+55 11 4193 5660 PT Free assessment

Paper · AI governance

ISO/IEC 42001: the first certifiable standard for AI management.

Published in December 2023, it is the first international standard that treats artificial intelligence as an auditable management system rather than a recommendation. This paper explains what it requires, where it meets the ISO 27001 your company may already hold, and what changes in practice for whoever puts a model into production.

Updated on August 2026 · 9 minute read

  • What it is

    An AI management system standard (AIMS), in the same structural family as ISO 27001 and ISO 9001.

  • Published

    December 2023, by the joint committee ISO/IEC JTC 1/SC 42.

  • Certifiable

    Yes, by an accredited body, with an audit cycle like any other management standard.

  • Scope

    It applies to whoever develops, supplies or merely uses AI systems, including third-party ones.

Why now

The standard went from nowhere to the
list of most cited milestones.

Regulatory frameworks most cited by companies

% of companies

ISO/IEC 42001 did not appear among the regulatory frameworks cited by companies in the 2024 edition of the AI Index and reaches 36% in the 2026 edition, above the NIST AI RMF at 33%. The intermediate edition has no published value.

0% 10% 20% 30% 40% not on the list ISO/IEC 42001 NIST AI RMF · 33% 36% AI Index 2024 AI Index 2025 AI Index 2026 no published value

Source: Stanford HAI, AI Index Report 2026. The stretch between the two editions is dashed because the ends are measured and the path between them is not: the intermediate edition published no value. The scale runs to 40 per cent rather than one hundred, so the three-point difference stays visible.

The AI Index Report 2026, from Stanford HAI, records ISO/IEC 42001 entering the list of most cited regulatory influences on companies, mentioned by 36% of respondents, with the NIST AI RMF just behind at 33%. Two years earlier it did not appear on the list at all.

In the same report, documented AI incidents rose to 362 in 2025, up from 233 in 2024. The pressure for evidence of control has stopped being hypothetical.

The standard is the instrument that turns intent into proof. An AI usage policy in a slide deck does not pass an audit; a management system with records, assigned roles and impact assessments does.

Clauses 4 to 10

The mandatory part, and the auditable one.

The seven clauses follow the ISO harmonized structure, the same one used by 27001 and 9001. Anyone already living in that format recognizes the ground on the first read.

  1. 4

    Context of the organisation

    Define where AI enters your business, who the interested parties are, and what the scope of the management system is. This is where you decide what falls inside and outside the certification.

  2. 5

    Leadership

    An AI policy approved by top management, with roles and responsibilities assigned to named people. Without explicit sponsorship, the standard holds up neither in audit nor in operation.

  3. 6

    Planning

    AI risk assessment and an assessment of the system’s impact on people and society, with measurable objectives. This is the clause that differs most from ISO 27001, which looks at risk to information, not risk to whoever is affected by it.

  4. 7

    Support

    Competence, awareness, communication and documented information. In practice: who understands what they are operating, and where it is recorded.

  5. 8

    Operation

    Operational control of the AI system lifecycle, from conception to decommissioning, including whatever a supplier does.

  6. 9

    Performance evaluation

    Monitoring, measurement, internal audit and management review. With no metric collected, there is nothing to review.

  7. 10

    Improvement

    Handling nonconformity, corrective action and continual improvement. The cycle that stops the system from becoming a document nobody touches.

Annex A

Nine objectives, 38 controls.

It is the standard control catalogue. The statement of applicability justifies what is in and what is out, exactly as in 27001.

  • A.2

    Policies related to AI

    The organisation’s AI policy, its approval and its periodic review.

  • A.3

    Internal organisation

    Roles, responsibilities, and the channel for raising a concern about an AI system.

  • A.4

    Resources for AI systems

    Data, tooling, compute and people documented as part of the system.

  • A.5

    Assessing impact

    Assessment of the AI system’s impact on individuals, groups and society.

  • A.6

    AI system lifecycle

    Objective, design, verification, validation, deployment, operation and decommissioning.

  • A.7

    Data for AI systems

    Provenance, quality, preparation and governance of the data feeding the model.

  • A.8

    Information for interested parties

    What is communicated to users, customers and regulators about what the system does and does not do.

  • A.9

    Use of AI systems

    Responsible use inside the organisation, including third-party tools under contract.

  • A.10

    Third parties and customers

    How risk is distributed along the chain when the model, the data or the operation belongs to someone else.

What you already have

It does not start from zero.
It fits what already exists.

ISO/IEC 27001

Shared structure

The same ISO harmonised structure (Annex SL): clauses 4 to 10 identical in form. Whoever already holds 27001 reuses governance, internal audit and management review. What changes is the object of the risk: 27001 protects the information, 42001 answers for the effect of the system on people.

NIST AI RMF

Complementary

The NIST framework is voluntary and organises practice into govern, map, measure and manage. It helps you do the work; 42001 lets you prove it. Many organisations use both: NIST in engineering, ISO for certification.

EU AI Act

Regulatory

The European regulation imposes obligations by risk tier. 42001 does not replace legal compliance, but it assembles much of the evidence the Act will ask for: risk management, technical documentation, human oversight and post-market monitoring.

LGPD and GDPR

Personal data overlap

Where the AI system processes personal data, the two meet: legal basis, minimisation, data subject rights and impact assessment. The 42001 assessment is broader, and looks at effects beyond the data itself.

Adoption path

Five phases, each with a deliverable.

It is the route we apply to PCI-DSS and ISO 27001, adapted to the new object. And it is the same one we are walking internally before taking it to a client.

  1. Phase 1

    Inventory and scope

    List every AI system in use, including the contracted ones and whatever went live without passing by anyone. Without an inventory there is no scope, and without scope no certification is possible.

    AI system inventory and the defined AIMS scope

  2. Phase 2

    Gap analysis

    Compare what exists today against clauses 4 to 10 and the 38 Annex A controls. Companies that already hold 27001 usually start with 40% to 60% of the road behind them.

    Gap report with estimated effort per control

  3. Phase 3

    Policy, roles and impact assessment

    Write the AI policy, assign responsibility to named people, and run the first impact assessment on the systems with the most exposure.

    Approved policy, role matrix and impact assessments

  4. Phase 4

    Controls in the operation

    Deploy the controls inside the workflow that already exists, not as a parallel process. Governance living outside the pipeline is abandoned at the first tight deadline.

    Controls running, with records generated by the operation itself

  5. Phase 5

    Internal audit and certification

    Internal audit, management review, correction of nonconformities, and then the two-stage certification audit.

    Certificate issued and a maintenance cycle in place

Where it usually stalls

Five mistakes we have already seen in other standards.

  • Too large a scope on the first certification

    Certifying the whole organisation at once multiplies the effort and delays the result. Starting with the set of systems that already concentrates risk and value delivers the certificate sooner and teaches more.

  • Impact assessment treated as a form

    The impact assessment is the heart of the standard and the item that fails most often in audit when it becomes paperwork. It has to change a project decision, or it serves no purpose.

  • Forgetting the third-party model

    Most of the AI a company uses today was not built by that company. Annex A.10 exists precisely for that, and it is where the first gap analysis finds the widest hole.

  • Controls that generate no record

    An audit does not assess intent, it assesses evidence. A control that depends on somebody remembering to write things down does not survive the second cycle.

  • Governance separated from engineering

    When the team writing the policy is not the team operating the system, the distance between document and reality grows with every sprint. The two need to share the same pipeline.

Back to services

Want to know where your AI operation stands against the standard?

A gap analysis at no cost against clauses 4 to 10 and Annex A, with the estimated effort per control and the order that makes sense to tackle them in.