An independent overview from DQS, an accredited certification body.

ISO/IEC 42001 is the international management system standard for artificial intelligence (AI). It specifies requirements for an AI Management System (AIMS) that supports the responsible development, deployment, and use of AI systems within an organization. The standard addresses the governance, risk management, and continual improvement of AI activities, recognizing the specific characteristics of AI — including data dependency, continuous learning, transparency expectations, and impacts on people, organizations, and society.

The standard is relevant to any organization that provides, develops, or uses AI systems — across the public sector, private enterprise, and academia. Customers, regulators, supply-chain partners, and the public are increasingly expecting documented evidence that organizations manage AI responsibly. ISO/IEC 42001 provides the first internationally recognized framework against which an AI management system can be assessed.

The current edition is ISO/IEC 42001:2023, published in December 2023. As the standard is relatively new, the population of certified organizations is still growing and the accreditation landscape — through national accreditation bodies and IAF-recognized accreditation arrangements — is being progressively built out. ISO/IEC 42001 certification is rapidly becoming a recognized means for organizations to demonstrate responsible AI governance in the context of the EU AI Act and other emerging AI regulations and codes of practice.

Already developing or deploying AI systems in your organization?

If your organization is establishing an AI Management System based on ISO 42001 and you are looking for a certification partner, our dedicated certification page has everything you need — from process overview to a personalized quote.

Go to ISO 42001 Cer­ti­fic­a­tion with DQS

What is ISO 42001, from a certification body's perspective?

From a certification body's perspective, ISO/IEC 42001 is the first certifiable management system standard for AI. An accredited certification body assesses an organization's AI Management System against the standard's requirements through an independent, two-stage audit and, on conformity, issues a certificate that is then maintained by periodic surveillance.

ISO/IEC 42001 follows the Harmonized Structure used by other ISO management system standards, which makes it compatible with ISO 9001, ISO 27001, and ISO 14001 within an integrated management system. Third-party certification is independent evidence of conformance and is increasingly relied on by customers, regulators, and supply-chain partners as evidence of responsible AI governance. The standard is referenced in policy discussions on the EU AI Act, the EU General-Purpose AI Code of Practice, and other emerging frameworks.

As a certification body, DQS assesses and certifies conformity — it does not design or implement your AI Management System. That independence is what gives a certificate its value: the organization builds and runs the system, and an accredited third party verifies it against the standard.

 

Key Facts at a Glance

Full TitleISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system
Published byInternational Organization for Standardization (ISO) and International Electrotechnical Commission (IEC), through joint technical committee ISO/IEC JTC 1/SC 42 (Artificial Intelligence).
First PublishedDecember 2023
Current VersionISO/IEC 42001:2023 (first edition). Accreditation arrangements continue to be developed by national accreditation bodies and through IAF-recognized arrangements.
Management System TypeAI Management System (AIMS)
Applicable toAny organization that provides, develops, or uses AI systems, regardless of size, sector, or geography — including public-sector bodies, private enterprises, and academia.
CertifiableYes. Independent third-party certification by an accredited certification body is the most widely recognized form of demonstrating conformance.
StructureHarmonized Structure (10 clauses) plus Annex A (reference control objectives and controls for AI), Annex B (implementation guidance for the controls), Annex C (AI-related organizational objectives and risk sources), and Annex D (use across domains and sectors).
Related StandardsISO 27001, ISO/IEC 23894, ISO/IEC 38507 

 

Context and Drivers

AI Regulation and the EU AI Act

Public and regulatory expectations regarding AI have intensified rapidly. The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) introduces a horizontal, risk-based regulatory framework for AI systems placed on the EU market, with phased applicability through 2025 and 2026. ISO/IEC 42001 does not by itself confer compliance with the AI Act, but its risk-based, management-system approach is well-aligned with the act's expectations on risk management, transparency, and oversight, and ISO/IEC 42001 is widely referenced in implementation discussions.

Customer, Supply-Chain, and Procurement Expectations

Organizations that provide AI-based products or services are increasingly asked by their customers and procurement counterparties to demonstrate documented AI governance. ISO/IEC 42001 certification gives these organizations a standardized way to evidence that they manage AI systems responsibly across the system life cycle — from design and data through training, deployment, monitoring, and decommissioning.

