Skip to content

Framework

ISO 42001, the AI management system standard

Reviewed 25 August 2026

ISO 42001

ISO/IEC 42001 is the international standard for AI management systems, published in December 2023. It specifies requirements for establishing, implementing, maintaining and continually improving governance over AI systems within an organisation. UK and EU organisations deploying AI use ISO 42001 to evidence responsible AI practice to regulators, customers and investors.

Definition

What is ISO 42001?

ISO/IEC 42001 is a management system standard, which means it certifies a way of working rather than a product. It follows the same Annex SL structure as ISO 27001 and ISO 9001: context, leadership, planning, support, operation, performance evaluation and improvement. Anyone who has run an ISO 27001 programme will recognise the shape immediately.

What makes ISO 42001 different is Annex A. Its controls cover things no previous management standard addressed: AI system impact assessment, data provenance and quality for training, allocation of responsibility across the AI lifecycle, transparency to affected parties, and human oversight of automated decisions. These are the controls that map most directly onto what the EU AI Act expects a high-risk provider to already have in place.

ISO 42001 is not a legal obligation anywhere. Its value is evidential: it is the most direct existing way to demonstrate to a regulator, an enterprise customer or an investment committee that AI governance inside the organisation is systematic rather than improvised.

Who ISO 42001 applies to

  • Organisations developing AI systems, including anyone fine-tuning or materially adapting a third-party model.
  • Organisations deploying AI in decisions that affect people - hiring, credit, pricing, triage, eligibility, content moderation.
  • Suppliers to regulated sectors who are now receiving AI-specific questions inside enterprise security questionnaires.
  • Providers preparing for EU AI Act Annex III obligations, which apply from 2 December 2027 after the Digital Omnibus deferral.
  • Any organisation whose board has asked who is accountable for an AI system already in production.

The path

How long does ISO 42001 actually take?

Realistic elapsed durations for an organisation starting without a dedicated compliance function. Elapsed time, not effort - the two are routinely confused when this gets scoped.

  1. 013-5 weeks

    Gap analysis and scope

    Establish which AI systems are in scope, including the ones nobody has declared. Assess current practice against the ISO 42001 clauses and Annex A controls, and produce a prioritised gap register. Scope definition is where most of the eventual cost is decided.

  2. 022-4 months

    Build the management system

    Draft the AI policy, the impact assessment methodology, the roles and responsibilities matrix and the lifecycle controls. Stand up the AI system inventory. This is the bulk of the work and the part that benefits most from being run as sprints rather than a document exercise.

  3. 032-3 months

    Operate and generate evidence

    The management system has to actually run before it can be audited. Complete impact assessments on real systems, hold the governance meetings, log the decisions, and run at least one internal audit and one management review. Auditors look for evidence of operation, not the existence of documents.

  4. 046-10 weeks

    Stage 1 and Stage 2 audit

    Stage 1 checks the management system is documented and ready. Stage 2, typically four to six weeks later, tests whether it is genuinely operating. Certification follows once any non-conformities are closed, with surveillance audits annually thereafter.

Cost and internal effort figures are being confirmed with the practice before publication: cost and effort figures · Q15

Failure points

Where ISO 42001 programmes usually go wrong

Not the theory. The specific things that cause a delayed audit, a major non-conformity, or a certificate that does not survive its first surveillance visit.

Scoping to the AI you know about

The inventory built in week one is almost never complete. Teams have models in spreadsheets, vendor features that quietly became AI, and staff using consumer tools on company data. A scope drawn around the declared systems fails at Stage 2 when the auditor finds one that was not declared.

Treating impact assessment as a form

The AI system impact assessment is the substantive control in Annex A. Filled in retrospectively to satisfy the auditor it adds no value and reads as exactly that. It has to sit before deployment in the actual release process, with the authority to stop a release.

No named accountable owner

ISO 42001 requires allocated responsibility across the AI lifecycle. Distributing it across a committee means nobody owns it. Auditors probe this directly, and 'the AI working group' is not an answer that survives the question 'who signed off on this deployment?'.

Ignoring the supply chain

Most organisations do not train models, they consume them. Provenance, licensing, training data claims and change notification from model providers are all in scope, and they are the hardest evidence to obtain retrospectively. Start supplier engagement early - it has the longest lead time in the whole programme.

