Skip to content

ISO/IEC 42001

The first certifiable standard for artificial intelligence management systems. Voluntary, and less optional every year.

What ISO 42001 is

ISO/IEC 42001 defines an artificial intelligence management system. Published in December 2023, it is the first certifiable standard dedicated to how an organisation develops, provides or uses AI systems.

It follows the common management system structure, so if you already hold ISO 27001 the skeleton will look familiar. What changes is the subject: where ISO 27001 manages information security risk, ISO 42001 manages risk arising from the use of AI, including risk to people.

Its Annex A holds 38 controls.

Who ISO 42001 applies to

No organisation by legal obligation. It is adopted under market pressure and in anticipation of regulation:

  • Companies developing or embedding AI in their product
  • Vendors whose customers are starting to ask about AI governance
  • Organisations that want a management structure in place before the EU AI Act becomes enforceable for them

What ISO 42001 requires

The usual management system requirements: context, leadership, planning, support, operation, performance evaluation and improvement. Applied to AI.

And on top of that, what is specific to the standard: assessment of the impact of AI systems on people and society, life cycle management, data governance, and the 38 Annex A controls with their objectives.

How ISO 42001 is demonstrated

With certification issued by an independent accredited body, on the same cycle model as ISO 27001.

With Zerod

ISO 42001 and the AI Act solve the same problem from two sides. In Zerod they live in the same place.

Activate ISO 42001 and Zerod gives you the 38 Annex A controls with their implementation guidance, and organises evidence collection against each one. The Statement of Applicability is built from the audit module.

Frequently asked questions

Does ISO 42001 make me compliant with the EU AI Act?

No. ISO 42001 is a voluntary management system standard; the AI Act is a legal obligation with its own requirements. They overlap across much of the governance work, but certifying exempts you from nothing.

Do I need ISO 27001 before ISO 42001?

It is not a prerequisite. They share a structure, so having it already saves work, but ISO 42001 can be approached on its own.

ISO/IEC 42001 · Zerod