Do I need ISO 42001?
No law requires ISO 42001. It is a certifiable management system for AI, and buyers increasingly ask for it. Answer five questions about your AI, your buyers and your existing certifications, and see whether to certify now, use it as a guide, or wait.
No law requires ISO/IEC 42001. It is a voluntary, certifiable standard for an AI management system. It is worth doing when AI is central to what you sell and enterprise or regulated buyers ask how you govern it, especially if you already hold ISO 27001. It does not give conformity with the EU AI Act: the Commission says it will not be a harmonised standard under the Act.
Result
Enterprise buyers are asking how you govern AI, and you already run a management system. ISO 42001 shares the ISO 27001 structure (context, leadership, risk, internal audit, management review), so much of the system carries over and an integrated audit is possible. A certificate turns a long AI questionnaire into one document.
- Scope: decide which AI systems and which part of the organisation the management system covers. Start with the products customers ask about.
- Build: an AI policy, an AI system inventory, AI risk and impact assessments, and the Annex A controls that apply. See the ISO 42001 guide.
- Certify: with an accredited certification body: a stage 1 documentation review, a stage 2 audit, then yearly surveillance audits.
What ISO 42001 is
ISO/IEC 42001:2023 specifies requirements for an AI management system: the policies, roles, risk and impact assessments, controls, monitoring and improvement an organisation uses to develop, provide or use AI responsibly. It follows the same clause structure as ISO 27001, with AI-specific controls in Annex A. It is voluntary and certifiable: an accredited certification body audits it, and ISO/IEC 42006 sets the rules those bodies follow.
Why buyers ask for it
Enterprise and regulated buyers now send AI questionnaires alongside security ones: which models you use, what data trains them, how you test and monitor them, who signs off. A certificate from an independent auditor answers the governance part in one document, in the same way SOC 2 or ISO 27001 does for security. That is the whole case for it: no regulator requires it.
ISO 42001 and the EU AI Act
The two are often confused. The European Commission says ISO/IEC 42001 will not be a harmonised standard under the AI Act, because its goals and definitions do not match the quality management system the Act requires, and it has asked CEN-CENELEC to write a new one. So an ISO 42001 certificate does not give presumption of conformity with any AI Act requirement. It is still a sound way to run the governance work the Act expects. See EU AI Act vs ISO 42001.
Sources
- ISO: ISO/IEC 42001:2023 Artificial intelligence: Management system
- ISO: ISO/IEC 42006 Requirements for bodies auditing and certifying AI management systems
- European Commission: Understanding standardisation of the AI Act
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
Is ISO 42001 mandatory?
No. ISO/IEC 42001 is a voluntary standard. It becomes a requirement only when a customer's procurement policy or contract asks for it.
Does ISO 42001 certification mean EU AI Act compliance?
No. The European Commission says ISO 42001 will not be a harmonised standard under the AI Act, so a certificate does not give presumption of conformity. It helps you organise the work, but the Act's own requirements still apply.
Who needs ISO 42001?
Companies whose product is or relies on AI and whose enterprise or regulated buyers ask how that AI is governed. Companies that only use AI tools internally rarely need it.
Can I get ISO 42001 if I already have ISO 27001?
Yes, and it is easier. Both follow the same management-system structure, so the leadership, risk, audit and review processes carry over and many certification bodies offer an integrated audit.
How is ISO 42001 certified?
By an accredited certification body, in a stage 1 documentation review and a stage 2 audit, followed by yearly surveillance audits within a three-year certificate. ISO/IEC 42006 sets the requirements for those bodies.
Is ISO 42001 or NIST AI RMF better?
They do different jobs. The NIST AI RMF is a free, voluntary framework with no certificate; ISO 42001 is certifiable, which is what buyers who want evidence ask for. Many companies use the NIST AI RMF to guide the work and ISO 42001 to prove it.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.