If you run ISO 27001, you’re most of the way here.
ISO 42001 shares its skeleton with every ISO management system you already operate — same clauses, same audit rhythm, same document control. What is genuinely new is short, specific, and the part teams under-build: the AI system impact assessment, the Annex A controls, and the lifecycle evidence. We assess you against all of it before the certification body arrives, and hand you the gap by clause.
Six questions. Then you’ll know roughly where you stand.
No email. No signup. A position, not a certification opinion — and if you already run a management system, expect the answer to be better than you assumed.
Your readiness position
Most of it you already own. Three things you don’t.
The Harmonised Structure gives the core text of clauses 4–10 in common across ISO management system standards — so the reuse is structural, not a sales line.
From an existing ISO management system
- Document control and documented information — clause 7.5
- Competence and awareness — clauses 7.2 and 7.3
- The internal audit programme — clause 9.2
- Management review — clause 9.3
- Nonconformity and corrective action — clause 10.2
- Leadership, policy and context machinery — clauses 4 and 5
Not free — each still has to be extended to cover AI and evidenced in the new scope. But you are editing something that exists rather than building it.
The AI system impact assessment
Clause 6.1.4No predecessor in ISO 27001 or 9001. A structured, documented and dated assessment per system of consequences for individuals, groups and society. This is the requirement first attempts most reliably under-build.
The Annex A control set
A.2 – A.10Your existing Statement of Applicability transfers as a format. Its contents do not: these are AI controls across policy, organisation, resources, impacts, lifecycle, data, information, use and third parties.
Lifecycle evidence
Clause 8 · A.6Design, verification and validation, deployment approval and operational monitoring — each leaving a record, so a gate that was passed can be shown to have been passed rather than asserted.
What is ISO 42001?
An international standard for an AI management system — the governance, roles, controls and continual improvement around how an organisation builds and runs AI. It is risk-based and it runs on Plan–Do–Check–Act, which is the practical point: it is designed to be operated, not completed. What separates it from every other AI framework is that an accredited body can audit you against it and issue a certificate.
- Standard ISO/IEC 42001:2023 The first international AI management system standard, published December 2023.
- Type Certifiable Audited by an accredited certification body — this is the one AI framework you can hold a certificate for.
- Structure Clauses 4–10 + Annex A The harmonised management-system structure, plus 38 controls across nine groups.
- Cycle Plan–Do–Check–Act A management system, not a project. It is designed to be operated, not completed.
- Annexes A, B, C and D A is the controls; B their implementation guidance; C potential AI-related objectives and risk sources; D the domains an AIMS can be applied across.
Who needs ISO 42001?
Nobody is legally required to hold it. It arrives through commercial pressure — a procurement questionnaire, a supervisor, an insurer — and it answers all three with one document instead of forty.
- Organisations selling AI into enterprise A certificate answers a vendor security review in one document instead of forty. It is increasingly the fastest route through procurement.
- Teams already running ISO 27001 or 9001 Same harmonised structure, same audit rhythm, largely the same internal audit and management review machinery. Integration is the cheap path.
- Regulated industries A named, audited management system is what a supervisor asks for when the question moves from "do you have a policy" to "show me it works".
- Anyone with EU AI Act exposure It covers much of the same operational ground. It does not make you compliant with the Act — see the comparison further down, which is the section most people need.
