Published in December 2023, ISO/IEC 42001 is the first certifiable standard dedicated to the management of artificial intelligence. It gives organisations a structured, and above all auditable, framework for designing, deploying and operating AI systems responsibly, at the very moment the European AI Act comes into application. For a management team wondering how to prove that it keeps its AI under control, this is now the most widely recognised answer.

Key facts

  • ISO/IEC 42001:2023, official title Information technology, Artificial intelligence, Management system, published in December 2023 by the joint committee ISO/IEC JTC 1/SC 42 (source: ISO).
  • The world's first standard for an AI management system, built on the proven model of ISO 9001 and ISO/IEC 27001.
  • Annex A: 38 controls across 9 control objectives (A.2 to A.10), selected through a statement of applicability.
  • Certifiable by a third party, following a two-stage audit conducted by an accredited body.
  • AI Act: Regulation (EU) 2024/1689, in force since 1 August 2024 (source: EUR-Lex).

A management standard, not a technical one

ISO/IEC 42001 does not say how to train a model, which architecture to choose or what performance threshold to aim for. It defines an AI management system: the organisation, responsibilities, processes and evidence that allow a company to demonstrate that it governs its AI. The distinction matters. An excellent technical team can ship a high-performing model without leaving any trace that would allow anyone, six months later, to say who approved what, on which data, and with what safeguards. That is exactly the gap the standard fills.

It was developed by ISO/IEC JTC 1/SC 42, the joint ISO and IEC subcommittee devoted to artificial intelligence, and builds on standards already available: ISO/IEC 22989 for concepts and terminology, ISO/IEC 23894 for AI risk management.

A familiar architecture: the harmonized structure

Like every recent management system standard, 42001 follows the harmonized structure and the PDCA cycle (plan, do, check, act). Its auditable requirements run across clauses 4 to 10: context of the organisation, leadership, planning, support, operation, performance evaluation, improvement.

That kinship is not an administrative detail, it is an operational shortcut. An organisation already running an ISO/IEC 27001 ISMS or an ISO 9001 QMS already has its management review, internal audit, documented information control and nonconformity handling. It does not need to build a parallel system: it extends the one it has. In practice, that markedly reduces the workload: most of the management machinery is already there, and only needs extending to AI systems.

The operational core: Annex A and its 38 controls

The standard comes with a reference set of 38 controls across 9 control objectives, numbered A.2 to A.10: AI policy, internal organisation, resources for AI systems, impact assessment, AI system life cycle, data governance, information for interested parties, responsible use, and third-party and customer relationships.

As with ISO/IEC 27001, these controls do not apply mechanically: the organisation produces a statement of applicability justifying the inclusion or exclusion of each one against its risk assessment. Three informative annexes complete the picture: Annex B guides the implementation of the controls, Annex C lists the objectives and risk sources specific to AI (bias, security, explainability, data quality), and Annex D covers application by domain and by sector.

What really sets 42001 apart: the impact assessment

A conventional management system assesses risks to the organisation. 42001 asks for more: an assessment of the impacts of AI systems on individuals, groups and society. Fairness, transparency, safety of the people concerned, effects on populations that are neither customers nor employees of the organisation.

This is the requirement that unsettles organisations used to management standards the most, because it demands looking beyond the company's own boundary. It comes with two other AI-specific pillars: governance of the data feeding the models (quality, provenance, preparation) and control of the life cycle, from design to retirement of the system.

Certifiable, and that is what changes everything

Voluntary frameworks already existed, starting with the NIST AI RMF, which offers a risk management methodology. But a voluntary framework cannot be certified: there is no third-party auditor, no statement of applicability, and no certificate to show a client or a prime contractor.

ISO/IEC 42001 is certifiable by a third party, following a two-stage audit conducted by an accredited body. For an organisation that sells services embedding AI, or that buys them, this is currently the main way to publicly demonstrate governed AI without having to open up its code or its models.

One piece in a regulatory ecosystem

These frameworks are complementary rather than competing. The NIST AI RMF provides the risk management method. ISO/IEC 42001 provides the auditable management system. The European AI Act, Regulation (EU) 2024/1689 in force since 1 August 2024, provides the legal obligation, with its provisions applying in stages.

42001 is expected to be taken up at European level by CEN-CENELEC and could contribute to the presumption of conformity with the AI Act. That is something to watch rather than something acquired: the list of harmonised standards is still being built, and we will not present as settled an equivalence that is not.

Where to start

  1. Map your AI systems and the role you hold for each one: provider, developer, user. The role determines the obligations.
  2. Set the scope of the management system: which systems, which processes, which entities.
  3. Assess the risks and evaluate the impacts, two distinct exercises, both required.
  4. Build the statement of applicability for the 38 Annex A controls, justifying every exclusion.
  5. Graft onto what exists rather than duplicate it, if you already run an ISMS or a QMS.
  6. Audit internally, close the gaps, then go for the certification audit.

Free resource

ISO/IEC 42001:2023 self-assessment grid

Position your organisation against the 33 key requirements of the standard, clauses 4 to 10 and the Annex A objectives, with a conformity score and a dashboard computed automatically. HEMC Excel file, available in French, English, Spanish and Arabic.

Download the free grid

How HEMC supports organisations

We help organisations map their AI systems and the roles they hold in them, run the risk assessment and the impact assessment, build the statement of applicability and prepare for the certification audit. Where an ISMS already exists, we systematically favour extending it over building a second system: it is faster, cheaper, and it avoids running two management reviews where one is enough. To go further, read our guide on corporate cybersecurity in Morocco and ISO/IEC 27001, follow our ISO standards watch, discover our information security expertise or talk to our consultants.

This article is provided for information purposes and does not constitute legal advice. The reference texts prevail: consult the official publication of ISO/IEC 42001 and the text of Regulation (EU) 2024/1689.