Skip to main content
ISO/IEC 42001 · AI MANAGEMENT SYSTEM

ISO 42001, and what it requires of an AI management system

ISO/IEC 42001 is the international standard for an AI management system. It asks an organisation to govern the AI systems it builds or uses across their lifecycle: what they are for, what they affect, what data feeds them, who is accountable and how that is evidenced. Clauses 4 to 10 are the management system. Annex A is the AI specific control set.

  • Published as ISO/IEC 42001:2023
  • Same clause structure as ISO 27001
  • Certificates issued by accredited certification bodies
Clauses 4 to 10

Shared with ISO 27001

Annex A

New: AI specific controls

The overlap is the point.

A customer put it in a questionnaire

The fastest growing reason. An enterprise buyer or a platform partner asks whether you hold ISO 42001, and the honest answer decides whether the deal moves.

You sell into the EU

The EU AI Act creates obligations that differ sharply depending on whether you are a provider or a deployer of an AI system. Most organisations get that classification wrong before they get anything else wrong.

You already run an ISMS

You have clauses 4 to 10 running and audited. Building a second, parallel management system for AI is the expensive mistake, and it is what a twelve month programme usually produces.

Do you need ISO 42001, and what would it take?

Four questions tells you whether this is yours to worry about. Four more sizes it. Nothing is stored and nothing is sent.

01

What is your relationship to the AI?

02

Has anyone actually asked you for it?

03

Do you sell into the EU?

04

Do you hold ISO 27001?

Result

Answer the questions and the result updates here as you go.

Four more questions and it tells you which route fits and what it costs.

What the standard contains

Clauses 4 to 10, the management system

  • Context and interested parties
  • Leadership and AI policy
  • Planning, risk and objectives
  • Support, competence and awareness
  • Operation
  • Performance evaluation, internal audit and management review
  • Improvement and corrective action

If you hold ISO 27001, this half already exists. It needs extending to cover AI, not rebuilding.

Annex A, the AI specific controls

  • AI policy and governance structure
  • Roles and responsibilities for AI systems
  • Resources, including data and tooling
  • Impact assessment for AI systems
  • AI system lifecycle, from objectives through design, verification, deployment and monitoring
  • Data for AI systems, including provenance and quality
  • Information for interested parties
  • Use of AI systems by the organisation
  • Third party and customer relationships

This half is genuinely new, and it is where the work is.

If you already hold ISO 27001, this is not a second management system

ISO 42001 and ISO 27001 share the ISO Harmonised Structure, so clauses 4 to 10 are the management system an ISO 27001 certified organisation already runs and already audits. Context, leadership, planning, support, operation, performance evaluation and improvement extend to cover AI rather than being rebuilt alongside. What is genuinely new is Annex A. That is why the twelve to eighteen months commonly quoted describes an organisation building a management system from nothing, not one extending a certified system.

Clause 9.2 requires an internal audit carried out objectively and impartially, which means the people who built a management system cannot audit it themselves.

Who issues the certificate

Not Goldline. ISO 42001 certificates are issued by accredited certification bodies, and in the UK that currently includes BSI, LRQA, NQA, Intertek and Amtivo. Goldline implements, prepares and audits. Selling you the implementation and then certifying it would defeat the purpose of the certificate, so we do not do both and we would be sceptical of anyone who offers to.

Questions

Where to go next

This page explains the standard. These pages set out the work.

  • ISO 42001 Sprint

    Practitioner-led implementation of the AI management system to the point of audit readiness.

  • ISO 42001 Guided

    For teams with an internal owner who want direction rather than delivery.

  • ISO 42001 internal audit

    The clause 9.2 audit, carried out independently of the build.

Three short tools sit alongside this page: the AI Governance Readiness Check, the ISO 27001 to 42001 Bridge for organisations already certified, and the Microsoft Sensitive Use Classifier.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.