ISO 42001: The AI Management System Standard, Explained
Somewhere around question 140 of a customer's vendor security questionnaire, a new line has started showing up. Describe your AI governance program. Are you ISO/IEC 42001 certified? Two years ago nobody asked. Now the question sits next to the SOC 2 and ISO 27001 boxes on the same form, and plenty of teams honestly can't tell whether their answer should be no or not applicable. ISO 42001 belongs in the same conversation as the other frameworks a compliance program already juggles, but it asks a question those frameworks never did. Who decides how AI gets used here, and can you prove it?
Table of Contents
ISO/IEC 42001 is the international standard for an AI management system (AIMS), the policies, risk assessments, and controls a business uses to govern how it builds, sells, or uses AI. Certification is voluntary and handled by independent auditors.
Who actually needs the certificate is a narrower group than the sales emails suggest. If you build AI or sell a product with AI inside it, certification is becoming a contract question, because the enterprise buyers sending those questionnaires want an auditor's signature rather than your word. If you only use AI tools like Microsoft Copilot or ChatGPT, you almost certainly need the discipline the standard describes and almost certainly don't need the audit.

What Is ISO 42001?
ISO/IEC 42001:2023 is the first international standard that sets requirements for an AI management system. ISO and IEC published it in December 2023. It applies to any organization that develops, provides, or uses AI, regardless of size or industry.
A management system sounds abstract. It isn't. It's the written answer to four plain questions. What AI do we run, who owns each piece, what could go wrong, and how do we check that the controls we picked are working? The standard makes you write those answers down, act on them, review them with leadership, and improve them on a cycle. Plan, do, check, act. Repeat every year.
The standard doesn't tell you which AI tools to buy or ban. It doesn't grade your models. ISO's own explainer on ISO/IEC 42001 is direct that certification is voluntary, and that adopting the standard without certifying still delivers value. That second point gets lost in the marketing. A business can follow the standard for years and never pay an auditor, and for a lot of companies that only buy AI tools rather than build them, that's the right call.
It also doesn't live alone. It follows Annex SL, the common skeleton ISO uses for every management system standard, which is why its clauses line up almost one for one with ISO 27001.
Who Needs ISO 42001 Certification, and Who Just Needs to Follow It?
Your AI role decides it. Companies that build AI models or sell products with AI inside face growing customer pressure to certify. Companies that only use third-party AI tools usually need the governance, not the certificate.
The standard borrows its roles from ISO/IEC 22989, the AI vocabulary standard. Schellman, which says it was the first certification body accredited by ANAB (the ANSI National Accreditation Board, which accredits US auditors) for ISO 42001, has a clear breakdown of how each AI role changes audit scope. Translated into business terms, it looks like this.

One wrinkle trips people up. Take an AI customer that wraps a third-party model into something it sells, say an accounting firm that builds a client-facing tax assistant on top of an OpenAI model and puts its own logo on the result. That firm just became an AI provider. Same model, but now the firm answers for what the assistant tells its clients.
If you're firmly in the customer row, skip the certificate and put the effort into an AI acceptable use policy, an inventory of every AI tool your people touch, and a vendor review process. That's the part of the standard that actually reduces risk for a business using AI rather than building it. Our AI governance advisory work usually starts in that row.
What's Inside the Standard: Clauses 4-10 and Annex A
ISO 42001 has two parts that matter. Clauses 4 through 10 are the mandatory management system requirements an auditor tests. Annex A is a reference list of 38 AI-specific controls you choose from based on your own risks.
The clauses read like any ISO management standard, with the same context, leadership, and audit machinery you'd recognize from an ISO 27001 or ISO 9001 program, right up until you hit clause 6. That's where the AI-specific work lives.
- Clause 4, context. Define what AI you have, who cares about it (customers, regulators, employees), and what's in scope.
- Clause 5, leadership. Top management signs an AI policy and assigns real owners. Not whoever runs IT, by default.
- Clause 6, planning. The heart of it. An AI risk assessment, a risk treatment plan, and an AI system impact assessment, which looks at how your AI could affect people outside the company, not just your own operations.
- Clause 7, support. Staff, skills, training, documentation.
- Clause 8, operation. Actually running the controls you picked.
- Clause 9 is measurement. Monitoring, internal audits, and a management review where leadership looks at the results.
- Clause 10, improvement. Fix what the reviews found.
Annex A holds the controls. Certification body Glocert's clause-by-clause summary walks through how they connect. You don't implement all 38. You pick the ones your risk assessment calls for and record every choice, including every control you excluded and the reason you excluded it, in a single document called the Statement of Applicability. Expect the auditor to spend more time on it than on anything else you hand over.

