Blog · AI Governance

ISO/IEC 42001 Explained: The AI Management System Standard

ISO 42001 is the world's first certifiable standard for governing artificial intelligence. This guide explains what the standard requires, how an AI management system is structured, how it relates to ISO/IEC 27001, the NIST AI RMF, and the EU AI Act, and the practical path from readiness to accredited certification.

Executive summary

ISO/IEC 42001 is the first international standard for an artificial intelligence management system, or AIMS. Published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) in December 2023, it gives an organization a structured, auditable way to govern how it develops, provides, and uses AI — and, crucially, it is certifiable by an accredited independent body.

If your organization is building or buying AI and needs to prove to customers, regulators, and boards that it is being managed responsibly, ISO 42001 is fast becoming the reference point. It does for AI governance what ISO/IEC 27001 did for information security: it converts good intentions into a repeatable management system with defined roles, documented controls, evidence, and a cycle of continual improvement that an external auditor can inspect.

This guide explains the standard in plain language for the people who have to sponsor, budget for, and stand behind AI governance decisions — CISOs, heads of AI, chief risk and compliance officers, general counsel, and the boards they answer to. We cover what the standard is, how an AI management system is structured around the Plan-Do-Check-Act cycle, the Annex A controls, how ISO 42001 fits alongside the NIST AI RMF and the EU AI Act, who should pursue certification, and exactly how the certification process works. Where a capability has a dedicated page, we link to it so you can go deeper.

The one-sentence version

ISO/IEC 42001 is a certifiable management-system standard that lets an organization prove — not just assert — that its AI is governed responsibly across its full lifecycle, using the same discipline the world already trusts for information security.

What ISO/IEC 42001 actually is

ISO/IEC 42001:2023 is a management-system standard. That specific phrase matters, because it tells you what kind of document you are dealing with and what conformity to it means. A management-system standard does not prescribe a particular technology, model architecture, or single technical control. Instead, it specifies the requirements for a system of governance — the policies, roles, processes, objectives, and records an organization must have in place to manage a subject area consistently over time and to improve it continually.

The subject area here is artificial intelligence. The standard's full title is Information technology — Artificial intelligence — Management system. It applies to any organization that provides or uses products or services that use AI, regardless of size, sector, or whether the organization builds its own models or consumes them from third parties. A hospital deploying a clinical decision-support model, a bank running a credit-scoring system, and a software company shipping an AI feature are all in scope for the same standard, because all three make decisions about how AI is developed, procured, operated, and overseen.

Two attributes distinguish a management-system standard like ISO 42001 from a voluntary framework such as the NIST AI RMF:

  • It contains requirements. The clauses use the word "shall." To conform, an organization must actually do the things the standard requires — not merely consider them. This is what makes the standard auditable against a pass/fail bar.
  • It is certifiable. Because conformity can be objectively assessed, an accredited certification body can audit an organization and, if it conforms, issue a formal certificate. A certificate is a third-party attestation that carries weight with customers, regulators, and insurers in a way that a self-declared framework alignment cannot.

ISO 42001 was developed by the joint technical committee ISO/IEC JTC 1, Subcommittee 42 (SC 42), the same standards body responsible for the broader family of AI standards, including terminology, bias, and AI risk management. It is deliberately designed to interlock with the other standards SC 42 produces, which is why the pieces fit together so neatly, as we will see later.

A note on "certifiable"

Being certifiable does not make ISO 42001 a law. It remains voluntary. What "certifiable" means is that the standard is written precisely enough that an independent, accredited auditor can test an organization against it and reach a defensible conclusion — the same property that makes ISO 9001 (quality) and ISO/IEC 27001 (security) certificates meaningful in the market.

The AI management system (AIMS)

The object that ISO 42001 asks you to build and run is the AI management system, abbreviated AIMS. An AIMS is not a piece of software you install; it is the organizational machinery — governance bodies, policies, roles, processes, objectives, and records — through which the organization directs and controls its AI activities.

A useful mental model is to think of the AIMS as the answer to a simple question an auditor, regulator, or customer might ask: "Show me how you decide what AI to build or buy, how you assess its risks and impacts, who is accountable, what controls you apply, how you monitor it in production, and how you improve when something goes wrong." If the honest answer is a collection of ad hoc habits held in a few people's heads, you do not have a management system. If the answer is a documented, operating, evidenced system that the whole organization follows and that leadership actively steers, you do.

Several ideas are central to how the standard frames the AIMS:

Scope and context

An AIMS has a defined scope. The organization decides which parts of the business, which AI systems, and which activities the management system covers, and it justifies that boundary. Scope is a deliberate choice: it can be narrow (one product line's AI) or broad (all AI across the enterprise), but it must be documented and defensible, because the certificate an auditor issues applies only to the declared scope.

Interested parties and their expectations

The standard requires the organization to understand its interested parties — customers, users, regulators, employees, and the individuals or communities affected by its AI — and their relevant needs and expectations. AI governance is not only about protecting the organization; it explicitly considers the effects of AI systems on the people and society around them. This outward-facing lens is one of the features that distinguishes an AI management system from a purely internal security or quality system.

Roles beyond the provider

ISO 42001 recognizes that organizations play different roles in the AI value chain — as a provider that develops AI, as a user that deploys someone else's AI, or as a partner in between — and that the obligations differ by role. An organization that fine-tunes and ships a model carries different responsibilities than one that embeds a vendor's API, and the AIMS is expected to reflect the organization's actual role or roles.

The management-system structure and the PDCA cycle

ISO 42001 is built on the same skeleton as every modern ISO management-system standard: the harmonized structure (formerly called the High-Level Structure, or HLS). This shared architecture is why organizations that already run ISO 27001 or ISO 9001 recognize the shape of ISO 42001 immediately — the top-level clauses are numbered and named almost identically. The standard's requirements live in Clauses 4 through 10, and together they implement the Plan-Do-Check-Act (PDCA) cycle of continual improvement.

PDCA is the engine of the whole system. You plan what you intend to achieve and how you will manage risk; you do the work of operating the controls; you check how well the system is performing through monitoring, internal audit, and management review; and you act to correct problems and improve. The cycle then repeats, which is what "continual improvement" means in practice — not a one-time project, but a system that gets better on a schedule.

Here is how the clauses map onto that cycle:

Clause 4 — Context of the organization (Plan)

The organization determines the internal and external issues relevant to its AI, identifies interested parties and their expectations, decides the scope of the AIMS, and establishes the management system itself. This clause sets the boundary and purpose for everything that follows.

Clause 5 — Leadership (Plan)

Top management must demonstrate genuine leadership and commitment: establishing an AI policy, assigning roles and responsibilities, and ensuring the AIMS is resourced and integrated into the business. This clause is deliberately demanding. Certification auditors look hard for evidence that leadership is actually engaged, because a management system that lives only in the compliance function rarely holds up. Accountability for AI cannot be delegated to a diagram.

Clause 6 — Planning (Plan)

The organization addresses risks and opportunities, conducts AI risk assessment and AI impact assessment (covered in detail below), and sets measurable AI objectives with plans to achieve them. This is where the standard's distinctive AI content begins to concentrate. Planning also includes deciding which Annex A controls are applicable and documenting that decision.

Clause 7 — Support (Do)

The organization provides the resources the AIMS needs: competent people, awareness, communication, and — importantly for auditability — documented information. This clause requires that the right records exist, are controlled, and are kept current, because a management system that cannot be evidenced cannot be certified.

Clause 8 — Operation (Do)

The organization plans, implements, and controls the processes needed to meet its requirements and to treat the risks and impacts identified in Clause 6. In practice, this is where AI systems are actually developed, procured, deployed, and operated under the controls the organization has chosen, and where impact assessments are carried out and acted upon across the AI system lifecycle.

Clause 9 — Performance evaluation (Check)

The organization monitors, measures, analyzes, and evaluates the AIMS; conducts internal audits; and holds management reviews. This is the "check" that keeps the system honest. Internal audit is a formal, documented examination of whether the system conforms to the standard and to the organization's own requirements, and it is a prerequisite the certification body will expect to see before it audits you.

Clause 10 — Improvement (Act)

The organization addresses nonconformities with corrective action and pursues continual improvement of the AIMS. When something fails — a model behaves unexpectedly, a control is missed, an audit finding is raised — the system requires you to investigate the root cause, fix it, and prevent recurrence, then feed that learning back into planning.

Why the shared structure is an advantage

Because Clauses 4 through 10 mirror ISO/IEC 27001, an organization that already operates an information security management system can extend it into an integrated management system rather than standing up a parallel bureaucracy. The context, leadership, competence, documentation, internal-audit, and management-review machinery are largely reusable. You add the AI-specific requirements — impact assessment and the Annex A controls — on top of a foundation you already have.

Risk and AI impact assessment

Two assessment disciplines sit at the heart of ISO 42001, and understanding the difference between them is essential to understanding what makes the standard specific to AI.

AI risk assessment

The first is a familiar management-system idea: risk assessment from the organization's own perspective. The organization establishes and maintains a process to identify, analyze, and evaluate risks related to its AI, and to decide how to treat them. This is the same logical structure as information-security risk management, and it aligns with the guidance in ISO/IEC 23894, the SC 42 standard dedicated to AI risk management. Risks here include the things that could harm the organization: security failures, poor model performance, non-compliance, reputational damage, and operational disruption.

AI system impact assessment

The second discipline is what genuinely distinguishes ISO 42001 from a conventional security standard: the AI system impact assessment. Where risk assessment looks at consequences to the organization, impact assessment looks outward at the potential consequences of an AI system for individuals, groups, and society — fairness and bias, safety, privacy, transparency, environmental effects, and the broader rights and interests of people affected by the system's outputs.

This outward orientation is not incidental; it is the philosophical core of the standard. AI systems make consequential decisions about people, and ISO 42001 obliges an organization to assess and document those human impacts across the AI system lifecycle, to record the results, and to feed them back into how the system is designed, deployed, and monitored. The companion standard ISO/IEC 42005 provides detailed guidance on how to conduct AI system impact assessments, and organizations frequently use it alongside 42001.

Together, risk assessment and impact assessment give the AIMS its two eyes: one watching the organization's exposure, the other watching the effect on the world. A mature program treats them as continuous, not as documents produced once and shelved. Both feed the operational controls in Clause 8 and the improvement loop in Clause 10.

The Annex A controls

Clauses 4 through 10 describe the management system; Annex A tells you what controls to consider putting inside it. Annex A is a structured reference set of controls and control objectives spanning the AI lifecycle, and it functions much like Annex A in ISO/IEC 27001: it is a catalogue you draw on, not a checklist you blindly complete.

The mechanism that connects Annex A to the rest of the standard is the Statement of Applicability — a document, also familiar from ISO 27001, in which the organization records which Annex A controls it applies, which it excludes, and the justification for each decision, tied back to the risks and impacts it identified. The Statement of Applicability is one of the first artifacts a certification auditor will ask to see, because it demonstrates that the organization has reasoned deliberately about controls rather than adopting a generic template.

The Annex A control areas address the full arc of responsible AI. Without reproducing the standard, the themes they cover include:

  • Policies for AI — establishing and maintaining the organizational policies that govern AI development and use.
  • Internal organization and accountability — defining roles, responsibilities, and reporting lines so that ownership of AI decisions is clear.
  • Resources for AI systems — documenting and managing the data, tooling, computing, and human resources that AI systems depend on.
  • Impact assessment — the processes for assessing impacts on individuals and society and acting on the results.
  • The AI system lifecycle — responsible design, development, verification, deployment, operation, and eventual retirement of AI systems.
  • Data for AI systems — governance of the data used across the lifecycle, including provenance, quality, and appropriate handling.
  • Information for interested parties — transparency and the information provided to users and affected parties so they can understand and appropriately rely on the system.
  • Use of AI systems — responsible, intended use, including controls on how deployed systems are actually used in practice.
  • Third-party and supplier relationships — managing the risks that arrive through vendors, external models, and the broader AI supply chain.

The point of Annex A is to give an organization a defensible, comprehensive vocabulary of controls so that it does not have to invent responsible-AI governance from a blank page. The organization selects the controls that its risk and impact assessments justify, implements them, and records the rationale — and that documented, reasoned selection is a large part of what the auditor evaluates.

ISO 42001 does not exist in isolation. It was designed to interlock with a wider ecosystem of standards and regulations, and understanding those relationships is what lets an organization avoid duplicating effort. Here is how it sits alongside the four regimes leaders ask about most.

