top of page
logooption6.png

ISO 42001: 

What the AI management system standard does and doesn't prove

In December 2023, two of the world's main standards organizations published the first international standard that an organization can be certified against for how it governs artificial intelligence. It’s called ISO/IEC 42001, and in under two years it has gone from a document almost nobody had heard of to the credential enterprise buyers increasingly ask their AI vendors to produce.

 

Amazon, Anthropic, Microsoft, and Google have all been certified. Microsoft has begun requiring it of some of its own AI suppliers. If you build or deploy AI, ISO 42001 is fast becoming the standard answer to a question your customers are starting to ask: how do you know your AI is responsibly run? It’s worth understanding what that answer actually certifies — and, just as important, what it does not.

What is ISO 42001?

ISO 42001 is the international standard for AI management systems. It was published jointly by ISO and IEC, the two main international standards bodies, and written by their joint subcommittee on artificial intelligence, which has been at work on the field since 2017. An AI management system, in its language, is the set of policies, roles, processes, and controls an organization uses to govern its AI: how it decides what to build, how it weighs the risks, who is accountable, how it watches what it has deployed, and how it improves over time.

The word that matters most in the title is management. ISO 42001 is a management system standard, the same type as ISO 9001 for quality and ISO 27001 for information security. A standard of this kind sets out how an organization should run an activity — the governance around it — rather than how a product should perform. This is the single most important thing to understand about ISO 42001, and the rest of this article keeps coming back to it: it certifies the system you build around your AI, not the behavior of the AI itself.

It was written to be broad and applies across every sector and every kind of AI, from a simple predictive model to a generative chatbot or agent that acts on its own. And it applies whether you build AI, sell it, or use someone else's — a company that runs its customer service on a third-party model is as much in scope as the lab that trained it. Adoption is voluntary; no law currently requires ISO 42001. What makes it notable is that it is certifiable. Unlike most of the guidance that has crowded into AI governance, an independent body can audit you against it and issue a certificate that means the same thing in Frankfurt as it does in San Francisco.

Why this matters now

Nothing forces an organization to get certified, so the reason to pay attention is not a deadline. It’s that the market has started to treat the certificate as a cost of doing business.

The clearest signal comes from procurement. Enterprise buyers, wary of the gap between what AI vendors promise and what their systems actually do, have begun asking suppliers to prove they govern AI properly — and ISO 42001 is the proof they are learning to ask for. It is turning up in vendor questionnaires and due-diligence checklists, and at least one large buyer, Microsoft, has begun requiring it of some of its own AI suppliers. The pattern is familiar to anyone who watched SOC 2 and ISO 27001 go from nice-to-have to non-negotiable in security: once a credential becomes available, buyers start to expect it, and the cost of not having it climbs whether or not any law is involved.

The biggest names moved first, which is what set the expectation. Amazon's cloud arm was certified in late 2024, Anthropic in early 2025, with Microsoft, Google, and SAP following across their AI products. The base is still small, but growing quickly: by one count, fewer than two dozen organizations were certified worldwide at the start of 2025, a few hundred by 2026. That combination — marquee adopters over a tiny base — is exactly why certification is still worth something as a differentiator, and why the firms chasing it now are doing so before their competitors can.

Other frameworks have started pointing at ISO 42001 as a common reference. The American AI risk framework maps to it, the European Union's forthcoming quality-management standard is being built to connect to it, and regulators in finance and elsewhere lean on it. For an organization facing several regimes at once, building the management system ISO 42001 describes is increasingly the way to satisfy more than one of them with a single effort.

What ISO 42001 requires

ISO 42001 has two halves. The first is a set of requirements for the management system itself, organized into the same numbered clauses every ISO management standard uses — context, leadership, planning, support, operation, performance evaluation, improvement. The second is a menu of AI-specific controls, thirty-eight of them grouped into nine categories, that you draw on to treat the risks you have found. You are not required to adopt all thirty-eight; you choose the ones your risks call for and record, in a document called the Statement of Applicability, and justify why you included or excluded each. Beneath the structure, the substance comes down to a handful of things you have to get right.

Leadership and accountability. Someone senior has to own AI governance, set a written AI policy, name who is responsible for what, and resource the work. The standard wants AI risk treated as a leadership concern, not a side project in the data-science team.