Annexes B through D are guidance, not requirements. Annex B explains how to implement the Annex A controls, which is the part you'll actually reread.
Your AI Vendor's Certificate Doesn't Cover You
Microsoft holds ISO 42001 certification for Microsoft Copilot, GitHub Copilot, Security Copilot, and several other AI services, and it publishes the audit reports on its Service Trust Portal for customers to download. Anthropic announced its accredited 42001 certification in January 2025, issued by Schellman. Good news, and it's worth checking before you buy anything with AI in it.
It says nothing about you.
Microsoft says so itself. Its ISO 42001 compliance page tells customers they can use Microsoft's certification in their own assessment, but that they're responsible for engaging an assessor to evaluate the controls and processes within their own organization. Microsoft's certificate covers how Microsoft builds Copilot. It doesn't cover which of your employees can point Copilot at the HR share, or whether anyone reviewed what it summarized from the board folder last quarter before the summary went out in an email. That configuration question is yours, and it's what our guide to Copilot security and governance is built around.
Compliance doesn't equal security. AI hasn't changed that. It's just added a new place for the gap to hide. Schellman's July 2026 AI governance research, which surveyed 525 US professionals at organizations with 500 or more employees, found 74% believe they could pass an AI compliance audit today. Only 27% describe their governance program as fully mature. And just 44% have incident response procedures written specifically for AI. What happens at the other 56% when a chatbot leaks a customer list? Somebody improvises.
That's a sample of larger companies with bigger budgets. If they're this far behind, treat those numbers as a ceiling on how prepared your peers are, not a floor.
How Does ISO 42001 Compare to ISO 27001, NIST AI RMF, and the EU AI Act?
ISO 42001 is the only one of the three AI frameworks you can be certified against. The NIST AI RMF is a voluntary US framework with no audit. The EU AI Act is a law with fines. ISO 27001 covers information security, not AI behavior.

The NIST AI Risk Management Framework and ISO 42001 get pitched as rivals. They aren't. NIST tells you what good AI risk management looks like. The ISO standard gives you a system an outsider can audit. Plenty of US companies use the NIST language internally, because their risk and security teams already speak it, and then use the ISO structure when a customer or auditor wants proof from someone outside the building. We cover the NIST side in the NIST AI RMF explained.
The EU AI Act is a different animal. It's law, and the top penalty tier in Regulation (EU) 2024/1689 reaches €35 million or 7% of worldwide annual turnover for prohibited AI practices. A 42001 certificate doesn't make you compliant with the Act. It does mean the risk assessments, documentation, and oversight the Act expects mostly already exist. No EU customers and no EU users? The Act probably isn't your problem yet.
If you're sorting through the wider field, including the OECD principles, our guide to AI governance frameworks maps them side by side.
Already ISO 27001 Certified? Start There.
You're further along than you think. Because both standards share the Annex SL structure, clauses 4 through 10 are close to identical, and your document control, internal audit program, management review, and corrective action process all carry over. A-LIGN's comparison of ISO 42001 and ISO 27001 covers the overlap control by control. The genuinely new work is the AI risk assessment, the impact assessments, and the Annex A controls around data provenance and the AI life cycle.
Run them as one integrated management system with one audit calendar. Two separate binders maintained by two separate people, reviewed in two separate meetings nobody wants to attend, is how the second management system quietly dies within a year of the first audit. If ISO 27001 is still on your roadmap rather than on your wall, it's usually the better first move for a business that handles customer data, and our ISO 27001 certification services are built so the AI layer bolts on later. Weighing 27001 against SOC 2 first? That's its own decision, covered in SOC 2 vs ISO 27001.
How Does ISO 42001 Certification Work?
You build and run the AI management system for a few months, audit it internally, then pass a two-stage external audit. The certificate lasts 3 years, with a surveillance audit every year in between.
- Gap assessment. Compare what you do today against clauses 4-10 and Annex A.
- Build the AIMS. AI inventory, policy, risk and impact assessments, Statement of Applicability, and the controls themselves.
- Run it. Auditors want evidence the system has operated, not a folder of documents dated last Tuesday. Plan on at least a couple of months of real records.
- Internal audit and management review, both required before certification.
- Stage 1 audit. The auditor reviews your documentation and readiness.
- Stage 2 audit. The auditor tests whether the controls actually operate as written.
- Certificate issued, followed by a surveillance audit in each of the next 2 years and a recertification audit before it expires.

