All posts

ISO/IEC 42001, Explained for People Who Have to Pass It

The first certifiable standard for managing AI. What it asks for, how it relates to ISO 27001 and the EU AI Act, and what an audit against it actually checks.

Published 4 min readBy the Auditly teamDiesen Beitrag auf Deutsch lesenLire cet article en français

ISO/IEC 42001 was published in December 2023. It is a management-system standard, which means it belongs to the same family as ISO 27001 and ISO 9001: it does not tell you how to build a safe model, it tells you how to run an organisation that builds, buys or operates AI responsibly, in a way that a third party can verify.

That distinction is the whole point. Most AI governance guidance is a list of principles. 42001 turns the principles into requirements with the word "shall" in them, which is what makes it auditable and certifiable.

The shape of the standard

If you have seen ISO 27001, the structure is familiar. Clauses 4 to 10 follow the harmonised structure every modern ISO management-system standard uses:

  • Clause 4, context: what the organisation does with AI, who the interested parties are, and the scope of the AI management system (AIMS). The scope statement decides what the certificate covers, so it is the first thing an auditor reads.
  • Clause 5, leadership: an AI policy signed off at the top, and roles with authority to enforce it.
  • Clause 6, planning: an AI risk assessment, an AI system impact assessment, objectives, and the statement of applicability.
  • Clause 7, support: resources, competence, awareness, communication and documented information.
  • Clause 8, operation: the risk and impact assessments actually being run, and the controls actually applied, through the lifecycle of each system.
  • Clause 9, performance evaluation: monitoring, internal audit and management review.
  • Clause 10, improvement: nonconformities and corrective action.

Annex A lists 38 reference controls in nine groups, from policies and internal organisation through resources, impact assessment, system lifecycle, data, information for interested parties, use of AI systems, and third-party relationships. Annex B gives implementation guidance for each. Annex C lists objectives and risk sources to draw on, and Annex D describes how the standard applies across domains and sectors.

Where it differs from ISO 27001

The overlap with 27001 is large enough that most organisations run the two as one integrated system, and certification bodies will audit them together. Three things are new.

The AI system impact assessment. 27001 asks you to assess risk to the organisation. 42001 adds an assessment of the impact of each AI system on individuals, groups and society: fairness, transparency, accountability, safety, privacy and the environment. This is the control most companies have never done before, and it is the one auditors spend the most time on.

Lifecycle controls. The standard walks through requirements, design, verification, deployment, operation and retirement of AI systems, with documentation and human oversight expectations at each stage.

Data for AI. Provenance, quality, preparation and labelling of training and evaluation data get their own control group, separate from the classic information-security view of data.

How it lines up with the EU AI Act

They were written by different bodies for different purposes, and neither replaces the other. The AI Act is law, with specific obligations for specific risk classes and dates. 42001 is a voluntary standard for how you manage AI in general.

The reason they are discussed together is that the AI Act requires providers of high-risk systems to run a quality management system (Article 17) and a risk management system (Article 9), to govern data (Article 10), to keep technical documentation (Article 11) and to monitor after placing on the market (Article 72). A 42001-shaped AIMS already produces most of that evidence. Until harmonised standards for the Act are published, it is the most concrete scaffold available, and it is what many auditors are being asked to assess readiness against.

It is worth being precise about the limits. A 42001 certificate is not a presumption of conformity with the AI Act, and it does not perform the conformity assessment the Act requires. It shows that your management of AI is systematic and audited. That is valuable to a customer, a regulator or a board, but it is not the same claim.

What the audit checks

Certification follows the normal two-stage pattern. Stage 1 is a readiness review: scope, policy, risk methodology, impact assessment methodology, statement of applicability, internal audit and management review. Stage 2 tests whether the system operates: the auditor picks AI systems in scope and follows them through the records.

Expect to be asked for:

  • An inventory of AI systems with an owner, a purpose and a lifecycle stage for each.
  • The risk assessment and the impact assessment for each system in scope, with evidence that the outcomes changed something.
  • The data governance records: where training data came from, how it was checked, who labelled it, how bias was looked for.
  • Evidence of human oversight in operation, not just a policy that says there is some.
  • Third-party arrangements for models or components you did not build, including what information the supplier gave you.
  • Incident and complaint handling, and what was learned.
  • Internal audit results and the management review minutes.

The certification bodies themselves must meet ISO/IEC 42006, published in 2025, which sets competence requirements for people auditing an AIMS. Ask the body who will be on the team and what their AI background is; it is a fair question, and the answer varies.

Who should do this now

Providers of systems that will be high-risk under the AI Act, because the management-system work takes longer than the technical file. Companies selling AI-enabled products into enterprises whose procurement questionnaires have started asking. Organisations already holding 27001 who use AI in ways that touch people, because the incremental work is bounded and the integrated audit is efficient.

For everyone else, the useful first step is smaller than certification: write the inventory, run one impact assessment properly, and see what it turns up. Most organisations find that exercise changes at least one deployment decision, which is the standard doing its job before any auditor arrives.

ShareLinkedInXEmail
Keep reading