ISO/IEC 42001:2023 is the first certifiable management system standard for artificial intelligence. It sets requirements for establishing, maintaining, and continually improving an AI management system, and applies to organisations that build AI and to those that merely use it. Like other management system standards it follows the harmonised structure across clauses 4 to 10, so it can be integrated with an existing ISO 27001 system rather than run beside it.
The requirements sit in the clauses; the controls sit in Annex A. Thirty-eight controls are grouped under nine objectives running from A.2 to A.10, covering AI policy, internal organisation, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI systems, and third-party relationships. The annex is explicitly not a checklist: controls are selected against assessed risk and recorded, with justification, in a Statement of Applicability.
One requirement separates this standard from its information security sibling. ISO 27001 assesses risk to the organisation; ISO 42001 additionally requires an AI system impact assessment that considers consequences for individuals and groups of individuals, and for society. An organisation that simply relabels its existing risk register as an AI risk register will fail that requirement, because the register asks a narrower question than the standard does.
Certification comes from an accredited body on the familiar cycle: a documentation review, then an audit verifying the system operates in practice, then a certificate valid for three years with annual surveillance. What certification does not provide is conformity with the EU AI Act. That regime requires its own role determination, classification, and — for high-risk systems — a conformity assessment, with harmonised standards being developed separately under CEN-CENELEC JTC 21.