What is ISO 42001 Certification?
What Is ISO 42001?
ISO/IEC 42001 is the international standard for an artificial intelligence management system (AIMS). Published on 18 December 2023 under the full title Information technology — Artificial intelligence — Management system, it specifies how an organization establishes, operates, monitors, and improves governance over the AI systems it develops or uses. It is certifiable by an accredited third party and is the only certifiable AI governance standard.
Key Takeaways
- ISO 42001 governs the organization's management of AI, not the safety of any individual model.
- The structure is Clauses 4–10 plus Annex A: 38 controls across nine objectives, selected through a Statement of Applicability.
- ISO 42001 certification does not confer a presumption of conformity with the EU AI Act.
- ISO/IEC 42006:2025 sets the accreditation rules for certification bodies, which is what separates an accredited certificate from a self-declared claim.
- CyberStrong maps ISO 42001 controls against the frameworks you already run, so evidence assessed once satisfies every standard it maps to.
What Does ISO 42001 Require?
ISO 42001 follows the Harmonized Structure used across ISO management system standards, so Clauses 4 through 10 are the certifiable requirements. An auditor tests these directly.
|
Clause |
Requirement |
What it means in practice |
|---|---|---|
|
4 — Context of the organization |
Define the AIMS scope and the internal, external, and stakeholder factors that shape it |
Name which AI systems and business units are in scope, and defend the boundary |
|
5 — Leadership |
Establish AI policy, assign roles, secure top-management commitment |
A named accountable owner, not a distributed responsibility |
|
6 — Planning |
AI risk assessment, AI system impact assessment, objectives, Statement of Applicability |
The impact assessment is the requirement most organizations underestimate |
|
7 — Support |
Resources, competence, awareness, communication, documented information |
Evidence that the people running AI systems are qualified to |
|
8 — Operation |
Operational planning and control, risk treatment, impact assessment execution |
Where policy becomes a running process |
|
9 — Performance evaluation |
Monitoring, measurement, internal audit, management review |
The clause that requires you to prove the system works, not that it exists |
|
10 — Improvement |
Nonconformity, corrective action, continual improvement |
Closing the loop on findings |
Clause 6's AI system impact assessment is what distinguishes ISO 42001 from a general management system standard. It requires you to assess consequences for individuals and groups, not only risk to the organization, which is the same directional shift the EU AI Act makes.
What Are the ISO 42001 Annex A Controls?
Annex A contains 38 reference controls grouped under nine objectives. They are not all mandatory. You select applicable controls and justify exclusions in a Statement of Applicability, the same mechanism ISO 27001 uses.
|
Objective |
Title |
Controls |
|---|---|---|
|
A.2 |
Policies related to AI |
3 |
|
A.3 |
Internal organization |
2 |
|
A.4 |
Resources for AI systems |
5 |
|
A.5 |
Assessing impacts of AI systems |
4 |
|
A.6 |
AI system life cycle |
9 |
|
A.7 |
Data for AI systems |
5 |
|
A.8 |
Information for interested parties of AI systems |
4 |
|
A.9 |
Use of AI systems |
3 |
|
A.10 |
Third-party and customer relationships |
3 |
|
Total |
38 |
A.6 (AI system life cycle) carries the most controls and the most audit weight — it covers objectives, design, verification, deployment, operation, and decommissioning. A.10 is the one most organizations discover late, because it governs AI you buy rather than build, and most enterprises consume far more third-party AI than they produce.
The standard also includes Annex B (implementation guidance for each control), Annex C (potential AI-related organizational objectives and risk sources), and Annex D (using the AIMS across domains and sectors).
Who Needs ISO 42001?
ISO 42001 applies to any organization that develops, provides, or uses AI systems, regardless of size or sector. In practice, three groups pursue it:
AI vendors and SaaS providers whose enterprise buyers now ask for AI governance evidence in security questionnaires. Certification answers the question once, not per deal.
Regulated enterprises deploying AI in decisions affecting people, credit, hiring, healthcare, insurance, where an auditable governance record is the difference between a defensible decision and an indefensible one.
Organizations already certified to ISO 27001 that need to extend a working management system to AI without standing up a parallel program.
How Is ISO 42001 Different From ISO 27001?
They are structurally similar and substantively different. ISO 27001 protects information. ISO 42001 governs AI behavior and its consequences.
|
ISO 27001 |
ISO 42001 |
|
|---|---|---|
|
Manages |
Information security (ISMS) |
Artificial intelligence (AIMS) |
|
Protects |
Confidentiality, integrity, availability |
Individuals and society, alongside the organization |
|
Annex A controls |
93, in four themes |
38, in nine objectives |
|
Distinctive requirement |
Risk assessment and treatment |
AI system impact assessment |
|
Scope unit |
Information assets and systems |
AI systems and their life cycle |
|
Certifiable |
Yes |
Yes |
The overlap is real and useful: shared clause structure, a shared Statement of Applicability mechanism, and a shared internal audit and management review cadence. Organizations running a mature ISMS typically find Clauses 4, 5, 7, 9, and 10 largely satisfied by existing processes. The new work concentrates on Clause 6 and Annex A.
The two are not substitutes. An ISO 27001 framework certificate says nothing about whether a model was trained on appropriate data or whether its outputs are monitored for drift.
Does ISO 42001 Satisfy the EU AI Act?
No, and this is the most common misunderstanding about the standard.
For an AI standard to grant a presumption of conformity with the EU AI Act, the European Commission must request and review it, designate it as a harmonized standard, and officially publish it in the Official Journal of the European Union. ISO 42001 meets none of those conditions.
