InsightsAI Governance & Compliance

ISO 42001 Explained: The New Standard for AI Management Systems

Idrak Insights TeamAugust 22, 202613 min read

ISO/IEC 42001:2023 · AIMS

Key takeaways

  • ISO/IEC 42001:2023, published in December 2023, is the world's first international, certifiable standard for AI management systems.
  • It follows the same Harmonized Structure (Annex SL) shared by other ISO management standards like ISO 27001, making it easier to integrate into existing governance rather than building something entirely separate.
  • Certification is voluntary, and its 38 Annex A controls function as a reference set, not a mandatory checklist; organizations select and justify which controls apply based on their own risk assessment.
  • As of 2026, ISO 42001 is not yet a harmonized standard under the EU AI Act, so certification alone doesn't grant automatic legal compliance, even though it demonstrates exactly the kind of governance the Act expects.
  • Real organizations are already certified, including AWS (the first major cloud provider, November 2024) and Miro, one of the first SaaS companies certified.

Introduction

Most AI governance frameworks in circulation are guidance: useful, thoughtful, and entirely voluntary in the sense that no independent body checks whether you actually followed them. ISO 42001 is different. It's a certifiable standard, meaning an accredited third party can formally audit an organization against it and issue a certificate that customers, regulators and partners can verify. That distinction matters, and so does understanding exactly what certification does and doesn't prove. This guide covers what ISO 42001 actually requires, how the certification process works, and where it sits relative to frameworks like NIST's AI RMF and binding regulation like the EU AI Act.

What ISO 42001 Actually Is

ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an AI Management System, or AIMS, within an organization. An AIMS is a structured set of policies, processes and controls governing how AI systems are designed, developed, deployed and used. The standard is built for any organization role relative to AI: producer, developer, provider or user, and applies regardless of company size or industry.

Where It Sits in the ISO Family

The ISO management system family

Harmonized Structure (Annex SL)
  • Context
  • Leadership
  • Planning
  • Support
  • Operation
  • Performance evaluation
  • Improvement
ISO 42001Artificial intelligence
ISO 27001Information security
ISO 9001Quality
ISO 22301Business continuity

ISO 42001 isn't a standalone framework built from scratch. It follows the same Harmonized Structure used across modern ISO management system standards, the same clause architecture organizations already use for ISO 27001 (information security) or ISO 9001 (quality). For any organization that already holds one of these certifications, this shared structure meaningfully lowers the lift of adding ISO 42001, since the governance skeleton, management review, internal audit, corrective action, is already familiar.

What It Actually Requires

Core AIMS components

AI Management System (AIMS)
01AI policy and governance structure
02Roles, responsibilities, accountability
03AI risk assessment (bias, safety, robustness)
04Data governance for AI systems
05Lifecycle management, design to decommissioning
06Third-party and supplier management
07Monitoring, measurement, internal audit
08Continual improvement

The standard's Annex A contains 38 controls organized around 9 objectives covering these areas in detail. Worth being precise about this: Annex A is a reference set, not a checklist to complete in full. Organizations run a risk assessment first, then select the controls that actually treat the risks they've identified, documenting both what's included and what's deliberately excluded in a Statement of Applicability that an auditor reviews. Treating it as "implement all 38" misunderstands how the standard is meant to work.

The Certification Journey

The certification path

  1. 01

    Gap assessment

    Compare current AI governance practices against the standard's requirements.

  2. 02

    Implementation

    Build out policies, controls and documentation based on the Statement of Applicability.

  3. 03

    Internal audit

    Test the AIMS against the standard before bringing in an external auditor.

  4. 04

    Stage 1 certification audit

    An accredited body reviews documentation and readiness.

  5. 05

    Stage 2 certification audit

    The body assesses whether the AIMS is actually operating as documented.

  6. 06

    Certification issued

    Valid for three years, contingent on ongoing compliance.

  7. 07

    Surveillance audits

    Typically annual, confirming the AIMS remains active and effective.

  8. 08

    Recertification

    A fuller reassessment at the end of the three-year cycle.

Who's Actually Getting Certified

This isn't a theoretical standard sitting unused. AWS became the first major cloud provider to earn accredited ISO 42001 certification in November 2024. Microsoft has pursued certification for its AI systems, stating explicitly that customers can use the certification in their own compliance assessments, while remaining responsible for their own evaluation. Miro was among the first SaaS companies certified. Certification bodies including BSI, NQA, A-LIGN, Schellman, DNV and KPMG are all now active in this market, evidence that the certification ecosystem itself has matured past the early-adopter stage.

How ISO 42001 Relates to NIST's AI RMF and the EU AI Act

Three frameworks, different roles

ISO 42001NIST AI RMFEU AI ActDocumentationRiskassessmentHumanoversightShared governance core

ISO 42001

International, certifiable standard; voluntary but independently verifiable.

NIST AI RMF

Voluntary, non-certifiable US framework built around four functions: Govern, Map, Measure, Manage.

EU AI Act

Binding law, not a voluntary framework at all, with real financial penalties for non-compliance.

Here's the nuance worth getting right: as of 2026, ISO 42001 is not a harmonized standard under the EU AI Act. Presumption of legal conformity requires a specific European harmonized standard cited in the Official Journal of the EU, and the AI Act's dedicated AI-management-system deliverable, prEN 18286, being developed by CEN-CENELEC and aligned closely with ISO 42001, is still in progress. ISO 42001 certification gives you certifiable, third-party evidence of exactly the kind of governance the Act expects, a genuine head start, but not automatic legal compliance. That status is expected to change once the harmonized standard is finalized; worth reconfirming at the point you rely on it. It's also worth noting the AI Act's own high-risk compliance deadline was itself deferred to December 2, 2027 following the Digital Omnibus on AI, giving organizations more runway than the original 2026 date suggested. If you're working through what that means in practice, our guide to AI impact assessments covers the assessment instruments the Act relies on.

Very Current: European Adoption Update

Also worth flagging directly: EN ISO/IEC 42001:2026, the European adoption of the standard, was approved by CEN on March 13, 2026. The 34 member countries involved are required to give it national-standard status by September 2026. This formalizes ISO 42001's role within the European standards landscape even ahead of the AI Act's own harmonized standard being finalized.

Should Your Organization Pursue Certification?

Is certification worth pursuing now?

Do customers, partners, or procurement processes already ask about your AI governance practices, or are you likely to face that question soon?

Does your organization already hold ISO 27001 or another Annex SL-structured certification, making integration meaningfully easier?

Are you developing or deploying AI systems that would qualify as high-risk under emerging regulation, where demonstrable governance matters most?

Is competitive differentiation valuable in your market while the certified population is still relatively small?

Do you have the internal capacity for an ongoing management system, not just a one-time policy document, since surveillance audits are recurring?

The more of these you answer yes to, the stronger the case for starting a gap assessment now rather than waiting for the harmonized standard.

Sources

  • ISO, "ISO 42001 explained" official guidance (iso.org)
  • Microsoft, ISO/IEC 42001 compliance documentation (learn.microsoft.com)
  • BSI, ISO 42001 AI Management System certification information (bsigroup.com)
  • CEN, EN ISO/IEC 42001:2026 European adoption, approved March 13, 2026

This article reflects publicly available standards information as of July 2026. ISO 42001's relationship to the EU AI Act's harmonized standards is actively evolving; verify current status before relying on certification for regulatory purposes.

Frequently Asked Questions

What is ISO 42001?+

The world's first international, certifiable standard for AI management systems, published December 2023, specifying requirements for establishing and maintaining an AI Management System (AIMS).

Is ISO 42001 certification mandatory?+

No, certification is voluntary, chosen by organizations wanting independent confirmation their AI governance meets the standard.

Does ISO 42001 certification mean you're compliant with the EU AI Act?+

Not automatically. It's not currently a harmonized standard under the Act, so certification doesn't grant automatic legal presumption of conformity, though it demonstrates the kind of governance the Act expects.

What's the difference between ISO 42001 and NIST's AI Risk Management Framework?+

NIST's AI RMF is a voluntary, non-certifiable US framework. ISO 42001 is an international standard organizations can be independently certified against, complementary rather than competing.

What are the 38 Annex A controls?+

A reference set of controls across 9 objectives; organizations select applicable ones based on their own risk assessment rather than implementing all of them by default.

Which companies have achieved ISO 42001 certification?+

AWS (November 2024, first major cloud provider), Miro (among the first SaaS companies), and Microsoft, with certification bodies including BSI, NQA, A-LIGN, Schellman, and KPMG active in the market.

Advisory

Building an AI management system worth certifying? Idrak advises on AI governance and compliance.

Explore our AI Solutions practice