ISO 42001

Certification

ISO 42001 certification, sized for the AI you actually run.

ISO/IEC 42001 implementation, internal audit leadership, and Stage 1 / Stage 2 certification audit support — led by a PECB-certified ISO/IEC 42001 Lead Auditor, built on the AI Governance & Security substrate. Body-independent across the EU.

Overview

A management system for AI — not an AI Act shortcut.

ISO/IEC 42001:2023 is the first certifiable international standard for an Artificial Intelligence Management System (AIMS). It specifies the requirements for establishing, implementing, maintaining, and continually improving an AIMS — regardless of the size of the organisation, the sector, or the role it plays (deployer, provider, GPAI integrator).

The standard has two components. The management framework — 10 clauses built on the Annex SL backbone (the same backbone used by ISO 27001), covering how your organisation plans, implements, monitors, and improves its AIMS. Annex A — a reference set of 38 AI-specific controls across 9 categories (policies, internal organisation, resources, AI system impact assessment, AI system lifecycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships). You select, implement, and document control applicability based on your AI risk assessment in a Statement of Applicability.

ISO 42001 sits alongside — not on top of — EU AI Act compliance. The standard treats the AI Act as an interested-party requirement input: the AIMS must operate within the regulatory environment, but ISO 42001 certification itself does not constitute AI Act conformity assessment. The AI Governance & Security service produces the AI Act-specific evidence pack; ISO 42001 Certification wraps the same governance work into a certifiable AIMS and takes it through the audit.

Who ISO 42001 is for

Voluntary today — but increasingly a procurement and assurance differentiator for organisations whose AI footprint is now material.

  • SaaS companies and AI-product vendors

    Enterprise procurement processes are starting to ask vendors for AI governance evidence. ISO 42001 is the most defensible single answer. The AIMS also wraps cleanly around the Article 17 QMS that the AI Act requires of Providers.

  • Regulated-AI deployers

    Financial-services credit scoring, emergency patient triage, recruiting and HR screening platforms, education assessment, critical-infrastructure operators, public-sector decision-making systems. The AIMS structures the governance their Article 26 obligations now require.

  • Companies shipping AI features on foundation models

    Internal copilots, customer-facing chatbots, AI agents, retrieval-augmented apps. An AIMS scoped to GPAI integration produces the documented model-selection, evaluation, and monitoring practices that procurement and insurers ask for.

  • Suppliers to enterprises with AI vendor assurance

    Large EU enterprises now extend AI governance requirements down their supply chain. ISO 42001 is a recognised way to meet that bar without bespoke audits per customer.

  • Public-sector AI tenderers

    EU and national procurement frameworks are starting to list AI management evidence as a qualification for AI-related IT and data-processing contracts. ISO 42001 maps directly to that requirement.

  • Any business seeking AI-related cyber insurance

    Insurers are pricing AI-related cyber risk separately. A certified AIMS is a clear signal of managed AI governance for underwriters.

The 10 management clauses

What every AIMS must demonstrate.

  1. 01Clause 4

    Context of the organisation

    Business environment, AI systems in scope, interested parties (the EU AI Act sits here as a regulatory interested-party requirement), AIMS scope statement.

  2. 02Clause 5

    Leadership

    Top-management commitment, the AI policy, AI roles and responsibilities and authorities.

  3. 03Clause 6

    Planning

    AI risk assessment (ISO/IEC 23894-aligned), AI system impact assessment, risk treatment plan, AI objectives.

  4. 04Clause 7

    Support

    Resources, AI-specific competence, awareness, communication, documented information control.

  5. 05Clause 8

    Operation

    Operational planning and control, AI system lifecycle (design, data, validation, deployment, monitoring), third-party AI relationships.

  6. 06Clause 9

    Performance evaluation

    Monitoring, measurement, analysis, internal audit (mandatory), management review.

  7. 07Clause 10

    Improvement

    Non-conformities, corrective actions, continual improvement of the AIMS.