Trust, Transparency, and Societal Impact

AI systems operate in contexts where their effects on people, organizations, and society are visible and consequential. ISO/IEC 42001 requires organizations to consider these impacts systematically, supports informed decision-making by leadership and stakeholders, and provides a documented basis for the management of AI risks alongside the realization of AI opportunities.

 

Core Requirements

Clause 4 — Context of the Organization

Defines the external and internal context relevant to the AI Management System, including stakeholders, regulatory environment, and the boundaries of the AIMS. Organizations must consider the specific characteristics of AI systems in their context, including data sources, intended uses, and reasonably foreseeable misuses.

Clause 5 — Leadership

Establishes top management responsibility for the AIMS, the AI policy, organizational roles and responsibilities, and the integration of AI governance into wider organizational governance. Leadership commitment is central to responsible AI.

Clause 6 — Planning

Covers risk and opportunity management, AI objectives, planning of changes, and the AI risk assessment and AI impact assessment processes. Annex C provides AI-specific risk sources to consider; Annex A and B provide AI-specific controls and implementation guidance.

Clause 7 — Support

Addresses resources, competence, awareness, communication, and documented information, including the specific competence and awareness needs associated with AI development and deployment teams.

Clause 8 — Operation

Specifies requirements for operational planning and control, including AI risk treatment, AI impact assessment, controls across the AI system life cycle, data management, and management of AI suppliers and partners.

Clause 9 — Performance Evaluation

Covers monitoring, measurement, analysis and evaluation, internal audits, and management review, with particular attention to monitoring of AI system performance and ongoing review of AI risks.

Clause 10 — Improvement

Covers corrective action and continual improvement, including learning from AI incidents and adapting controls as AI systems and their context evolve.

Annex A and Annex B — Reference Controls and Guidance

Annex A lists reference control objectives and controls for the AIMS; Annex B provides implementation guidance. Together they cover policies for AI, internal organization for AI, resources for AI systems, assessing impacts, AI system life cycle, data for AI, information for stakeholders, use of AI systems, and third-party and customer relationships.

 

Target Groups and Application Areas

ISO/IEC 42001 is applicable to any organization that provides, develops, or uses AI systems. Typical scope includes technology companies developing AI products and services; organizations in regulated sectors (financial services, healthcare, public administration) deploying AI in decision-making and operational processes; public-sector bodies using AI in service delivery and policy implementation; and organizations in manufacturing, logistics, and consumer services using AI in operations.

The standard supports informed decisions by boards and executive teams, risk and compliance functions, technology and data leaders, and customers and procurement partners. ISO/IEC 42001 certification provides a structured basis for demonstrating responsible AI governance and for engaging credibly with regulators, customers, and the public.

Organizations that are at an early stage of AI adoption may use ISO/IEC 42001 as a framework for designing their AI governance from the outset. Organizations with mature AI activities may use the standard to integrate fragmented AI governance practices into a single, certifiable management system.

 

Related Standards

Harmonized Structure and Integration with Other Management Systems

ISO/IEC 42001 follows the Harmonized Structure used by ISO 9001, ISO 27001, ISO 14001, and other management system standards. Organizations already operating an integrated management system can extend their existing governance, internal audit, management review, and improvement processes to include the AI Management System.

ISO/IEC 42005 and AI Impact Assessment

ISO/IEC 42005:2025 provides comprehensive guidelines for assessing the impacts of AI systems on individuals, groups, and society throughout their lifecycle, as it is a requirement for AIMS. It acts as a supporting standard for ISO/IEC 42001:2023, the Artificial Intelligence Management System (AIMS) standard, by offering a structured approach to evaluate, document, and manage potential harms and benefits.

ISO 27001 and Information Security

AI systems depend heavily on data, and information security is a fundamental element of responsible AI. ISO/IEC 27001 specifies requirements for an information security management system; ISO/IEC 42001 references information security as part of the controls for AI but does not duplicate ISO 27001. Organizations holding ISO 27001 certification are well positioned to extend their management system to ISO/IEC 42001.