ISO/IEC 27001 — information security management

ISO/IEC 27001 is the established certifiable standard for an information security management system (ISMS). ISO 42001 is its sibling for AI: same harmonized clause structure, same PDCA engine, same Annex-plus-Statement-of-Applicability model, same audit and certification lifecycle. The two are complementary rather than overlapping. 27001 secures information; 42001 governs AI, adding the AI-specific requirements — impact assessment, lifecycle controls, transparency to affected parties — that a security standard was never meant to cover. Organizations already certified to 27001 are usually well positioned to add 42001 as part of an integrated management system, reusing much of the governance machinery they already run. If your security posture also needs to withstand the cryptographic threats of the coming decade, ISO 42001 governance pairs naturally with a post-quantum encryption foundation — ML-KEM-1024 (FIPS 203) for key encapsulation, a hybrid X25519 + ML-KEM key exchange, and AES-256 for data at rest and in transit.

ISO/IEC 23894 — AI risk management

ISO/IEC 23894 is the SC 42 guidance standard for AI risk management. It is not certifiable; it provides detailed direction on how to identify, analyze, evaluate, and treat AI risk. ISO 42001 requires a risk-management process, and 23894 is the natural companion that tells you how to run one well. In practice, organizations use 23894 (and the foundational ISO 31000 risk-management principles it builds on) to operationalize the risk requirements that 42001 mandates.

The NIST AI Risk Management Framework

The NIST AI RMF is a voluntary framework, published by the U.S. National Institute of Standards and Technology, organized around four functions — GOVERN, MAP, MEASURE, and MANAGE — and a set of trustworthy-AI characteristics. It is not certifiable and not a law. ISO 42001 and the NIST AI RMF are highly complementary: the RMF gives an organization a rich, well-articulated way to think about AI risk and trustworthiness, while ISO 42001 gives it a certifiable management system to operationalize and prove that thinking. Many organizations use the RMF's concepts to inform the risk and impact work that 42001's clauses require, and map their controls to both so a single control set satisfies more than one audience.

The EU AI Act

The EU AI Act is binding regulation — a law with real obligations for providers and deployers of AI systems in the European market, structured around risk tiers with the heaviest duties falling on high-risk systems. ISO 42001 is a voluntary standard, so certification to it does not by itself equal legal compliance with the Act. But the two are strongly aligned in spirit and substance: the Act requires risk management, data governance, transparency, human oversight, and quality-management-style processes, and an operating ISO 42001 AIMS produces much of the governance, documentation, and evidence those obligations demand. As harmonized standards under the Act mature, a certified management system is expected to be a practical vehicle for demonstrating conformity. In short, ISO 42001 is not a substitute for reading and meeting the law, but it is one of the most effective ways to be ready for it.

The mental model

Think of the NIST AI RMF as the vocabulary, ISO/IEC 23894 as the risk methodology, ISO/IEC 42001 as the certifiable management system that operationalizes both, and the EU AI Act as the law you must ultimately satisfy. A well-designed program maps one coherent set of controls to all four, so effort spent once counts everywhere.

Who should pursue ISO 42001, and the benefits

ISO 42001 is written to apply to any organization that provides or uses AI, but the organizations that gain the most from certifying tend to share a few traits: AI is becoming material to how they operate, they sell into or are regulated by demanding markets, and they need to demonstrate trustworthiness rather than merely claim it.

That profile includes:

  • AI providers and SaaS companies shipping AI features into enterprise and regulated markets, where a certificate shortens security reviews and unblocks procurement.
  • Financial services deploying models for credit, fraud, and decisioning, where governance and auditability are prerequisites, not niceties.
  • Healthcare and life sciences using AI in clinical, diagnostic, or operational settings, where impact on individuals is direct and consequential.
  • Public sector and government organizations that must meet high assurance and accountability expectations for AI.
  • Any enterprise whose customers, regulators, or board have begun asking how its AI is governed — and expect a credible, evidenced answer.

The benefits of pursuing and achieving certification fall into three broad categories:

Trust and market credibility

A certificate from an accredited body is independent evidence that the organization governs AI to a recognized international standard. That evidence is persuasive to customers, partners, insurers, and boards in a way that self-attestation is not. As AI trust becomes a purchasing criterion, certification becomes a differentiator.

