
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
The first certifiable international standard for AI management systems — what its 38 Annex A controls require, and how it relates to the EU AI Act.
If your organization already holds ISO/IEC 27001, ISO/IEC 42001 will look structurally familiar — the same Plan-Do-Check-Act management-system logic, the same internal audit and management review machinery, applied to a different subject: how you govern the AI systems you build, provide, or use, rather than how you secure information generally.
Published in December 2023, ISO 42001 is the first international standard for an AI management system (AIMS) — a structured, auditable way to govern AI development and use, modeled on the same framework family as ISO 9001 (quality) and ISO 27001 (information security). It's not a technical standard for how an AI model itself should work; it's a management-system standard for how an organization governs its use of AI, the same relationship ISO 27001 has to information security generally rather than to any specific technology.
ISO 42001's Annex A sets out 38 controls organized into 9 control objectives, covering AI policy, internal organization, resources, impact assessment, the AI system lifecycle, data governance for AI systems, transparency to interested parties, responsible use of AI systems, and third-party and supplier relationships. That last category matters more than it might sound — most organizations' actual AI risk today comes from a vendor's foundation model or a third-party AI feature bolted into a SaaS product they already use, not a model they built themselves, and ISO 42001 explicitly treats that supply-chain exposure as in scope.
Certification is issued by an accredited certification body (the same model as ISO 27001), runs on a 3-year cycle with annual surveillance audits required to maintain it, and typically takes 6 to 12 months from a standing start, with initial audit costs commonly running $5,000 to $30,000 or more depending on scope. It's already been achieved by major AI providers — AWS, Anthropic, and Microsoft all hold it — which matters if you're evaluating vendors: asking whether a provider is ISO 42001 certified is a genuine, verifiable signal, not a vague reassurance.
Not on its own — ISO 42001 certification doesn't automatically discharge any specific EU AI Act obligation, and no regulator has said otherwise. What it does do is build exactly the governance structures, risk assessments, and documentation discipline that feed directly into the Act's own technical documentation requirements — genuinely complementary infrastructure, not a substitute for legal compliance work. The same logic applies to NIST's AI Risk Management Framework: ISO 42001 gives you the certifiable management-system shell, the RMF's Govern/Map/Measure/Manage functions give you the underlying risk-process content, and neither one replaces actually reading the specific law that binds you in whichever jurisdiction you're regulated in.
For an organization that already runs ISO 27001, the incremental lift is meaningfully smaller than building an AIMS from a cold start — the internal audit program, document control, and management review structure your ISMS already requires largely carries over, with AI-specific risk assessment and lifecycle controls layered on top rather than an entirely separate system. For an organization with no existing ISO management system, it's a heavier undertaking, and worth scoping honestly against how much of your actual business genuinely depends on AI before committing to a 6-12 month certification process.
If you're deciding whether ISO 42001 is worth pursuing, or need the underlying governance and risk-assessment work done regardless of whether you ultimately certify, our Cybersecurity Consulting team can help scope what an AI management system would actually need to look like for your real environment, and our AI Services engagements provide the adversarial testing evidence a genuine impact assessment — Annex A's own requirement — actually depends on.
Tell us about your environment and goals — we'll help you scope the right engagement.