Key Facts: ISO/IEC 42001:2023 at a Glance #
- Published: December 18, 2023 — the world’s first international standard for AI Management Systems [cite: 1]
- Developed by: ISO/IEC JTC 1/SC 42 (Artificial Intelligence subcommittee) [cite: 1]
- Scope: Any organization that develops, provides, or uses AI-based products or services — all sizes, all industries [cite: 1]
- Structure: Follows the ISO Annex SL High-Level Structure (same backbone as ISO 27001 and ISO 9001), with four informative annexes covering AI-specific controls and guidance [cite: 1, 2]
- Regulatory alignment: Closely aligns with the EU AI Act (legally binding August 1, 2024), GDPR data governance requirements, and emerging national AI legislation [cite: 3]
- Adoption signal: 76% of organizations plan to pursue AI compliance with a framework like ISO 42001 — A-LIGN 2025 Compliance Benchmark Report [cite: 4]
- Early adopters: AWS, Anthropic, KPMG Australia, Cognizant, Synthesia, Changi Airport, Thomson Reuters, and others achieved certification in 2024–2025 [cite: 5]
- Certification cycle: Stage 1 + Stage 2 audit, annual surveillance, full recertification every 3 years [cite: 2]
What Is ISO/IEC 42001:2023? #
ISO/IEC 42001:2023 is the world’s first international standard dedicated to AI Management Systems (AIMS). Published on December 18, 2023, it gives organizations a structured framework for governing the way they develop, deploy, and use artificial intelligence — responsibly, systematically, and in a way that can be independently audited[cite: 1].
If you are familiar with ISO 27001 for information security or ISO 9001 for quality management, ISO 42001 will feel structurally familiar. It uses the same Annex SL High-Level Structure — the common backbone that ISO applies across its management system standards. That shared architecture is deliberate: it means organizations that already hold ISO 27001 or ISO 9001 certification can integrate ISO 42001 into their existing management system rather than building something from scratch[cite: 2].
But the substance is different. Where ISO 27001 focuses on protecting information assets, ISO 42001 focuses on the unique risks that AI introduces — bias in decision-making, lack of transparency, ethical concerns, data quality issues, and the challenge of governing systems that learn and change over time.
What Does the Standard Actually Require? #
ISO 42001 follows the Plan-Do-Check-Act (PDCA) cycle across seven requirement clauses (Clauses 4 through 10), supported by four informative annexes[cite: 1, 2]:
| Clause | Title | What It Requires |
|---|---|---|
| 4 | Context of the Organization | Define the scope of your AIMS. Identify internal and external issues, interested parties, and their requirements related to AI. |
| 5 | Leadership | Top management commitment. Establish an AI policy. Assign roles, responsibilities, and authorities. |
| 6 | Planning | Conduct an AI risk assessment (6.1.2) and an AI system impact assessment (6.1.4). Set measurable AI objectives. Produce a Statement of Applicability mapping selected controls. |
| 7 | Support | Ensure competence, awareness, and training. Establish communication processes. Maintain documented information. |
| 8 | Operation | Implement the AI risk treatment plan. Execute operational controls for AI systems across their lifecycle. |
| 9 | Performance Evaluation | Monitor and measure AIMS performance. Conduct internal audits. Hold management reviews. |
| 10 | Improvement | Address nonconformities and corrective actions. Drive continual improvement of the AIMS. |
What Do the Annexes Cover? #
The four annexes are all informative — meaning they provide guidance rather than mandatory requirements. However, they are central to how the standard operates in practice[cite: 2]:
- Annex A — Reference control objectives and controls, organized across nine domains: AI policies (A.2), internal organization (A.3), resources for AI systems (A.4), assessing impacts of AI systems (A.5), AI system lifecycle (A.6), data for AI systems (A.7), information for interested parties (A.8), use of AI systems (A.9), and third-party and customer relationships (A.10).
- Annex B — Implementation guidance for each Annex A control.
- Annex C — Potential AI-related organizational objectives and risk sources — essentially an idea bank for conducting risk assessments.
