How to prepare for ISO/IEC 42001 certification
ISO/IEC 42001:2023, AI management system
- Status
- Voluntary
- Binding
- No
- Object analysed
- Organisation
- Requirements
- 13
- Next milestone
- Dec 2026
In short
Certifiable AI management system (AIMS) standard, modelled on ISO 27001. Clauses 4 to 10 and 38 Annex A controls. Buyer reference and a Colorado safe harbour.
Steps to compliance
- Qualify each AI systemAxes to decide: System impact level (Cl. 6.1.4).
- Determine your roleDuties vary by role: Provider, User and Producer.
- Apply the 13 requirementsThey focus on: Governance & accountability, Quality & conformity, Post-deployment monitoring and Risk management.
- Prove it with checks29 checks to document, 26 of which also serve NIST AI RMF, AI Act and PL 2338.
- Track the deadlinesNext milestone: Dec 2026, CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS) (potential).
Scope and penalties
- Kind
- Certifiable standard
- Scope
- Organisations providing or using AI systems.
- Territorial reach
- International.
- Penalties
- None; certification lost or refused.
- Jurisdiction
- International
Timeline
Qualifying a system
Classification axes and possible verdicts
System impact level (Cl. 6.1.4)
Requirements
13 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| ISO-4.3 | Cl. 4.3, 4.4 | Scope of the AIMS | ||
| ISO-5.2 | Cl. 5.2, A.2 | AI policy | ||
| ISO-5.3 | Cl. 5.3, A.3 | Roles, responsibilities, reporting of concerns | ||
| ISO-6.1.2 | Cl. 6.1.2, 6.1.3 | AI risk assessment and treatment, Statement of Applicability | ||
| ISO-6.1.4 | Cl. 6.1.4, A.5 | AI system impact assessment | ||
| ISO-7.2 | Cl. 7.2, A.4 | Competence and resources | ||
| ISO-A.6 | A.6 | Lifecycle: design, verification, deployment, operation, event logs | ||
| ISO-A.7 | A.7 | Data for AI systems: acquisition, quality, provenance | ||
| ISO-A.8 | A.8 | Information for interested parties, incident communication | ||
| ISO-A.9 | A.9 | Responsible use of AI systems | ||
| ISO-A.10 | A.10 | Third-party and customer relationships | ||
| ISO-9 | Cl. 9.2, 9.3 | Internal audit and management review | ||
| ISO-10 | Cl. 10 | Nonconformity and continual improvement |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| CHK-LEGAL-MAP | Applicable legal and regulatory requirements for AI are identified, mapped and monitored | Organisation | ||
| NEW-ISO42001-01 | AIMS scope defined and approved proposed | System | ||
| CHK-POL-TRUST | Trustworthy-AI characteristics are embedded in organizational policies and a safety-first culture | Organisation | ||
| CHK-ROLES-CLARIFIED | Roles, responsibilities and delegated authorities are documented and clear to relevant stakeholders | Organisation | ||
| CHK-EXEC-ACCOUNT | Executive leadership is accountable for AI risk decisions (board committee, risk appetite) | Organisation | ||
| CHK-POL-RISK | An AI risk-management policy and process are established through transparent, documented controls | Organisation | ||
| VER-003-01 | Documented and up-to-date risk register | System | ||
| CHK-RISK-RESPONSE | Risk treatment is prioritized and high-priority responses are planned and documented | System | ||
| NEW-ISO42001-02 | Annex A Statement of Applicability kept up to date proposed | System | ||
| CHK-IMPACT-ASSESS | An impact assessment is performed, documented and used in go/no-go and risk decisions | System | ||
| VER-020-D-01 | FRIA carried out in accordance with Art. 27 | System | ||
| CHK-TRAINING | Personnel and partners receive AI risk-management training | Organisation | ||
| VER-001-F-01 | Documented and implemented AI training programme | Organisation | ||
| VER-005-01 | Complete technical documentation compliant with Annex IV | System | ||
| VER-006-02 | Automatic logging operational and compliant | System | ||
| CHK-TEVV | TEVV plan, test sets, metrics and data considerations are documented | System | ||
| VER-021-F-01 | Operational monitoring plan | System | ||
| VER-004-01 | Documented data governance (collection process, bias, quality) | System | ||
| VER-004-02 | Input data relevant and representative in view of the intended purpose | System | ||
| VER-007-01 | Instructions for use complete and compliant with Art. 13 | System | ||
| VER-022-F-01 | Risk and incident response procedure | Organisation | ||
| VER-027-D-01 | Use compliant with the purpose intended by the provider verified | System | ||
| VER-008-03 | Competent overseers assigned to the system | System | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | Organisation | ||
| VER-026-F-01 | Contractual responsibilities documented between provider and third parties | Provider | ||
| CHK-REVIEW-PLAN | Ongoing monitoring and periodic review of the risk-management process are planned, with defined roles and review frequency | Organisation | ||
| NEW-ISO42001-03 | AIMS internal audit completed for the cycle proposed | System | ||
| VER-013-F-01 | Documented non-conformity management procedure | Organisation | ||
| CHK-CONTINUAL-IMPROVE | Continual-improvement activities are integrated with stakeholder engagement | System |
Themes covered
Frequently asked questions
Who is in scope of ISO 42001?
Organisations providing or using AI systems. International.
What penalties does ISO 42001 carry?
None; certification lost or refused.
When do the ISO 42001 obligations apply?
May 2025: ISO/IEC 42005 (impact assessment); Jul 2025: ISO/IEC 42006 (certification bodies); Dec 2026: CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS).
Is ISO 42001 binding?
No. Kind: certifiable standard. Status: voluntary.
How does ISO 42001 relate to other regulations?
The same checks serve several texts. Shared checks: NIST AI RMF (16), AI Act (14) and PL 2338 (9).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.