ISO/IEC 42001
// Certifiable Standard - The Audit Anchor
ISO/IEC 42001 is not a law but something arguably more practical: a certifiable management-system standard that turns AI governance into auditable machinery. Regulators do not mandate it, yet it is becoming the fastest way to prove the governance every new law assumes.
Key Highlights
What the standard contains and why certification suddenly matters.
- 01
ISO/IEC 42001:2023, published December 2023 by ISO/IEC JTC 1/SC 42, is the world's first certifiable management-system standard for artificial intelligence.
- 02
It defines an AI Management System (AIMS) across clauses 4-10: organizational context, leadership accountability, planning, support, operation, performance evaluation, and continual improvement.
- 03
Annex A provides a reference catalogue of controls spanning AI governance policies, lifecycle management, data quality, transparency, responsible use, and third-party relationships.
- 04
Certification is delivered by accredited bodies under ISO/IEC 42006. Accreditation went live in January 2026 (UKAS), making externally verified AI governance a purchasable reality.
- 05
Companion standards complete the stack: ISO/IEC 23894 for AI risk management guidance and ISO/IEC 22989 for shared terminology.
- 06
Procurement increasingly accepts it: major supplier-assurance programs now accept ISO/IEC 42001 certification as evidence of AI governance maturity in lieu of bespoke questionnaires.
Action Items for Governance and Compliance
Five moves from ad-hoc governance to certified AIMS.
Stand up an AI Management System
A01Establish leadership accountability, defined roles, a documented AI policy, and measurable objectives reviewed by executives.
Implement clauses 4-10 with a Statement of Applicability over Annex A controls - the artifact certification auditors examine first.
Institutionalize risk and impact assessment
A02Name a methodology owner and tie assessment reviews to the management-review calendar.
Produce documented AI risk assessments and impact analyses that feed defensible control selection.
Control the AI supply chain
A03Adopt a supplier policy requiring notification of model or data-handling changes over the contract lifetime.
Embed vendor assurance checks into onboarding and renewal gates rather than one-off procurement questionnaires.
Prove competence and awareness
A04Maintain a role-based competency matrix with funded training paths.
Keep training records audit-ready for surveillance visits throughout the certificate cycle.
Prepare deliberately for certification
A05Run an internal-audit program with corrective-action tracking owned outside the audited teams.
Sequence stage-1 and stage-2 audits after evidence exists; never buy the certificate before the system does.
Engineering Translation
High-level capabilities that make the AIMS self-sustaining.
>_Policy objects stored as machine-readable artifacts consumed directly by build pipelines.
>_One shared evidence store tagged so a single control satisfies multiple frameworks at once.
>_Supplier questionnaires automated into onboarding workflows with expiration and re-checks.
>_Audit-ready exports generated on demand instead of assembled manually before each visit.
Delivered as capabilities, not paperwork
Each obligation above is translated into product-level engineering capabilities. The underlying stack and internal tooling are intentionally abstracted here; they are covered in technical briefings.
Educational summary only. This is not legal advice. Confirm obligations with qualified counsel for your jurisdiction.
Make Certification a Byproduct of Good Engineering
Book a technical briefing to wire ISO/IEC 42001 evidence collection directly into your delivery pipeline.