- Annex D — Use of the AIMS across domains and sectors, helping organizations tailor the standard to their specific context.
The nine Annex A domains span the full lifecycle — from the policies that govern AI use to the relationships with third parties who supply or consume AI services. Together, they form a comprehensive control framework that goes well beyond what a generic risk management standard would cover.
Who Should Get ISO 42001 Certified? #
The short answer: any organization that develops, provides, or uses AI-based products or services, regardless of size or industry[cite: 1].
The more useful answer involves understanding where the standard creates the most value.
Which Organizations Benefit Most? #
| Organization Type | Why ISO 42001 Matters |
|---|---|
| AI product and platform companies | Demonstrates responsible development practices to customers, investors, and regulators. Differentiates in a market where trust is a competitive asset. |
| Enterprises deploying AI internally | Provides governance structure for AI tools used in HR, finance, customer service, operations, and decision support — where ungoverned AI creates liability. |
| Consulting and professional services firms | Validates AI advisory capabilities. Several global firms (KPMG, Cognizant) have already certified[cite: 5]. |
| Healthcare organizations | AI is increasingly used in diagnostics, patient triage, and clinical decision support. ISO 42001 provides a governance layer that complements health privacy legislation. |
| Financial services | AI in credit scoring, fraud detection, and algorithmic trading carries significant regulatory and ethical risk. Certification signals mature risk management. |
| Public sector and government agencies | AI used in citizen-facing services (benefits adjudication, law enforcement, immigration) requires demonstrable fairness and transparency. |
| Cloud and infrastructure providers | AWS achieved certification in November 2024 — signalling to its customer base that the AI services running on its infrastructure are governed by an auditable standard[cite: 5]. |
What Is Driving Adoption? #
Three forces are converging to make ISO 42001 certification increasingly relevant:
- Regulation. The EU AI Act became legally binding on August 1, 2024, with phased enforcement through 2027. It imposes specific requirements for high-risk AI systems — risk management, transparency, documentation, human oversight — that map closely to ISO 42001’s control framework. While ISO 42001 is not yet an officially harmonized standard under the EU AI Act, it provides a strong compliance foundation[cite: 3]. Canada’s proposed Artificial Intelligence and Data Act (AIDA) and emerging US state-level AI legislation add to the regulatory momentum.
- Customer and supply chain demand. Organizations are beginning to require AI governance assurances from their vendors and partners, just as ISO 27001 became a procurement requirement for information security. The 76% of organizations planning to pursue AI compliance frameworks — reported in the A-LIGN 2025 Compliance Benchmark Report — signals where the market is heading[cite: 4].
- Risk and liability. AI failures — biased hiring algorithms, hallucinating chatbots, opaque credit decisions — generate lawsuits, regulatory enforcement, and reputational damage. A certified AIMS does not eliminate these risks, but it provides a documented, auditable process for identifying, assessing, and mitigating them.
What Are the Benefits of ISO 42001 Certification? #
Why Invest in Certification Rather Than Just “Doing AI Governance”? #
Many organizations practice some form of AI governance without seeking certification. The standard is valuable regardless, but formal certification adds distinct advantages:
Competitive differentiation. In the current market, certified organizations are early movers. As AI governance expectations mature — driven by regulation and customer demand — certification shifts from differentiator to baseline. Organizations that certify now build institutional capability before it becomes mandatory.
Regulatory preparedness. The EU AI Act, GDPR’s data governance requirements, and emerging national AI legislation all demand documented governance processes. ISO 42001 provides a structured, internationally recognized framework that maps to these requirements. Pursuing certification now avoids the reactive scramble that organizations experienced when GDPR enforcement began in 2018.
Systematic risk management. The standard requires formal AI risk assessments (Clause 6.1.2) and AI system impact assessments (Clause 6.1.4) — forcing organizations to surface risks that informal governance often misses. These include bias in training data, lack of explainability in high-stakes decisions, data quality degradation over time, and third-party AI supply chain risks.
