Certifiable standardGlobal
ISO 42001
ISO/IEC 42001:2023
ISO/IEC 42001 specifies requirements for an AI management system (AIMS): governance, risk and impact assessment, lifecycle controls and data governance for organisations that develop, provide or use AI. Published December 2023; certifiable by accredited bodies.
Who it reaches
- Providers of AI systems that will be high-risk under the EU AI Act, who need the management-system evidence the Act requires.
- Companies selling AI-enabled products into enterprises whose procurement asks how AI is governed.
- ISO 27001 certificate holders using AI in ways that affect people, where the incremental work is bounded.
What the audit checks
- 01Stage 1: readiness review of scope, AI policy, risk and impact assessment methods, statement of applicability.
- 02Stage 2: the auditor follows AI systems in scope through the records: impact assessments, data provenance, oversight, incidents.
- 03Three-year cycle with annual surveillance, often integrated with ISO 27001.
A typical engagement
Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.
| Phase | Weeks |
|---|---|
| AI inventory, scope and policy | 2 to 4 |
| Risk and impact assessment methodology and first runs | 4 to 8 |
| Lifecycle and data controls, documentation | 8 to 20 |
| Internal audit, management review, certification | 4 to 10 |
Evidence to have ready
- AI policy and roles
- AI system inventory with owners and lifecycle stage
- AI risk assessment and AI system impact assessments
- Statement of applicability against the 38 Annex A controls
- Data provenance, quality and labelling records
- Human oversight evidence in operation
- Supplier and model provider information
- Incident and complaint handling
- Internal audit report and management review minutes
Questions people ask
- How does ISO 42001 relate to ISO 27001?
- Same harmonised structure, so they integrate into one management system and can be audited together. 42001 adds the AI system impact assessment, lifecycle controls and data-for-AI controls that 27001 does not have.
- Who audits ISO 42001?
- Certification bodies accredited for the standard. ISO/IEC 42006, published in 2025, sets the competence requirements for bodies and auditors; ask who will be on the audit team.