All frameworks
Certifiable standardGlobal

ISO 42001

ISO/IEC 42001:2023

ISO/IEC 42001 specifies requirements for an AI management system (AIMS): governance, risk and impact assessment, lifecycle controls and data governance for organisations that develop, provide or use AI. Published December 2023; certifiable by accredited bodies.

Who it reaches

  • Providers of AI systems that will be high-risk under the EU AI Act, who need the management-system evidence the Act requires.
  • Companies selling AI-enabled products into enterprises whose procurement asks how AI is governed.
  • ISO 27001 certificate holders using AI in ways that affect people, where the incremental work is bounded.

What the audit checks

  1. 01Stage 1: readiness review of scope, AI policy, risk and impact assessment methods, statement of applicability.
  2. 02Stage 2: the auditor follows AI systems in scope through the records: impact assessments, data provenance, oversight, incidents.
  3. 03Three-year cycle with annual surveillance, often integrated with ISO 27001.

A typical engagement

Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.

PhaseWeeks
AI inventory, scope and policy2 to 4
Risk and impact assessment methodology and first runs4 to 8
Lifecycle and data controls, documentation8 to 20
Internal audit, management review, certification4 to 10

Evidence to have ready

  • AI policy and roles
  • AI system inventory with owners and lifecycle stage
  • AI risk assessment and AI system impact assessments
  • Statement of applicability against the 38 Annex A controls
  • Data provenance, quality and labelling records
  • Human oversight evidence in operation
  • Supplier and model provider information
  • Incident and complaint handling
  • Internal audit report and management review minutes

Questions people ask

How does ISO 42001 relate to ISO 27001?
Same harmonised structure, so they integrate into one management system and can be audited together. 42001 adds the AI system impact assessment, lifecycle controls and data-for-AI controls that 27001 does not have.
Who audits ISO 42001?
Certification bodies accredited for the standard. ISO/IEC 42006, published in 2025, sets the competence requirements for bodies and auditors; ask who will be on the audit team.

Go deeper