Skip to content
Compliance Framework

ISO/IEC 42001

ISO/IEC 42001 is the international standard for an artificial intelligence management system, and the first AI management standard that can be certified by an accredited body. What it certifies is how you govern AI, not any individual model.

Compliance Guide
7 min read

What ISO/IEC 42001 is

ISO/IEC 42001 is the international standard for an artificial intelligence management system, or AIMS. It is the first AI management system standard that can be certified by an accredited body, which makes it the only way at present to hold a recognised certificate for how you govern AI.

It follows the same management system structure as ISO/IEC 27001. If you already run a certified ISMS, the machinery will be familiar and a good deal of it can be shared rather than rebuilt.

Who it applies to

The standard is written to cover any organization that develops, provides, or uses AI, which deliberately includes organizations that only buy it.

  • Companies building AI systems or embedding AI features into a product
  • Companies deploying third-party AI in ways that affect customers, employees, or applicants
  • Vendors whose enterprise buyers have started asking for AI governance assurance
  • Organizations preparing for the EU AI Act that want a certifiable structure underneath it

The management system

What is certified is the management system, not any individual model. An organization with well-tested models and no governing structure will not pass.

  • Context and scope: which AI systems and activities the AIMS covers, and the roles you occupy across them
  • Leadership: an AI policy, assigned responsibilities, and evidence of management commitment
  • Planning: AI risk assessment and treatment, plus an AI system impact assessment considering effects on individuals and society
  • Support and operation: competence, awareness, documented information, and the operating record
  • Performance evaluation: monitoring, internal audit, and management review
  • Improvement: nonconformities logged, corrected, and driven to root cause

Annex A and the Statement of Applicability

As with ISO 27001, Annex A provides reference controls and you produce a Statement of Applicability accounting for each one: whether it applies, why, and where its implementation lives.

The controls cover ground that is specific to AI rather than inherited from information security: policies for AI, internal organization and accountability, resources for AI systems, impact assessment, the system lifecycle, data for AI systems, information for interested parties, and responsible use.

How it relates to the other AI work

These three do different jobs, and it is worth being clear about which one a given demand is actually asking for.

The NIST AI RMF gives you the practices and vocabulary but nobody certifies it. ISO/IEC 42001 gives you a certifiable management system. The EU AI Act imposes binding legal obligations on specific systems and does not accept a certificate in place of them.

They overlap heavily in evidence. A single well-run governance record can serve all three, which is the argument for building it once rather than three times.

How Verdict helps

Verdict builds and runs the AIMS: scope, AI policy, risk and impact assessment methodology, the Statement of Applicability, and the internal audit and management review cycle certification depends on.

Where you already hold ISO 27001, we extend the management system you have rather than standing up a parallel one. We carry it through Stage 1 and Stage 2, hold the corrective action record, and keep it live through surveillance. You review all of it in a client portal.

ISO/IEC 42001 is part of ai governance, the work that covers what an organization building or deploying AI has to be able to show about how those systems are governed. The same lane also covers EU AI Act, and NIST AI RMF. For the mechanics of an engagement, see how we work.

If you are pursuing certification, or extending an existing ISO 27001 management system to cover AI, we can run that work end to end.

Talk to a Consultant