INTLInternationalVoluntaryISO 42001

How to prepare for ISO/IEC 42001 certification

ISO/IEC 42001:2023, AI management system

Status
Voluntary
Binding
No
Object analysed
Organisation
Requirements
13
Next milestone
Dec 2026

In short

Certifiable AI management system (AIMS) standard, modelled on ISO 27001. Clauses 4 to 10 and 38 Annex A controls. Buyer reference and a Colorado safe harbour.

Steps to compliance

  1. Qualify each AI systemAxes to decide: System impact level (Cl. 6.1.4).
  2. Determine your roleDuties vary by role: Provider, User and Producer.
  3. Apply the 13 requirementsThey focus on: Governance & accountability, Quality & conformity, Post-deployment monitoring and Risk management.
  4. Prove it with checks29 checks to document, 26 of which also serve NIST AI RMF, AI Act and PL 2338.
  5. Track the deadlinesNext milestone: Dec 2026, CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS) (potential).

Scope and penalties

Kind
Certifiable standard
Scope
Organisations providing or using AI systems.
Territorial reach
International.
Penalties
None; certification lost or refused.
Jurisdiction
International

Timeline

Dec 18, 2023ISO/IEC 42001 published
May 2025ISO/IEC 42005 (impact assessment)
Jul 2025ISO/IEC 42006 (certification bodies)
Release
Dec 2026CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS)Potential
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

System impact level (Cl. 6.1.4)

Significant impactLimited impact

Requirements

13 requirements

CodeArticleRequirementApplies toChecks
ISO-4.3Cl. 4.3, 4.4Scope of the AIMS
All
ISO-5.2Cl. 5.2, A.2AI policy
All
ISO-5.3Cl. 5.3, A.3Roles, responsibilities, reporting of concerns
All
ISO-6.1.2Cl. 6.1.2, 6.1.3AI risk assessment and treatment, Statement of Applicability
All
ISO-6.1.4Cl. 6.1.4, A.5AI system impact assessment
All
ISO-7.2Cl. 7.2, A.4Competence and resources
All
ISO-A.6A.6Lifecycle: design, verification, deployment, operation, event logs
All
ISO-A.7A.7Data for AI systems: acquisition, quality, provenance
All
ISO-A.8A.8Information for interested parties, incident communication
All
ISO-A.9A.9Responsible use of AI systems
All
ISO-A.10A.10Third-party and customer relationships
All
ISO-9Cl. 9.2, 9.3Internal audit and management review
All
ISO-10Cl. 10Nonconformity and continual improvement
All

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
NEW-ISO42001-01AIMS scope defined and approved proposedSystem
—
CHK-POL-TRUSTTrustworthy-AI characteristics are embedded in organizational policies and a safety-first cultureOrganisation
CHK-ROLES-CLARIFIEDRoles, responsibilities and delegated authorities are documented and clear to relevant stakeholdersOrganisation
CHK-EXEC-ACCOUNTExecutive leadership is accountable for AI risk decisions (board committee, risk appetite)Organisation
CHK-POL-RISKAn AI risk-management policy and process are established through transparent, documented controlsOrganisation
VER-003-01Documented and up-to-date risk registerSystem
CHK-RISK-RESPONSERisk treatment is prioritized and high-priority responses are planned and documentedSystem
NEW-ISO42001-02Annex A Statement of Applicability kept up to date proposedSystem
—
CHK-IMPACT-ASSESSAn impact assessment is performed, documented and used in go/no-go and risk decisionsSystem
VER-020-D-01FRIA carried out in accordance with Art. 27System
CHK-TRAININGPersonnel and partners receive AI risk-management trainingOrganisation
VER-001-F-01Documented and implemented AI training programmeOrganisation
VER-005-01Complete technical documentation compliant with Annex IVSystem
VER-006-02Automatic logging operational and compliantSystem
CHK-TEVVTEVV plan, test sets, metrics and data considerations are documentedSystem
VER-021-F-01Operational monitoring planSystem
VER-004-01Documented data governance (collection process, bias, quality)System
VER-004-02Input data relevant and representative in view of the intended purposeSystem
VER-007-01Instructions for use complete and compliant with Art. 13System
VER-022-F-01Risk and incident response procedureOrganisation
VER-027-D-01Use compliant with the purpose intended by the provider verifiedSystem
VER-008-03Competent overseers assigned to the systemSystem
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testingOrganisation
VER-026-F-01Contractual responsibilities documented between provider and third partiesProvider
CHK-REVIEW-PLANOngoing monitoring and periodic review of the risk-management process are planned, with defined roles and review frequencyOrganisation
NEW-ISO42001-03AIMS internal audit completed for the cycle proposedSystem
—
VER-013-F-01Documented non-conformity management procedureOrganisation
CHK-CONTINUAL-IMPROVEContinual-improvement activities are integrated with stakeholder engagementSystem

Themes covered

Frequently asked questions

Who is in scope of ISO 42001?

Organisations providing or using AI systems. International.

What penalties does ISO 42001 carry?

None; certification lost or refused.

When do the ISO 42001 obligations apply?

May 2025: ISO/IEC 42005 (impact assessment); Jul 2025: ISO/IEC 42006 (certification bodies); Dec 2026: CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS).

Is ISO 42001 binding?

No. Kind: certifiable standard. Status: voluntary.

How does ISO 42001 relate to other regulations?

The same checks serve several texts. Shared checks: NIST AI RMF (16), AI Act (14) and PL 2338 (9).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo