Everything you need to know about ISO/IEC 42001:2023, what it is, who it applies to, how certification works, how it interacts with the EU AI Act and NIST AI RMF, and how organisations are actually implementing it today.
ISO/IEC 42001:2023 is the world's first international management-system standard specifically for artificial intelligence. Published on 19 December 2023, it specifies requirements for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS) within an organisation.
The standard follows the same Harmonised Structure as ISO 9001 (quality management), ISO 27001 (information security), and ISO 14001 (environmental management). Organisations familiar with any of these will recognise the Plan-Do-Check-Act cycle, the clause structure (Context → Leadership → Planning → Support → Operation → Performance Evaluation → Improvement), and the Annex A control set.
Unlike technical standards that specify how an AI model should work, ISO 42001 is a governance framework, it specifies how an organisation should manage AI systems across their lifecycle. It's certifiable through accredited certification bodies.
Section 2The standard comprises seven main requirement clauses (Clauses 4 through 10) plus an Annex A containing 38 AI-specific controls organised into 9 control groups:
Annex A control groups:
ISO 42001 is designed for any organisation that develops, provides, or uses AI systems, including:
Although voluntary as a standard, ISO 42001 has become a de facto requirement in several contexts:
ISO 42001 certification is issued by accredited certification bodies following an independent audit. The process:
ISO/IEC 42006 (published 2025) specifies how certification bodies themselves must operate to issue ISO 42001 certificates. Accreditation bodies like ANAB (US), UKAS (UK), and DAkkS (Germany) certify the certification bodies, ensuring consistent, internationally-recognised certification.
Current accredited certification bodies include Schellman (first ANAB-accredited for 42001), BSI, DNV, A-LIGN, SGS, and, as of April 2026, Palindrome Technologies.
Section 5Certification cost varies widely by organisational size, scope complexity, and existing maturity. Published ranges from industry sources:
Specific cost elements:
Against this total cost, the toolkit represents 0.5%–10% of certification budget. That's the value frame.
Section 6Since the standard published, ISO 42001 certifications have spread quickly. Selected public examples:
In April 2026, Palindrome Technologies became an additional ANAB-accredited certification body, joining Schellman, BSI, DNV and others, expanding auditor capacity as demand accelerates.
Version 2.5 · 30 July 2026
He was reading AIMS-06 and noticed it referenced treatment actions by
identifier, TRT-001 through TRT-016, without
ever describing what any of them were. He was right.
So we audited the whole set and found two more defects he hadn't spotted. Four risks with no treatment action at all, one of them marked "in treatment" with nothing treating it. And two control back-links in the Statement of Applicability that didn't reconcile with the treatment plan. An auditor tracing controls would have found both, as a finding against his AI management system, not against our toolkit.
We rebuilt the documents, wrote a new one — AIMS-06a, the Risk
Treatment Action Catalogue — and shipped v2.3 free to every existing customer
with a written explanation of exactly what had been wrong.
In v2.5 we found a second defect of the same class that our own v2.3 audit had missed:
nine risk scores in AIMS-06a did not match the register they cited. That
audit traced every identifier in both directions; it did not trace the values carried
alongside them. Both accounts are public, and so is the automated check that now runs
before every release.
The free FRIA starter for Article 27 of the EU AI Act. Six sections, ten rights, and the two mistakes almost everyone makes.
Free. No sales call. Unsubscribe whenever.