Running it as a documentation project

A complete document set with no operating record fails. The standard requires demonstrated operation: meetings held, decisions logged, incidents handled, an internal audit completed and a management review minuted. That evidence takes calendar time and cannot be compressed at the end.

Assuming ISO 27001 covers it

ISO 27001 covers information security, not AI-specific risk. Bias, explainability, human oversight, model drift and training data provenance are outside its scope. An existing ISMS gives a real head start on the management system clauses, but the Annex A controls are new work.

Dates that apply

The deadlines attached to ISO 42001

  • In force · 2 months agoArticle 50 transparency obligations apply
  • Deferred · 14 months awayAnnex III standalone high-risk system obligations apply
  • In force · since 2023Certifiable now

Verified 25 August 2026Full regulatory horizon ->

How we run it

ISO 42001, delivered in sprints

  • 01A discovery sprint that finds the AI actually in use, including shadow AI, rather than the AI on the register.
  • 02Scope and gap analysis delivered as a prioritised backlog, so remediation can start in week two instead of after a report.
  • 03Policy, impact assessment methodology and lifecycle controls drafted with your engineers, in your tooling, not handed over as templates.
  • 04The AI inventory stood up as something your team maintains, because an inventory nobody updates fails the first surveillance audit.
  • 05Internal audit and management review run properly, so the evidence exists before Stage 1 rather than being assembled for it.
  • 06Stage 1 and Stage 2 audit support, including handling the questions the auditor will actually ask.

Choosing between them

ISO 42001 or ISO 27001?

ISO 27001 certifies how an organisation manages information security. ISO 42001 certifies how it manages AI. They share the same Annex SL skeleton, so an existing ISO 27001 management system carries most of the clause-level work across - context, leadership, internal audit, management review. What does not carry across is Annex A: AI impact assessment, data provenance, human oversight and lifecycle responsibility are new controls with no ISO 27001 equivalent. In practice, organisations with a live ISMS reach ISO 42001 materially faster, and organisations with neither should usually do ISO 27001 first, because most enterprise customers still ask for it by name.

ISO 27001

FAQ

ISO 42001: questions people actually ask

Is ISO 42001 mandatory?

ISO 42001 is not mandatory anywhere. No jurisdiction requires certification. It is used voluntarily as evidence, and increasingly it is required contractually rather than legally - enterprise customers and public sector buyers have begun asking for it in procurement, which is a faster-moving pressure than regulation.

Does ISO 42001 make an organisation EU AI Act compliant?

No. ISO 42001 certification does not confer EU AI Act compliance and is not a recognised presumption of conformity. The two overlap substantially - impact assessment, risk management, documentation, human oversight and post-market monitoring all appear in both - so an ISO 42001 management system covers a significant share of what a high-risk provider must demonstrate. It is a strong foundation, not a substitute.

How long does ISO 42001 certification take?

Six to twelve months of elapsed time is realistic for an organisation starting without an existing management system, with roughly seven to nine months typical. Organisations already certified to ISO 27001 usually reach it in four to seven months, because the clause-level management system already exists and only the AI-specific Annex A controls are new. The constraint is rarely effort, it is the operating evidence, which needs calendar time to accumulate.

What is the difference between ISO 42001 and the NIST AI Risk Management Framework?

ISO 42001 is a certifiable management system standard: an accredited body audits it and issues a certificate. The NIST AI Risk Management Framework is voluntary guidance with no certification path. NIST AI RMF is often the better starting point for structuring AI risk thinking, and ISO 42001 is what an organisation certifies against once it needs to prove that thinking to somebody else.

Can a small organisation certify to ISO 42001?

Yes. ISO 42001 scales with the scope of AI use rather than headcount, so an organisation with three AI systems certifies a much smaller management system than one with thirty. Small organisations frequently certify faster because approval paths are shorter and the AI inventory is genuinely knowable. The binding constraint is having someone who can own it, not company size.

What does ISO 42001 certification cost?

Cost splits into the certification body's audit fees, which vary with scope and headcount, and the internal or consulting effort to build and operate the management system, which is normally the larger figure. Cloudgap publishes indicative figures only where they reflect delivered engagements, and those figures are being confirmed before publication rather than estimated here.