ISO/IEC 42001:2023 is the international standard for AI management systems, published by the International Organization for Standardization in December 2023. It provides a structured framework for organisations to establish, implement, maintain, and continuously improve responsible AI governance, regardless of the type or scale of AI they use.
Key point: ISO 42001 is a management system standard, not a technical standard. It specifies what governance processes, policies, and accountability structures an organisation should have, not how to build an AI model. The target audience is the organisation managing AI, not the data scientist building it.
ISO/IEC 42001, the international management system standard for artificial intelligence, published in December 2023, against which organisations can be independently certified.
ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS). It follows the same Annex SL structure as ISO 27001 and ISO 9001, making it integrable with existing management systems. APRA's 30 April 2026 industry letter implicitly positioned it as the de facto answer to its expectation of "globally recognised control frameworks" for AI.
Source: ISO/IEC 42001:2023
The standard follows the same ten-clause high-level structure as ISO 27001 and ISO 9001, covering:
Scope, references, definitions
Defines what the standard covers and key AI governance terms.
Context of the organisation
Understanding internal and external context; identifying interested parties and their AI-related expectations.
Leadership
Top management commitment; AI governance policy; roles and responsibilities.
Planning
AI risk and opportunity assessment; AI objectives and planning to achieve them.
Support
Resources; competence; awareness; communication; documented information.
Operation
AI impact assessment; AI system lifecycle controls; data governance; supplier relationships.
Performance evaluation
Monitoring and measurement; internal audit; management review.
Improvement
Nonconformity and corrective action; continual improvement.
Alongside the ten management clauses, ISO 42001 carries a normative Annex A of 38 reference controls grouped under nine control objectives, numbered A.2 to A.10. Organisations do not implement all 38 by default: they select the applicable controls through a Statement of Applicability driven by their AI risk and impact assessment, the same mechanism ISO 27001 uses for information security.
Policies related to AI
Management direction and a documented AI policy.
Internal organization
Roles, responsibilities and reporting lines for AI.
Resources for AI systems
Data, tooling, compute and human resources for AI.
Assessing impacts of AI systems
Assessing AI system impacts on individuals, groups and society.
AI system life cycle
Responsible design, development and deployment controls.
Data for AI systems
Data quality, provenance and governance across the pipeline.
Information for interested parties
Transparency and documentation for users and affected parties.
Use of AI systems
Responsible, intended use and operating controls.
Third-party and customer relationships
Allocating AI responsibilities across the supply chain.
ISO 42001 is certified by independent third-party certification bodies, not self-declared. Those bodies are accredited against ISO/IEC 42006:2025, the standard that sets AI-specific requirements for auditing and certifying AI management systems (published July 2025). Certification runs as a two-stage audit: Stage 1 reviews the documented management system and readiness, and Stage 2 tests whether the controls are implemented and effective in practice. The certificate is valid for three years, maintained by annual surveillance audits, with recertification before it expires.
The two frameworks are complementary rather than equivalent. ISO 42001 provides the governance management system; the EU AI Act provides the legal compliance requirements. An organisation with ISO 42001 certification has strong AI governance, but still needs to assess and address EU AI Act obligations separately.
ISO 42001 provides
EU AI Act requires additionally
This page is general information about ISO/IEC 42001 and AI management system certification, not legal, regulatory, or professional advice, and it does not capture every nuance, exception, or certification-body-specific requirement. Standards, accreditation rules, and how ISO 42001 interacts with laws like the EU AI Act can change and are often fact-specific. Always verify current requirements against ISO, an accredited certification body, and your own qualified legal counsel before relying on it.
Standard: ISO/IEC 42001:2023 · Last reviewed July 2026
Free self-assessment