  8. 08Annex A

    38 controls across 9 categories

    Policies (A.2), internal organisation (A.3), resources (A.4), AI system impact assessment (A.5), AI system lifecycle (A.6), data for AI systems (A.7), information for interested parties (A.8), use of AI systems (A.9), and third-party and customer relationships (A.10). Selected and justified in the Statement of Applicability.

Consequences (non-fines)

No statutory penalties — but commercial cost compounds.

ISO/IEC 42001 is voluntary, so there are no statutory fines for non-certification. The cost of lacking certification, however, compounds: disqualification from procurement tenders that increasingly require AI governance evidence, inability to meet enterprise client AI vendor-assurance requirements, exposure to AI-related cyber-insurance gaps, and friction with EU and national public-sector procurement frameworks that are starting to require AI management evidence.

Certified organisations also use ISO 42001 to meet substantial portions of EU AI Act obligations — the AIMS structure maps directly to Article 17 QMS for Providers, Article 9 risk management, Article 10 data governance, Annex IV technical documentation, and the broader management-system requirements that sit under both Chapter III (Provider) and Article 26 (Deployer) duties. The AIMS is the most cost-effective single foundation for AI Act readiness.

  • AI Act Art. 17

    Large overlap

    the AIMS structure maps onto most provider QMS obligations.

  • AI Act Chapter III

    Substantial

    of provider obligations supported by a well-scoped AIMS.

  • AI Act Art. 26

    Partial

    deployer duties supported; the rest is AI Act-specific.

Our approach

AIMS certification, designed for SMB scale.

What we deliver

  • Gap analysis against the 10 management clauses and Annex A — costed roadmap to certification
  • AIMS scope and context — sized for your AI estate, not enterprise-bloated
  • AI risk assessment (ISO/IEC 23894), AI system impact assessment, treatment plan, and Statement of Applicability
  • AIMS policy stack — AI policy, AI roles, competence and awareness framework
  • Annex A control design pack — 38 controls scoped through the SoA, implemented by your teams and vendors
  • Mandatory internal audit (Clause 9.2) — ISO/IEC 19011-aligned, led by a PECB ISO/IEC 42001 Lead Auditor
  • Management review (Clause 9.3) and pre-certification readiness review
  • Certification body selection guidance — body-independent across the EU
  • Stage 1 / Stage 2 audit support and Phase 6 surveillance retainer

Typical timeline

8–12 months for most SMBs starting from a low baseline. Clients with prior AI Governance & Security history finish meaningfully faster — the substrate is already in place.

  1. Weeks 1–4

    Gap analysis & AIMS scope

    Current state vs ISO 42001 requirements, AIMS scope definition, interested-parties analysis, prioritised costed action plan.

  2. Months 2–6

    AIMS build

    AI risk assessment and treatment, AI system impact assessment, AI policy stack, Annex A control design with your team, Statement of Applicability, awareness programme rollout.

  3. Month 7

    Internal audit & management review

    Independent internal audit against all clauses and selected Annex A controls, led by a PECB ISO/IEC 42001 Lead Auditor. Management review. Corrective actions resolved before the external auditor sees the AIMS.

  4. Months 8–11

    Certification audit

    Stage 1 (document review) then Stage 2 (on-site assessment) with your chosen accredited certification body.

FAQ

Common questions.

