Published in 2023, ISO/IEC 42001 is the first international standard for managing artificial intelligence, according to the International Organization for Standardization. It gives an organization a certifiable way to govern the AI it builds, buys, or uses, by defining an AI management system and the controls that sit inside it. In plain terms, ISO/IEC 42001:2023 is an AI management system standard: it sets out what a responsible AI governance system must contain, from leadership and risk planning through to operation, audit, and improvement. The AI Governance Certification Institute (AIGCI) builds its training around this standard, because it has quickly become the reference point organizations and regulators look to.

ISO/IEC 42001 is an international management system standard that specifies requirements for establishing, implementing, maintaining, and continually improving an artificial intelligence management system (AIMS) within an organization.

Key facts at a glance

Attribute

Detail

Full name

ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system

Published

2023

What it is

The first international AI management system (AIMS) standard

Structure

Clauses 4 to 10, plus Annex A controls

Annex A

38 AI-specific controls across 9 control objectives (A.2 to A.10)

Who it is for

Any organization that develops, provides, or uses AI

Certifiable

Yes, organizations can achieve accredited certification

What ISO/IEC 42001:2023 actually is

ISO/IEC 42001 belongs to the same family as widely used standards such as ISO 9001 for quality and ISO/IEC 27001 for information security. Like them, it is a management system standard, which means it does not tell you which AI models to build. Instead it defines the AI management system it defines, the set of policies, roles, processes, and controls an organization uses to govern AI responsibly and repeatedly. It is voluntary and certifiable, which sets it apart from a framework like the NIST AI Risk Management Framework, which offers valuable guidance but cannot be certified against. That certifiability is the reason ISO/IEC 42001 has become the anchor for demonstrating AI governance to customers, partners, and regulators.

How the standard is structured

ISO/IEC 42001 follows the high-level structure shared across modern ISO management standards, so anyone who has worked with ISO 27001 will recognise its shape. The management requirements sit in Clauses 4 to 10 and follow the Plan, Do, Check, Act cycle of continual improvement. Alongside them, Annex A adds the AI-specific controls.

Figure 1. The structure of ISO/IEC 42001: management requirements in Clauses 4 to 10, plus 38 Annex A controls.

The seven management clauses cover context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A then sets out 38 controls organised under 9 control objectives, spanning AI policy, internal roles, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI systems, and third-party relationships. For a clause-by-clause walkthrough, see clauses 4-10. The important point for now is the split: the clauses tell you how to run the system, and Annex A tells you which AI-specific risks to control.

Why ISO/IEC 42001 matters now

The standard arrived just as AI regulation gained teeth. Under the EU AI Act, penalties reach up to 35 million euro or 7 percent of worldwide annual turnover for the most serious violations, whichever is higher for large firms. That level of exposure has made a recognised, auditable way to show responsible AI governance genuinely valuable. ISO/IEC 42001 does not replace the law, and it is not a shortcut to compliance, but it gives organizations a structured, independently checkable system that maps closely to what regulators and international bodies expect. Its emphasis on risk, transparency, and human oversight aligns with the OECD AI Principles and with the direction of the EU regulatory framework for AI, which is why adopting it is increasingly treated as a mark of maturity rather than a nice to have.

Who should use it, and how certification works

ISO/IEC 42001 is written for any organization in the AI value chain, whether you develop AI, embed it in a product, or simply deploy tools built by others. An organization demonstrates conformity by building the management system and then undergoing an audit by an accredited certification body, which is a different thing from the professional certifications that individuals earn. If you are pursuing certification for your organization, our guide on how to get certified walks through the steps. Individuals, by contrast, build their expertise through professional certifications such as Foundation, Lead Implementer, and Lead Auditor.

ISO/IEC 42001 at a Glance.

The seven management clauses (Clauses 4 to 10)

Clause

What it requires

What you produce

4. Context

Understand your organization, its AI, and interested parties

Defined AIMS scope

5. Leadership

Top management commitment, an AI policy, and assigned roles

Policy and role assignments

6. Planning

Address AI risks and opportunities and set objectives

Risk assessment and objectives

7. Support

Provide resources, competence, awareness, and documentation

Trained people and records

8. Operation

Run the AI processes and controls day to day

Operating records and evidence

9. Performance evaluation

Monitor, measure, audit, and review the AIMS

Internal audit and review results

10. Improvement

Correct problems and improve the system continually

Corrective actions and updates

The nine Annex A control objectives (A.2 to A.10)

Objective

Focus

Example of what it covers

A.2 AI policy

Direction

A documented, approved AI policy

A.3 Internal organization

Accountability

Roles, responsibilities, and reporting

A.4 Resources

Inputs

Data, tooling, compute, and people

A.5 Impact assessment

Risk to people

Assessing effects of AI systems

A.6 AI system life cycle

Build and run

Responsible development and deployment

A.7 Data for AI

Data quality

Data provenance, quality, and governance

A.8 Information for parties

Transparency

What you tell users and stakeholders

A.9 Use of AI systems

Responsible use

Intended use and human oversight

A.10 Third-party relationships

Supply chain

Governing vendors and suppliers

 

Getting started with ISO/IEC 42001

A practical first step is to read the standard against what your organization already does. Most teams find they have pieces in place, a policy here, a risk process there, but no single system that connects them or produces evidence on demand. ISO/IEC 42001 gives that connective structure a recognised shape. Put simply, it is the first international AI management system standard, it is organised into Clauses 4 to 10 plus 38 Annex A controls, it is certifiable, and it has become the common language for proving that AI is governed well. Everything else in AI governance tends to hang off those points.

Frequently asked questions

Is ISO/IEC 42001 a law?

No. It is a voluntary international standard. Laws such as the EU AI Act are mandatory, but adopting ISO/IEC 42001 helps an organization build the governance structures those laws expect.

What is the difference between ISO 42001 and an AIMS?

ISO/IEC 42001 is the standard, the document that sets the requirements. An AIMS, or AI management system, is the working system an organization builds to meet those requirements.

How many controls does ISO 42001 have?

Annex A contains 38 controls grouped under 9 control objectives, from A.2 to A.10. They cover areas such as AI policy, impact assessment, data, and third-party relationships.

Can a person be certified in ISO 42001?

Organizations are certified against the standard. Individuals earn professional certifications, such as Foundation or Lead Implementer, that show they can help implement or audit an AIMS.

How does ISO 42001 relate to ISO 27001?

They share the same high-level structure, so they integrate well. ISO 27001 governs information security; ISO 42001 governs AI. Many organizations run them together.

Learn the standard properly

The most direct way to understand ISO/IEC 42001 in depth is to train against it. AIGCI's professional ISO 42001 certifications take you from the fundamentals through implementation and audit, so the standard becomes something you can apply rather than just describe. To see how the institute structures its programme, read more about the institute.