What is ISO 42001?
ISO/IEC 42001 is the world's first international standard for AI Management Systems (AIMS). Published in December 2023, it provides a structured framework for organisations to manage AI responsibly, covering risk management, accountability, transparency, monitoring, and continuous improvement. It is certifiable through independent third-party audit.
Who needs ISO 42001 certification?
ISO 42001 applies to any organisation that develops AI, sells AI products, or uses AI tools in its operations, regardless of size or sector. It is particularly relevant for organisations selling AI products to enterprise clients, operating in regulated industries where AI governance is scrutinised, using AI in decisions that affect individuals, or seeking to demonstrate responsible AI practices to customers and partners.
How is ISO 42001 different from having an AI policy?
An AI policy is a statement of intent. ISO 42001 certification requires demonstrated evidence that you have a working management system: you know which AI systems you are running, you have assessed the risks, someone is accountable for each system, you have tested for bias, you monitor performance, and an independent auditor has verified all of this is actually happening. It is the difference between aspiration and evidence.
How long does ISO 42001 certification take?
Organisations that already hold ISO 27001 typically achieve certification in 3 to 6 months, since the management system structure is already in place. Organisations starting from scratch should plan for 9 to 12 months. Larger organisations with complex AI portfolios may need longer.
How much does ISO 42001 certification cost?
Costs vary by organisation size and AI complexity. Smaller organisations with narrow scope are most cost-efficient. Mid-size organisations face higher costs as AI systems, stakeholders, and documented processes increase. The most commonly underestimated cost is internal staff time — whoever leads the implementation will invest significant hours over several months.
What is the relationship between ISO 42001 and ISO 27001?
ISO 42001 is designed to complement ISO 27001, not replace it. ISO 27001 covers information security management broadly. ISO 42001 addresses the specific challenges AI introduces: bias, explainability, autonomous decision-making, model drift, and ethical dimensions. Organisations with ISO 27001 have a significant head start because the management system structure, audit discipline, and governance practices transfer directly.
What are the 38 controls in ISO 42001?
ISO 42001 includes 38 controls grouped into nine areas: AI policies, internal roles and responsibilities, resources, impact assessments, lifecycle management, data governance, transparency with affected parties, responsible use, and third-party supplier relationships. They are risk-driven — you implement the controls relevant to your situation and document your reasoning for any exclusions in a Statement of Applicability.
What is an AI impact assessment under ISO 42001?
An AI impact assessment evaluates the potential effect of an AI system on real people — on fairness, rights, and society — before the system goes live. ISO 42001 requires these assessments as part of its lifecycle management controls. It is not enough to ask whether an AI tool works; you must ask whether it works fairly and for whom.
How does the ISO 42001 certification process work?
The process has five stages: a gap analysis (optional but recommended), building the management system (policies, risk assessments, controls, training), Stage 1 audit (documentation review), Stage 2 audit (on-site verification that the system is operating), and certificate issuance. The certificate is valid for three years with annual surveillance audits.
Does ISO 42001 apply if we only use AI tools but do not develop them?
Yes. The standard applies to any organisation that uses AI in its operations, not just developers. If you use AI tools for customer service, hiring, fraud detection, or any operational purpose, ISO 42001 provides a framework for governing that usage responsibly.
What is a Statement of Applicability in ISO 42001?
The Statement of Applicability documents which of the 38 Annex A controls your organisation has implemented, how they are implemented, and — for any excluded controls — why they do not apply. Auditors examine every exclusion. You cannot skip a control simply because it is inconvenient.
Is ISO 42001 certification legally required?
ISO 42001 is a voluntary standard, not a legal requirement. However, enterprise customers and regulated-sector procurement processes are increasingly expecting it. The EU AI Act and other emerging regulations align closely with ISO 42001's requirements, making certification a practical way to demonstrate compliance readiness.
How does ISO 42001 support ethical AI governance?
ISO 42001 supports ethical AI governance by providing a structured framework for establishing, maintaining and improving an Artificial Intelligence Management System (AIMS). The standard helps organizations manage AI-related risks, promote transparency and accountability, define roles and responsibilities and create processes for responsible AI development and deployment. It enables organizations to align AI practices with ethical principles and governance best practices.