STANDARDS

ISO/IEC 42001 AI Management System

ISO/IEC 42001 is the international standard for establishing, implementing, maintaining, and continually improving an artificial intelligence management system (AIMS) within organisations that provide or use AI-based products and services.

Section 01 · The standard

What ISO 42001 establishes

ISO/IEC 42001:2023 is the first certifiable management system standard for artificial intelligence. It sets requirements for establishing, maintaining, and continually improving an AI management system, and applies to organisations that build AI and to those that merely use it. Like other management system standards it follows the harmonised structure across clauses 4 to 10, so it can be integrated with an existing ISO 27001 system rather than run beside it.

The requirements sit in the clauses; the controls sit in Annex A. Thirty-eight controls are grouped under nine objectives running from A.2 to A.10, covering AI policy, internal organisation, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI systems, and third-party relationships. The annex is explicitly not a checklist: controls are selected against assessed risk and recorded, with justification, in a Statement of Applicability.

One requirement separates this standard from its information security sibling. ISO 27001 assesses risk to the organisation; ISO 42001 additionally requires an AI system impact assessment that considers consequences for individuals and groups of individuals, and for society. An organisation that simply relabels its existing risk register as an AI risk register will fail that requirement, because the register asks a narrower question than the standard does.

Certification comes from an accredited body on the familiar cycle: a documentation review, then an audit verifying the system operates in practice, then a certificate valid for three years with annual surveillance. What certification does not provide is conformity with the EU AI Act. That regime requires its own role determination, classification, and — for high-risk systems — a conformity assessment, with harmonised standards being developed separately under CEN-CENELEC JTC 21.

42001:2023
First AI management system standard
38
Annex A controls
9
Control objectives, A.2 to A.10
3 years
Certification cycle
SoA
Statement of Applicability required
What the standard enumerates

Implementation is measured against the published structure of the standard rather than a private maturity model. Each cell represents one entry; point at a group to see its contents. Counts are the complete sets.

Control objectives A.2 to A.10, holding 38 controls

9 of 24
  • A.2 Policies related to AI
  • A.3 Internal organisation
  • A.4 Resources for AI systems
  • A.5 Assessing impacts of AI systems
  • A.6 AI system life cycle
  • A.7 Data for AI systems
  • A.8 Information for interested parties
  • A.9 Use of AI systems
  • A.10 Third-party and customer relationships
Section 02 · Adoption drivers

Why organisations certify an AI management system

ISO 42001 is rarely pursued for its own sake. It is adopted because an enterprise customer has started asking how AI use is governed and will not accept a policy document as the answer, because a board wants a defensible position before approving further AI spending, or because a regulatory programme is coming and management wants a structure to hang it on. The certificate answers a procurement question quickly; the management system is what makes the answer true.

  1. 01 Customer and procurement pressure Buyers ask how AI use is governed, and a certificate closes the question faster than a policy pack. Strength 5 of 5
  2. 02 Structure ahead of the AI Act An AIMS gives the inventory, roles and records that AI Act work needs, without being a conformity assessment. Strength 4 of 5
  3. 03 Existing ISO 27001 system The harmonised structure lets one management system carry both standards rather than duplicating audits. Strength 4 of 5
  4. 04 Impact assessment gap Clause 6 and control A.5 require effects on people and society to be assessed, which most risk registers do not cover. Strength 3 of 5
  5. 05 Board assurance for AI spending Management review and internal audit give a repeatable basis for approving further deployment. Strength 2 of 5
Indicative strength on a 1–5 scale, based on Up Secure engagement patterns.
Organisations building AI products

The life cycle controls in A.6 and the data controls in A.7 apply directly to development, from design records through data provenance to release decisions.

Organisations using bought AI

The standard applies to users as well as builders, with A.9 covering responsible use and A.10 the third-party relationships that most AI risk now arrives through.

Certified ISO 27001 organisations

A shared harmonised structure means one context, leadership, internal audit and management review process can serve both standards, with a combined audit reducing duplication.

Section 03 · How Up Secure helps

Where you will get supported

The areas we work in, and where each one falls across the certification lifecycle. The services that deliver them are listed further down.

