ISO/IEC 42001 AI Management System Standard

ISO/IEC 42001 specifies an AI management system for organizations developing, providing or using AI. It connects policies, responsibilities, risk assessment and improvement across the AI lifecycle. Organizations can seek certification from an external certification body; certification concerns the defined management-system scope and does not by itself establish EU AI Act compliance.

Updated 2026-09-06 · 294 tracked updates

ISO/IEC 42001 is the first international standard for AI management systems. It provides a framework for organizations to manage AI responsibly, addressing AI-specific risks, governance, and lifecycle management.

294
Regulations Tracked
14
Jurisdictions
10
Upcoming Milestones
2026-09-06
Last Updated

Do I Need This?

CISOhigh

ISO 42001 provides the governance framework to manage AI-specific security and privacy risks systematically. If your organization develops or deploys AI at scale, this is the international benchmark for demonstrating responsible AI management to regulators and partners.

  • Assess overlap with existing ISO 27001 ISMS — the shared Annex SL structure accelerates implementation
  • Map AI system inventory to ISO 42001 scope requirements
  • Evaluate joint ISO 27001 + 42001 certification with your existing audit body
Compliance Officerhigh

Use an AI management system to organize scope, responsibilities, risk treatment and evidence. Keep management-system conformity and applicable AI Act duties as separate review questions; certification alone does not resolve the legal assessment.

  • Begin gap assessment against ISO 42001 Annex A controls
  • Engage an accredited certification body (BSI, SGS, TÜV SÜD) for scoping
  • Plan evidence collection, internal audit and management review around the scope and identified gaps
Legal Counselhigh

Treat certification as evidence about a defined management system. Assess AI Act scope, duties and conformity routes separately, and verify any claimed harmonised-standard reference against the EU Official Journal and the requirements it covers.

  • Verify the applicable legal provisions and any cited harmonised-standard references
  • Check a supplier certificate's scope and current status before relying on it
  • Separate contractual assurance requirements from legal compliance obligations

Key Control Areas

4Context of the Organization

Understanding the organization's context, stakeholder needs, and scope of the AI management system including internal and external factors affecting AI objectives.

5Leadership & Commitment

Top management commitment to the AIMS, establishing AI policy, assigning roles and responsibilities, and ensuring resources for responsible AI governance.

6Planning

AI risk assessment, opportunity identification, and planning to achieve AI objectives including actions to address risks related to AI system development and deployment.

7Support

Competence, awareness, communication, and documented information requirements for maintaining and operating the AI management system effectively.

8Operation

Operational planning, AI risk assessment execution, AI risk treatment, and management of AI system lifecycle including design, development, and deployment.

9Performance Evaluation

Monitoring, measurement, analysis, evaluation, internal audit, and management review of the AI management system's effectiveness and outcomes.

10Improvement

Nonconformity handling, corrective actions, and continual improvement of the AI management system based on audit findings and performance data.

AAnnex A Controls

Reference controls covering AI policies, responsible AI practices, data management, impact assessment, AI system lifecycle, third-party relationships, and AI incident management.

Key Dates & Timeline

ISO/IEC 42001:2023 was published in December 2023. ISO/IEC 42005:2025, on AI system impact assessment, was published in May 2025. ISO/IEC 42006:2025, for AIMS audit and certification bodies, was published in July 2025.

Upcoming Milestones

2026-10-31

ECB-requested comprehensive action plan for significant institutions

ESRB Warning on systemic cyber risks from frontier AI models
2026-12-02

Article 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply

Digital Omnibus on AI amends the EU AI Act
2026-12-02

Providers of AI systems generating synthetic audio, image, video or text must comply with Article 50(2) marking steps if placed on market before 2 Aug 2026

Digital Omnibus on AI amends the EU AI Act
2026-12-31
2026-12-31

BAIT continues for some firms during transition period before DORA replacement

BaFin DORA implementation guidance and filing procedures

Framework Crosswalks

NIST AI RMFoverlaps
Risk managementGovernanceMeasurement & monitoringLifecycle management
Certification pathManagement system requirementsAnnex A control catalog

NIST AI RMF is a voluntary risk framework; ISO 42001 adds certifiable management system requirements and formal control catalog.

EU AI Actsupplements
Risk assessmentHuman oversightTransparencyData governance
Legal enforcementRisk classification tiersConformity assessment

ISO 42001 certification does not by itself establish AI Act conformity. Article 40 links presumption of conformity to applicable harmonised standards cited in the EU Official Journal and the requirements they cover.

SOC 2 + AIoverlaps
Data governanceSecurity controlsThird-party risk management
AI-specific lifecycle controlsImpact assessmentResponsible AI practices

SOC 2 focuses on trust services criteria for service organizations; ISO 42001 provides deeper AI-specific governance and risk management.

ISO 27001extends
Management system structureRisk-based approachAudit methodologyContinuous improvement
AI-specific risk categoriesAI lifecycle managementResponsible AI controls

ISO 42001 follows the same Annex SL management system structure as ISO 27001, making joint implementation straightforward.

Adoption Signals

established3 certified organizations

Certified Organizations

Microsoft2024Early adopter across Azure AI services
Google2024Applied to Google Cloud AI products
IBM2024Certified for Watson and AI governance platform

Auditors & Assessors

BSISGSTÜV SÜDBureau VeritasDNVLRQASchellman

Key Contributors

ISO/IEC JTC 1/SC 42IEEEOECDNIST

Regulatory References

European Commission

AI Act Article 40 links presumption of conformity to applicable harmonised standards cited in the EU Official Journal, only for the requirements those standards cover. A management-system certificate alone does not establish legal compliance.