What's the difference between ISO/IEC 42001 and ISO/IEC 27001?
ISO 27001 is the standard for an Information Security Management System (ISMS) — it certifies that you systematically manage the confidentiality, integrity, and availability of information. ISO 42001 is the standard for an Artificial Intelligence Management System (AIMS) — it certifies that you systematically manage the design, deployment, and lifecycle of AI systems. The two are complementary and built on the same Annex SL backbone, so management clauses 4–10 read very similarly. The differences are in the controls: ISO 27001's Annex A covers 93 information-security controls; ISO 42001's Annex A covers 38 AI-specific controls. ISO 42001 also uses ISO/IEC 23894 as its AI-specific risk methodology, alongside the ISO 31000 baseline that ISO 27001 also references.
Do we need to do AI Governance & Security work first?
Not strictly — but it's almost always how it ends up. ISO 42001 needs a real AI estate to certify: AI systems in scope, AI risks assessed, AI controls implemented, AI evidence collected. Most clients reach us before that substrate exists. The AI Governance & Security service builds it — every Phase 3 deliverable from AI G&S maps to ISO 42001 clauses and Annex A controls, so the certification engagement becomes assembly work rather than rework. Clients with prior AI G&S history pay a prior-work coefficient that reflects the overlap, down to a 40% reduction for clients who have already completed the AI System Provider sub-service.
How does ISO/IEC 42001 relate to the EU AI Act?
ISO 42001 treats the AI Act as an *interested-party requirement input* — the AIMS must operate within the regulatory environment, but ISO 42001 certification itself does not constitute AI Act conformity assessment. In practice, a well-scoped AIMS covers much of the Article 17 quality-management obligations for providers and supports parts of the broader Chapter III and Article 26 duties. ISO 42001 alone does not constitute AI Act compliance — that requires the AI Act-specific evidence pack (Annex IV technical documentation, Article 27 FRIA, Article 13 transparency materials, etc.) which is what the AI Governance & Security service produces. Together they prepare you for certification by an accredited certification body and assemble the AI Act evidence in one engagement set.
Can a business that doesn't build AI still get ISO 42001 certified?
Yes — the standard applies to deployers and providers alike. An SMB using third-party AI for productivity (Copilot, ChatGPT Enterprise, AI features inside SaaS) can certify an AIMS scoped to its deployer duties: Article 4 literacy, acceptable-use policy, supplier due diligence, risk assessment, monitoring. The AIMS sized for a deployer is leaner than the AIMS sized for an AI System Provider — Annex A control applicability narrows in the Statement of Applicability based on the role the organisation plays. The certification effort for a deployer-scoped AIMS is meaningfully smaller.
Which certification body should we use?
ISO/IEC 42001 published in December 2023, so the accredited certification-body landscape is younger and narrower than for ISO 27001. Major bodies operating across the EU are actively building 42001 accreditation; coverage matures month by month. We are certification-body independent — we help you select an accredited body suitable for your jurisdiction, sector, and AI footprint, and we do not refer, partner, or take commission from any specific CB. We track which bodies have live 42001 accreditation in each EU member state.
What happens if we fail the Stage 2 audit?
An outright fail is rare when properly prepared. More commonly, Stage 2 identifies major non-conformities that must be resolved within a defined window (typically 90 days) before certification is issued. Minor non-conformities are noted in the audit report but do not prevent certification — they are addressed at the first surveillance audit. Our pre-certification internal audit is designed to surface and resolve issues before the external auditor sees them.
Can ISO 42001 be combined with ISO 27001?
Yes — and many SMBs do this from the start. Both standards share the Annex SL management-system backbone, so clauses 4–10 are essentially the same. The shared elements (top-management commitment, risk methodology, internal audit, management review, documented information control) get built once and serve both AIMS and ISMS. We routinely run combined ISO 27001 + ISO 42001 engagements for SaaS companies and AI-product vendors where the ISMS and AIMS scopes overlap, so shared work is done once.
Does ISO/IEC 42001 cover GDPR?
Partially. ISO 42001 Annex A.7 (Data for AI systems) addresses data governance practices that map to several GDPR principles (data quality, purpose limitation, training-data provenance, retention), and Annex A.5 (AI system impact assessment) integrates cleanly with the DPIA process. But ISO 42001 is not a GDPR compliance standard — it does not cover lawful basis, data subject rights, breach notification, DPO requirements, or international data transfers. Most clients pair their AIMS with their existing GDPR programme (or our GDPR Compliance service) rather than try to use 42001 as a GDPR substitute. EDPB Opinion 28/2024 on AI models and personal data sits between the two and is part of how we scope the integration.