Timelines swing on how much you already have. Vanta's ISO 42001 cost breakdown puts the typical run at 6-12 months with manual processes and roughly 3-6 months with automation. An existing ISO 27001 program lands you toward the short end. Starting from zero, with no AI inventory, no written policy, and nobody who owns the question, lands you at the long end of that range, or well past it if leadership won't free up the people.
Cost is the question every CFO asks first, and the honest answer is a wide range. Vanta's published estimates, which are a compliance-platform vendor's numbers rather than an independent survey, put initial certification audit fees at $7k-$20k, surveillance audits at $3.5k-$9k, a readiness assessment at $3k-$10k or more, and implementation and internal effort at $10k-$40k or more. The audit fee is the smallest line. Your people's time is the biggest, because the risk assessments, impact assessments, and evidence collection all land on managers who already have full-time jobs.
Book the auditor early. The list of accredited bodies is still short, and a Stage 2 slot can land weeks past the date you promised a customer.
How to Tell If an ISO 42001 Certificate Is Real
Whether you're certifying or buying, the certificate itself deserves a hard look. Some come from accredited bodies. Some come from companies that print them. From across a table they look the same.
ISO doesn't certify anyone. Independent certification bodies do, and ISO notes they may be accredited by national accreditation bodies. May. An unaccredited certificate isn't illegal. It just doesn't carry the same weight with a buyer who knows the difference.
In 2025 ISO published ISO/IEC 42006, which sets the extra requirements a body must meet to audit AI management systems. That's the standard accreditors now test auditors against. In the US that accreditor is usually ANAB, which runs an ISO/IEC 42001 accreditation program. BSI, for example, announced its ANAB accreditation for ISO 42001 in March 2026. The same release cited BSI research finding only 26% of organizations had taken steps to align with the standard.
When a vendor hands you a 42001 certificate, or when you're choosing an auditor, check these.
- Is there an accreditation mark on it, from ANAB, UKAS, or another recognized national body?
- Look the certificate up on IAF CertSearch, the International Accreditation Forum's database of accredited certifications.
- Read the scope statement. A certificate covering one internal chatbot pilot tells you nothing about the AI product you're buying.
- Expiry date, and whether the last surveillance audit happened.
- Ask which AI role they certified under. A vendor certified only as an AI customer hasn't been audited on how it builds the product it's selling you.
A scope statement tells you more than the logo does. Ask for it every time.
Where to Start This Quarter
Whether you certify next year or never, the first moves are the same, none of them needs an auditor, and all of them are work you'd want done anyway the first time an employee pastes client data into a chatbot.
Start with an inventory. Every AI tool, feature, and integration in use, including the ones nobody approved. Expect surprises in marketing and finance. Then decide your role against the table above, because it sets everything downstream. Write the acceptable use policy next, since it's the control your employees actually feel. Last, pull the 42001 certificates and scope statements from your major AI vendors, and note which ones don't have one, so the gaps in your own supply chain show up on your list before they show up in a customer's audit.
At Consilien, we're a security-first IT and advisory firm serving businesses nationwide, and our compliance practice runs separately from managed IT. For this standard, that means the gap assessment, the AIMS build, and audit preparation, working alongside whichever accredited certification body you choose rather than replacing it. The work turns a vendor questionnaire answer from a guess into a document. If the answer to question 140 is going to be no, you want it to be a no with a plan attached. Speak to an AI governance expert about scoping ISO 42001 readiness for how your business actually uses AI.