ISO 42001 provides the governance scaffolding those obligations assume: documented roles, impact assessments, life cycle controls, and third-party oversight. Organizations certified to ISO 42001 are meaningfully further along on AI Act readiness. They are not compliant by virtue of the certificate, and a vendor claiming otherwise is overselling.
How Does ISO 42001 Compare to the NIST AI RMF?
|
ISO/IEC 42001 |
NIST AI RMF |
|
|---|---|---|
|
Type |
Certifiable management system standard |
Voluntary guidance framework |
|
Structure |
Clauses 4–10 plus 38 Annex A controls |
Four functions: Govern, Map, Measure, Manage |
|
Output |
Third-party certificate |
Self-assessment and internal documentation |
|
Answers |
"Do we run AI governance as a system?" |
"Have we identified and managed this AI risk?" |
|
Cost |
Audit fees, surveillance audits, recertification |
No certification cost |
They pair naturally. NIST AI RMF gives you the risk-identification vocabulary; ISO 42001 gives you the management system and the certificate that proves it runs. Many enterprises use NIST AI RMF to structure the risk work and ISO 42001 to make it auditable.
How Do You Get ISO 42001 Certified?
Certification follows the standard ISO management system path:
- Scope the AIMS. Define which AI systems, business units, and geographies are in. An overbroad scope is the most common cause of a stalled first attempt.
- Run a gap assessment against Clauses 4–10 and the 38 Annex A controls.
- Build the Statement of Applicability, justifying every included and excluded control.
- Complete AI risk and impact assessments for in-scope systems.
- Operate the system long enough to generate records — typically three months minimum, since Clause 9 requires evidence of monitoring and internal audit.
- Internal audit and management review.
- Stage 1 audit (documentation readiness), then Stage 2 audit (implementation effectiveness).
- Surveillance audits annually, recertification on a three-year cycle.
One detail that determines whether the certificate is worth anything: ISO/IEC 42006:2025 sets the requirements certification bodies must meet to audit against ISO 42001. It builds on ISO/IEC 17021-1 and requires team-level AI competence across the audit group. Certificates from bodies accredited under recognized authorities carry weight. Verify accreditation before you sign, and ask any vendor presenting a certificate to name their accreditation body.
How Long Does ISO 42001 Certification Take?
Most organizations reach certification in six to twelve months. Clause 9 sets the floor: you need a functioning system producing monitoring records and a completed internal audit before Stage 2, which no amount of preparation compresses below roughly three months of operation.
Organizations with a mature ISO 27001 program move fastest, because the management system clauses transfer. Organizations starting without one spend most of their time on Clause 6 and on building an accurate inventory of AI systems, which is almost always larger than the initial estimate.
Making ISO 42001 a Byproduct, Not a Project
ISO 42001 asks for what a well-run AI governance program already produces: a current inventory, assessed risks, documented impacts, monitored controls, and evidence that someone owns each one. Organizations that struggle treat it as a separate documentation exercise rather than an output of how they already manage risk.
CyberSaint built CyberStrong to close that gap — assessing a control once and applying the evidence across every framework it maps to, so ISO 42001 readiness accumulates alongside NIST CSF, ISO 27001, and your other obligations instead of competing with them. Control posture connects to risk, and risk connects to financial exposure, which is what turns an audit result into a decision your board can act on.
Want to see where your program stands against ISO 42001 today? Request a demo.
Learn more:
- AI-Powered Framework Crosswalking
- NIST CSF 2.0
- Cyber AI Governance Frameworks
- ISO 27001 to NIST CSF Mapping
FAQs About ISO 42001
What is ISO 42001?
ISO/IEC 42001 is the international standard for an artificial intelligence management system. It defines how an organization governs the AI it develops or uses. It is the only certifiable AI governance standard.
How many controls does ISO 42001 have?
38 controls, organized under nine objectives. They are reference controls, not mandatory requirements; organizations select applicable controls and justify exclusions in a Statement of Applicability.
Is ISO 42001 mandatory?
No. ISO 42001 is voluntary. It becomes effectively mandatory through commercial pressure rather than law, when enterprise buyers, procurement teams, and vendor risk assessments start requiring it as evidence of AI governance.
Does ISO 42001 certification make us compliant with the EU AI Act?
No. Presumption of conformity requires a harmonized standard cited in the EU Official Journal, and ISO 42001 was not developed under the Commission's standardization request. Certification demonstrates governance maturity and substantially reduces AI Act readiness work, but it is not a legal shield.
What is the difference between ISO 42001 and ISO 27001?
ISO 27001 manages information security; ISO 42001 manages AI systems and their impact on people. They share the same clause structure and Statement of Applicability mechanism, so a mature ISO 27001 program transfers most of Clauses 4, 5, 7, 9, and 10. ISO 27001 has 93 Annex A controls; ISO 42001 has 38, plus an AI system impact assessment requirement that has no ISO 27001 equivalent.
How long does ISO 42001 certification take?
Six to 12 months for most organizations. Clause 9 sets the floor: you need roughly three months of operating records and a completed internal audit before the Stage 2 audit. Organizations already certified to ISO 27001 move faster because the management system clauses carry over.
Does ISO 42001 apply if we only use third-party AI and don't build models?
Yes. Annex A.10 covers third-party and customer relationships, and A.9 covers use of AI systems, both written for organizations that consume AI rather than develop it. Most enterprises find their in-scope AI inventory is dominated by purchased and embedded AI once they count it properly.
Can we combine ISO 42001 with our existing ISO 27001 audit?
Yes. Both use the Harmonized Structure, and certification bodies commonly run integrated audits covering both in a single engagement, reducing audit days and avoiding duplicate evidence for the shared clauses.




