Published in 2023, ISO/IEC 42001 is the first international standard for managing artificial intelligence, according to the International Organization for Standardization. It gives an organization a certifiable way to govern the AI it builds, buys, or uses, by defining an AI management system and the controls that sit inside it. In plain terms, ISO/IEC 42001:2023 is an AI management system standard: it sets out what a responsible AI governance system must contain, from leadership and risk planning through to operation, audit, and improvement. The AI Governance Certification Institute (AIGCI) builds its training around this standard, because it has quickly become the reference point organizations and regulators look to.
ISO/IEC 42001 is an international management system standard that specifies requirements for establishing, implementing, maintaining, and continually improving an artificial intelligence management system (AIMS) within an organization.
Key facts at a glance
|
Attribute |
Detail |
|---|---|
|
Full name |
ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system |
|
Published |
2023 |
|
What it is |
The first international AI management system (AIMS) standard |
|
Structure |
Clauses 4 to 10, plus Annex A controls |
|
Annex A |
38 AI-specific controls across 9 control objectives (A.2 to A.10) |
|
Who it is for |
Any organization that develops, provides, or uses AI |
|
Certifiable |
Yes, organizations can achieve accredited certification |
What ISO/IEC 42001:2023 actually is
ISO/IEC 42001 belongs to the same family as widely used standards such as ISO 9001 for quality and ISO/IEC 27001 for information security. Like them, it is a management system standard, which means it does not tell you which AI models to build. Instead it defines the AI management system it defines, the set of policies, roles, processes, and controls an organization uses to govern AI responsibly and repeatedly. It is voluntary and certifiable, which sets it apart from a framework like the NIST AI Risk Management Framework, which offers valuable guidance but cannot be certified against. That certifiability is the reason ISO/IEC 42001 has become the anchor for demonstrating AI governance to customers, partners, and regulators.
How the standard is structured
ISO/IEC 42001 follows the high-level structure shared across modern ISO management standards, so anyone who has worked with ISO 27001 will recognise its shape. The management requirements sit in Clauses 4 to 10 and follow the Plan, Do, Check, Act cycle of continual improvement. Alongside them, Annex A adds the AI-specific controls.

Figure 1. The structure of ISO/IEC 42001: management requirements in Clauses 4 to 10, plus 38 Annex A controls.
The seven management clauses cover context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A then sets out 38 controls organised under 9 control objectives, spanning AI policy, internal roles, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI systems, and third-party relationships. For a clause-by-clause walkthrough, see clauses 4-10. The important point for now is the split: the clauses tell you how to run the system, and Annex A tells you which AI-specific risks to control.
Why ISO/IEC 42001 matters now
The standard arrived just as AI regulation gained teeth. Under the EU AI Act, penalties reach up to 35 million euro or 7 percent of worldwide annual turnover for the most serious violations, whichever is higher for large firms. That level of exposure has made a recognised, auditable way to show responsible AI governance genuinely valuable. ISO/IEC 42001 does not replace the law, and it is not a shortcut to compliance, but it gives organizations a structured, independently checkable system that maps closely to what regulators and international bodies expect. Its emphasis on risk, transparency, and human oversight aligns with the OECD AI Principles and with the direction of the EU regulatory framework for AI, which is why adopting it is increasingly treated as a mark of maturity rather than a nice to have.
Who should use it, and how certification works
ISO/IEC 42001 is written for any organization in the AI value chain, whether you develop AI, embed it in a product, or simply deploy tools built by others. An organization demonstrates conformity by building the management system and then undergoing an audit by an accredited certification body, which is a different thing from the professional certifications that individuals earn. If you are pursuing certification for your organization, our guide on how to get certified walks through the steps. Individuals, by contrast, build their expertise through professional certifications such as Foundation, Lead Implementer, and Lead Auditor.
ISO/IEC 42001 at a Glance.
The seven management clauses (Clauses 4 to 10)
|
Clause |
What it requires |
What you produce |
|---|---|---|
|
4. Context |
Understand your organization, its AI, and interested parties |
Defined AIMS scope |
|
5. Leadership |
Top management commitment, an AI policy, and assigned roles |
Policy and role assignments |
|
6. Planning |
Address AI risks and opportunities and set objectives |
Risk assessment and objectives |
|
7. Support |
Provide resources, competence, awareness, and documentation |
Trained people and records |
|
8. Operation |
Run the AI processes and controls day to day |
Operating records and evidence |
|
9. Performance evaluation |
Monitor, measure, audit, and review the AIMS |
Internal audit and review results |
|
10. Improvement |
Correct problems and improve the system continually |
Corrective actions and updates |
The nine Annex A control objectives (A.2 to A.10)
|
Objective |
Focus |
Example of what it covers |
|---|---|---|
|
A.2 AI policy |
Direction |
A documented, approved AI policy |
|
A.3 Internal organization |
Accountability |
Roles, responsibilities, and reporting |
|
A.4 Resources |
Inputs |
Data, tooling, compute, and people |
|
A.5 Impact assessment |
Risk to people |
Assessing effects of AI systems |
|
A.6 AI system life cycle |
Build and run |
Responsible development and deployment |
|
A.7 Data for AI |
Data quality |
Data provenance, quality, and governance |
|
A.8 Information for parties |
Transparency |
What you tell users and stakeholders |
|
A.9 Use of AI systems |
Responsible use |
Intended use and human oversight |
|
A.10 Third-party relationships |
Supply chain |
Governing vendors and suppliers |
Getting started with ISO/IEC 42001
A practical first step is to read the standard against what your organization already does. Most teams find they have pieces in place, a policy here, a risk process there, but no single system that connects them or produces evidence on demand. ISO/IEC 42001 gives that connective structure a recognised shape. Put simply, it is the first international AI management system standard, it is organised into Clauses 4 to 10 plus 38 Annex A controls, it is certifiable, and it has become the common language for proving that AI is governed well. Everything else in AI governance tends to hang off those points.
Frequently asked questions
Is ISO/IEC 42001 a law?
No. It is a voluntary international standard. Laws such as the EU AI Act are mandatory, but adopting ISO/IEC 42001 helps an organization build the governance structures those laws expect.
What is the difference between ISO 42001 and an AIMS?
ISO/IEC 42001 is the standard, the document that sets the requirements. An AIMS, or AI management system, is the working system an organization builds to meet those requirements.
How many controls does ISO 42001 have?
Annex A contains 38 controls grouped under 9 control objectives, from A.2 to A.10. They cover areas such as AI policy, impact assessment, data, and third-party relationships.
Can a person be certified in ISO 42001?
Organizations are certified against the standard. Individuals earn professional certifications, such as Foundation or Lead Implementer, that show they can help implement or audit an AIMS.
How does ISO 42001 relate to ISO 27001?
They share the same high-level structure, so they integrate well. ISO 27001 governs information security; ISO 42001 governs AI. Many organizations run them together.
Learn the standard properly
The most direct way to understand ISO/IEC 42001 in depth is to train against it. AIGCI's professional ISO 42001 certifications take you from the fundamentals through implementation and audit, so the standard becomes something you can apply rather than just describe. To see how the institute structures its programme, read more about the institute.