Independent validation. Internal claims of “responsible AI” are easy to make and hard to verify. A certification audit by an accredited third party — BSI, SGS, Schellman, DNV, or others — provides independent evidence that the organization’s AI governance is real, not aspirational[cite: 5].
Integration efficiency. Because ISO 42001 shares the Annex SL backbone with ISO 27001 and ISO 9001, organizations with existing certifications can integrate AIMS into their management system without duplicating governance infrastructure. Policies, internal audit programs, management reviews, and documented information can be extended rather than rebuilt.
Stakeholder confidence. Investors, board members, customers, and regulators increasingly ask: “How do you govern your AI?” A certified AIMS provides a clear, auditable answer. Several organizations that achieved early certification — including Anthropic (January 2025) and AWS (November 2024) — have publicly highlighted it as a trust signal[cite: 5].
What Is the Process to Design and Implement an AIMS Based on ISO 42001? #
Implementation follows the PDCA cycle — the same methodology used across all ISO management system standards. The steps below translate the standard’s requirements into a practical implementation roadmap.
Phase 1: Plan — Establish the Foundation #
Step 1 Secure leadership commitment.
ISO 42001 Clause 5 requires top management to demonstrate commitment to the AIMS. In practice, this means obtaining executive sponsorship, allocating budget and resources, and designating a compliance owner — typically a Chief AI Officer, Chief Privacy Officer, or Head of AI Governance. Without genuine leadership commitment, the AIMS will lack the authority to change how AI is developed and used across the organization.
Step 2 Define the AIMS scope.
Under Clause 4, the organization must define what the AIMS covers. This includes identifying which AI systems, processes, and organizational units are in scope; understanding the internal and external context (regulatory environment, stakeholder expectations, strategic objectives); and documenting the needs and expectations of interested parties — regulators, customers, employees, affected individuals, and AI supply chain partners.
Step 3 Conduct a gap analysis.
Assess the organization’s current AI governance practices against ISO 42001 requirements. The gap analysis should cover all seven requirement clauses (4–10) and the Annex A control domains. Organizations with existing ISO 27001 or ISO 9001 certifications will find that many elements — documented information, internal audit programs, management review processes — already exist and can be extended.
Step 4 Perform the AI risk assessment and AI system impact assessment.
This is where ISO 42001 diverges most significantly from generic management standards. Clause 6.1.2 requires a formal AI risk assessment that identifies risks specific to AI — bias, lack of transparency, data quality issues, security vulnerabilities, ethical concerns, and regulatory non-compliance. Clause 6.1.4 requires an AI system impact assessment that evaluates the potential effects of AI systems on individuals, groups, and society.
Use Annex C as a starting point — it provides a catalogue of potential AI-related objectives and risk sources that can be tailored to the organization’s context.
Step 5 Develop the AI policy, objectives, and Statement of Applicability.
The AI policy (Clause 5.2) establishes the organization’s commitment to responsible AI and sets the direction for the AIMS. AI objectives (Clause 6.2) must be measurable and consistent with the policy. The Statement of Applicability maps the Annex A controls to the organization’s context, documenting which controls are applied, which are excluded, and the justification for each decision.
Phase 2: Do — Implement Controls and Processes #
Step 6 Implement Annex A controls.
Working through the nine Annex A domains, implement the controls selected in the Statement of Applicability. Annex B provides implementation guidance for each control. Key areas include:
| Domain | What to Implement |
|---|---|
| A.2 – AI policies | Documented policies for responsible AI development, deployment, and use. |
| A.3 – Internal organization | Defined roles, responsibilities, and accountability for AI governance. |
| A.4 – Resources | Competence requirements, training, and infrastructure for AI systems. |
| A.5 – Impact assessment | Processes for assessing AI system impacts on individuals and society. |
| A.6 – Lifecycle | Controls across the AI system lifecycle — design, development, testing, deployment, monitoring, and decommissioning. |
| A.7 – Data | Data quality, provenance, bias assessment, and data governance for AI training and operation. |
| A.8 – Information for interested parties | Transparency and communication about AI system capabilities, limitations, and decisions. |
| A.9 – Use of AI systems | Appropriate use policies, human oversight, and monitoring of AI system behaviour in operation. |
| A.10 – Third-party relationships | Governance of AI components, services, and data sourced from or provided to third parties. |
Step 7 Establish documentation and records.