Singapore IMDA

References ISO 42001 as a recognized framework for AI governance in Singapore's Model AI Governance Framework.

Certification Process

Certification is performed by external certification bodies, not ISO. Establish the AI management system, prepare evidence against its requirements, and agree the assessment scope with the chosen body. Check that body's competence and accreditation status; ISO/IEC 42006 sets additional requirements for AIMS audit and certification bodies.

6–12 months
Typical duration
3-year cycle with annual surveillance audits
Renewal
  1. 1
    Scope definition

    Define which AI systems, processes, and organizational units fall within the AIMS scope.

  2. 2
    Gap assessment

    Evaluate current AI governance practices against ISO 42001 requirements and Annex A controls to identify implementation gaps.

  3. 3
    AIMS implementation

    Establish AI policies, conduct AI risk assessments, implement controls, and build documentation including the Statement of Applicability.

  4. 4
    Internal audit

    Conduct a full internal audit of the AIMS to verify conformity and identify nonconformities before the certification audit.

  5. 5
    Management review

    Top management reviews AIMS performance, audit findings, and improvement opportunities — a mandatory ISO requirement.

  6. 6
    Stage 1 audit (documentation)

    Certification body reviews AIMS documentation, policies, and readiness for the Stage 2 audit.

  7. 7
    Stage 2 audit (implementation)

    On-site assessment verifying that the AIMS is effectively implemented, controls are operating, and evidence of conformity exists.

  8. 8
    Certification & surveillance

    Certificate issued for 3 years. Annual surveillance audits verify continued conformity. Full recertification audit at the end of the 3-year cycle.

Latest ISO/IEC 42001 Updates

guidancehigh2026-09-06

Singapore updates agentic AI governance framework and PDPC personal-data guidance

Singapore has updated its model AI governance framework for agentic AI and already has advisory guidelines for personal-data use in AI recommendation and decision systems, so organizations should refresh governance, human oversight, and data-use controls now.

guidancemedium2026-09-06

FCA confirms no new AI-specific rules for financial services

The FCA says it is not planning AI-specific regulation and will rely on existing frameworks such as Consumer Duty and SM&CR, so firms should focus on fitting AI governance into current control regimes rather than waiting for a new rulebook.

guidancemedium2026-09-06

ICO AI and data protection guidance remains active but under review

The ICO says its AI guidance supports audit and enforcement activity and is under review following the Data (Use and Access) Act 2025, so UK organizations should keep using it as the current baseline while planning for revisions.

guidancehigh2026-09-06

Swiss FDPIC guidance on AI and data protection, plus legislative roadmap

The FDPIC has made clear that Switzerland’s data protection law already applies to AI-supported processing and that the federal government is targeting an AI bill by the end of 2026, so organizations should harden transparency and automated-decision controls now.

guidancehigh2026-09-06

FDA AI-enabled medical device and PCCP guidance baseline

FDA’s August 2025 PCCP guidance provides recommendations for planned modifications to AI-enabled devices reviewed through the 510(k), De Novo and PMA pathways.

guidancelow2026-09-06

SEC announces internal AI task force

The SEC announced an internal AI task force on 1 August 2025 to coordinate responsible AI adoption across the agency; the announcement does not introduce a new external compliance obligation.

enforcementhigh2026-09-06

FTC AI enforcement actions on deceptive claims and substantiation

These records cover separate FTC proceedings concerning AI claims, an AI companion chatbot inquiry, and the later setting aside of the Rytr order; they do not establish a common new compliance deadline.

guidancemedium2026-09-06

AICPA SOC 2 resources reaffirm current Trust Services Criteria for AI-enabled services

AICPA’s SOC resources confirm the current Trust Services Criteria baseline and do not create AI-specific rules, but they reinforce that AI-enabled services must still satisfy existing security, privacy, and processing integrity controls in audits.

guidancehigh2026-09-06

NIST AI RMF revision and critical-infrastructure profile development

NIST says the AI RMF is being revised and that a new trustworthy-use profile for critical infrastructure is under development, while the baseline AI RMF 1.0 remains voluntary and headed for review no later than 2028.

guidancehigh2026-09-06

ISO/IEC 42006:2025 defines requirements for AI management system certification bodies

ISO/IEC 42006:2025 supplements the requirements for bodies auditing and certifying AI management systems against ISO/IEC 42001; the ISO catalog records its publication in July 2025.

Jurisdiction Coverage

Related Frameworks

Key Topics

Frequently Asked Questions

What is ISO 42001 and who should implement it?

ISO/IEC 42001 specifies an AI management system for organizations developing, providing or using AI. It connects policies, responsibilities, risk assessment and improvement across the AI lifecycle. Organizations can seek certification from an external certification body; certification concerns the defined management-system scope and does not by itself establish EU AI Act compliance.

What is ISO 42001?

ISO/IEC 42001 is the international standard for AI Management Systems (AIMS). It provides requirements and guidance for establishing, implementing, maintaining, and improving an AI management system, covering governance, risk management, and responsible AI practices.

How does ISO 42001 certification help with EU AI Act compliance?

An AI management system can organize governance evidence, but certification does not by itself establish EU AI Act compliance. Under Article 40, presumption of conformity depends on applicable harmonised standards whose references are published in the EU Official Journal, and only covers the requirements those standards address. Review the organization's legal duties separately.

What does an ISO 42001 AI management system cover?

It covers AI governance policies, risk assessment for AI systems, AI lifecycle management, data quality and bias assessment, transparency and explainability, human oversight mechanisms, and continuous monitoring and improvement of AI systems.

Keep exploring

This hub tracks published actions referencing ISO/IEC 42001; external certification bodies make certification decisions. The overview and starter prompts do not replace the standard or a review of your organization's obligations.