How iDharma supports ISO 42001 certification
A verified auditor works the standard in its own structure, so the report reads clause by clause — which is how your certification body will read it too.
| ISO/IEC 42001 requirement | What the assessment does |
|---|---|
| Clause 4 — Context | Scope of the AI management system fixed in writing: which systems, which sites, which parts of the organisation, and what is deliberately outside it. |
| Clause 5 — Leadership | AI policy, roles and accountability read against what actually happens, not against the org chart. Leadership evidence is the first thing an auditor tests. |
| Clause 6 — Planning | Risk assessment and treatment, the AI system impact assessment, and the Statement of Applicability with a justification per control. |
| Clause 7 — Support | Competence, awareness, communication and documented information — including whether your document control survives contact with a real audit. |
| Clause 8 — Operation | The lifecycle controls in practice: design, verification, deployment, monitoring, and the records each stage is supposed to leave behind. |
| Clause 9 — Evaluation | Monitoring and measurement, internal audit and management review — the three places a young management system is usually thinnest. |
| Clause 10 — Improvement | Nonconformity handling, corrective action and continual improvement, with the trail an auditor can follow from finding to closure. |
| Annex A controls | All 38 controls reviewed, each mapped to the evidence that supports it and to your inclusion or exclusion decision in the SoA. |
AI system inventory and context mapping
Register every AI system with the metadata clause 4 and Annex A ask for — purpose, data, deployment context, interested parties — so the scope statement is derived from the inventory rather than asserted above it.
Addresses: Clause 4 context and scope, A.4 resources
Risk assessment and treatment workflow
Risk identification, analysis, evaluation and treatment run as a repeatable process with owners and dates, so clause 6 produces a comparable series rather than a snapshot taken the week before the audit.
Addresses: Clause 6.1 risk, Clause 8.2 treatment
AI system impact assessment
The requirement that separates ISO 42001 from every management system standard before it: structured assessment of consequences for individuals, groups and society, documented and dated per system.
Addresses: Clause 6.1.4 impact assessment, A.5 assessing impacts
Statement of Applicability
Every Annex A control with an included-or-excluded decision and the reasoning behind it. The SoA is the document a certification auditor opens first, and the one most often assembled last.
Addresses: Clause 6.1.3 SoA, Annex A 38 controls
Lifecycle controls and deployment gates
Objectives for responsible development, verification and validation, deployment approval and operational monitoring — each with the record the clause expects, so a gate that was passed can be shown to have been passed.
Addresses: A.6 AI system life cycle, Clause 8 operation
Internal audit and management review
The clause 9 machinery stood up properly: an audit programme with independence, findings tracked to closure, and a management review with inputs and outputs that match what the standard asks for.
Addresses: Clause 9.2 internal audit, Clause 9.3 management review
An assessment is not a certification. We are the independent read before the certification body arrives — deliberately a different role, because the same firm cannot both prepare you and impartially certify you.
Complete ISO 42001 requirements coverage
All 7 management clauses and all 38 Annex A controls, with dedicated tooling behind each one.
- Clause 4 Context of the organisation Scope, interested parties, and what the AIMS covers
- Covered in full by the assessment
- Clause 5 Leadership AI policy, roles, responsibilities and authorities
- Covered in full by the assessment
- Clause 6 Planning Risk, impact assessment, objectives and the SoA
- Covered in full by the assessment
- Clause 7 Support Competence, awareness, communication, documentation
- Covered in full by the assessment
- Clause 8 Operation Operational planning and control across the lifecycle
- Covered in full by the assessment
- Clause 9 Performance evaluation Monitoring, internal audit and management review
- Covered in full by the assessment
- Clause 10 Improvement Nonconformity, corrective action, continual improvement
- Covered in full by the assessment
- Annex A All 38 controls Nine control groups, each mapped to your SoA decision
- 38/38 controls covered
Statement of Applicability
Built from your inventory rather than from a template, with a justification per control that survives being read aloud.
Management system evidence
The clause 9 and 10 machinery — audits, reviews, corrective actions — stood up so it produces records, not intentions.
AI impact assessment
The requirement with no predecessor in 27001 or 9001, and the one most teams under-build on their first attempt.
Supplier governance
Third-party and foundation-model relationships mapped to A.10, because most of the AI in a modern stack was not built in it.
ISO 42001 and the EU AI Act
The two overlap, but they are not substitutes. Here is what each gives you — and, more usefully, what the certificate does not.
