What it requires
ISO 42001, published in December 2023, follows the same management system structure as ISO 27001: context, leadership, planning, support, operation, performance evaluation and improvement. Specific to AI are the AI risk assessment, the AI system impact assessment, which looks at effects on individuals and society, and controls covering the AI lifecycle, data, transparency, human oversight and the use of third party AI.
Who it is for
Both companies that build AI systems and companies that use AI in their products or operations. Customers increasingly ask for it when they want assurance about how a supplier uses AI with their data.
ISO 42001 and the EU AI Act
The EU AI Act is a law; ISO 42001 is a voluntary standard. Certification does not on its own prove compliance with the AI Act, but it provides the governance, risk management, documentation and oversight processes the regulation expects, especially for high risk systems.
Integration with other systems
Because it shares its structure with ISO 27001 and ISO 27701, many companies extend their existing information security management system to cover AI rather than building a separate one. The standard is available from ISO.




