In this article
Introduction
Most AI governance frameworks in circulation are guidance: useful, thoughtful, and entirely voluntary in the sense that no independent body checks whether you actually followed them. ISO 42001 is different. It's a certifiable standard, meaning an accredited third party can formally audit an organization against it and issue a certificate that customers, regulators and partners can verify. That distinction matters, and so does understanding exactly what certification does and doesn't prove. This guide covers what ISO 42001 actually requires, how the certification process works, and where it sits relative to frameworks like NIST's AI RMF and binding regulation like the EU AI Act.
What ISO 42001 Actually Is
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an AI Management System, or AIMS, within an organization. An AIMS is a structured set of policies, processes and controls governing how AI systems are designed, developed, deployed and used. The standard is built for any organization role relative to AI: producer, developer, provider or user, and applies regardless of company size or industry.
Where It Sits in the ISO Family
The ISO management system family
- Context
- Leadership
- Planning
- Support
- Operation
- Performance evaluation
- Improvement
ISO 42001 isn't a standalone framework built from scratch. It follows the same Harmonized Structure used across modern ISO management system standards, the same clause architecture organizations already use for ISO 27001 (information security) or ISO 9001 (quality). For any organization that already holds one of these certifications, this shared structure meaningfully lowers the lift of adding ISO 42001, since the governance skeleton, management review, internal audit, corrective action, is already familiar.
What It Actually Requires
Core AIMS components
The standard's Annex A contains 38 controls organized around 9 objectives covering these areas in detail. Worth being precise about this: Annex A is a reference set, not a checklist to complete in full. Organizations run a risk assessment first, then select the controls that actually treat the risks they've identified, documenting both what's included and what's deliberately excluded in a Statement of Applicability that an auditor reviews. Treating it as "implement all 38" misunderstands how the standard is meant to work.
The Certification Journey
The certification path
- 01
Gap assessment
Compare current AI governance practices against the standard's requirements.
- 02
Implementation
Build out policies, controls and documentation based on the Statement of Applicability.
- 03
Internal audit
Test the AIMS against the standard before bringing in an external auditor.
- 04
Stage 1 certification audit
An accredited body reviews documentation and readiness.
- 05
Stage 2 certification audit
The body assesses whether the AIMS is actually operating as documented.
- 06
Certification issued
Valid for three years, contingent on ongoing compliance.
- 07
Surveillance audits
Typically annual, confirming the AIMS remains active and effective.
- 08
Recertification
A fuller reassessment at the end of the three-year cycle.
Who's Actually Getting Certified
This isn't a theoretical standard sitting unused. AWS became the first major cloud provider to earn accredited ISO 42001 certification in November 2024. Microsoft has pursued certification for its AI systems, stating explicitly that customers can use the certification in their own compliance assessments, while remaining responsible for their own evaluation. Miro was among the first SaaS companies certified. Certification bodies including BSI, NQA, A-LIGN, Schellman, DNV and KPMG are all now active in this market, evidence that the certification ecosystem itself has matured past the early-adopter stage.
How ISO 42001 Relates to NIST's AI RMF and the EU AI Act
Three frameworks, different roles
ISO 42001
International, certifiable standard; voluntary but independently verifiable.
NIST AI RMF
Voluntary, non-certifiable US framework built around four functions: Govern, Map, Measure, Manage.
EU AI Act
Binding law, not a voluntary framework at all, with real financial penalties for non-compliance.
Here's the nuance worth getting right: as of 2026, ISO 42001 is not a harmonized standard under the EU AI Act. Presumption of legal conformity requires a specific European harmonized standard cited in the Official Journal of the EU, and the AI Act's dedicated AI-management-system deliverable, prEN 18286, being developed by CEN-CENELEC and aligned closely with ISO 42001, is still in progress. ISO 42001 certification gives you certifiable, third-party evidence of exactly the kind of governance the Act expects, a genuine head start, but not automatic legal compliance. That status is expected to change once the harmonized standard is finalized; worth reconfirming at the point you rely on it. It's also worth noting the AI Act's own high-risk compliance deadline was itself deferred to December 2, 2027 following the Digital Omnibus on AI, giving organizations more runway than the original 2026 date suggested. If you're working through what that means in practice, our guide to AI impact assessments covers the assessment instruments the Act relies on.
Very Current: European Adoption Update
Also worth flagging directly: EN ISO/IEC 42001:2026, the European adoption of the standard, was approved by CEN on March 13, 2026. The 34 member countries involved are required to give it national-standard status by September 2026. This formalizes ISO 42001's role within the European standards landscape even ahead of the AI Act's own harmonized standard being finalized.
Should Your Organization Pursue Certification?
Is certification worth pursuing now?
Do customers, partners, or procurement processes already ask about your AI governance practices, or are you likely to face that question soon?
Does your organization already hold ISO 27001 or another Annex SL-structured certification, making integration meaningfully easier?
Are you developing or deploying AI systems that would qualify as high-risk under emerging regulation, where demonstrable governance matters most?
Is competitive differentiation valuable in your market while the certified population is still relatively small?
Do you have the internal capacity for an ongoing management system, not just a one-time policy document, since surveillance audits are recurring?
The more of these you answer yes to, the stronger the case for starting a gap assessment now rather than waiting for the harmonized standard.
Sources
- ISO, "ISO 42001 explained" official guidance (iso.org)
- Microsoft, ISO/IEC 42001 compliance documentation (learn.microsoft.com)
- BSI, ISO 42001 AI Management System certification information (bsigroup.com)
- CEN, EN ISO/IEC 42001:2026 European adoption, approved March 13, 2026
This article reflects publicly available standards information as of July 2026. ISO 42001's relationship to the EU AI Act's harmonized standards is actively evolving; verify current status before relying on certification for regulatory purposes.
Frequently Asked Questions
What is ISO 42001?+
The world's first international, certifiable standard for AI management systems, published December 2023, specifying requirements for establishing and maintaining an AI Management System (AIMS).
Is ISO 42001 certification mandatory?+
No, certification is voluntary, chosen by organizations wanting independent confirmation their AI governance meets the standard.
Does ISO 42001 certification mean you're compliant with the EU AI Act?+
Not automatically. It's not currently a harmonized standard under the Act, so certification doesn't grant automatic legal presumption of conformity, though it demonstrates the kind of governance the Act expects.
What's the difference between ISO 42001 and NIST's AI Risk Management Framework?+
NIST's AI RMF is a voluntary, non-certifiable US framework. ISO 42001 is an international standard organizations can be independently certified against, complementary rather than competing.
What are the 38 Annex A controls?+
A reference set of controls across 9 objectives; organizations select applicable ones based on their own risk assessment rather than implementing all of them by default.
Which companies have achieved ISO 42001 certification?+
AWS (November 2024, first major cloud provider), Miro (among the first SaaS companies), and Microsoft, with certification bodies including BSI, NQA, A-LIGN, Schellman, and KPMG active in the market.