Where the two converge
Ground you cover once and can evidence for both
- A risk management process running across the whole AI lifecycle
- Data governance — provenance, quality and preparation
- Documentation and records that outlive the people who made them
- Human oversight with named roles and real authority
- Post-deployment monitoring and incident handling
- Assessment of impacts on the people a system reaches
Where they diverge
The gap a certificate leaves open
- ISO 42001 is voluntary; the Act is binding law with penalties attached
- ISO certifies your management system; the Act regulates specific systems by risk tier
- The Act adds prohibited practices and Article 50 transparency duties with no ISO equivalent
- High-risk systems need conformity assessment and CE marking — a certificate is not one
- The Act's presumption of conformity runs on harmonised European standards from CEN-CENELEC JTC 21 — a separate track from ISO
- Annex III high-risk obligations apply from 2 December 2027 — ISO work done now lowers that cost but does not discharge it
The sentence to avoid: “we are ISO 42001 certified, so we are EU AI Act compliant.” Certification is strong evidence of a managed system and it lowers the cost of everything the Act asks for. It is not a conformity assessment, not a CE mark, and not a presumption of conformity. See the EU AI Act page for what is actually required.
90 days to audit-ready
An implementation roadmap with clear phases and deliverables. The days are elapsed position, not effort — the phases overlap, and this assumes you already run document control and internal audit for something else.
-
Phase 1 Days 1–20
Get organised
Scope, inventory and who owns what
- Fix the AIMS scope and write it down
- Inventory every AI system in and out of scope
- Assign roles, authorities and escalation
- Draft or adapt the AI policy
- Agree the risk method before running it
-
Phase 2 Days 21–50
Close the big gaps
Risk, impact and the Statement of Applicability
- Run the risk assessment and treatment plan
- Complete AI system impact assessments
- Draft the Statement of Applicability
- Fill the documentation gaps Annex A exposes
- Set supplier and third-party terms
-
Phase 3 Days 51–75
Operationalise
Make the controls something people do
- Stand up lifecycle gates and approvals
- Turn on monitoring and event logging
- Run awareness and competence training
- Establish the incident and nonconformity route
- Start generating records, not just documents
-
Phase 4 Days 76–90
Prove it works
Evidence an auditor can follow
- Run a full internal audit against the standard
- Hold the first management review
- Close or plan out the findings
- Assemble the evidence pack by clause
- Book stage 1 with the certification body
38 Annex A controls, simplified
The 38 controls sit in nine groups. You apply the ones that fit your context — and justify every inclusion and every exclusion in the Statement of Applicability.
Policies related to AI
The AI policy itself, how it lines up with your other policies, and who reviews it.
Internal organisation
Roles and responsibilities for AI, and a working route for reporting concerns.
Resources for AI systems
Data, tooling, compute and people — documented as resources rather than assumed.
Assessing impacts of AI systems
The impact assessment process, and impacts on individuals, groups and society.
AI system life cycle
Responsible design and development, verification and validation, deployment, operation.
Data for AI systems
Acquisition, quality, provenance and preparation of the data a system is built on.
Information for interested parties
System documentation for users, external reporting and communication of incidents.
Use of AI systems
Responsible use: the processes, the objectives, and the intended use actually held to.
Third-party and customer relationships
Allocating responsibilities across suppliers and customers — where most AI now comes from.
What auditors will look for
Stage 1 asks whether the system is designed. Stage 2 asks whether it runs. Nearly every first-attempt finding lives in the gap between those two questions — and it is why a management system assembled the month before an audit reads as one. The third column is where certificates are lost.
Readiness and design
- AIMS scope and boundaries
- AI policy and objectives
- Statement of Applicability
- Risk method and results
- Impact assessment process
- Internal audit programme
Effectiveness
- Controls operating in practice
- Records against each clause
- Lifecycle gates actually applied
- Monitoring output and response
- Management review minutes
- Corrective actions closed
Maintenance
- Surveillance audits between cycles
- Scope kept current as systems change
- Continued internal audit coverage
- Nonconformities trending down
- Supplier reviews repeated
- Recertification at the cycle end
Evidence your auditor will expect
Six families of record. A management system is judged on what it leaves behind, not on what it intended.
