ISO/IEC 42001 AI Management System Standard
ISO/IEC 42001 specifies an AI management system for organizations developing, providing or using AI. It connects policies, responsibilities, risk assessment and improvement across the AI lifecycle. Organizations can seek certification from an external certification body; certification concerns the defined management-system scope and does not by itself establish EU AI Act compliance.
Updated 2026-09-06 · 294 tracked updates
ISO/IEC 42001 is the first international standard for AI management systems. It provides a framework for organizations to manage AI responsibly, addressing AI-specific risks, governance, and lifecycle management.
Do I Need This?
ISO 42001 provides the governance framework to manage AI-specific security and privacy risks systematically. If your organization develops or deploys AI at scale, this is the international benchmark for demonstrating responsible AI management to regulators and partners.
- Assess overlap with existing ISO 27001 ISMS — the shared Annex SL structure accelerates implementation
- Map AI system inventory to ISO 42001 scope requirements
- Evaluate joint ISO 27001 + 42001 certification with your existing audit body
Use an AI management system to organize scope, responsibilities, risk treatment and evidence. Keep management-system conformity and applicable AI Act duties as separate review questions; certification alone does not resolve the legal assessment.
- Begin gap assessment against ISO 42001 Annex A controls
- Engage an accredited certification body (BSI, SGS, TÜV SÜD) for scoping
- Plan evidence collection, internal audit and management review around the scope and identified gaps
Treat certification as evidence about a defined management system. Assess AI Act scope, duties and conformity routes separately, and verify any claimed harmonised-standard reference against the EU Official Journal and the requirements it covers.
- Verify the applicable legal provisions and any cited harmonised-standard references
- Check a supplier certificate's scope and current status before relying on it
- Separate contractual assurance requirements from legal compliance obligations
Key Control Areas
Understanding the organization's context, stakeholder needs, and scope of the AI management system including internal and external factors affecting AI objectives.
Top management commitment to the AIMS, establishing AI policy, assigning roles and responsibilities, and ensuring resources for responsible AI governance.
AI risk assessment, opportunity identification, and planning to achieve AI objectives including actions to address risks related to AI system development and deployment.
Competence, awareness, communication, and documented information requirements for maintaining and operating the AI management system effectively.
Operational planning, AI risk assessment execution, AI risk treatment, and management of AI system lifecycle including design, development, and deployment.
Monitoring, measurement, analysis, evaluation, internal audit, and management review of the AI management system's effectiveness and outcomes.
Nonconformity handling, corrective actions, and continual improvement of the AI management system based on audit findings and performance data.
Reference controls covering AI policies, responsible AI practices, data management, impact assessment, AI system lifecycle, third-party relationships, and AI incident management.
Key Dates & Timeline
ISO/IEC 42001:2023 was published in December 2023. ISO/IEC 42005:2025, on AI system impact assessment, was published in May 2025. ISO/IEC 42006:2025, for AIMS audit and certification bodies, was published in July 2025.
Upcoming Milestones
ECB-requested comprehensive action plan for significant institutions
ESRB Warning on systemic cyber risks from frontier AI modelsArticle 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply
Digital Omnibus on AI amends the EU AI ActProviders of AI systems generating synthetic audio, image, video or text must comply with Article 50(2) marking steps if placed on market before 2 Aug 2026
Digital Omnibus on AI amends the EU AI ActPlanned Swiss AI bill target year-end 2026
Swiss FDPIC guidance on AI and data protection, plus legislative roadmapBAIT continues for some firms during transition period before DORA replacement
BaFin DORA implementation guidance and filing proceduresFramework Crosswalks
NIST AI RMF is a voluntary risk framework; ISO 42001 adds certifiable management system requirements and formal control catalog.
ISO 42001 certification does not by itself establish AI Act conformity. Article 40 links presumption of conformity to applicable harmonised standards cited in the EU Official Journal and the requirements they cover.
SOC 2 focuses on trust services criteria for service organizations; ISO 42001 provides deeper AI-specific governance and risk management.
ISO 42001 follows the same Annex SL management system structure as ISO 27001, making joint implementation straightforward.
Adoption Signals
Certified Organizations
Auditors & Assessors
Key Contributors
Regulatory References
AI Act Article 40 links presumption of conformity to applicable harmonised standards cited in the EU Official Journal, only for the requirements those standards cover. A management-system certificate alone does not establish legal compliance.
References ISO 42001 as a recognized framework for AI governance in Singapore's Model AI Governance Framework.
Certification Process
Certification is performed by external certification bodies, not ISO. Establish the AI management system, prepare evidence against its requirements, and agree the assessment scope with the chosen body. Check that body's competence and accreditation status; ISO/IEC 42006 sets additional requirements for AIMS audit and certification bodies.
- 1Scope definition
Define which AI systems, processes, and organizational units fall within the AIMS scope.
