CertAI
ISO/IEC 42001 explained: what it is, who needs it and how the first AI management standard works
D

Domenico Ruggiano

updated on

AI Governance

ISO/IEC 42001 explained: what it is, who needs it and how the first AI management standard works

Until 2023, a company wanting to prove it managed artificial intelligence responsibly had no shared language to do so: internal policies, self-declared ethical principles, slide decks. Then came ISO/IEC 42001, the first certifiable international standard for AI management systems. In 2026, with the AI Act in its operational phase and vendor questionnaires starting to ask for it, it has gone from a curiosity for pioneers to a board-level topic.

Let's look at what it is, how it's built and who should move now.

In short
ISO/IEC 42001 (December 2023) defines the requirements of an AIMS, an AI Management System: the system through which an organisation governs AI development and use.
It covers what no standard covered before: impact assessments, bias, human oversight, model monitoring, training data quality.
It applies both to those who develop AI and those who use it: the scope adapts to the organisation's role.
Same structure as ISO 27001: the two standards integrate, and holders of ISO 27001 start halfway there.
It is not legally mandatory, but it is the most solid way to demonstrate the governance that the AI Act and enterprise customers demand.

#What an AIMS is (and why "management system" doesn't mean bureaucracy)

ISO/IEC 42001 does not certify an algorithm, a model or a product. It certifies the management system: the set of roles, processes, controls and documentation through which the organisation decides how AI is developed, procured, used and monitored.

It's the same logic as ISO 9001 for quality or ISO 27001 for information security: not "this product is perfect", but "this organisation has a structured method for managing risks and improving over time".

The standard follows the harmonised structure common to all ISO management systems:

  1. Context: which AI systems you use or develop, which stakeholders, which scope
  2. Leadership: management responsibility, AI policy
  3. Planning: risk and opportunity assessment, objectives
  4. Support: resources, competence, awareness, documentation
  5. Operation: the controls on AI systems across their life cycle
  6. Performance evaluation: monitoring, internal audits, management review
  7. Improvement: nonconformities and corrective actions

#The specific controls: what the standard actually requires

The operational core is Annex A, with the AI-specific controls. The main themes:

  • AI system impact assessment: before developing or adopting a system, assess its consequences for individuals, groups and society.
  • Bias management and fairness: identify and mitigate distortions in data and models.
  • Data quality: provenance, representativeness and quality of training and production data.
  • Human oversight: who can intervene in the system's decisions, how and when.
  • Life-cycle monitoring: models change behaviour over time (model drift); continuous controls are needed, not a one-off check.
  • Transparency and communication: what to disclose to users and stakeholders about AI use.
  • Suppliers and third parties: AI that is bought or integrated (APIs, third-party models) must be governed as much as AI built in-house.

None of this requires slowing down development: it requires knowing what you are doing, documenting it and controlling it, which is exactly what customers and regulators want to see.

#Who needs it (and who needs it first)

  • AI startups and scaleups selling to enterprises: the most urgent case. ISO 42001 is entering vendor questionnaires, and presenting it today is a competitive differentiator (see our ISO 27001 + ISO 42001 article).
  • Companies embedding third-party AI in their products: even without developing models, responsibility towards customers remains; the standard explicitly covers procured AI.
  • Organisations with systems that will fall under AI Act high-risk (HR tech, credit scoring, med tech, edtech): obligations arrive between late 2027 and 2028, but an AIMS is built beforehand (see our AI Act deadlines guide).
  • Companies using AI internally on critical processes: ISO 42001 is also the tool for governing internal adoption, including the shadow AI phenomenon.

#ISO 42001 and the AI Act: how they relate

Let's clear up a frequent misunderstanding: ISO/IEC 42001 is not the "AI Act certification". The European regulation is law and must be complied with as such; the standard is voluntary.

The relationship is different: the AI Act requires governance, risk management, documentation, human oversight and monitoring, but does not say how to organise them. ISO 42001 provides exactly that structure: a system that produces, in an orderly way, the evidence the regulation (and any audit) requires. European harmonised standardisation work for the AI Act is also underway, and management system standards are its starting point.

Translated: complying with the AI Act without a management system means producing evidence by hand, every time. With an AIMS, compliance becomes an output of the system.

#How you get to compliance

The typical path:

  1. Gap analysis: scope, AI system inventory, distance from requirements
  2. AIMS design: policy, roles, AI risk management process
  3. Control implementation: impact assessments, data controls, oversight, monitoring
  4. Documentation and evidence: the bulk of the perceived work, and where automation changes the timeline
  5. Internal audit and management review: verifying the system actually works
  6. Certification audit: with an independent third-party body, for those who want a certificate to present to the market

With traditional tools (manual consulting, documentation from scratch) this takes many months. With AI-generated and AI-maintained documentation and a well-defined scope, reaching compliance is measured in weeks.

#How CertAI helps

CertAI takes you to ISO/IEC 42001 compliance (see the CertAI service for ISO 42001): AI system inventory and classification, gap analysis, tailored generated documentation, continuous controls and monitoring, through to audit preparation with independent certification bodies. And if you already hold (or are building) ISO 27001, the journey starts halfway there.

Want to know how far you are from ISO/IEC 42001 compliance? Start with a CertAI gap analysis.

Book a demo

Last updated: July 2026.