An honest inventory and a risk assessment. You have to know what AI you are actually running and assess what could go wrong with it — not security risk in the conventional sense, but the particular ways an AI system can fail or do harm.

An impact assessment — the new part. This is what sets ISO 42001 apart from the older standards. Beyond asking what an AI system could cost you, it asks what that system could do to other people: to the individuals it touches, to groups, to society. It pushes an organization to think the way a human-rights or privacy review would, about consequences that land outside the company's internal operations.

Controls over data and the full lifecycle. The data feeding a model has to be governed for quality and provenance, and the system has to be managed across its whole life, from design through deployment to the day it is retired, with monitoring while it runs and disclosure to the people it affects.

Proof that the system runs, not just that it exists. Internal audits, management reviews, corrective action, and continual improvement — the machinery meant to keep the governance active after policies are written.

One feature runs through all of it: the standard tells you to have a process for these things, to assess risk, test, and monitor, but it does not tell you what the process must conclude. It sets no minimum accuracy, bias threshold, or required test. It governs that you have a defensible, risk-based way of deciding, not what you decide. That choice is the key to understanding both the standard's reach and its limits.

How to get ISO 42001 certified

For an organization starting from scratch, certification follows a well-worn path:
 

  1. Decide your scope and your role. Which AI systems, business units, and geographies are in, and whether you build, supply, or use the AI. Scope is the most consequential decision in the whole process, because it defines exactly what the certificate will and will not cover.

  2. Run a gap analysis. Measure your current state against the clauses and the thirty-eight controls, and build a workplan from what is missing.

  3. Craft the governance. Write the AI policy, set objectives, assign the roles, and integrate it into how the organization already manages risk.

  4. Do the two AI assessments. The risk assessment and the impact assessment, in practice rather than on paper. This is where new programs spend most of their time, because the questions are unfamiliar even to teams seasoned in security risk.

  5. Implement the controls. Put the chosen controls in place, each with an owner and evidence, and write the Statement of Applicability.

  6. Audit yourself first. Run an internal audit and a management review; both are required before anyone outside is allowed to certify you.

  7. Pass the external audit. An accredited certification body reviews your documentation, then checks that your everyday practice matches it, and issues the certificate.

  8. Maintain it. The certificate lasts three years, with a surveillance audit each year and a full recertification at the end of the cycle.
     

Few organizations do all of this unaided. Most bring in outside help somewhere along the way — a consultant to design the framework, or, for the technical testing that the assessments and controls depend on, a specialist who does that work.

One distinction is worth carrying into any conversation about ISO 42001, because not every certificate means the same thing. The body that audits you and issues the certificate is a certification body, and is in turn accredited by a national accreditation body — ANAB in the United States, UKAS in Britain, DAkkS in Germany. Accredited certification for ISO 42001 only became available in late 2024, and because the standard is young, there is already confusion between accredited certificates and self-declared ones. The sensible questions to ask of anyone holding a certificate are: who issued it, who accredited them, and what was actually in scope.

The work takes most organizations somewhere between four months and a year — faster for a small company with an existing management system, far longer for a large enterprise with significant AI buildouts. Audit fees run from the high four figures for a small business into six figures for a large one; the full program, including the internal work to get ready, runs higher and depends almost entirely on how much help you bring in. The key factor at present is not money but auditors: qualified, accredited assessors are scarce, and lead times can stretch for months.

What ISO 42001 doesn't prove

Most of ISO 42001 is recognizable governance work, and done seriously it delivers something substantial. It forces an organization to answer questions it has usually been avoiding (who owns this, what could it do to people, how would we know if it broke) and it puts an independent party's name behind the answers. None of what follows is an argument against the standard. It is an argument about its extent and limits.

A certificate attests that an organization has built, and operates, a sound system for governing its AI. It does not attest that any particular AI system is accurate, fair, robust, or safe. Three things make that gap fundamental to ISO 42001 rather than incidental:

  • The scope can be narrow. You certify a defined boundary, and a certificate covering one customer-service chatbot says nothing about other AI systems the company runs.

  • The auditor checks the process, not the product. An assessor confirms that you ran your own bias test and kept the logs; the assessor does not independently run the test, evaluate the model, or red-team the system. The audit is of your governance, not of your AI.