Clause 7.5 requires documented information that supports the AIMS. This includes the AI policy, risk assessment results, impact assessments, the Statement of Applicability, operational procedures, training records, and evidence of control implementation. Organizations experienced with ISO 27001 will recognize most of these documentation requirements.
Step 8 Train and build awareness.
Clause 7.2 and 7.3 require that personnel are competent and aware of the AI policy, their role in the AIMS, and the implications of non-conformity. Training should cover AI ethics, responsible use, data handling, and the specific controls relevant to each role.
Phase 3: Check — Monitor and Evaluate #
Step 9 Monitor, measure, and evaluate.
Clause 9.1 requires the organization to determine what needs to be monitored and measured, and how. This includes monitoring AI system performance, tracking risk indicators, and evaluating whether AI objectives are being met.
Step 10 Conduct internal audits.
Clause 9.2 requires a planned internal audit program. Audits should verify that the AIMS conforms to ISO 42001 requirements, that controls are implemented and effective, and that the system is maintained and continually improved. Internal auditors must be objective and independent of the processes they audit.
Step 11 Hold management reviews.
Clause 9.3 requires top management to review the AIMS at planned intervals. The review should consider audit results, risk assessment updates, AI system performance, stakeholder feedback, and opportunities for improvement.
Phase 4: Act — Improve and Certify #
Step 12 Address nonconformities and drive improvement.
Clause 10 requires the organization to react to nonconformities, take corrective action to address root causes, and continually improve the suitability, adequacy, and effectiveness of the AIMS.
Step 13 Undergo the certification audit.
The formal certification process consists of two stages[cite: 2]:
| Stage | What Happens | Purpose |
|---|---|---|
| Stage 1 | Documentation review. The certification body reviews your AIMS documentation, scope, AI policy, risk assessments, Statement of Applicability, and overall readiness. | Confirm the organization is ready for the full audit. Identify gaps before Stage 2. |
| Stage 2 | Implementation assessment. Auditors evaluate evidence that controls are actually implemented and operating effectively — not just documented. Includes interviews, record reviews, and observation. | Determine whether the AIMS conforms to ISO 42001 and is effective. |
| Surveillance | Annual audits covering a subset of the AIMS. | Maintain certification and verify ongoing conformity. |
| Recertification | Full audit every 3 years. | Renew the certification. |
How Long Does Implementation Take? #
Typical timelines range from 3 to 6 months for implementation, depending on organizational size, the complexity of AI systems in scope, and the maturity of existing management systems. Organizations with ISO 27001 certification in place can often move faster because the governance infrastructure — internal audit, management review, documented information — already exists[cite: 2, 4].
Who Are the Early Adopters? #
The following organizations achieved ISO 42001 certification in 2024–2025, signalling the standard’s trajectory[cite: 5]:
| Organization | Certification Date | Certification Body |
|---|---|---|
| AWS | November 2024 | Schellman |
| Anthropic | January 2025 | Schellman |
| KPMG Australia | October 2024 | BSI |
| Cognizant | December 2024 | DNV |
| Synthesia | September 2024 | A-LIGN |
| Changi Airport (Singapore) | February 2025 | SGS |
| i-PRO (Japan) | May 2025 | BSI |
Frequently Asked Questions About ISO/IEC 42001:2023 #
What is ISO/IEC 42001:2023? #
ISO/IEC 42001:2023 is the world’s first international standard for Artificial Intelligence Management Systems (AIMS). Published on December 18, 2023 by ISO/IEC JTC 1/SC 42, it specifies requirements for establishing, implementing, maintaining, and continually improving a management system for organizations that develop, provide, or use AI-based products and services. The standard addresses AI-specific challenges including ethical considerations, transparency, bias, and explainability, and follows the same Plan-Do-Check-Act methodology and high-level structure used by ISO 27001 and ISO 9001.
