An independent, third-party certification body · operating to ISO/IEC 17021-1:2015
Verify a Certificate ↗·Global · Remote & on-site·EN
Certification

What ISO/IEC 42001 actually asks of you

The question arrives in a procurement form. Describe your AI governance framework. Sometimes it is one line in a security questionnaire that has run to nine pages. Sometimes a customer’s legal team has sent it directly.

Either way the organisation receiving it is usually in the same position: several AI features already in production, no single person accountable for them, and three weeks to produce an answer that sounds deliberate.

ISO/IEC 42001 is what that question is reaching for.

The idea underneath it

ISO/IEC 42001:2023 is an AI management system standard. It follows the same structure as ISO 9001 and ISO/IEC 27001, built on the shared clauses 4 to 10 that every modern management system standard uses, with a set of AI-specific reference controls attached.

What it asks is narrower than people expect, and more useful:

Do you know which AI systems you are running, what they are for, who is accountable for each one, and what you would do if one behaved badly?

That is the whole idea. Not a philosophy of machine ethics. An inventory, an owner, a risk assessment, and a route for something to be escalated, stopped or rolled back by someone with the authority to do it.

Most organisations discover, working through it, that the hard part is not the controls. It is the inventory. Very few can produce a complete list of the AI systems and third-party models in use across their own product.

What the standard requires

In outline, ISO/IEC 42001 asks you to:

  • Identify the AI systems you develop, provide or use, and what each is for
  • Decide which roles your organisation occupies, whether developer, provider or deployer, because the obligations differ
  • Assess the risks each system creates, including risks to people affected by it rather than only risks to you
  • Apply controls proportionate to those risks, and record why the ones you excluded were excluded
  • Keep human oversight meaningful, with a named accountable owner rather than a committee
  • Handle incidents, monitor systems in operation, and improve on what you find
A team leader looking over the shoulder of a developer at a workstation
Governance is not a document. It is a named person who has to answer for a decision.

The phrase to hold onto is impact on people. A quality management system asks whether the output was correct. An AI management system also asks who was affected by it, and whether they had any route to contest it.

The thing it is assumed to prove, and does not

This is the most important paragraph in this article, and it is the one most often left out.

ISO/IEC 42001 certification does not make an AI system compliant with the EU AI Act.

The mechanism people have in mind is Article 40. Under it, applying a harmonised standard, meaning one published in the Official Journal of the European Union for that purpose, earns a presumption of conformity. The burden shifts, and a provider is taken to have met the relevant requirement unless shown otherwise.

ISO/IEC 42001 is not cited as a harmonised standard under the AI Act. It therefore confers no presumption of conformity. A separate European standard, prEN 18286, is being developed for that role.

The practical difference matters. A provider of a high-risk system still has to evidence the quality management system obligations the Act sets out in Article 17, element by element. Holding a 42001 certificate is a strong organisational signal and a genuine head start on that work. It is not the legal shield it is often sold as.

Two colleagues reviewing output on a monitor together
The standard asks what you did when the model was wrong, not whether it ever was.

What else it does not do

An honest account has to include the rest.

It does not certify your models. ISO/IEC 42001 certifies the management system around them. A certified organisation can still ship a model that is biased, wrong, or unsafe. What the standard asks is that the organisation notices, records it, finds the cause, and changes something. That is the same logic ISO 9001 applies to a defective unit.

It does not certify your training data. Data governance sits inside the system’s scope, but no auditor certifies a dataset as fair.

It does not make you better than an uncertified competitor. It demonstrates that you have a system and that an independent party has examined it.

How to check a 42001 certificate

If you are the buyer rather than the seller, this part is worth knowing, because 42001 is new enough that the market has not settled.

Accredited certification against ISO/IEC 42001 runs under ISO/IEC 17021-1 together with ISO/IEC 42006:2025, published on 7 July 2025, which sets what a certification body must demonstrate before an accreditation body will put AI management systems into its scope.

Accreditation is granted per standard, not in general. A certification body accredited for ISO 9001 or ISO/IEC 27001 does not thereby hold ISO/IEC 42001. So the question to ask about any 42001 certificate is not are they accredited. It is is 42001 inside the scope they are accredited for, and that is checkable on the accreditation body’s own schedule.

The same applies to the certificate in front of you: read its scope statement. It names which systems and which activities were assessed. A narrow scope, honestly stated, is worth more than a broad one that will not survive reading.

Where it starts

It starts, as every management system does, with scope: deciding which AI systems and which parts of the business are being certified. That scope is what appears on the certificate, and it is what your customer reads when they check it.

Get the scope wrong and the certificate says something you did not intend.

If a customer has already sent you that question about your AI governance framework, you know what it costs not to have an answer. The question is whether the next one finds you ready.