Framework
ISO 42001, the AI management system standard
Reviewed 25 August 2026
ISO 42001
ISO/IEC 42001 is the international standard for AI management systems, published in December 2023. It specifies requirements for establishing, implementing, maintaining and continually improving governance over AI systems within an organisation. UK and EU organisations deploying AI use ISO 42001 to evidence responsible AI practice to regulators, customers and investors.
Definition
What is ISO 42001?
ISO/IEC 42001 is a management system standard, which means it certifies a way of working rather than a product. It follows the same Annex SL structure as ISO 27001 and ISO 9001: context, leadership, planning, support, operation, performance evaluation and improvement. Anyone who has run an ISO 27001 programme will recognise the shape immediately.
What makes ISO 42001 different is Annex A. Its controls cover things no previous management standard addressed: AI system impact assessment, data provenance and quality for training, allocation of responsibility across the AI lifecycle, transparency to affected parties, and human oversight of automated decisions. These are the controls that map most directly onto what the EU AI Act expects a high-risk provider to already have in place.
ISO 42001 is not a legal obligation anywhere. Its value is evidential: it is the most direct existing way to demonstrate to a regulator, an enterprise customer or an investment committee that AI governance inside the organisation is systematic rather than improvised.
Who ISO 42001 applies to
- Organisations developing AI systems, including anyone fine-tuning or materially adapting a third-party model.
- Organisations deploying AI in decisions that affect people - hiring, credit, pricing, triage, eligibility, content moderation.
- Suppliers to regulated sectors who are now receiving AI-specific questions inside enterprise security questionnaires.
- Providers preparing for EU AI Act Annex III obligations, which apply from 2 December 2027 after the Digital Omnibus deferral.
- Any organisation whose board has asked who is accountable for an AI system already in production.
The path
How long does ISO 42001 actually take?
Realistic elapsed durations for an organisation starting without a dedicated compliance function. Elapsed time, not effort - the two are routinely confused when this gets scoped.
- 013-5 weeks
Gap analysis and scope
Establish which AI systems are in scope, including the ones nobody has declared. Assess current practice against the ISO 42001 clauses and Annex A controls, and produce a prioritised gap register. Scope definition is where most of the eventual cost is decided.
- 022-4 months
Build the management system
Draft the AI policy, the impact assessment methodology, the roles and responsibilities matrix and the lifecycle controls. Stand up the AI system inventory. This is the bulk of the work and the part that benefits most from being run as sprints rather than a document exercise.
- 032-3 months
Operate and generate evidence
The management system has to actually run before it can be audited. Complete impact assessments on real systems, hold the governance meetings, log the decisions, and run at least one internal audit and one management review. Auditors look for evidence of operation, not the existence of documents.
- 046-10 weeks
Stage 1 and Stage 2 audit
Stage 1 checks the management system is documented and ready. Stage 2, typically four to six weeks later, tests whether it is genuinely operating. Certification follows once any non-conformities are closed, with surveillance audits annually thereafter.
Cost and internal effort figures are being confirmed with the practice before publication: cost and effort figures · Q15
Failure points
Where ISO 42001 programmes usually go wrong
Not the theory. The specific things that cause a delayed audit, a major non-conformity, or a certificate that does not survive its first surveillance visit.
Scoping to the AI you know about
The inventory built in week one is almost never complete. Teams have models in spreadsheets, vendor features that quietly became AI, and staff using consumer tools on company data. A scope drawn around the declared systems fails at Stage 2 when the auditor finds one that was not declared.
Treating impact assessment as a form
The AI system impact assessment is the substantive control in Annex A. Filled in retrospectively to satisfy the auditor it adds no value and reads as exactly that. It has to sit before deployment in the actual release process, with the authority to stop a release.
No named accountable owner
ISO 42001 requires allocated responsibility across the AI lifecycle. Distributing it across a committee means nobody owns it. Auditors probe this directly, and 'the AI working group' is not an answer that survives the question 'who signed off on this deployment?'.
Ignoring the supply chain
Most organisations do not train models, they consume them. Provenance, licensing, training data claims and change notification from model providers are all in scope, and they are the hardest evidence to obtain retrospectively. Start supplier engagement early - it has the longest lead time in the whole programme.
Running it as a documentation project
A complete document set with no operating record fails. The standard requires demonstrated operation: meetings held, decisions logged, incidents handled, an internal audit completed and a management review minuted. That evidence takes calendar time and cannot be compressed at the end.
Assuming ISO 27001 covers it
ISO 27001 covers information security, not AI-specific risk. Bias, explainability, human oversight, model drift and training data provenance are outside its scope. An existing ISMS gives a real head start on the management system clauses, but the Annex A controls are new work.
Dates that apply
The deadlines attached to ISO 42001
- In force · 2 months agoArticle 50 transparency obligations apply
- Deferred · 14 months awayAnnex III standalone high-risk system obligations apply
- In force · since 2023Certifiable now
Verified 25 August 2026Full regulatory horizon ->
How we run it
ISO 42001, delivered in sprints
- 01A discovery sprint that finds the AI actually in use, including shadow AI, rather than the AI on the register.
- 02Scope and gap analysis delivered as a prioritised backlog, so remediation can start in week two instead of after a report.
- 03Policy, impact assessment methodology and lifecycle controls drafted with your engineers, in your tooling, not handed over as templates.
- 04The AI inventory stood up as something your team maintains, because an inventory nobody updates fails the first surveillance audit.
- 05Internal audit and management review run properly, so the evidence exists before Stage 1 rather than being assembled for it.
- 06Stage 1 and Stage 2 audit support, including handling the questions the auditor will actually ask.
Choosing between them
ISO 42001 or ISO 27001?
ISO 27001 certifies how an organisation manages information security. ISO 42001 certifies how it manages AI. They share the same Annex SL skeleton, so an existing ISO 27001 management system carries most of the clause-level work across - context, leadership, internal audit, management review. What does not carry across is Annex A: AI impact assessment, data provenance, human oversight and lifecycle responsibility are new controls with no ISO 27001 equivalent. In practice, organisations with a live ISMS reach ISO 42001 materially faster, and organisations with neither should usually do ISO 27001 first, because most enterprise customers still ask for it by name.
ISO 27001FAQ
ISO 42001: questions people actually ask
Is ISO 42001 mandatory?
Does ISO 42001 make an organisation EU AI Act compliant?
How long does ISO 42001 certification take?
What is the difference between ISO 42001 and the NIST AI Risk Management Framework?
Can a small organisation certify to ISO 42001?
What does ISO 42001 certification cost?
Start
Three ways in, depending on how close the deadline is.
- Book it
Book a discovery call
Thirty minutes, no deck. We work out whether there is a real engagement here, and say so if there is not.
- Go
Check the EU AI Act applies
Six questions, a dated list of the obligations that reach you, and a calendar file so the deadlines land somewhere you will see them again.
- Go
Request a roadmap
You know the obligation and the deadline. We scope the sprints, the deliverables and the dates.
Or just email a human: hello@cloudgap.ai
We reply within24 hours