Scope and inventory
A scope statement derived from a real inventory, with the exclusions stated and reasoned.
Policies and procedures
Approved, dated, version-controlled, and demonstrably known to the people expected to follow them.
Risk and impact records
Assessments with method, inputs, owners and dates — not a spreadsheet regenerated for the audit.
Lifecycle records
Design decisions, verification and validation results, deployment approvals, change history.
Monitoring and incidents
Logs, metrics, thresholds and what happened when one was crossed.
Audit and review
Internal audit reports, management review minutes, and corrective actions traced through to closure.
Records the system produces on its own, not for the audit
Complete AI governance policy repository
33 ready-to-use templates aligned to ISO 42001, and mapped across to EU AI Act and NIST AI RMF requirements.
Core governance
- AI Policy (Clause 5.2)
- AIMS Scope Statement
- Roles & Authorities
- AI Objectives & Planning
- Statement of Applicability
- Management Review Pack
+ 5 more policies
Data & security
- Data Governance Standard
- Data Provenance Record
- Data Quality Procedure
- Data Preparation Standard
- AI Security & Robustness
- Event Logging Standard
+ 4 more policies
Lifecycle & compliance
- AI Impact Assessment Template
- Lifecycle & Release Procedure
- Supplier & Third-Party Terms
- Internal Audit Programme
- Nonconformity & Corrective Action
- Competence & Awareness Plan
+ 6 more policies
Frequently asked questions
What comes up in every ISO 42001 scoping call.
Is certification mandatory?
No. ISO/IEC 42001 is voluntary. What makes it feel mandatory is where it is asked for — enterprise procurement, vendor security reviews and increasingly insurer and supervisor diligence. It is the only AI framework you can hold a certificate for, which is precisely why it gets named in contracts.
How long does certification take?
For an organisation with an existing management system, roughly three to six months to audit-ready, then the certification body's own stage 1 and stage 2 audits. Starting from nothing, plan for longer than the ninety days on this page — that roadmap assumes someone is already doing document control and internal audit for something else.
How do we choose a certification body?
Check that it is accredited for ISO/IEC 42001 specifically by a recognised accreditation body, not merely certified to other standards. We do not certify — we are the independent assessment before the auditor arrives, which is a different role and deliberately so.
What happens after certification?
Surveillance audits between cycles and recertification at the end of one, typically three years. The management system has to keep producing records in between; a certificate held over a dormant system is the thing surveillance is designed to find.
Can we certify specific AI systems rather than the whole organisation?
You certify a management system with a defined scope, so yes — the scope can be drawn around a business unit or a set of systems. It has to be drawn honestly: a scope that carves out the AI everyone actually asks about will be noticed, and it is the fastest way to make a certificate worth less than not having one.
Do we have to implement all 38 Annex A controls?
No — but you have to make and justify a decision about every one of them. That is what the Statement of Applicability is: each control included or excluded, with the reasoning recorded. An exclusion with a real reason is fine; an exclusion with no reason is a finding.
What is the difference between ISO 42001 and ISO 27001?
27001 protects information; 42001 governs how AI is developed and used. They share the harmonised structure, so clauses 4 to 10 will feel familiar, and much of the machinery — document control, internal audit, management review — is reusable. What is new is the AI system impact assessment and the lifecycle controls in Annex A.
Can we integrate it with an existing ISMS or QMS?
Yes, and it is the cheap path. One audit programme, one management review, one document control system, one nonconformity process. What you cannot merge away is the AI-specific content: the impact assessment and the lifecycle controls have no equivalent in 27001 or 9001.
We already have ISO 27001. What actually carries over?
The clause 4 to 10 machinery, largely: document control under 7.5, competence and awareness under 7.2 and 7.3, the internal audit programme under 9.2, management review under 9.3, nonconformity and corrective action under 10.2, and the leadership and context work in clauses 4 and 5. The Harmonised Structure means that core text is common across ISO management system standards. What does not carry over is the AI system impact assessment under clause 6.1.4, the Annex A control set, and the lifecycle evidence in clause 8 and A.6. Your Statement of Applicability transfers as a format; its contents do not.
What are Annexes B, C and D for?
Annex B is implementation guidance for the Annex A controls. Annex C lists potential AI-related organisational objectives and risk sources, which is useful input when you are setting risk criteria rather than inventing them from scratch. Annex D covers the domains and sectors an AI management system can be applied across. None of the three is a requirement; all three save time, and most implementations discover them late.
What if we rely on third-party or foundation models?
A.10 covers third-party and customer relationships precisely because most AI in a modern stack was not built in it. Buying a model in does not move the responsibility; it changes what evidence you can produce yourself and what you have to obtain from the supplier. In practice this is the weakest area we find.
What documentation is required?
The standard names some documented information explicitly — scope, policy, objectives, risk method and results, the Statement of Applicability, impact assessments, competence records, internal audit results, management review outputs, nonconformities and corrective actions. Beyond that, whatever is needed for the system to work. Producing more than that is a common and expensive mistake.
How do internal audits work for an AIMS?
A planned programme covering the whole management system over a defined period, conducted by people independent of the work being audited. Findings get tracked to closure. This is where a young management system is usually thinnest, and it is the first thing a stage 2 auditor tests.
How does ISO 42001 address bias and fairness?
Through the impact assessment and the lifecycle and data controls rather than through a prescribed fairness metric. The standard requires you to consider impacts on individuals and groups and to act on what you find; it does not tell you which test to run, which is a feature — the right test depends on the system.
What training is required?
Competence for anyone whose work affects AI performance, and awareness of the policy and their contribution for everyone in scope. Both have to be evidenced. A training deck with no attendance record satisfies neither.
Is it suitable for smaller teams?
Yes, and the standard scales by design — the requirement is a management system appropriate to your context, not a fixed volume of paperwork. Small teams usually over-document and under-evidence. The fix is fewer, shorter documents and more records.
Does ISO 42001 make us EU AI Act compliant?
No, and this is the most expensive assumption on the subject. The Act regulates specific systems by risk tier and adds prohibited practices, transparency duties and conformity assessment with CE marking — none of which a management system certificate supplies. What certification does is cover a lot of the same operational ground, so the remaining gap is smaller and easier to evidence.
Will it become a harmonised standard under the Act?
The Act's presumption of conformity runs on harmonised European standards, which are a separate track. Treat ISO 42001 as a strong operational foundation that lowers the cost of whatever the Act asks for, not as a shortcut through it.
We are also running NIST AI RMF. Is that wasted?
No — they do different jobs and they compose well. AI RMF is better at structuring the risk work itself; ISO 42001 is better at proving to a third party that the system around it is managed. We map findings across both so one body of evidence answers two asks.
On this page
References are to ISO/IEC 42001:2023. The standard is not freely available — clause and control references here are summarised rather than quoted, and checking them requires a licensed copy. The control total of 38 is the figure in general circulation and is the one number on this page we would want you to confirm against your own copy before quoting it back to anyone.
This is general information about what the standard requires. It is not legal advice, not certification advice, and not a certification — we do not issue certificates, deliberately, because the same firm cannot both prepare you and impartially certify you.
Ready to achieve ISO 42001 certification?
Clauses 4–10, all 38 Annex A controls, the Statement of Applicability and the evidence pack — assessed before your certification body sees any of it.
We assess; we do not certify. This page is guidance on how we scope an assessment, not legal advice or a substitute for the standard.