ISO 42001, and what it requires of an AI management system
ISO/IEC 42001 is the international standard for an AI management system. It asks an organisation to govern the AI systems it builds or uses across their lifecycle: what they are for, what they affect, what data feeds them, who is accountable and how that is evidenced. Clauses 4 to 10 are the management system. Annex A is the AI specific control set.
- Published as ISO/IEC 42001:2023
- Same clause structure as ISO 27001
- Certificates issued by accredited certification bodies
Shared with ISO 27001
New: AI specific controls
The overlap is the point.
A customer put it in a questionnaire
The fastest growing reason. An enterprise buyer or a platform partner asks whether you hold ISO 42001, and the honest answer decides whether the deal moves.
You sell into the EU
The EU AI Act creates obligations that differ sharply depending on whether you are a provider or a deployer of an AI system. Most organisations get that classification wrong before they get anything else wrong.
You already run an ISMS
You have clauses 4 to 10 running and audited. Building a second, parallel management system for AI is the expensive mistake, and it is what a twelve month programme usually produces.
Do you need ISO 42001, and what would it take?
Four questions tells you whether this is yours to worry about. Four more sizes it. Nothing is stored and nothing is sent.
Result
Answer the questions and the result updates here as you go.
Four more questions and it tells you which route fits and what it costs.
What the standard contains
Clauses 4 to 10, the management system
- Context and interested parties
- Leadership and AI policy
- Planning, risk and objectives
- Support, competence and awareness
- Operation
- Performance evaluation, internal audit and management review
- Improvement and corrective action
If you hold ISO 27001, this half already exists. It needs extending to cover AI, not rebuilding.
Annex A, the AI specific controls
- AI policy and governance structure
- Roles and responsibilities for AI systems
- Resources, including data and tooling
- Impact assessment for AI systems
- AI system lifecycle, from objectives through design, verification, deployment and monitoring
- Data for AI systems, including provenance and quality
- Information for interested parties
- Use of AI systems by the organisation
- Third party and customer relationships
This half is genuinely new, and it is where the work is.
If you already hold ISO 27001, this is not a second management system
ISO 42001 and ISO 27001 share the ISO Harmonised Structure, so clauses 4 to 10 are the management system an ISO 27001 certified organisation already runs and already audits. Context, leadership, planning, support, operation, performance evaluation and improvement extend to cover AI rather than being rebuilt alongside. What is genuinely new is Annex A. That is why the twelve to eighteen months commonly quoted describes an organisation building a management system from nothing, not one extending a certified system.
Clause 9.2 requires an internal audit carried out objectively and impartially, which means the people who built a management system cannot audit it themselves.
Who issues the certificate
Not Goldline. ISO 42001 certificates are issued by accredited certification bodies, and in the UK that currently includes BSI, LRQA, NQA, Intertek and Amtivo. Goldline implements, prepares and audits. Selling you the implementation and then certifying it would defeat the purpose of the certificate, so we do not do both and we would be sceptical of anyone who offers to.
Questions
Where to go next
This page explains the standard. These pages set out the work.
- ISO 42001 Sprint
Practitioner-led implementation of the AI management system to the point of audit readiness.
- ISO 42001 Guided
For teams with an internal owner who want direction rather than delivery.
- ISO 42001 internal audit
The clause 9.2 audit, carried out independently of the build.
Three short tools sit alongside this page: the AI Governance Readiness Check, the ISO 27001 to 42001 Bridge for organisations already certified, and the Microsoft Sensitive Use Classifier.
