web analytics
AI Governance

ISO/IEC 42001

The AI Management System Standard

The one-paragraph answer

ISO/IEC 42001 is the first international standard for artificial intelligence management systems, published in December 2023 by the International Organization for Standardization. It requires seven things from any organization using AI: leadership ownership, documented risk assessment, written operational controls, records, internal audit, management review, and corrective action. Companies aligned to ISO/IEC 42001 win RFPs, get better insurance pricing, and can answer the board question “do we have an AI management system?” without stumbling. Companies without it are already getting cut from procurement.

The pain ISO/IEC 42001 is solving for our customers

Every executive we work with tells us the same story. The board meets. Someone opens their laptop and asks: “Do we have an AI management system?” The room goes quiet. Then a buyer sends a due diligence questionnaire with the same question. Then the cyber insurance renewal shows up with an AI supplement. Then a large customer's procurement team asks for a copy of the AI policy. Four questions, from four different rooms, all pointing at the same thing.

The pain is not that leaders do not care about doing AI well. The pain is that until very recently, there was no accepted answer to the question. Leaders were left inventing their own frameworks, pulling pieces from cybersecurity standards, quality standards, and privacy regulations, and hoping the result would hold up under scrutiny. It usually did not.

Nine out of ten AI programs we assess have no written owner, no documented risk process, no operating cadence, and no audit trail. They have activity. They do not have a management system. When the board question arrives, the honest answer is “not yet.” That answer is losing companies real business right now.

ISO/IEC 42001 is what the board question was really asking about. It is what the buyer was asking about. It is what the insurer was asking about. Getting aligned to it is what closes the gap between AI activity and an AI program you can defend.

What ISO/IEC 42001 actually is, in plain English

ISO/IEC 42001 is a rulebook. Not a law. Not a certification you are forced to buy. A rulebook, published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), that describes what a well-run AI program contains.

Think of it like ISO 9001 for quality, or ISO 27001 for information security. Same shape. Same discipline. Different subject. Where ISO 27001 tells you how to run a security program, ISO/IEC 42001 tells you how to run an AI program. It went final in December 2023 and is now the reference standard that everyone else in the AI governance space points at.

Three things worth knowing at the executive level. First, ISO/IEC 42001 is voluntary. No government forces you to adopt it. Second, it is fast becoming expected. The EU AI Act cites it. Insurance underwriters cite it. Large enterprise buyers cite it. Third, you do not have to be formally certified to benefit. Alignment (following the standard without a certification audit) is enough to answer the buyer, the insurer, and the board. Certification is available if you want the credential.

ISO/IEC 42001 lives in a small family of AI standards. Its companion, ISO/IEC 22989, defines the vocabulary. ISO/IEC 23894 is the risk-management guidance. ISO/IEC 42001 is the operating standard that ties them together. If you only pick one to build against, pick ISO/IEC 42001.

What ISO/IEC 42001 requires you to do

The standard has seven main sections, called clauses, numbered 4 through 10. There is also an Annex A that lists reference controls. Here is what each one asks for, in plain language.

Clause 4: Context of the organization

Understand where AI shows up in your business. What do you use it for? Who cares about how you use it (customers, regulators, employees, investors)? What are the boundaries of your AI management system? This is the “draw the map” step. If leadership cannot describe the AI landscape in the company, this clause is why you cannot describe it: nobody has ever been asked to draw the map.

Clause 5: Leadership

Someone at the top of the company owns AI. Not IT. Not procurement. An accountable executive whose name is written down. This clause also requires a written AI policy signed by that executive. If the accountable person cannot be named in one sentence, the clause is not satisfied.

Clause 6: Planning

You have identified AI risks and set objectives for handling them. Risks include bias, security exposure, regulatory drift, and business-outcome misses. Objectives are the specific things you plan to achieve (for example, “every high-risk AI tool gets a governance review before deployment”). This is not just a risk register. It is a plan tied to the risks.

Clause 7: Support

You have the people, the training, the documented information, and the communication practices required to run the AI program. Everyone who touches AI decisions knows what their role is. This clause is why AI literacy programs exist: ISO/IEC 42001 asks whether people are competent for their AI-related roles.

Clause 8: Operation

You actually do the AI work under written controls. Every AI use case has a documented lifecycle: how it gets proposed, reviewed, approved, deployed, monitored, and retired. Third-party AI tools go through the same discipline. Data used for AI has quality standards. This is the workshop floor of the AI management system.

Clause 9: Performance evaluation

You measure how the program is doing. Monitoring runs continuously. Internal audits happen on a schedule. Management review, meaning the accountable executive sits down with the results, happens at least annually. Without measurement, the standard is not met.

Clause 10: Improvement

When something breaks or slips, you fix it in a documented way. Nonconformities get logged. Corrective actions get assigned and completed. The program gets better over time. A standard that does not require improvement is a snapshot; ISO/IEC 42001 is a living system.

