ISO/IEC 42001:2023 is the world's first certifiable standard for an AI management system (AIMS). It is the anchor of the entire ISO/IEC AI standards portfolio: the one standard an organization can actually be audited and certified against, with the surrounding standards providing the guidance that supports it.
For the first time, there is a recognized international answer to the question procurement teams, regulators, and boards have been asking for years: prove that your AI is governed responsibly. This guide explains what ISO/IEC 42001 requires, how it connects the rest of the AI standards, how certification works, and how to get ready for it.
What is ISO/IEC 42001?
ISO/IEC 42001:2023 was published in December 2023 by ISO/IEC JTC 1/SC 42. Its title is Information technology — Artificial intelligence — Management system. Unlike the guidance standards around it — such as ISO/IEC 23894 on risk management or ISO/IEC 42005 on impact assessment — ISO/IEC 42001 is certifiable. An organization builds an AI management system against the standard, and an independent accredited body audits it and issues a certificate.
It applies to any organization that develops, provides, or uses AI systems, regardless of size or sector. A certificate from an accredited body signals that an independent third party has verified that your AI governance is real and operating — not a policy document, but a system.
Why ISO/IEC 42001 matters now
Before ISO/IEC 42001, there was no serious, internationally recognized way to demonstrate responsible AI governance. Now there is, and the pressure to show it is rising from several directions at once:
- Procurement and customer trust — buyers increasingly require evidence of responsible AI before they will adopt a product or service.
- Regulatory alignment — the standard's risk-based approach maps closely to the EU AI Act, and provides a structured foundation for obligations under regimes such as Korea's AI Basic Act.
- Internal governance — boards and executives need assurance that AI risk is being managed deliberately rather than informally.
Certification turns “responsible AI” from a claim into an auditable, externally verified fact.
What ISO/IEC 42001 requires
ISO/IEC 42001 follows the same harmonized high-level structure (Annex SL) as ISO/IEC 27001 and ISO 9001, so organizations already running those standards will recognize the layout. The normative requirements sit in Clauses 4 to 10, all of which are mandatory and cannot be excluded:
- Clause 4 — Context. Define which AI systems, data, and activities fall within the management system, and the internal and external factors that shape it.
- Clause 5 — Leadership. Top management commitment, an AI policy, and clear roles.
- Clause 6 — Planning. Address risks and opportunities and set AI objectives.
- Clause 7 — Support. Resources, competence, awareness, communication, and documented information.
- Clause 8 — Operation. The AI-specific heart of the standard: operational controls, AI risk assessment, AI risk treatment, and AI system impact assessment.
- Clause 9 — Performance evaluation. Monitoring, internal audit, and management review.
- Clause 10 — Improvement. Corrective action and continual improvement.
Four informative annexes support the requirements: Annex A provides a set of reference controls and their objectives, selected according to your risk profile; Annex B gives implementation guidance for those controls; Annex C sets out potential AI-related objectives and risk sources; and Annex D covers using the AI management system across domains and integrating it with other management system standards.
How ISO/IEC 42001 connects the other AI standards
ISO/IEC 42001 is the hub; the rest of the SC 42 portfolio supplies the detail behind its requirements:
- Its AI risk assessment and treatment obligations (Clause 8) are operationalized by ISO/IEC 23894, the AI risk management guidance.
- Its AI system impact assessment obligation (Clause 8) is operationalized by ISO/IEC 42005.
- Its terminology rests on the foundational standards ISO/IEC 22989 and ISO/IEC 23053.
- The lifecycle perspective draws on ISO/IEC 5338.
- And the bodies that certify you are governed by ISO/IEC 42006.
This is why implementing ISO/IEC 42001 well means engaging the standards around it, not treating it in isolation. (Explore the full picture on our SC 42 standards map.)
How ISO/IEC 42001 certification works
Certification must be performed by an independent accredited certification body. You cannot certify yourself, and the body that certifies you must be independent of whoever helped you prepare — that separation is precisely what gives the certificate its credibility.
The process typically runs in two stages: a Stage 1 review of your documentation and readiness, followed by a Stage 2 audit of whether the management system is genuinely operating. A certificate is normally valid for three years, with annual surveillance audits in between. Timelines vary — roughly three to six months if your AIMS is already mature, longer if you are starting from scratch.
How to get ready for certification
A practical roadmap to a certifiable AI management system:
- Scope the AIMS. Decide which AI systems, teams, and data are in scope.
- Run a gap analysis. Compare your current state against Clauses 4–10 and the applicable Annex A controls.
- Build the system. Establish the AI policy, risk assessment and treatment process, AI system impact assessment, and the selected controls with a statement of applicability.
- Operate it and collect evidence. The standard certifies a working system, so it needs a track record, not just documents.
- Internal audit and management review. Confirm the system works before an external auditor does.
- Certification audit. Engage an accredited body for Stage 1 and Stage 2.
The single most useful first step is an honest readiness check, so you know where the gaps are before investing in the build.
What an audit looks for — and common pitfalls
From an audit perspective, the traits that tend to support a clean result are:
- The management system actually operates — there is evidence of risk assessments, impact assessments, reviews, and decisions, not just templates.
- Risk and impact assessments are real and current, tied to the organization's actual AI systems.
- Leadership is genuinely engaged, not a signature on a policy.
- The AIMS is integrated with how the organization already works, rather than a parallel paper exercise.
Failure modes to watch for: treating certification as a documentation project, using generic copy-pasted policies that do not reflect the business, skipping real risk and impact work, and having no evidence that the system has been operating.
Getting started
You do not need to commit to a full implementation to find out where you stand. Start with our free AI governance readiness assessment for a fast, self-service view of how prepared you are against ISO/IEC 42001.
When you want a deeper, expert view, our remote assessment is an in-depth review by a certified ISO/IEC 42001 lead auditor, with benchmarking against peers by industry, size, and region — so you see not just your gaps, but how you compare.
And as you build, the artifacts you will need are ready: our AI Risk Management Template and AI System Impact Assessment Template operationalize the Clause 8 requirements that sit at the center of the standard.
Written by a certified ISO/IEC 42001 Lead Auditor and principal consultant at ITG insights.
ITG insights specializes in ISO/IEC 42001 and ISO/IEC 20000 certification consulting, risk management, and governance framework design. Consulting and training inquiries: info@ai42001.ai
ai42001.ai is an AI governance platform structured around ISO/IEC 42001, operated by ITG insights Co., Ltd.
📚 SC 42 AI Standards Series
← Previous: ISO/IEC 23053:2022 — Framework for ML-based AI Systems (forthcoming)
📍 Current: ISO/IEC 42001:2023 — The AI Management System Standard
→ Next: ISO/IEC 23894:2023 — Guidance on AI Risk Management (forthcoming)