What it actually is
ISO/IEC 42001:2023 sets out the requirements for an AI management system. The phrase sounds bureaucratic, but it means something concrete: the set of policies, roles, processes and records with which an organisation decides and demonstrates how it uses AI.
It is the first international standard of its kind and, as things stand, the only one an accredited body can issue a certificate against. Frameworks like the NIST AI RMF guide; ISO 42001 audits.
It uses the high-level structure common to ISO management-system standards: the same ten clauses as ISO 9001 or ISO 27001. For an organisation with a live ISO certification, much of the scaffolding — context, leadership, competence, internal audit, management review — is reusable. What changes is the object: instead of quality or information security, what is being managed is the impact of AI on people and organisations.
How it differs from ISO 27001
This is almost everyone's first question, and confusing the two costs money in audit hours.
| ISO 27001 | ISO 42001 | |
|---|---|---|
| What it protects | The organisation's information | The people affected by AI systems |
| Central question | Is the information secure? | Is our use of AI responsible and traceable? |
| Typical risk | Leakage, unavailability, tampering | Bias, opacity, misuse, unforeseen impact |
| Key instrument | Security risk analysis | AI system impact assessment |
They do not replace each other. An organisation certified to 27001 that deploys AI still has not covered AI-specific risk, and one certified to 42001 without basic security hygiene does not stand up.
What it asks for in practice
Translated into what an auditor will ask you to show:
- An AI policy. A document approved by management setting out which uses are permitted, which are forbidden and who decides the borderline cases.
- Roles and responsibilities. By name. Who authorises a new system, who reviews incidents, who answers to management.
- An inventory of AI systems. What is used, for what, with what data and with which provider behind it. No audit starts without this.
- Risk and impact assessment. Risk to the organisation and, specifically, impact on the people affected. This is the part most particular to this standard.
- Statement of applicability. Which Annex A controls you apply, which you do not, and why. Excluding a control is legitimate; excluding it without justification is not.
- Annex A operational controls. Resources and data used by the systems, lifecycle management, information for affected people, responsible use and supplier relationships.
- Evidence that it works. Records, incidents, exceptions, training, internal audit and management review. It is what separates a real management system from a folder of documents.
That last point is where most first audits fail. Policies are written in a month; the evidence that they are applied only accumulates over time, and it cannot be manufactured the week before stage 2.
What certification looks like
| Stage | What it involves |
|---|---|
| Gap analysis | Comparing what exists with what the standard asks for. Not mandatory, but it avoids sitting an audit you are going to fail |
| Implementation | Policy, roles, inventory, risk and impact assessment, statement of applicability and controls |
| Evidence period | Months of real operation producing records. This is the bottleneck in the timeline |
| Stage 1 audit | Documentary review of the management system |
| Stage 2 audit | On-site verification: interviews, review of evidence and assessment of the controls |
| Certification decision | Taken by a committee independent of the audit team |
| Maintenance cycle | Annual surveillance and recertification after three years |
Much of this work overlaps with what the EU AI Act already requires of you by law — and unlike this standard, that one is not voluntary.