
Artificial intelligence has entered the day-to-day operations of businesses faster than legal frameworks and standards have been able to keep up with it. ISO 42001 is the standardisation community’s first response to this challenge – and it raises many questions. Below, we answer the most frequently asked ones.
ISO/IEC 42001:2023 is the first international standard setting out requirements for an Artificial Intelligence Management System (AIMS). It describes how an organisation should manage AI-related risks, ensure algorithm transparency, oversee the lifecycle of AI systems, and meet ethical and regulatory requirements. Published on 18 December 2023, this standard aims to help companies and organisations develop a robust framework for managing AI.
The ISO 42001 system can be implemented in organisations of any size, type and nature that supply or use products or services based on AI systems. This means that the standard covers both technology companies developing AI systems from scratch and organisations in other sectors that use off-the-shelf AI tools in their processes – for example, companies using chatbots, recommendation systems, data analysis tools or decision automation.

The standard follows the HLS (High Level Structure) – the same as ISO 27001, ISO 9001 and ISO 22301. For organisations that already hold other ISO certificates, integration with ISO 42001 is much simpler and cheaper, as many elements of the management system – policies, internal audits, management reviews, non-conformity management – can be shared. ISO 42001 complements other ISO standards relating to AI, such as ISO/IEC 22989 (AI terminology), ISO/IEC 23053 (framework for AI systems) and ISO/IEC 23894 (AI risk management).
AIMS (AI Management System) is an artificial intelligence management system – a set of policies, processes, procedures and practices that an organisation implements to manage AI responsibly. ISO 42001 imposes stringent requirements, ensuring that aspects critical to AI – such as security, fairness, transparency, as well as the quality of data and systems – are taken into account throughout the technology’s lifecycle. An AI Management System (AIMS) must include, amongst other things, the identification and assessment of AI-related risks, the management of the life cycle of AI systems, oversight of the data used to train models, mechanisms for the explainability and transparency of algorithms, and procedures for responding to AI-related incidents.
Yes. ISO/IEC 42001 certification is granted following the successful completion of an audit and enables the secure implementation of artificial intelligence, with evidence of responsibility and accountability. The certificate is issued by accredited certification bodies following a two-stage audit – similar to the certification process for ISO 27001 or ISO 9001. The certificate confirms that the organisation’s AI management system meets the requirements of the standard and is maintained and improved.
It is the first standard of its kind in the world – holding the certificate today sends a clear signal to customers, regulators and investors that the company takes AI seriously. At the same time, the standard aligns directly with the requirements of the EU AI Act – a regulation governing the use of artificial intelligence in the EU, which imposes specific obligations on providers and users of high-risk AI systems. Organisations that establish an AI management system compliant with ISO 42001 will be much better prepared to meet regulatory requirements before they become mandatory.