Published in December 2023, ISO/IEC 42001 is the first international management system standard for artificial intelligence. It specifies requirements for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS) — the AI equivalent of what ISO 27001 is for information security or ISO 9001 for quality.
With the EU AI Act now in force and enforcement ramping up through 2026–2027, organizations that develop or deploy AI systems need demonstrable governance. ISO/IEC 42001 provides the certifiable framework; the AI Act provides the legal obligation. They complement each other.
Who Needs ISO/IEC 42001?
The standard applies to any organization that provides or uses AI-based products or services — not just AI vendors. If you integrate a third-party LLM into customer-facing workflows, you are an AI user with governance obligations. Typical adopters include SaaS companies embedding AI features, financial institutions using ML models, healthcare providers, and public-sector bodies.
Structure: Clauses 4–10
Like all modern ISO management system standards, ISO/IEC 42001 follows the Harmonized Structure (Annex SL):
- Clause 4 — Context: define the scope of your AIMS and which AI systems it covers.
- Clause 5 — Leadership: top management accountability and an AI policy.
- Clause 6 — Planning: AI risk assessment, AI impact assessment, and measurable AI objectives.
- Clause 7 — Support: competence, awareness, communication, and documented information.
- Clause 8 — Operation: operational planning, AI system lifecycle controls, and impact assessments.
- Clause 9 — Performance evaluation: monitoring, internal audit, management review.
- Clause 10 — Improvement: nonconformity handling and continual improvement.
Annex A: The Control Catalog
Annex A defines 38 controls across 9 domains, including AI policy, internal organization, resource management, AI system impact assessment, lifecycle management, data management, information for interested parties, responsible use, and third-party relationships. You select applicable controls via a Statement of Applicability — the same mechanism as ISO 27001.
How ISO 42001 Relates to the EU AI Act
The AI Act is a regulation with risk-tiered obligations (prohibited, high-risk, limited, minimal). ISO/IEC 42001 is a voluntary management system standard. Implementing an AIMS does not replace AI Act compliance, but it gives you the governance machinery — risk processes, documentation, accountability — that regulators expect to see. Harmonized European standards under the AI Act are still being finalized; ISO/IEC 42001 is the closest internationally recognized anchor today.
Assess Your Readiness in 10 Minutes
Before engaging consultants or auditors, get a baseline. Our free ISO 42001 AI Readiness Assessment walks you through all clauses and Annex A controls, produces a maturity score, a prioritized gap list, and a downloadable PDF report — entirely in your browser, no data uploaded.
If you already run ISO 27001 or ISO 9001, much of the management-system scaffolding transfers. You can also check those baselines with our ISO 27001 Gap Analysis and ISO 9001 Readiness Checker.
Frequently Asked Questions
Is ISO/IEC 42001 certification mandatory?
No — it is voluntary. But it is increasingly requested in procurement and is strong evidence of AI governance maturity under the EU AI Act.
How long does implementation take?
For organizations with an existing ISO management system, typically 4–8 months. Starting from scratch, expect 9–18 months depending on the number and risk profile of AI systems in scope.
Can it be integrated with ISO 27001?
Yes — both share the Harmonized Structure, so context, leadership, audit, and improvement processes can be integrated into a single management system.