Who should get ISO 42001 certified? #
ISO 42001 is designed for any organization — regardless of size, type, or industry — that develops, provides, or uses AI-based products or services. This includes technology companies building AI models, enterprises deploying AI tools in their operations, consulting firms advising on AI strategy, healthcare and financial services organizations using AI for decision support, and public sector agencies implementing AI in citizen-facing services. Both AI developers and AI deployers benefit from certification, as the standard covers the full AI lifecycle.
How does ISO 42001 relate to the EU AI Act? #
ISO 42001 aligns closely with the requirements of the EU AI Act, which became legally binding on August 1, 2024. While ISO 42001 is not yet an officially harmonized standard under the EU AI Act, it provides a structured framework that addresses many of the Act’s requirements for risk management, transparency, documentation, and human oversight of AI systems. Organizations pursuing ISO 42001 certification build a compliance foundation that positions them well for EU AI Act obligations, particularly for high-risk AI system governance. According to the A-LIGN 2025 Compliance Benchmark Report, 76% of organizations plan to pursue AI compliance with a framework like ISO 42001.
What are the main benefits of ISO 42001 certification? #
ISO 42001 certification delivers several benefits: competitive differentiation as a leader in responsible AI governance; structured alignment with emerging regulations including the EU AI Act, GDPR, and national AI legislation; systematic identification and mitigation of AI-specific risks across the entire lifecycle; independent validation of responsible AI practices that enhances stakeholder, customer, and investor confidence; operational efficiency through embedded lifecycle monitoring; and integration with existing management systems such as ISO 27001 and ISO 9001, reducing duplication of effort.
What is the process to implement an AI Management System under ISO 42001? #
Implementation follows the Plan-Do-Check-Act (PDCA) cycle. Key steps include: securing top management commitment and designating a compliance owner; defining the AIMS scope and conducting a gap analysis against ISO 42001 requirements; performing AI risk assessments and AI system impact assessments; developing the AI policy, objectives, and Statement of Applicability; implementing controls from Annex A covering nine areas from AI policies to third-party relationships; establishing monitoring, measurement, and internal audit processes; and undergoing the formal two-stage certification audit. Typical implementation timelines range from 3 to 6 months depending on organizational maturity.
How long does ISO 42001 certification take and how much does it cost? #
Implementation typically takes 3 to 6 months depending on organizational size, complexity, and existing management system maturity. Organizations with an existing ISO 27001 or ISO 9001 certification can leverage the shared high-level structure to accelerate implementation. The certification audit itself consists of two stages: Stage 1 (documentation review) and Stage 2 (implementation assessment). After certification, annual surveillance audits maintain the certificate, with full recertification every 3 years. Certification costs vary by organization size and certification body but are not standardized — organizations should obtain quotes from accredited certification bodies such as BSI, SGS, Schellman, or DNV.
Sources and References #
- ISO, ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system. Published December 18, 2023. Available at: iso.org
- Modulos AG, ISO 42001 Annex A, B, C, D Breakdown and Implementation Guidance. See also: ControlCase, ISO 42001 Certification Guide.
- European Parliament and Council, Regulation (EU) 2024/1689 — Artificial Intelligence Act. Entered into force August 1, 2024. See also: A-LIGN, ISO 42001 and EU AI Act Alignment Analysis, 2025.
- A-LIGN, 2025 Compliance Benchmark Report. See also: Vanta, ISO 42001 Certification Process and Timeline Guide.
- Certiget, ISO 42001 Certification Market Report, June 2025. Certification data for AWS, Anthropic, KPMG Australia, Cognizant, Synthesia, Changi Airport, i-PRO, and others. See also: Schellman, BSI, SGS, and DNV certification announcements.
- IBM / Ponemon Institute, Cost of a Data Breach Report 2024 — AI and automation impact on breach costs and lifecycle.
This article is for informational purposes only and does not constitute legal, regulatory, or certification advice. Organizations should consult qualified professionals for guidance specific to their circumstances. For the official text of ISO/IEC 42001:2023, refer to iso.org.