  • The standard sets no technical bar. Because it is non-prescriptive, two organizations can both be fully certified while their actual systems differ enormously in how well they behave.
     

So when someone asks the question that brings most people to this topic — does ISO 42001 mean my AI is safe? — the honest answer is no, and the standard's own defenders say as much. One certified cloud provider notes plainly that the standard does not mandate specific AI controls; another concedes that it does not certify the accuracy of any specific model. What the certificate promises is more narrow: an independent body found that, for the AI in scope, this organization runs a governance system conforming to ISO 42001 at the time it was checked. It does not promise that the AI works.

That scoping is the purpose of the standard, but it leaves an obvious gap, and the gap is the part customers, regulators, and courts ultimately care about: whether the AI, when actually tested, behaves. Closing it takes the different discipline of independent, hands-on technical validation of how the systems themselves perform. That’s the natural complement to a governance certificate, and what the certificate, by design, doesn’t provide.

How ISO 42001 fits with other frameworks

ISO 42001 does not stand alone, and anyone tracking AI rules elsewhere will recognize its relatives.

Its closest is ISO 27001, the information-security standard many organizations already hold. The two share the same structure, which is why a company with 27001 tends to reach 42001 faster — much of the infrastructure is already there. They are not the same, though: 27001 protects data, while 42001 governs the distinctly AI problems of bias, impact, transparency, and lifecycle. Having one helps with the other; neither is a prerequisite for the other.

The most obscure relationship is with the EU AI Act. ISO 42001 is not a harmonized standard under the Act, and holding it does not grant the legal presumption of conformity that harmonized standards confer — those are being written separately by Europe's own standards bodies. What ISO 42001 does is build most of the management system the Act will expect, and the European quality-management standard now in development is being designed to connect to it directly. ISO 42001 is a running start on the AI Act, but not a substitute for complying with it.

The American picture is simpler. The NIST AI Risk Management Framework is a voluntary method with no certificate attached; NIST has published a crosswalk mapping it to ISO 42001, so the common move is to use NIST for how you think about risk and ISO 42001 for the certifiable system you build around it. Around these sit a cluster of companion ISO standards (terminology, risk management, impact assessment) that fill in detail ISO 42001 points to but doesn’t discuss explicitly.

The emerging pattern is that ISO 42001 is the common backbone of AI governance standards. Other regimes map to it, buyers ask for it, and it increasingly serves as the shared reference point. It sits beneath the legal obligations that carry penalties, and beneath the technical validation that proves a system actually works.

How Conformance AI can help

The organizations that get the most out of ISO 42001 treat it as the governance layer it is, and then build the technical layer the certificate stops short of. That second layer is what Conformance AI does.

We are an independent, third-party check on AI systems. Where the certificate confirms you have a process for testing and monitoring your AI, we are the ones who actually do the testing, producing the evidence that the systems behave as intended:

  • Adversarial and behavioral testing. We probe AI systems the way a determined attacker or an unlucky user would, surfacing unsafe and off-policy behavior that a documentation review can’t assess.

  • Bias, fairness, and explainability evaluation. The technical work behind the impact and lifecycle controls ISO 42001 asks you to have.

  • Continuous monitoring. Drift detection and QA tracking on live systems, so the governance you certified once keeps matching reality between audits.

  • Remediation and evidence. We turn findings into engineering-ready fixes and author third-party proof, the record an auditor, a buyer, or a regulator will want to see.
     

Because the work underneath is the same, one body of technical evidence can support several frameworks at once — ISO 42001, the EU AI Act, the NIST framework, sectoral rules — so you are not rebuilding it for every standard you’re subject to.

If ISO 42001 is on your roadmap, we are the part that makes the certificate validate what your customers assume it validates. In the end the question a buyer, regulator, or court asks is whether the AI behind it actually works and whether you can show it.

This article is general information, not legal advice. ISO/IEC 42001 and the certification landscape around it are evolving; confirm specifics against the current text of the standard and with your own advisors.

This article is general information, not legal advice. ISO/IEC 42001 and the certification landscape around it are evolving; confirm specifics against the current text of the standard and with your own advisors.

bottom of page