Certifiable standard

ISO 42001 (AI)

ISO/IEC 42001 is the world’s first certifiable standard for an Artificial Intelligence Management System (AIMS). Published in December 2023, it lets organisations demonstrate that they develop and use AI responsibly, under proper oversight and in line with incoming regulation — the EU AI Act above all.

Start assessmentRead about the standard
38
controls in Guardiso
28
free-test questions
PL · EN
two languages

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is an international standard published jointly by ISO and IEC, specifying the requirements for establishing, implementing, maintaining and continually improving an artificial intelligence management system. It follows the same harmonised structure as ISO 27001 and ISO 9001 (clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement), so organisations that already run a management system can extend it to cover AI instead of building everything from scratch.

Alongside the system requirements, the standard includes Annex A with controls addressing the specifics of AI — including an AI policy, impact assessment of AI systems on individuals and society, AI system life cycle management, data quality and provenance, transparency and explainability, human oversight, and relationships with AI component suppliers. A distinguishing feature is the required AI system impact assessment — the analysis covers not only risk to the organisation but also the consequences for the people the system affects.

Who is it for?

The standard is intended for any organisation that develops, provides or uses AI systems — regardless of size or industry. This includes both companies building their own models and AI products, and organisations that "merely" use ready-made solutions: models accessed via API, AI assistants in office work, scoring or recommendation systems. In both roles the organisation is accountable for the effects of AI and needs governance over the area.

In practice the earliest adopters are technology and SaaS companies shipping AI features in their products, service providers to the financial, healthcare and public sectors (where customers ask about AI governance in vendor questionnaires), and organisations preparing for the EU AI Act. The ISO/IEC 42001 certificate is becoming for AI governance what ISO 27001 is for information security — a market-recognised proof that the topic is managed systematically rather than declaratively.

Relationship to the EU AI Act

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the world’s first comprehensive AI law. It entered into force on 1 August 2024 and applies in stages: first the bans on unacceptable practices and AI literacy obligations, then requirements for general-purpose AI models, and ultimately the full obligations for high-risk systems — including a risk management system, data governance, technical documentation, event logging, human oversight and a provider quality management system.

ISO/IEC 42001 and the AI Act are not the same thing: the standard is voluntary and certifiable, the regulation is law backed by fines. An ISO/IEC 42001 certificate does not grant an automatic presumption of conformity with the AI Act — that will be the role of harmonised standards being developed at the European Commission’s request. There is, however, substantial overlap: the elements the AI Act requires (risk management, data governance, documentation, human oversight, post-market monitoring) have counterparts in ISO/IEC 42001 requirements and controls. Implementing the standard therefore puts in order exactly the areas you will need to demonstrate to the regulator — and is today the best documented path to AI Act readiness.

What does certification look like?

Certification is performed by accredited certification bodies following the same model as ISO 27001: a two-stage certification audit (Stage 1 — documentation and readiness review, Stage 2 — implementation audit through sampling and interviews), a certificate valid for 3 years, annual surveillance audits and recertification before the end of the cycle. Because the standard is young, certification offerings are still maturing — it is worth asking your chosen body early about the availability of auditors competent in AI.

Organisations that already hold a certified ISO 27001 or ISO 9001 system have a substantial head start: the shared elements — context, leadership, internal audits, management review, document control, supplier management — are already in place, and only need extending with the AI specifics: an AI policy, an AI system register, impact assessments, life cycle controls and human oversight. For such organisations implementing ISO/IEC 42001 is an extension of the existing system rather than a new project.

How does Guardiso help?

Guardiso guides you through building an AI management system from the AI system inventory to auditor-ready evidence — and connects the ISO/IEC 42001 work with the other standards you already run.

  • The full catalogue of AI requirements and controls seeded automatically when you enable the standard — with descriptions, implementation statuses and assigned owners.
  • A free AI governance maturity self-assessment — within minutes it shows which areas (AI policy, impact assessments, life cycle, data, human oversight) need work.
  • An AI policy and system documentation generated from templates and tailored to the organisation’s real AI uses, with versioning and management approval.
  • A risk register covering AI-specific risks — bias, model drift, over-reliance — with treatment plans and residual risk tracking.
  • Evidence collected in one place: impact assessment records, model validation results, AI incident registers and recurring tasks that enforce reviews.
  • Cross-mapping to ISO 27001 and the EU AI Act — shared requirements count towards each other, and gaps are visible at a glance on one dashboard.
  • An auditor portal: controlled access to AIMS documentation and evidence without files being emailed around.
Official sources
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
ISO 42001 (AI) readiness score
0/28 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLSOC 2GlobalDORAEUTISAXAutomotiveISO 9001GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards