Moviwa

What is ISO 42001, and why are people asking you for it?

8 min read · Reviewed in September 2026

In short

ISO/IEC 42001:2023 is the first international standard for governing artificial intelligence inside an organisation, and the only one an independent third party can certify. It does not regulate a specific tool: it regulates who approves which use, under what policy, with what risk assessment and with what evidence.

What it actually is

ISO/IEC 42001:2023 sets out the requirements for an AI management system. The phrase sounds bureaucratic, but it means something concrete: the set of policies, roles, processes and records with which an organisation decides and demonstrates how it uses AI.

It is the first international standard of its kind and, as things stand, the only one an accredited body can issue a certificate against. Frameworks like the NIST AI RMF guide; ISO 42001 audits.

It uses the high-level structure common to ISO management-system standards: the same ten clauses as ISO 9001 or ISO 27001. For an organisation with a live ISO certification, much of the scaffolding — context, leadership, competence, internal audit, management review — is reusable. What changes is the object: instead of quality or information security, what is being managed is the impact of AI on people and organisations.

How it differs from ISO 27001

This is almost everyone's first question, and confusing the two costs money in audit hours.

ISO 27001ISO 42001
What it protectsThe organisation's informationThe people affected by AI systems
Central questionIs the information secure?Is our use of AI responsible and traceable?
Typical riskLeakage, unavailability, tamperingBias, opacity, misuse, unforeseen impact
Key instrumentSecurity risk analysisAI system impact assessment

They do not replace each other. An organisation certified to 27001 that deploys AI still has not covered AI-specific risk, and one certified to 42001 without basic security hygiene does not stand up.

What it asks for in practice

Translated into what an auditor will ask you to show:

  • An AI policy. A document approved by management setting out which uses are permitted, which are forbidden and who decides the borderline cases.
  • Roles and responsibilities. By name. Who authorises a new system, who reviews incidents, who answers to management.
  • An inventory of AI systems. What is used, for what, with what data and with which provider behind it. No audit starts without this.
  • Risk and impact assessment. Risk to the organisation and, specifically, impact on the people affected. This is the part most particular to this standard.
  • Statement of applicability. Which Annex A controls you apply, which you do not, and why. Excluding a control is legitimate; excluding it without justification is not.
  • Annex A operational controls. Resources and data used by the systems, lifecycle management, information for affected people, responsible use and supplier relationships.
  • Evidence that it works. Records, incidents, exceptions, training, internal audit and management review. It is what separates a real management system from a folder of documents.

That last point is where most first audits fail. Policies are written in a month; the evidence that they are applied only accumulates over time, and it cannot be manufactured the week before stage 2.

What certification looks like

StageWhat it involves
Gap analysisComparing what exists with what the standard asks for. Not mandatory, but it avoids sitting an audit you are going to fail
ImplementationPolicy, roles, inventory, risk and impact assessment, statement of applicability and controls
Evidence periodMonths of real operation producing records. This is the bottleneck in the timeline
Stage 1 auditDocumentary review of the management system
Stage 2 auditOn-site verification: interviews, review of evidence and assessment of the controls
Certification decisionTaken by a committee independent of the audit team
Maintenance cycleAnnual surveillance and recertification after three years

Much of this work overlaps with what the EU AI Act already requires of you by law — and unlike this standard, that one is not voluntary.

How does Moviwa help?

ISO 42001 is passed or failed on evidence. Moviwa produces that evidence continuously, which is the only way to have it when the audit arrives.

  • An inventory drawn from real activity. Not from an internal survey, which is always incomplete because nobody declares what they suspect they should not be doing. The inventory is the standard's starting requirement and the one that saves the most manual work.

  • The policy, turned into a control. What the AI policy forbids, the platform blocks in the browser. An auditor tells a declarative policy from an applied one in two questions.

  • A log of incidents and exceptions. Every event with date, policy applied, user and outcome. It is literally what stage 2 reviews.

  • Indicators for management review. Exposure by team and how it moves over time, in a format you can put in front of a committee. Clause 9 asks for exactly that, and it is what usually gets improvised the week before.

See inside the platform

Checklist: seven steps towards ISO 42001

  1. 1

    Define the scope. Which units, which processes and which AI systems are in. A badly defined scope makes the audit more expensive and convinces nobody.

  2. 2

    Inventory what is already in use. Including the AI nobody approved. A management system that ignores half the real usage manages nothing.

  3. 3

    Write the AI policy and get management to approve it formally. Minuted.

  4. 4

    Assign roles to named people.

  5. 5

    Assess risk and impact per system, distinguishing risk to the organisation from impact on people.

  6. 6

    Draft the statement of applicability, justifying every exclusion.

  7. 7

    Let the evidence accumulate. Months, not weeks. Automating record generation is what makes the timeline viable.

Frequently asked questions

Is ISO 42001 mandatory?
No. It is voluntary. But it increasingly appears as a requirement in public tenders and corporate procurement, and that is how it reaches most companies: not demanded by a regulator, demanded by a customer.
Does certifying to ISO 42001 make me compliant with the EU AI Act?
No. They are different things: one is a voluntary standard, the other a binding regulation. That said, the work overlaps heavily — risk management, technical documentation, data governance, human oversight — and having the management system in place meaningfully reduces the effort of aligning with the regulation.
How long does it take?
It depends on scope and starting point, but the governing factor is not implementation: it is the evidence period. You need real, recorded operation before stage 2.
Is it worth it for a small company?
Yes, and the opposite myth holds back a lot of companies that already do things well. The standard scales with the scope. What does not scale is trying to certify an organisation that does not know which AI it is using.
Is Moviwa certified to ISO 42001?
No. Moviwa supplies the operational evidence your management system's audit requires. The certificate is something your organisation obtains from an accredited body.

Official sources

The inventory is the first requirement

No ISO 42001 audit starts with the policy. It starts by asking which AI systems the organisation uses. That is where almost everybody discovers they do not know.

No commitment · 15 minutes · No card

Related frameworks

Moviwa implements the technical and organisational controls these frameworks require, and produces the evidence to demonstrate them. Moviwa is not certified against these standards and does not certify your organisation: compliance remains your company's responsibility.

This content is informational and does not constitute legal advice. For decisions about your organisation's compliance, consult your legal adviser.