Skip to content

ISO 42001

ISO/IEC 42001 is the international standard for an artificial intelligence management system: the governance, risk processes, documentation and oversight an organisation runs around its use of AI, certifiable by a third party. It is to AI governance what ISO 27001 is to information security, and it is much newer.

The standard certifies how an organisation governs its AI, which is close to what the EU AI Act asks a provider to document, without being the same thing.

Why it matters when the plan changes

Procurement teams will increasingly ask for it for the same reason they ask for ISO 27001: it is a short answer to a long question. For a supplier of systems used in employment decisions, the management system it describes overlaps heavily with what the AI Act requires of a high-risk provider, including the documented quality management system in Article 17 and the risk management system in Article 9, so building toward one is building toward the other.

The tension is that a certificate can be mistaken for a compliance finding. Certification shows a management system operates. Conformity with the AI Act is a separate assessment against the Act's own requirements, such as the risk management system Article 9 mandates be established, implemented, documented and maintained. A supplier holding the first has not thereby established the second, and saying otherwise is a claim that cannot be evidenced.

In practice

A procurement questionnaire asks whether the supplier is ISO 42001 certified and whether it is AI Act compliant, as two rows. The accurate answer to both is what has been built, what it is being built against, and what has and has not been independently assessed. A yes in either row that means something weaker is the answer that fails the follow-up question.

Evidence

What it cannot tell you

ISO 42001 certifies that a management system operates; it does not certify that any given AI system is accurate, fair or lawful in a particular use. It is silent on the substance of a specific high-risk system's performance, and a certificate against it is not equivalent to conformity assessment under any specific AI regulation.

Questions

The governance of AI inside an organisation: policy, roles, risk assessment, impact assessment, data and model lifecycle controls, documentation, monitoring and continual improvement. It is written as a management system standard, so it describes how the organisation operates rather than what any specific model does.

No. Certification is a third-party finding that a management system conforms to the standard. AI Act compliance is conformity with specific requirements, such as the risk management system Article 9 requires be established, implemented, documented and maintained. The first supports the second and does not replace it.

Either can. A provider certifies how it governs the systems it builds; a deployer certifies how it governs the systems it uses. In employment, both have obligations under the Act, and an employer using assessment systems at scale may find its own certification asked for.

It was published in late 2023, so certification bodies, auditors and interpretation are all still maturing. A certificate today says less about consistency of interpretation than an ISO 27001 certificate does, simply because far fewer audits have been done against it.

What governance actually exists: how risks are assessed, how models are versioned and tested, how fairness and accuracy are checked, how incidents are handled, and what documentation the supplier can produce for the buyer's own assessment. Those answers are what the certificate would summarise.