Skip to content

ISO 42001 explained: the AI management system standard

By Sam Rivera, Founder, SentinelPanda · May 5, 2026 · 3 min read · ISO 42001

For organisations developing or deploying AI systems, ISO 42001 is what ISO 27001 was for information security: a defensible, certifiable management system that buyers and regulators will start to expect.

What ISO 42001 is

ISO/IEC 42001:2023 is a management system standard for artificial intelligence — an AI Management System (AIMS) — published by ISO and IEC. It uses the same Annex SL high-level structure as ISO 27001 and ISO 9001, so the clauses (context, leadership, planning, support, operation, performance evaluation, improvement) will be familiar to anyone running an existing management system.

It is certifiable. An accredited certification body assesses the program against the standard and issues a certificate. The certification body market is still maturing, but accredited bodies have begun offering ISO 42001 certifications and the demand for them is growing alongside the AI Act and other AI regulations.

Who needs it

The standard applies to any organisation that provides or uses AI systems — that includes AI vendors, organisations deploying AI into their products, and organisations using third-party AI internally. The depth of obligation scales with role: an AI provider operating a foundation model carries different responsibilities than an organisation using AI for internal task automation, and the standard lets you scope accordingly.

For most B2B SaaS companies adding AI features, ISO 42001 is becoming the way to demonstrate "we have a defensible AI governance programme" without spinning up a custom framework. Enterprise procurement teams have started asking for it; a small but growing number explicitly require it.

The AIMS clauses

Clauses 4 through 10 follow Annex SL: context, leadership, planning, support, operation, performance evaluation, improvement. Familiar territory for anyone running an ISMS. The AI-specific weight lands in clause 6 (planning — including AI-specific risk assessment) and clause 8 (operation — AI system development, deployment, monitoring, and lifecycle management).

An organisation with a mature ISO 27001 program can graft an AIMS onto the existing management system: a shared risk methodology with AI-specific risk types added, a shared internal audit and management review, a shared documented-information process. The control catalogues are different; the operating system is the same.

Annex A controls

ISO 42001 ships with Annex A — a normative control set covering AI-specific concerns the standard expects you to consider: data quality and provenance, model documentation and disclosure, bias and fairness, transparency, human oversight, and AI system impact assessments. Like ISO 27001 Annex A, each control is assessed for applicability and justified on a Statement of Applicability.

The control set is smaller than ISO 27001's and the controls are more outcome-oriented than prescriptive — reflecting the early state of operational practice in AI governance. Expect the catalogue to evolve through future revisions as practice matures.

How it relates to existing work

ISO 42001 does not replace ISO 27001 — the data security obligations for AI training data, model weights, and inference logs still live in 27001. It complements it: 27001 protects the information; 42001 governs the AI system that uses it. Most organisations doing both run them as one integrated management system with two Annex A catalogues and two Statements of Applicability.

It also does not replace any specific regulation. The EU AI Act is law; ISO 42001 is a voluntary standard. Compliance with one does not equal compliance with the other. The relationship is closer to "implementing ISO 42001 puts you in a strong position to demonstrate AI Act conformity" — see the companion article for the detail.

When to start

If you are developing or shipping AI features, the conversation is happening now whether you are part of it or not. Even if you are not pursuing certification this year, putting the AIMS scaffolding in place — risk assessment, system inventory, impact assessment process, oversight mechanisms — pays back the first time a customer asks how you govern your AI. Starting before the requirement is in your contracts is cheaper than starting after.

ISO 42001 vs NIST AI RMF: a side-by-side AI impact assessments ISO 42001 vs EU AI Act

Run your compliance program in one workspace.