ISO/IEC 42001:2023 is the international standard that defines how organizations should build, implement, and continually improve an AI Management System (AIMS). Published in December 2023 by the International Organization for Standardization, it is the first certifiable global framework specifically designed for responsible AI governance. Organizations — not individuals — get certified against it. It applies to any entity that develops, provides, or uses AI systems.

i
Quick Answer

ISO/IEC 42001:2023 is the world's first certifiable international standard for AI Management Systems (AIMS), published in December 2023. It tells organizations — not individuals — how to structure governance around how they develop, provide, or use AI responsibly. Companies get audited and certified against it; people get certified against credentials like AIGP. They're solving related but different problems. how ISO 42001 compares to AIGP and ISACA.

If you've read through more than two or three posts on this site, you've already run into ISO 42001 — it shows up in the AIGP BoK, in certification-stack comparisons, in job postings for AI Auditor roles, and in nearly every comparison of governance frameworks. What it's never gotten here is its own full explanation. That ends now.

Dec 2023
Standard Published
10
Core Clauses
38
Annex A Controls
9
Control Domains

What Problem Does ISO 42001 Actually Solve?

Before December 2023, there was no common international answer to "how should a company structure its AI governance?" Organizations were improvising — borrowing pieces from data protection programs, security frameworks, internal ethics committees, whatever was closest at hand. ISO/IEC 42001 gave the world its first purpose-built, auditable standard for this specific problem, the same way ISO 27001 did for information security two decades earlier. ISO 42001 vs EU AI Act: key differences.

That lineage matters. ISO 42001 follows ISO's High-Level Structure (HLS) — the same shape as ISO 27001, ISO 9001, and the rest of the ISO management-system family. If your organization has ever implemented any of those, ISO 42001 will feel structurally familiar: define your context, secure leadership commitment, plan (including risk treatment), provide support, operate, evaluate performance, improve. It's the Plan-Do-Check-Act cycle, applied specifically to AI.

The Structure: Clauses 4 Through 10

The actual management system requirements live in clauses 4 through 10. Here's what each one asks an organization to do:

4

Context of the Organization

Identify internal and external factors relevant to your AI activities, and define the scope of your AI Management System.

5

Leadership

Top management must demonstrate commitment, set AI policy, and assign roles and responsibilities for AI governance.

6

Planning

Identify and assess AI-specific risks and opportunities, and plan how to treat them — this is where formal AI risk assessments live.

7

Support

Resources, competence, awareness, communication, and documented information needed to run the system.

8

Operation

Day-to-day execution — including AI System Impact Assessments, where applicable, that map closely to the kind of DPIA work privacy professionals already know.

9

Performance Evaluation

Ongoing monitoring, measurement, internal audits, and management review of how the AIMS is actually performing.

10

Improvement

Identifying nonconformities, correcting them, and continually adapting the system as AI use and risk evolve.

Annex A: The 38 Controls That Actually Do the Work

If clauses 4–10 are the skeleton, Annex A is where the real operational substance lives. It contains 38 controls organized across nine domains, covering the full AI lifecycle — from data sourcing and model development through deployment, monitoring, and eventual retirement. A few examples of what these controls actually require:

  • Policy alignment. Determining how AI policy fits with existing organizational policies, rather than operating as an isolated silo.
  • Risk assessment for AI systems. Structured evaluation of risks specific to a given AI system before and during deployment.
  • Data governance. Provenance, quality, and suitability of data used to train and operate AI systems.
  • Third-party and supplier management. Oversight of AI components or systems sourced from outside vendors.
  • Transparency and communication. Ensuring stakeholders understand what an AI system does and how it makes decisions.

Organizations don't have to implement every single control — not every control applies to every business. Instead, you document a Statement of Applicability (SoA), formally justifying which controls you've included and which you've excluded, and why. This SoA becomes one of the central artifacts an auditor reviews during certification.

Who Actually Gets Certified Here?

This is the detail that trips up the most people coming from a background in personal certifications like AIGP or CIPP: ISO 42001 certifies organizations, not individuals. You don't sit an exam and walk away "ISO 42001 certified" the way you would with AIGP. Instead, your company builds an AI Management System, and an accredited certification body audits that system against the standard.

What individuals can get certified in is auditing or implementing against this standard — credentials like the ISO/IEC 42001 Lead Auditor or Lead Implementer designations (typically administered through bodies like PECB). Those prove a person's competence to do the auditing or implementation work. They are not the same thing as the organization itself holding ISO 42001 certification. ISO 42001 Lead Auditor certification guide.

Why This Distinction Matters

If a job posting says "ISO 42001 experience required," it almost always means experience implementing or auditing against the standard — not a personal "certification" that doesn't formally exist in the way AIGP does. Get this distinction right on your resume and in interviews.

The Certification Process, Step by Step

For an organization actually pursuing certification, the path typically looks like this:

1

Build the AIMS

Implement the requirements of clauses 4–10, and select the applicable Annex A controls for your context.

2

Document the Statement of Applicability

Formally record which controls apply, which don't, and the reasoning behind each decision.

3

Engage an accredited certification body

An independent, accredited auditor — not a consultant who helped you build the system — must conduct the certification audit.

4

Pass the Stage 1 audit

A documentation review confirming your AIMS is designed correctly on paper before anyone checks whether it works in practice.

5

Pass the Stage 2 audit

An operational audit confirming the system is actually being followed, with real evidence, not just documented intentions.

