Protocols and standards

ISO/IEC 42001

ISO/IEC 42001:2023 is the international standard specifying requirements for an artificial intelligence management system — the governance structure, processes and records an organisation puts in place to develop or use AI responsibly. It is the first AI standard an organisation can be certified against by an accredited certification body, and, like ISO/IEC 27001, it certifies a management system within a declared scope rather than any product, model or software.

also called ISO 42001 · AI management system · AIMS · ISO/IEC 42001:2023

Published in December 2023, ISO/IEC 42001 follows the Harmonised Structure shared by every modern ISO management-system standard, so its Clauses 4 to 10 are Context of the organisation, Leadership, Planning, Support, Operation, Performance evaluation and Improvement. An organisation already certified to ISO/IEC 27001 or ISO 9001 reuses most of that scaffolding, which is the main practical reason 42001 adoption has been quicker than a genuinely new standard would be. Two clauses carry the AI-specific weight. Clause 6.1.3 requires a Statement of Applicability naming the Annex A controls determined to be necessary, with justification for every inclusion and for every exclusion. Clause 6.1.4 requires a process for assessing the impact of AI systems on individuals, groups and society — the requirement that most clearly distinguishes an AI management system from a security one, because it asks about consequences for people who are not your users.

Annex A carries 38 controls in nine groups: A.2 policies related to AI, A.3 internal organisation, A.4 resources for AI systems, A.5 assessing impacts of AI systems, A.6 AI system life cycle, A.7 data for AI systems, A.8 information for interested parties, A.9 use of AI systems, and A.10 third-party and customer relationships. Annex B gives implementation guidance, Annex C lists organisational objectives and risk sources, and Annex D lists domains and sectors. The controls a runtime system genuinely touches are a minority of the 38 — recording of event logs under A.6.2.8, communication of incidents under A.8.4, and suppliers under A.10.3 are the usual three — and reading Annex A as a technical checklist is the most common way to misuse it. Most of its controls are documented processes, assigned responsibilities and evidence that a decision was taken by someone with the authority to take it.

Certification works the way every ISO management-system certification works, and the mechanics are worth knowing because they determine what a certificate means. A certification body accredited under ISO/IEC 17021-1, with the AI-specific requirements set out in ISO/IEC 42006, conducts a Stage 1 documentation review followed by a Stage 2 audit; a certificate typically runs three years with annual surveillance audits and a recertification audit at the end. The scope statement printed on the certificate matters more than the certificate does. A scope reading ‘the AI management system supporting the recruitment platform, at the London and Dublin offices’ is a claim about that and nothing else. A product cannot be certified to 42001 at all, so a vendor answering ‘yes’ has told you about its own management system and nothing about the software it is selling you — a conflation that survives most procurement processes unchallenged.

The relationship to law is narrower than marketing usually implies. ISO/IEC 42001 is not a harmonised standard under the EU AI Act and confers no presumption of conformity with it; the harmonised standards for the Act are being developed by CEN-CENELEC JTC 21, and the overlap between 42001 and the Act’s requirements is real but partial. A 42001 certificate is evidence that a governed process exists and is audited. It is not a defence, it does not classify your systems, and it does not substitute for any Article 26 duty. The neighbouring documents are worth knowing so they are not mistaken for it: ISO/IEC 23894 is guidance on AI risk management and is not certifiable, ISO/IEC 22989 fixes the terminology, and ISO/IEC 42005 gives guidance on the impact assessment Clause 6.1.4 requires.

Where implementations fail an audit, the failure is usually the same one and it is structural rather than clerical. The inventory of AI systems, the record of who owns each, and the assessment attached to each are maintained beside the runtime rather than inside it — a spreadsheet updated by whoever remembers, next to a deployment pipeline updated by whoever ships. The two diverge within weeks, and an auditor samples the divergence rather than the document. The property that removes the failure mode is not a better process for reconciling the two lists: it is that the record the enforcement point resolves on every call is the same row the inventory shows, so there is only one list and drift has nowhere to happen.

in practice

What the certificate on the wall actually covers

A supplier questionnaire asks whether the vendor is ISO 42001 certified and the vendor answers yes. Three follow-up questions turn that into information. Which certification body issued it, and which accreditation body accredited them? What does the scope statement say, verbatim? When was the most recent surveillance audit? The answers establish that a management system inside that scope was audited on that date. They do not establish that the product you are buying was in scope, that any model was assessed, or that any Annex A control is technically enforced anywhere in the code. A control mapping is a different artefact again, and reads very differently once you notice whether its rows say ‘helps evidence this clause’ or ‘complies with this clause’ — the first is a defensible statement about a feature, the second is a claim only a certification body can make.

not the same as

What iso/iec 42001 is routinely confused with

ISO/IEC 27001
27001 governs information security; 42001 governs AI-specific risk — impact on individuals and society, data provenance and quality, and life-cycle responsibility for systems whose behaviour is learned rather than specified. They share the Harmonised Structure and can be run as one integrated management system, but they have different Annex A control sets and separate certificates. A 27001 certificate says nothing about AI governance.
NIST AI RMF
42001 is a certifiable management-system standard with requirements clauses, an accredited audit and a certificate. The NIST AI RMF is voluntary guidance with no conformity scheme and nothing to be certified against. Organisations routinely use the RMF to structure how they think about risk and 42001 to produce something a customer’s procurement team accepts.
ISO/IEC 23894
23894 is guidance on AI risk management. It has no requirements clauses, so there is nothing to audit against and no certificate exists. It is the document you read to do the risk work that 42001 Clause 6.1 requires you to have done.
next

Related terms

EU AI Act

The EU AI Act is Regulation (EU) 2024/1689, which regulates AI systems placed on the market or used in the European Union in proportion to the risk they present, and which places materially different duties on the organisation that builds a system (the provider) and the organisation that uses it under its own authority (the deployer). It entered into force on 1 August 2024 and applies in stages: the prohibited practices from 2 February 2025, the general-purpose AI model obligations from 2 August 2025, and most remaining obligations, including those on high-risk systems listed in Annex III, from 2 August 2026.

NIST AI RMF

The NIST AI Risk Management Framework (AI RMF 1.0) is voluntary guidance published by the United States National Institute of Standards and Technology in January 2023 for identifying, measuring and managing the risks of AI systems across their life cycle. Its core organises that work into four functions — GOVERN, MAP, MEASURE and MANAGE — and, unlike a management-system standard, it carries no conformity or certification scheme, so an organisation adopts it and evidences its own adoption rather than being certified against it.

OWASP Top 10 for LLM Applications

The OWASP Top 10 for Large Language Model Applications is a community-maintained list of the ten most significant security risks in applications built on large language models, published by the OWASP GenAI Security Project. It is an awareness and prioritisation document rather than a standard: nothing certifies against it, and its ranking comes from consensus among contributing practitioners rather than from measured incident data.

Protocols and standards

The terms next to this one

The substrate everything here conforms to, and the four regulatory instruments that decide what evidence an operator has to be able to produce.

get in touch

Definitions are the easy part.

The glossary is written to be useful whether or not you ever buy anything. If you have got to the point of deciding how to implement one of these in your own estate, say what your agents do and you will get a straight answer about what it would actually take.

no form · no qualification step · no sales desk · the other three ways in