Free tool · ISO 42001

Do I need ISO 42001?

No law requires ISO 42001. It is a certifiable management system for AI, and buyers increasingly ask for it. Answer five questions about your AI, your buyers and your existing certifications, and see whether to certify now, use it as a guide, or wait.

Short answer

No law requires ISO/IEC 42001. It is a voluntary, certifiable standard for an AI management system. It is worth doing when AI is central to what you sell and enterprise or regulated buyers ask how you govern it, especially if you already hold ISO 27001. It does not give conformity with the EU AI Act: the Commission says it will not be a harmonised standard under the Act.

Answer for your organisation

ISO 42001 uses the same management-system structure, so an existing ISO 27001 programme covers much of the groundwork.
For example AI for hiring, credit scoring, education or a safety component of a regulated product. Check with the AI Act checker.
Worked example: an AI-first B2B company with ISO 27001, selling to enterprises

Result

An indication from your answers, not legal advice. Applicability turns on facts a form cannot see; confirm it with counsel or your auditor before you rely on it.
It depends: worth doing, alongside ISO 27001

Enterprise buyers are asking how you govern AI, and you already run a management system. ISO 42001 shares the ISO 27001 structure (context, leadership, risk, internal audit, management review), so much of the system carries over and an integrated audit is possible. A certificate turns a long AI questionnaire into one document.

AI management system clauses on the same structure as ISO 27001ISO/IEC 42001 clauses 4–10
AI system impact assessmentISO/IEC 42001 clause 6.1.4
Reference controlsISO/IEC 42001 Annex A
  • Scope: decide which AI systems and which part of the organisation the management system covers. Start with the products customers ask about.
  • Build: an AI policy, an AI system inventory, AI risk and impact assessments, and the Annex A controls that apply. See the ISO 42001 guide.
  • Certify: with an accredited certification body: a stage 1 documentation review, a stage 2 audit, then yearly surveillance audits.
01

What ISO 42001 is

ISO/IEC 42001:2023 specifies requirements for an AI management system: the policies, roles, risk and impact assessments, controls, monitoring and improvement an organisation uses to develop, provide or use AI responsibly. It follows the same clause structure as ISO 27001, with AI-specific controls in Annex A. It is voluntary and certifiable: an accredited certification body audits it, and ISO/IEC 42006 sets the rules those bodies follow.

02

Why buyers ask for it

Enterprise and regulated buyers now send AI questionnaires alongside security ones: which models you use, what data trains them, how you test and monitor them, who signs off. A certificate from an independent auditor answers the governance part in one document, in the same way SOC 2 or ISO 27001 does for security. That is the whole case for it: no regulator requires it.

03

ISO 42001 and the EU AI Act

The two are often confused. The European Commission says ISO/IEC 42001 will not be a harmonised standard under the AI Act, because its goals and definitions do not match the quality management system the Act requires, and it has asked CEN-CENELEC to write a new one. So an ISO 42001 certificate does not give presumption of conformity with any AI Act requirement. It is still a sound way to run the governance work the Act expects. See EU AI Act vs ISO 42001.

04

Sources

Questions

The things people ask us

Is ISO 42001 mandatory?

No. ISO/IEC 42001 is a voluntary standard. It becomes a requirement only when a customer's procurement policy or contract asks for it.

Does ISO 42001 certification mean EU AI Act compliance?

No. The European Commission says ISO 42001 will not be a harmonised standard under the AI Act, so a certificate does not give presumption of conformity. It helps you organise the work, but the Act's own requirements still apply.

Who needs ISO 42001?

Companies whose product is or relies on AI and whose enterprise or regulated buyers ask how that AI is governed. Companies that only use AI tools internally rarely need it.

Can I get ISO 42001 if I already have ISO 27001?

Yes, and it is easier. Both follow the same management-system structure, so the leadership, risk, audit and review processes carry over and many certification bodies offer an integrated audit.

How is ISO 42001 certified?

By an accredited certification body, in a stage 1 documentation review and a stage 2 audit, followed by yearly surveillance audits within a three-year certificate. ISO/IEC 42006 sets the requirements for those bodies.

Is ISO 42001 or NIST AI RMF better?

They do different jobs. The NIST AI RMF is a free, voluntary framework with no certificate; ISO 42001 is certifiable, which is what buyers who want evidence ask for. Many companies use the NIST AI RMF to guide the work and ISO 42001 to prove it.

Book a walkthrough

See what applies to you, and track it.

TryTrustable maps your controls to every framework you need and keeps the evidence current.