For an organization with an already-mature AI governance function, this typically takes three to six months. Starting from scratch, six to twelve months is more realistic. Certification isn't permanent either — like other ISO management-system standards, it typically runs on a three-year cycle with annual surveillance audits in between, meaning ISO 42001 is an ongoing operating discipline rather than a one-time project with a certificate at the end.

ISO 42001 and the EU AI Act: Related, Not Identical

ISO 42001 is a global, voluntary standard. The EU AI Act is binding law in the European Union with mandatory obligations and real penalties. They are not the same thing, and certification against ISO 42001 does not automatically mean an organization is compliant with the EU AI Act. That said, the overlap is substantial in practice: many of the structural requirements — risk assessment, documentation, monitoring, human oversight — point in the same direction. A growing number of organizations are using ISO 42001 implementation as the practical foundation for their broader EU AI Act readiness work, even though the two remain legally distinct.

ISO 42001 vs. NIST AI RMF: What's the Difference?

These two get confused constantly because they cover similar ground. The core distinction: NIST AI RMF is a voluntary framework (covered in full in our NIST AI RMF explainer) organized around four functions — Govern, Map, Measure, Manage — with no certification attached. You can adopt it, but no external body audits you against it. ISO 42001 is a certifiable management system standard with an actual audit and certificate at the end. Many organizations use both: NIST AI RMF to shape their thinking about AI risk, ISO 42001 to formalize and certify the system that results from it.

What Certification Actually Costs an Organization

Beyond the audit fees themselves — which vary significantly by organization size and certification body — the real cost of ISO 42001 certification is the internal effort of building the AIMS itself: risk assessments, documentation, staff training, and the ongoing maintenance clause 9 requires. Organizations that already hold ISO 27001 or another ISO management-system certification tend to move faster and cheaper, since much of the leadership commitment, documentation discipline, and audit-readiness culture already exists and just needs to be extended to cover AI-specific risk rather than built from zero.

A Practical Starting Point

If your organization is evaluating whether to pursue ISO 42001, the fastest diagnostic is checking whether you already hold ISO 27001. If so, you have a meaningful head start on the leadership, documentation, and audit infrastructure the AIMS requires — the work becomes extending an existing discipline, not inventing one.

Why This Matters If You're Studying for AIGP

ISO 42001 sits inside the AIGP Body of Knowledge as one of the major governance frameworks candidates need to recognize and apply conceptually. You won't be asked to design a Statement of Applicability on exam day, but you will be expected to know what an AI Management System is, how it relates to risk-based regulation like the EU AI Act, and how it's structurally different from a purely legal or regulatory framework. Understanding the organization-versus-individual certification distinction covered above is exactly the kind of conceptual clarity AIGP exam questions tend to probe.

A Realistic Scenario: What This Looks Like in Practice

Consider a mid-size fintech company deploying an AI-driven fraud detection model. Leadership wants to demonstrate to enterprise customers and regulators that AI risk is being managed responsibly, and a customer's procurement team has started asking about ISO 42001 status during vendor reviews.

The company's compliance lead builds out the AIMS: documenting the context of their AI use (clause 4), securing executive sign-off on an AI policy (clause 5), running a formal risk assessment on the fraud model specifically (clause 6), and selecting relevant Annex A controls — data governance for the transaction data feeding the model, third-party management for any vendor components, and transparency controls for how fraud decisions get communicated to affected customers. They document a Statement of Applicability explaining why certain controls, like those specific to computer-vision systems, don't apply to their tabular-data fraud model. An accredited certification body then conducts a two-stage audit, and the company receives certification — valid for three years, with annual surveillance audits to confirm the system stays operational rather than becoming a one-time paperwork exercise.

Note what this process didn't require: no individual on the compliance team walked away with a personal "ISO 42001 certified" credential. What the company gained was an audited, certifiable management system it can point to when a customer, regulator, or insurer asks how AI risk is actually being governed — which is precisely the gap ISO 42001 was built to fill.

Frequently Asked Questions

Can an individual person become "ISO 42001 certified"?

Not in the sense of holding the organizational certification itself — that applies to a company's management system, not a person. An individual can become certified as an ISO 42001 Lead Auditor or Lead Implementer, which certifies their competence to audit or build such a system, but that's a distinct credential from the organizational certification.

Is ISO 42001 certification legally required anywhere?

No. It remains a voluntary standard globally. Organizations pursue it for competitive, contractual, or risk-management reasons — increasingly including enterprise customers requiring it of vendors, or using it as a practical foundation for EU AI Act readiness — not because any jurisdiction mandates it directly.

Does ISO 42001 certification satisfy EU AI Act compliance automatically?

No. They're legally distinct. ISO 42001 certification demonstrates a mature AI management system and can meaningfully support EU AI Act readiness given the structural overlap, but it doesn't substitute for the Act's specific binding obligations if your organization falls under its scope.

How is ISO 42001 different from ISO/IEC 42005?

ISO/IEC 42005 is a newer, narrower companion standard focused specifically on AI System Impact Assessments, while ISO 42001 is the full management-system standard. Think of 42001 as the overall operating system and 42005 as detailed guidance for one specific operational activity within it.

Bottom Line

ISO 42001 is the closest thing the AI governance world has to a universal operating system for how companies should structure responsible AI practice — auditable, certifiable, and increasingly expected by regulators, enterprise customers, and risk committees alike. It doesn't replace the EU AI Act, and it doesn't certify individuals the way AIGP does. But understanding what it actually requires, structurally, is foundational knowledge for anyone working in AI governance today.

Related reading: NIST AI RMF's four core functions explained, how to become an ISO 42001 Lead Auditor, and how ISO 42001 compares to AIGP and ISACA's tracks.