ISO/IEC 23894 and AI Risk Management Guidance

ISO/IEC 23894 provides guidance on managing AI-related risks. It is a guidance document — not a certifiable management system standard — and complements ISO/IEC 42001 by giving more detailed risk management content that organizations can use to operationalize ISO/IEC 42001 requirements.

ISO/IEC 38507 and AI Governance Implications

ISO/IEC 38507 addresses the governance implications of AI for organizations and is directed at boards and governing bodies. It is a guidance document complementary to ISO/IEC 42001 rather than a certifiable scheme.

EU AI Act and Regulatory Codes of Practice

The EU AI Act is the primary AI-specific regulatory framework in the EU and applies in phases through 2025 and 2026. Codes of practice for general-purpose AI, sector-specific guidance, and harmonized standards are being developed alongside the act. ISO/IEC 42001 is widely referenced in these discussions and provides a recognized management-system reference point for organizations implementing AI Act-relevant controls — but ISO/IEC 42001 certification is not formally equivalent to AI Act compliance.

Build Confidence in Your AI Systems Through The ISO 42001 Certification

Your organization develops or deploys AI systems and you are now considering independent certification under ISO 42001? Learn more on our dedicated ISO 42001 Certification page.

ISO 42001 Cer­ti­fic­a­tion with DQS

About DQS as a certification body

This article is part of the DQS Knowledge Center, a resource on management system standards and certification processes. For context on who produced it:

  • One of Germany's first management system certifiers — DQS issued its first ISO 9001 certificate in 1986 and has audited and certified management systems for over 40 years.
  • Operates from more than 80 offices in 60 countries with a worldwide network of more than 3,000 auditors.
  • Active in ISO/IEC 42001 certification alongside related standards such as ISO 27001, ISO/IEC 27701, and ISO 9001 — so organizations can be served across AI, information security, and quality management certification from a single provider. 
  • Member of IQNet, the international certification network, supporting cross-border recognition of DQS certificates.

The articles in this Knowledge Center are written and reviewed by DQS specialists working with these standards in audit practice. Where applicable, content is verified against the current version of the standard, the issuing body's official publications, and recent regulatory or accreditation guidance. This article was last reviewed on 3 June 2026.

Frequently Asked Questions about ISO 42001

Is ISO 42001 mandatory?

No. ISO/IEC 42001 is a voluntary international standard. However, organizations developing or deploying AI systems are increasingly expected by customers, regulators, and the public to demonstrate documented AI governance. Certification under ISO/IEC 42001 provides a structured way to evidence such governance.

What is the current version of ISO 42001?

The current published edition is ISO/IEC 42001:2023, published in December 2023. It is the first edition of the standard.

Does ISO 42001 certification mean compliance with the EU AI Act?

No. The EU AI Act (Regulation (EU) 2024/1689) is a regulatory framework applicable to AI systems placed on the EU market, applied in phases through 2025 and 2026. ISO/IEC 42001 certification is not formally equivalent to AI Act compliance. The standard is, however, widely viewed as a useful management-system foundation that supports organizations in addressing many of the act's expectations around risk management, transparency, and human oversight.

How does ISO 42001 relate to ISO 27001?

ISO/IEC 27001 specifies requirements for an information security management system and is structured around the same Harmonized Structure as ISO/IEC 42001. AI systems depend heavily on data, so the two management systems are complementary, and many organizations integrate them. Holding ISO 27001 certification provides a strong foundation for extending the management system to ISO/IEC 42001.

Which organizations should consider ISO 42001 certification?

Any organization that provides, develops, or uses AI systems can consider ISO/IEC 42001 certification. The standard is sector-neutral and size-neutral. It is particularly relevant for organizations that operate AI in higher-risk or higher-impact contexts — such as financial decision-making, healthcare, public services, employment, and critical infrastructure — and for technology providers whose customers expect documented AI governance.

How is ISO 42001 certified?

ISO/IEC 42001 certification follows the established two-stage audit model: Stage 1 (documentation and readiness review) and Stage 2 (on-site audit) leading to the certification decision. After initial certification, the management system is maintained through annual surveillance audits and a recertification audit at the end of the three-year cycle. Certification must be carried out by an independent certification body; ISO itself does not certify organizations.