GRC Oversight

ISO/IEC 42001

ISO/IEC 42001 is the international management-system standard for artificial intelligence. It specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS).

Governed by ISO and IEC (ISO/IEC 42001:2023)
What it is

What ISO/IEC 42001 is, in plain terms

ISO/IEC 42001 is the world's first certifiable management-system standard for artificial intelligence. It defines an Artificial Intelligence Management System (AIMS), a structured way to govern how AI is developed, deployed, and overseen, using the same high-level structure as ISO 27001. It is becoming the reference point for organizations that want to demonstrate responsible, well-governed AI to customers and regulators.

Typical effort & timeline

As a management-system standard it follows the familiar certification path of a documentation and implementation audit plus ongoing surveillance. Effort is reduced significantly when an ISO 27001 ISMS is already in place.

Who needs it

Is this framework for you?

  • Organizations building or deploying AI features who need a defensible governance story.
  • Vendors whose enterprise customers are starting to ask how AI risk is managed.
  • Teams already certified to ISO 27001 who want to extend governance to AI systems.
About the framework

Key facts about ISO/IEC 42001

  • Published in 2023 as the first certifiable AI management system standard.
  • Follows the same high-level management-system structure as ISO 27001 (context, leadership, planning, support, operation, evaluation, improvement).
  • Requires AI risk assessment and an AI system impact assessment.
  • Annex A lists controls and implementation guidance for responsible AI.

Public information about the framework itself. We don't claim certifications, assessment status, or authorizations for our own product.

With this platform

How we help with ISO/IEC 42001

  • Track AIMS clauses and Annex A controls against tests and evidence.
  • Maintain an AI risk register and document impact assessments.
  • Reuse evidence already collected for ISO 27001 where controls overlap.
  • Keep AI governance activities documented for a certification audit.
Step by step

Get and stay compliant

How the platform supports your ISO/IEC 42001 program, from first scope to ongoing monitoring.

Set AI policy & governance

Establish AI objectives, roles, and oversight that anchor the AIMS.

Assess AI risk & impact

Maintain an AI risk register and document AI system impact assessments.

Map Annex A controls

Connect responsible-AI controls to tests and evidence, reusing ISO 27001 overlap.

Operate & review

Track AI lifecycle and supplier governance so the AIMS is demonstrably running at audit time.

Representative areas

What ISO/IEC 42001 covers

Public, high-level control or requirement areas, for orientation, not a complete control list.

AI policy & governance
AI risk assessment
AI system impact assessment
Data for AI systems
Lifecycle management
Third-party & supplier relationships
Do it once

Reuse evidence across frameworks

ISO/IEC 42001 shares controls with frameworks you may already run. A passing test can satisfy requirements in more than one place, so adding the next framework means reusing work, not repeating it.

FAQ

Common questions about ISO/IEC 42001

It shares the same management-system structure, so an existing ISMS gives you a strong head start and substantial reusable evidence.

No. ISO 42001 is a voluntary, certifiable standard; the EU AI Act is binding regulation. They complement each other and overlap on governance and risk practices.

A documented evaluation of the potential consequences of an AI system on individuals and groups, required as part of the AIMS.

Get audit-ready for ISO/IEC 42001

Get a guided demo, or start by scanning any domain for free.