Procurement and sales acceleration

Enterprise buyers increasingly include AI governance questions in their vendor due-diligence and security questionnaires. An ISO 42001 certificate answers many of those questions up front, shortening review cycles and removing a common source of stalled deals — much as ISO 27001 and SOC 2 do for security today.

Regulatory alignment and readiness

Because the standard's requirements overlap heavily with the substance of emerging regulation, an operating AIMS positions the organization to respond to the EU AI Act and comparable regimes with documented governance already in place, rather than scrambling to assemble it under deadline. The management system also imposes an internal discipline — risk and impact assessment, clear accountability, monitoring, and continual improvement — that reduces the likelihood of the incidents regulators are most concerned about in the first place.

The certification path

Certification against ISO 42001 follows the same well-established route as other ISO management-system certifications. The single most important point to understand is who does what: the certificate is issued by an independent, accredited certification body — not by ISO, and not by a software vendor. ISO writes the standard. An accreditation body (such as a national accreditation authority) accredits certification bodies to audit against it. The certification body performs the audit and issues the certificate. A platform or consultancy can help you prepare, but it cannot issue your certificate; if a vendor claims it can "certify" you itself, treat that as a red flag.

The path from starting point to certificate typically runs through the following stages:

  1. Readiness assessment (gap analysis). The organization compares its current AI governance against the requirements of ISO 42001 to identify where it already conforms and where gaps exist. This produces a prioritized remediation plan and a realistic view of scope, effort, and timeline.
  2. Implementation and remediation. The organization builds out the AIMS: defining scope and context, securing leadership commitment and an AI policy, running risk and impact assessments, selecting and implementing Annex A controls, producing the Statement of Applicability, and putting the required documented information in place.
  3. Internal audit and management review. Before inviting an external auditor, the organization audits itself against the standard and holds a formal management review. These are explicit requirements of Clause 9 and a prerequisite the certification body expects; they surface nonconformities while they are still cheap to fix.
  4. Stage 1 certification audit (readiness review). The certification body conducts a documentation-focused review to confirm the AIMS is designed correctly and the organization is ready to be audited in depth. Stage 1 typically identifies any areas that must be addressed before Stage 2.
  5. Stage 2 certification audit (implementation review). The certification body examines evidence that the AIMS is actually operating as designed — interviewing staff, sampling records, and testing that controls work in practice. If the system conforms, the body recommends certification; any major nonconformities must be resolved first.
  6. Certification and surveillance. On success, the certification body issues the certificate, which is typically valid for three years. During that period the body conducts periodic surveillance audits (usually annual) to confirm the AIMS remains effective, and a fuller recertification audit before the cycle renews. Certification is therefore an ongoing commitment, not a one-time event — which is exactly the point of a continual-improvement standard.
Who issues what

To be unambiguous: Deflected does not issue ISO 42001 certificates and cannot audit your management system for the purpose of certification — that role belongs exclusively to an accredited certification body. What Deflected does is help you build, evidence, and maintain the AI management system that such a body will then audit.

How a security and governance platform supports readiness

Much of the effort in reaching ISO 42001 certification is not writing policy documents — it is generating and maintaining the operational evidence that the management system is real and working. This is where a security and governance platform earns its place: it produces, in the ordinary course of operating your AI, the artifacts an internal auditor and a certification body will ask for.

Deflected's AI Governance & Compliance engagement is built for exactly this. It maps policy, controls, and evidence to the frameworks that matter — the NIST AI RMF, the EU AI Act, and SOC 2 — and helps an organization prepare the documented, operating AI management system that ISO 42001 certification requires. It is designed to make an AI program audit-ready, not merely secure, so that when a certification body arrives, the governance, the controls, and the records are already in place. You can see how this fits alongside our other frameworks on the compliance overview.

Concretely, the platform supports ISO 42001 readiness in several ways that map directly onto the standard's clauses and Annex A controls:

Governance & control mapping

Engagement

Policy, controls, and evidence mapped to recognized AI frameworks and organized so they can be reconciled against ISO 42001's clauses and Annex A — including the Statement of Applicability rationale a certification body will scrutinize.

See AI Governance & Compliance →

Operational control evidence

Recurring

An inline AI gateway that inspects prompts and responses in real time and logs every decision for audit — producing the immutable operational records that demonstrate lifecycle controls in Clause 8 are actually working, not just documented.