Annex A: Reference controls

The standard closes with a menu of specific controls organizations should consider, covering AI policies, roles, resource provisioning, impact assessments, data management, information for AI system users, third-party relationships, and communication with interested parties. Annex A is where the general clauses turn into specific to-do items.

Why ISO/IEC 42001 matters to you

There are four groups asking about your AI management system right now, and each one uses ISO/IEC 42001 as the reference point.

Your board is asking because AI now sits inside their fiduciary duty. Under the Caremark line of cases, directors have to oversee material risk categories. AI is one. When the board asks whether you have a program, they need a defensible yes. Alignment to ISO/IEC 42001 gives them that answer.

Your buyers are asking because their own procurement policies now require it. Enterprise vendors are being ranked on AI governance maturity. Companies with no AI management system get filtered out at the questionnaire stage, before the sales team ever sees the deal. This is happening today in financial services, healthcare, insurance, and government contracting.

Your insurers are asking because AI incidents are becoming a coverage category of their own. Cyber policies now include AI supplements. Directors and officers policies now ask about AI oversight. A management system aligned to ISO/IEC 42001 improves your pricing and, in some markets, your ability to get coverage at all.

Your regulators are watching because ISO/IEC 42001 is being referenced in enforcement matters, agency guidance, and international regulation. The EU AI Act treats it as evidence of compliance for certain obligations. The Federal Trade Commission has cited it in enforcement expectations. State attorneys general are learning it. If your AI program is not aligned, the regulatory conversation becomes much harder.

Every dollar of AI activity you cannot map to ISO/IEC 42001 is a dollar of exposure. Every RFP question you cannot answer with a management-system reference is a deal at risk. Every board meeting where the answer is “we are working on it” is trust eroding. This is why ISO/IEC 42001 matters to you, right now, whether or not you plan to seek formal certification.

What the research says about ISO 42001

The academic literature on ISO 42001 is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“AI governance is a system of rules, practices and processes employed to ensure an organization's use of AI aligns with its strategies, objectives, and values.”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“the understanding of how such principles can be operationalized in designing, executing, monitoring, and evaluating AI applications is limited”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about ISO 42001 arrives from the board, the buyer, or the regulator.

How to align to ISO 42001: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under ISO 42001. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. ISO 42001 applies to any organisation developing, providing, or using AI systems, which in practice means almost everyone. Decide whether you are pursuing certification or alignment, and write down which. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. ISO 42001 Clause 5 requires this explicitly. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Clauses 4 to 10 each demand artefacts: the scope statement, the AI policy signed by the accountable executive, the risk assessment, the operational controls, the internal audit record, and the management review minutes. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, ISO 42001 becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about ISO/IEC 42001

Is ISO/IEC 42001 mandatory?

No. It is a voluntary international standard. It is, however, being referenced by regulators, buyers, and insurers as the expected baseline. Voluntary in law does not mean optional in practice.

Do we have to get certified?

No. You can align to ISO/IEC 42001 without a formal certification audit. Alignment is enough to answer most stakeholder questions. Certification is a separate step, useful when you want the credential for procurement or public disclosure.

How long does alignment take?

Most mid-sized organizations reach defensible alignment in three to six months of focused work. The clock depends on how organized the existing AI activity already is, how many use cases are in production, and how accountable the executive owner can be.

We already have ISO 27001. Does that count?

Partially. ISO 27001 covers information security controls, some of which apply to AI systems. ISO/IEC 42001 adds the AI-specific governance layer that 27001 does not address, including AI risk categories, AI impact assessment, and the accountable executive for AI. If you have 27001, you have a head start. You do not have the standard.

What is the difference between ISO/IEC 42001 and the NIST AI Risk Management Framework?

Both cover AI governance. ISO/IEC 42001 is a management system standard: a rulebook for running a program. NIST AI RMF is a framework: a set of practices for identifying and treating AI risks. They complement each other. Most organizations use NIST AI RMF for the risk-mapping work and ISO/IEC 42001 for the management-system wrapper around it.

Where does ISO/IEC 42001 come up in The AI Risk & Governance Review™?

Everywhere. Volume III of The Operating Discipline for AI Library™ is built on the operating principles of ISO/IEC 42001, mapped to NIST AI RMF, the EU AI Act, and U.S. sector rules. The Appendix L crosswalk in that book shows the line-by-line mapping between the standard's requirements and SRJ's operating artifacts. Every operating instrument in the Library—the AI Usage Policy, the AI Accountability Matrix™, the AI Operating Calendar™, the AI Risk & Governance Review™ process itself—traces back to a specific clause of ISO/IEC 42001.

Where ISO 42001 sits among the other frameworks

ISO 42001 is the management system. It is not the whole picture. Pair it with NIST AI RMF for the risk identification and treatment work, with ISO 27001 for the information security foundation beneath it, and with director oversight for the board-level accountability that makes the whole thing enforceable. Organisations that adopt one and assume it covers the others end up with a certificate and a gap.

Primary sources on ISO 42001

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning ISO 42001 that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including ISO/IEC 42001, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation