is not aligned with the Act's quality management system requirement. The full side-by-side, including who assesses what and the legal effect of each, is on EU AI Act vs ISO 42001, and the Act's dates are in the EU AI Act compliance guide.

The NIST AI Risk Management Framework (AI RMF 1.0, January 2023) is voluntary guidance organised around four functions: Govern, Map, Measure and Manage. It is not certifiable. Teams often use it as the method inside the ISO 42001 risk process, since the standard asks for a risk assessment without prescribing how to do one.

09

ISO 42001 readiness checklist

The order below is the order that saves rework: the inventory and scope decide everything after them.

#TaskWhere it comes fromDone when
1List every AI system in scope: models built, models bought, AI features in SaaS you useClause 4.1, 4.3; A.4Each system has a purpose, owner, provider and data sources recorded
2Decide your role for each system: developer, provider, userClause 4.1Role recorded per system, not per company
3Write and approve the AI policyClause 5.2; A.2Signed off by top management and communicated
4Assign AI roles and a route for reporting concernsClause 5.3; A.3Named owners; a working channel
5Set the AI risk criteria and run the first risk assessmentClause 6.1.2, 8.2Risk register with owners and dates
6Run an impact assessment for each systemClause 6.1.4, 8.4; A.5Documented assessment per system, covering individuals, groups and society
7Select controls and write the Statement of ApplicabilityClause 6.1.3; Annex AEvery Annex A control included or excluded, with reasons
8Operate the life-cycle and data controls: validation, monitoring, event logs, data provenanceA.6, A.7Records produced as work happens, not reconstructed
9Set supplier and customer responsibilities for AIA.10Contracts and supplier reviews reflect them
10Run an internal audit and a management reviewClause 9.2, 9.3Reports exist and findings are in the corrective action log
11Choose an accredited certification bodyISO/IEC 17021-1, 42006Accreditation checked; stage 1 booked
10

What ISO 42001 compliance software does, and what it does not

Most AIMS effort is not writing documents. It is keeping the inventory accurate, reassessing when systems change, and producing records that controls operated when they should have.

  • The inventory. The AI governance engine registers the models, prompts and MCP servers you actually run, because the prompt and the tools a model can reach change its behaviour as much as the weights do
  • Evaluation records. Judge-scored evaluation runs keep the transcript alongside the score, so verification and monitoring evidence for Annex A.6 is a record from the date it ran rather than a number in a dashboard
  • Drift and bias over time. Scores are tracked across runs rather than as a single snapshot, which is what operation and monitoring asks for
  • One control set. Cross-framework mapping reuses the controls you already run for ISO 27001 or SOC 2, and the evidence ledger keeps hash-chained, timestamped evidence for passing and failing controls alike
  • EU AI Act classification per system, held next to the ISO 42001 record, so the two regimes read from the same inventory

What software does not do: decide your AI policy, run your management review, make the judgement in an impact assessment, or certify you. Only an accredited certification body issues an ISO 42001 certificate. TryTrustable does not hold ISO 42001 certification itself, and our own certification status is stated on the security page.

Questions

The things people ask us

What is ISO 42001?

ISO 42001, formally ISO/IEC 42001:2023, is the international standard that sets requirements for an artificial intelligence management system (AIMS): the policies, roles, risk and impact assessments, controls and review cycle an organisation uses to develop, provide or use AI responsibly. Published in December 2023, it is certifiable by accredited third-party auditors.

Is ISO 42001 certification mandatory?

No. ISO 42001 is voluntary everywhere, and no law we are aware of requires certification. It becomes effectively required when a customer, a procurement framework or a contract asks for it, which is increasingly how enterprise buyers screen suppliers of AI features. It is also a sensible way to build the governance the EU AI Act assumes you already have.

How many controls are in ISO 42001 Annex A?

ISO 42001 Annex A lists 38 reference controls grouped into nine areas, numbered A.2 to A.10, from AI policy through to third-party and customer relationships. Annex A is normative but not a checklist: you select the controls your risk treatment needs and justify every inclusion and exclusion in a Statement of Applicability.

What is the difference between an AI risk assessment and an AI system impact assessment?

An AI risk assessment, under clause 6.1.2, looks at risks to the organisation meeting its AI objectives. An AI system impact assessment, under clause 6.1.4, looks outward at the consequences an AI system can have for individuals, groups of individuals and societies. ISO 42001 requires both, and the results of the impact assessment feed the risk assessment.

How does ISO 42001 certification work?

ISO 42001 certification is an audit by an accredited certification body in two stages: stage 1 reviews your documentation and readiness, stage 2 tests whether the management system actually operates. A certificate lasts three years, with surveillance audits at least annually in between and a recertification audit before it expires.

Is ISO 42001 the same as ISO 27001?

No. ISO 27001 manages information security risk; ISO 42001 manages the risks and impacts of AI systems. They share the harmonized clause structure, so policies, internal audit, management review and corrective action can run as one integrated management system, but each has its own Annex A controls and its own certificate.

Does ISO 42001 certification satisfy the EU AI Act?

No. ISO 42001 certifies an organisation's management system; the EU AI Act regulates individual AI systems as products, with risk classification, technical documentation and conformity assessment per system. ISO/IEC 42001 has not been cited as a harmonised standard under the Act, so a certificate gives no presumption of conformity. It does build much of the governance the Act expects.

Can software make us ISO 42001 compliant?

Software can hold the inventory, run and record evaluations, map controls and keep the evidence an auditor samples. It cannot write your AI policy for your leadership, run your management review, or certify you: only an accredited certification body can issue an ISO 42001 certificate. Treat any tool promising compliance out of the box with suspicion.

Book a walkthrough

See an AI system evidenced end to end.

We register a real model, classify it, run a judged evaluation and show the evidence mapped to ISO 42001 and the EU AI Act from the same control set. Thirty minutes.