See Prompt Firewall →

Continuous testing & improvement

Recurring

Always-on adversarial testing that feeds the monitoring, performance-evaluation, and continual-improvement loops in Clauses 9 and 10 — turning findings into the corrective actions and evidence a surveillance audit expects to see.

See Continuous AI Red Team →

The division of labor is clean and honest: the platform and the governance engagement help you establish, operate, evidence, and continually improve the AI management system; an accredited certification body independently audits that system and, if it conforms, issues the certificate. Deflected's role is readiness and ongoing operation, not certification. That separation is not a limitation — it is what makes the certificate credible in the first place.

Frequently asked questions

What is ISO/IEC 42001?
ISO/IEC 42001 is the first international standard for an artificial intelligence management system, known as an AIMS. Published jointly by ISO and the IEC in December 2023, it specifies the requirements for establishing, implementing, maintaining, and continually improving a management system for the responsible development and use of AI within an organization. Like ISO/IEC 27001 for information security, it is a certifiable management-system standard, meaning an organization can be audited against it by an accredited certification body.
Is ISO 42001 certification mandatory?
No. ISO/IEC 42001 is a voluntary standard, not a law. Organizations choose to implement and certify against it to demonstrate responsible AI governance to customers, regulators, and partners. That said, certification can support compliance with binding regulation such as the EU AI Act by providing documented governance, risk management, and control evidence, and it is increasingly requested in enterprise procurement and vendor due diligence.
How does ISO 42001 relate to ISO/IEC 27001?
Both are certifiable management-system standards built on the same ISO harmonized high-level structure, so their clauses on context, leadership, planning, support, operation, performance evaluation, and improvement align closely. ISO/IEC 27001 governs an information security management system, while ISO/IEC 42001 governs an AI management system and adds AI-specific requirements such as AI impact assessment and Annex A controls for the AI lifecycle. Organizations already certified to 27001 can typically integrate 42001 into their existing management system rather than building a separate one.
Who issues ISO 42001 certification?
ISO 42001 certification is issued by an independent, accredited certification body, not by ISO itself and not by a software vendor. The certification body conducts a formal audit in two stages and, if the AI management system conforms to the standard, issues a certificate that is typically valid for three years with annual surveillance audits. Deflected does not issue certificates; it helps organizations prepare for and maintain the management system that an accredited body then audits.
How long does it take to get ISO 42001 certified?
Timelines vary with the size of the organization, the maturity of its existing governance, and the scope of AI systems in scope. Many organizations reach certification in roughly six to twelve months. Companies that already operate an ISO/IEC 27001 information security management system often move faster because the shared clause structure, risk methodology, and audit disciplines are already in place. The path generally runs from readiness assessment and gap remediation, through an internal audit and management review, to the certification body's Stage 1 and Stage 2 audits.

The takeaway

ISO/IEC 42001 marks a turning point in how organizations govern artificial intelligence. For the first time, there is a certifiable international standard that converts responsible-AI principles into an operating management system — with defined scope, engaged leadership, risk and impact assessment, a reasoned set of Annex A controls, monitoring, internal audit, and continual improvement — that an independent, accredited body can inspect and attest to.

Its power comes from familiarity and fit. It reuses the harmonized structure and PDCA engine that the world already trusts through ISO 27001, so it slots into existing management systems rather than displacing them. It aligns with ISO/IEC 23894 for risk, complements the NIST AI RMF's vocabulary, and produces much of the governance and evidence the EU AI Act will demand. And it answers, with a third-party certificate, the question customers and boards are increasingly asking: can you prove your AI is governed responsibly?

Getting there is a real program — readiness, implementation, internal audit, and a two-stage certification audit followed by ongoing surveillance — and the certificate itself is always issued by an accredited certification body, never by a vendor. What a security and governance platform like Deflected contributes is everything up to that line: the mapped controls, the operational evidence, and the continual-improvement discipline that make an AI management system genuinely audit-ready. Build the system well, and certification becomes the confirmation of work already done rather than a scramble at the deadline.

Get ISO 42001 ready

Book a working session with our team. We'll map your AI governance to ISO 42001's clauses and controls and show you exactly where the gaps — and the evidence — are.