Category: ISO 42001 & AI governance
ISO/IEC 42001 is the first certifiable management-system standard for artificial intelligence. Published in 2023, it specifies how to establish and run an AI Management System — governance for how AI is developed, deployed, monitored and retired.
It follows the same Annex SL structure as ISO 27001 and ISO 9001, so organisations with an existing management system can extend rather than rebuild. What is distinctive is Annex A’s AI-specific controls and the AI impact assessment, which considers effects on individuals and society, not just on the organisation.
Its commercial relevance is tied to the EU AI Act, the world’s first comprehensive AI law, which classifies systems into prohibited, high-risk, limited-risk and minimal-risk tiers and imposes substantial obligations on high-risk systems. ISO 42001 does not make you compliant with the Act, but it is the most credible way to evidence that AI governance is being managed systematically.
The NIST AI Risk Management Framework covers similar ground through four functions — Govern, Map, Measure and Manage — but is voluntary and not certifiable. Many organisations use the RMF to do the risk work and ISO 42001 to get it certified.
The guides below cover ISO 42001’s requirements and Annex A controls, the certification path, the EU AI Act’s risk tiers, deadlines, documentation requirements and scope, and how ISO 42001 compares with the NIST AI RMF.