- 2Gap assessment
Evaluate current AI governance practices against ISO 42001 requirements and Annex A controls to identify implementation gaps.
- 3AIMS implementation
Establish AI policies, conduct AI risk assessments, implement controls, and build documentation including the Statement of Applicability.
- 4Internal audit
Conduct a full internal audit of the AIMS to verify conformity and identify nonconformities before the certification audit.
- 5Management review
Top management reviews AIMS performance, audit findings, and improvement opportunities — a mandatory ISO requirement.
- 6Stage 1 audit (documentation)
Certification body reviews AIMS documentation, policies, and readiness for the Stage 2 audit.
- 7Stage 2 audit (implementation)
On-site assessment verifying that the AIMS is effectively implemented, controls are operating, and evidence of conformity exists.
- 8Certification & surveillance
Certificate issued for 3 years. Annual surveillance audits verify continued conformity. Full recertification audit at the end of the 3-year cycle.
Latest ISO/IEC 42001 Updates
Singapore updates agentic AI governance framework and PDPC personal-data guidance
Singapore has updated its model AI governance framework for agentic AI and already has advisory guidelines for personal-data use in AI recommendation and decision systems, so organizations should refresh governance, human oversight, and data-use controls now.
FCA confirms no new AI-specific rules for financial services
The FCA says it is not planning AI-specific regulation and will rely on existing frameworks such as Consumer Duty and SM&CR, so firms should focus on fitting AI governance into current control regimes rather than waiting for a new rulebook.
ICO AI and data protection guidance remains active but under review
The ICO says its AI guidance supports audit and enforcement activity and is under review following the Data (Use and Access) Act 2025, so UK organizations should keep using it as the current baseline while planning for revisions.
Swiss FDPIC guidance on AI and data protection, plus legislative roadmap
The FDPIC has made clear that Switzerland’s data protection law already applies to AI-supported processing and that the federal government is targeting an AI bill by the end of 2026, so organizations should harden transparency and automated-decision controls now.
FDA AI-enabled medical device and PCCP guidance baseline
FDA’s August 2025 PCCP guidance provides recommendations for planned modifications to AI-enabled devices reviewed through the 510(k), De Novo and PMA pathways.
SEC announces internal AI task force
The SEC announced an internal AI task force on 1 August 2025 to coordinate responsible AI adoption across the agency; the announcement does not introduce a new external compliance obligation.
FTC AI enforcement actions on deceptive claims and substantiation
These records cover separate FTC proceedings concerning AI claims, an AI companion chatbot inquiry, and the later setting aside of the Rytr order; they do not establish a common new compliance deadline.
AICPA SOC 2 resources reaffirm current Trust Services Criteria for AI-enabled services
AICPA’s SOC resources confirm the current Trust Services Criteria baseline and do not create AI-specific rules, but they reinforce that AI-enabled services must still satisfy existing security, privacy, and processing integrity controls in audits.
NIST AI RMF revision and critical-infrastructure profile development
NIST says the AI RMF is being revised and that a new trustworthy-use profile for critical infrastructure is under development, while the baseline AI RMF 1.0 remains voluntary and headed for review no later than 2028.
ISO/IEC 42006:2025 defines requirements for AI management system certification bodies
ISO/IEC 42006:2025 supplements the requirements for bodies auditing and certifying AI management systems against ISO/IEC 42001; the ISO catalog records its publication in July 2025.
Jurisdiction Coverage
Related Frameworks
Key Topics
Frequently Asked Questions
What is ISO 42001 and who should implement it?
ISO/IEC 42001 specifies an AI management system for organizations developing, providing or using AI. It connects policies, responsibilities, risk assessment and improvement across the AI lifecycle. Organizations can seek certification from an external certification body; certification concerns the defined management-system scope and does not by itself establish EU AI Act compliance.
What is ISO 42001?
ISO/IEC 42001 is the international standard for AI Management Systems (AIMS). It provides requirements and guidance for establishing, implementing, maintaining, and improving an AI management system, covering governance, risk management, and responsible AI practices.
How does ISO 42001 certification help with EU AI Act compliance?
An AI management system can organize governance evidence, but certification does not by itself establish EU AI Act compliance. Under Article 40, presumption of conformity depends on applicable harmonised standards whose references are published in the EU Official Journal, and only covers the requirements those standards address. Review the organization's legal duties separately.
What does an ISO 42001 AI management system cover?
It covers AI governance policies, risk assessment for AI systems, AI lifecycle management, data quality and bias assessment, transparency and explainability, human oversight mechanisms, and continuous monitoring and improvement of AI systems.
Keep exploring
This hub tracks published actions referencing ISO/IEC 42001; external certification bodies make certification decisions. The overview and starter prompts do not replace the standard or a review of your organization's obligations.