ISO 42001 is how organisations prove their AI is governed
The first certifiable AI management system standard gives structure to a question every board, customer and regulator is now asking: who is accountable for what your AI does?
- Published
- December 2023
- What it certifies
- An AI Management System (AIMS)
- Annex A
- 38 controls across 9 objectives
- Pairs with
- ISO 27001 · EU AI Act readiness
The highlights
Built on the same high-level structure as ISO 27001, the standard governs AI across its whole lifecycle — whether you develop models, fine-tune them, or simply deploy AI in your operations.
Governance for the AI lifecycleClauses 4–10
Context, leadership, planning, support, operation, evaluation, improvement — the familiar management-system spine, applied to how AI is selected, built, deployed, monitored and retired.
AI risk and impact assessmentClauses 6 & 8
Beyond conventional risk assessment, the standard requires AI system impact assessments — considering effects on individuals and society: fairness, safety, transparency and accountability, not just uptime.
38 controls for responsible AIAnnex A
Controls spanning AI policy, roles, resources and data governance, lifecycle documentation, information for interested parties, and third-party AI relationships — a concrete backbone for 'responsible AI' claims.
Roles, not vibesAnnex A.3
The standard forces clarity on whether you are an AI provider, developer or user for each system, and assigns accountable owners. Most AI governance failures trace back to precisely this ambiguity.
The regulatory bridgeWhy now
ISO 42001 doesn't certify EU AI Act compliance, but it operationalises what the Act demands — risk management, data governance, human oversight, logging and transparency — inside an auditable system. For firms already holding ISO 27001, the integration is natural and fast.
Where to start
- Start with the AI inventory — every governance obligation attaches to a system. Catalogue what you build, buy and embed.
- Define your role per system — provider, developer or user — obligations under both the standard and the AI Act follow from this.
- Integrate, don't duplicate — extend your existing ISMS: shared risk methodology, shared internal audit, one management review.
- Run your first impact assessment — pick your highest-stakes AI use and assess it properly. The methodology matters more than the template.
Ready to make responsible AI something you can evidence?
Sentinel42 builds ISO 42001 AI management systems — integrated with ISO 27001 where you hold it — led by a qualified ISO 42001 Lead Auditor and Implementer.