ISO/IEC 42001:2023 is the international management system standard for artificial intelligence, published 18 December 2023. It specifies requirements for establishing and operating an AI management system — the governance apparatus around AI, not the AI itself — and it is certifiable by accredited bodies.
What it actually requires
It follows the harmonized management system structure, so clauses 4 to 10 mirror ISO/IEC 27001: context, leadership, planning, support, operation, performance evaluation, improvement. An organization holding 27001 will recognize the shape immediately, and the two can be operated as one integrated system. Certification to 42001 does not require 27001.
Four annexes carry the AI-specific content. Annex A is normative — reference control objectives and controls. Annex B is also normative, which most commentary gets wrong by calling it informative guidance; it provides implementation guidance for the Annex A controls and runs to roughly twenty-five pages against Annex A's four. Annexes C and D are informative, covering organizational objectives and risk sources, and sector-specific use.
It does not give you EU AI Act conformity
This is the claim worth getting right, because it is routinely overstated in vendor material.
The European Commission has stated directly that although ISO/IEC 42001 helps set up an AI management system, "its goals and definitions are not aligned with the quality management system that is required under the AI Act" — and that because of this misalignment it requested development of a separate European standard. Harmonized standards are expected from CEN and CENELEC during 2026, and presumption of conformity attaches only once a harmonized standard is cited in the Official Journal of the European Union.
So the accurate position is that 42001 certification is credible evidence of governance maturity and supports an AI Act readiness case. It is not a harmonized standard and creates no presumption of conformity. See the EU AI Act approach for the obligations that do bite.
Certification, and the standards around it
Certification is voluntary and performed by independent bodies that may be accredited by national accreditation bodies. Accreditation is live rather than theoretical: ANAB in the US and UKAS in the UK both operate programs, with UKAS having concluded its pilot, and accredited certification bodies were announced during 2026.
One nuance worth knowing when assessing a supplier's certificate. ISO/IEC 42006:2025, published July 2025, sets the requirements for the certification bodies themselves. Certificates issued before it existed were assessed against the generic ISO/IEC 17021-1 alone, which is a different assurance level from one issued under accreditation referencing 42006. Ask which applies.
Related standards: ISO/IEC 42005:2025 on AI system impact assessment, ISO/IEC 23894:2023 on AI risk management guidance, and ISO/IEC 5338:2023 on AI system lifecycle processes. ISO/IEC 42003, implementation guidance for 42001, is under development with no publication date announced.
What a management system standard does not do is enforce anything at runtime. It requires that controls exist and operate; producing the evidence that they did is a separate problem — see runtime governance, tamper-evident audit logs and examination readiness.
Related terms
NIST AI RMF · MITRE ATLAS · AI bill of materials · Runtime governance · Full glossary
Verified against ISO and European Commission sources in September 2026.
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs