ISO 42001
Artificial Intelligence Management Systems
ISO 42001:2023 at a glance
- Current edition
- ISO/IEC 42001:2023 - Information technology — Artificial intelligence — Management system
- Published
- 2023
- Status
- Published
- Type of standard
- Management system standard
- Certifiable
- Yes — organizations can be certified by an accredited body
- Official ISO page
- View ISO 42001:2023 on iso.org
- Last verified
Overview
The first certifiable AI management system standard (AIMS), specifying requirements for the responsible development, provision and use of AI systems
ISO/IEC 42001:2023 specifies the requirements for establishing, implementing, maintaining and continually improving an artificial intelligence management system (AIMS). Published in December 2023 by ISO/IEC JTC 1/SC 42, it is the first AI management system standard and — unlike the AI guidance documents that surround it — it is written as auditable requirements, so organizations can be certified against it by an accredited certification body.
It applies to any organization, of any size, that develops, provides or uses products or services that use AI systems. That deliberately covers the whole chain: model developers, product companies embedding third-party models, and enterprises deploying AI internally. The management system governs how the organization makes decisions about AI, not the technical performance of any individual model.
The standard uses ISO's harmonized structure — context, leadership, planning, support, operation, performance evaluation, improvement — and adds AI-specific content. The central requirements are an AI policy, defined roles and responsibilities for AI, an AI risk assessment and risk treatment process, and an AI system impact assessment that considers consequences for individuals, groups and society, not just for the organization. The organization must also determine and document its role (for example provider, developer or user) for each AI system, because obligations differ by role.
Annex A provides a reference set of controls, grouped by control objective, covering areas such as AI policy and organizational governance, resources for AI systems (including data, tooling and human resources), impact assessment, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. Annex B gives implementation guidance for each control. Annex C lists potential AI-related organizational objectives and risk sources, and Annex D discusses use of the AIMS across domains and sectors.
Certification is performed by third-party certification bodies; ISO/IEC 42006:2025 specifies the requirements those bodies must meet to audit and certify AI management systems, building on ISO/IEC 17021-1, and national accreditation bodies accredit certification bodies against it. Certificates are typically issued for a three-year cycle with surveillance audits, as with other ISO management system certifications.
ISO/IEC 42001 is often discussed alongside the EU AI Act. It provides a governance structure that maps well onto the Act's expectations for risk management, data governance, technical documentation, human oversight and post-market monitoring, and onto the US NIST AI Risk Management Framework. It is not, however, a harmonised European standard, and certification to it does not by itself confer legal conformity with the AI Act.
The surrounding SC 42 portfolio supplies the technical detail: ISO/IEC 23894 (AI risk management guidance), ISO/IEC 22989 (AI concepts and terminology), ISO/IEC 23053 (framework for AI systems using machine learning), ISO/IEC 42005 (AI system impact assessment), ISO/IEC TR 24027 (bias in AI systems) and the ISO/IEC 5259 series (data quality for analytics and machine learning). ISO/IEC 42001 also integrates cleanly with ISO/IEC 27001 and ISO/IEC 27701 for organizations that already run information security and privacy management systems.
Purpose
To specify auditable requirements for an AI management system so that organizations that develop, provide or use AI systems can govern them responsibly, assess AI-specific risks and impacts, and demonstrate that governance through independent certification.
Key Benefits
- The first AI management system standard against which organizations can obtain accredited third-party certification
- Applies across the AI value chain — developers, providers and users of AI systems
- Requires an AI system impact assessment covering effects on individuals, groups and society
- Provides a reference control set (Annex A) with implementation guidance (Annex B) rather than abstract principles alone
- Establishes clear accountability, roles and authorities for AI within the organization
- Maps well onto EU AI Act governance expectations and the NIST AI Risk Management Framework
- Integrates with ISO/IEC 27001 and ISO/IEC 27701 using the shared harmonized structure
- Addresses data governance for AI, including data provenance, quality and preparation
- Covers the full AI system life cycle, including changes, monitoring and decommissioning
- Increasingly requested in enterprise procurement and vendor due diligence for AI products
Key Requirements
- Determine internal and external issues, interested parties and the scope of the AI management system
- Determine the organization's role — for example AI provider, AI developer, AI user — for each AI system in scope
- Establish an AI policy aligned with organizational objectives and other policies
- Assign roles, responsibilities and authorities for AI, with top management leadership and commitment
- Establish an AI risk assessment process with defined criteria, and perform assessments at planned intervals
- Implement an AI risk treatment process and produce a Statement of Applicability against the Annex A controls
- Conduct AI system impact assessments considering individuals, groups and societies
- Set AI objectives and plan the actions and resources needed to achieve them
- Ensure competence and awareness of persons working on AI systems, and manage communication
- Maintain documented information required by the standard and by the organization's own system
- Establish and control the AI system life cycle, including requirements, design, verification, validation, deployment, operation and monitoring
- Manage data for AI systems, including provenance, quality, preparation and data governance
- Provide information to interested parties, including documentation of intended use, limitations and reporting mechanisms
- Manage relationships with suppliers, third parties and customers involved in AI systems
- Monitor, measure, analyse and evaluate AI performance, and conduct internal audits
- Conduct management review, address nonconformities with corrective action, and continually improve
Who Needs This Standard?
Organizations that build, sell or deploy AI-enabled products and services: AI and software vendors, SaaS providers embedding models, enterprises operating AI in decision-making, and regulated organizations in finance, healthcare, HR and public services that must show AI governance to customers, auditors or regulators.
Where to get ISO 42001
The full text of ISO 42001 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 42001 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.
Get our free implementation resources
Our AI Risk Assessment Workbook is a set of blank, printable templates for running an AI risk process: an AI system inventory, a risk register with worked example rows, a likelihood and impact scoring matrix, a treatment plan and a monitoring log. Free, no account needed.
We'll only email you about this standard. Unsubscribe anytime.
Need help getting certified?
Certificates for ISO 42001 are issued by accredited certification bodies, not by ISO itself. Tell us what stage you are at and we will put you in touch with people who work with this standard — implementation support, audit or training. Free and no obligation.
Get help with ISO 42001 certification
In a hurry? You can also compare provider quotes on CertBetter (affiliate link — we earn a commission, and it stays free for you).