← ISO and SOC Certifications

ISO/IEC 42001

Artificial intelligence — Management system. Updated: September 29, 2026.

ISO/IEC 42001:2023 is the first certifiable AI management system standard. It was published in December 2023, which makes it much the youngest standard in this section, and it is the one moving fastest from “nobody has heard of it” to “it is on the procurement form”.

Structurally it will look familiar immediately: the same clause 4 to 10 skeleton as ISO 27001 and ISO 9001, an Annex A of controls you select from, a three-year certification cycle. If you already run one management system, you already own most of the machinery. What is new is the subject matter, and one specific requirement that has no counterpart in any of the others.

The Part That Is Genuinely Different

Diagram contrasting ISO 27001 risk assessment, which asks what could harm the organisation, with the ISO 42001 AI system impact assessment, which asks who outside the organisation could be harmed

ISO 27001 asks what could harm you. 42001 keeps that question and adds the AI system impact assessment, which asks who you could harm — individuals and groups affected by what the system decides, who are usually not your customers and did not choose to interact with you at all.

That is a different exercise, not a longer version of the same one. A person refused credit, filtered out of a hiring pipeline, or flagged by a detection model has an interest in your system and no relationship with your company. Teams fluent in security risk consistently find this the unfamiliar part, and it is where most of the real work of 42001 sits.

What the Controls Cover

Annex A groups its controls under objectives that will be new to most readers even where the underlying practice is not. In outline:

It Is Not Conformity With the EU AI Act

This needs saying plainly, because it is being blurred in a lot of marketing. The EU AI Act is legislation with its own conformity assessment route for high-risk systems, and harmonised standards for it are being developed separately. An ISO 42001 certificate does not establish compliance with the AI Act, and no certification body can issue that opinion.

What it does do is real and worth having: it gives you the governance structure, documentation and impact-assessment practice that the Act's obligations assume you already have, produced by an independently audited system rather than assembled under deadline. That is the same relationship ISO 27701 has with data protection law — strong evidence of diligence, not a legal safe harbour.

Worth distinguishing from the other framework you will hear about: the US NIST AI Risk Management Framework is voluntary guidance and is not certifiable. It is a useful implementation companion, in roughly the way ITIL sits next to ISO/IEC 20000-1.

Who Actually Needs It

If you do not build, deploy or embed AI systems, you do not need this and should not buy it.

Getting Certified

The same eight-step path as ISO 27001: gap analysis, scope and risk, implement, operate long enough to produce records, internal audit and management review, Stage 1, Stage 2, certificate for three years with annual surveillance.

Three things specific to this one:

Realistically, an organisation that already holds ISO 27001 can expect a meaningfully shorter path, because clauses 4 to 10 are already running and only the AI-specific controls and the impact assessment practice are new.

Written from an infrastructure perspective. We are not a certification body, an audit firm or a legal adviser, and this is not legal advice — least of all about the AI Act, which is being applied in phases and amended. Confirm the current position and your own obligations with counsel.