Areas of support across the ISO 42001 certification lifecycle
ISO 42001 support by certification stage
Area of support PrepareImplementCertifyMaintain
Advisory & leadership
AIMS scope and consulting Covered during Prepare Covered during Implement Covered during Certify Covered during Maintain
AI policy and decision rights Covered during Prepare Covered during Implement Covered during Certify Covered during Maintain
Management reviews Not covered during Prepare Not covered during Implement Covered during Certify Covered during Maintain
Assessment & assurance
Gap analysis against Annex A Covered during Prepare Covered during Implement Not covered during Certify Not covered during Maintain
AI risk assessment Covered during Prepare Covered during Implement Not covered during Certify Not covered during Maintain
AI system impact assessment Covered during Prepare Covered during Implement Covered during Certify Not covered during Maintain
Internal audit Not covered during Prepare Not covered during Implement Covered during Certify Covered during Maintain
Third-party and model provenance review Not covered during Prepare Covered during Implement Covered during Certify Covered during Maintain
Enablement & tooling
Statement of Applicability and records Covered during Prepare Covered during Implement Covered during Certify Not covered during Maintain
AI literacy and role-based training Not covered during Prepare Covered during Implement Covered during Certify Covered during Maintain
Section 04 · Related services

Services supporting ISO 42001 implementation

The catalogue below is selected from the live service graph and grouped by area of expertise. Implementation support and certification stay separate: the certification audit is performed by an accredited body, which cannot also be the party that designed the system it assesses.

Audits and Assessments

Systematic compliance audits, security assessments, and maturity evaluations across GDPR, ISO 27001, NIS 2, SOC 2, and AI Act frameworks for organizations in regulated industries.

AI System Privacy & Ethical Risk Audit

AI system audit covering data protection, ethical risks, bias assessment, and GDPR/AI Act compliance gaps.

AI ActISO 42001
Read more

AI Act Compliance Audit

EU AI Act compliance audit — risk classification, gap analysis, and conformity assessment for AI systems.

AI ActISO 42001
Read more

Consultancy and Advisory

Strategic consultancy and implementation advisory across GDPR, AI Act, ISO 27001, NIS 2, and cybersecurity for organizations building compliance programs or making security architecture decisions.

AI Act Implementation Consultancy

AI Act implementation consulting — governance framework, policies, roles, and conformity roadmap for AI deployers.

AI ActISO 42001
Read more

Role Outsourcing

Dedicated specialist roles including DPO, Privacy Engineer, Security Engineer, vCISO, and AI Compliance Officer available on a fractional or full-time outsourced basis.

AI Security Officer

Outsourced AI Compliance Officer — AI Act oversight, risk monitoring, and governance coordination for AI deployers.

AI ActISO 42001
Read more
Start the conversation

Scope an ISO 42001 engagement from your AI inventory, not from a policy template.

The first conversation defines the management-system boundary against the AI you actually run — who owns each system, which supplier provides it, and what it decides or influences. The Statement of Applicability follows from that, and it is the first document a certification auditor reads.

Why Up Secure
Inventory before policy A policy written against an unknown estate describes an organisation that does not exist, and the first internal audit will say so.
Impact, not only risk Clause 6 and control A.5 require effects on people and society to be assessed. An existing security risk register does not answer that question.
Integrated with ISO 27001 The harmonised structure lets one management system carry both standards, with a combined audit rather than two.
Section 05 · Frequently asked

Questions asked before committing to an AIMS

Frequently asked questions

Does ISO 42001 certification establish AI Act compliance?
No. The two answer different questions. ISO 42001 certifies that a management system for AI exists and operates; the AI Act requires a determination of the organisation's role, a classification of each system, and — for high-risk systems — a conformity assessment, registration, and post-market monitoring. Harmonised standards supporting the AI Act are being developed separately under CEN-CENELEC JTC 21. A certified AIMS makes that work substantially easier to run without discharging any of it.
How does it differ from ISO 27001?
The structure is shared; the risk question is not. ISO 27001 assesses risk to the organisation and its information. ISO 42001 additionally requires an AI system impact assessment addressing effects on individuals, on groups of individuals, and on society. That is a genuinely wider frame, and it is the requirement most often underestimated, because an existing security risk register cannot be relabelled to satisfy it.
Does it apply to organisations that only use bought-in AI?
Yes. The standard covers organisations that provide or use products and services involving AI. For a user, the weight falls on control area A.9, covering responsible use, and A.10, covering third-party and customer relationships — which is where most AI risk now enters an organisation. The development-oriented controls in A.6 will simply be marked as not applicable, with the reasoning recorded in the Statement of Applicability.
Are all 38 Annex A controls mandatory?
No. Annex A is a reference set, not a checklist. Controls are selected on the basis of the risk and impact assessments, and the Statement of Applicability records which apply, which do not, and why in each case. That document is what an auditor examines first, because it shows whether the selection was reasoned or simply copied.
Can it be certified together with ISO 27001?
Yes, and it usually should be. Both follow the harmonised structure, so context, leadership, competence, internal audit, management review, and improvement can be operated once and audited once. Certification bodies routinely offer combined or integrated audits. Running two separate management systems for overlapping scopes creates duplicate evidence and, eventually, contradictory records.
Where should implementation start?
With scope and inventory. The AIMS boundary has to be defined against the organisation's actual AI activities, which means knowing what AI is in use, who owns it, which supplier provides it, and what it decides or influences. Policy comes after that, not before — a policy written against an unknown estate describes an organisation that does not exist, and the first internal audit will say so.