ISO/IEC 42001 (ISO 42001)

ISO/IEC 42001:2023 is the international standard for artificial intelligence management systems. It sets requirements for establishing, operating, monitoring and improving an AI management system and addresses any organisation that offers or uses AI systems. As a management system standard it is an organisational framework, not a route to conformity with a regulation.

GRCLast reviewed:

ISO/IEC 42001 was published in December 2023 as the first management system standard for artificial intelligence, and it promptly acquired a reputation it does not deserve: the AI Act certificate. There is, so far, no newer main edition; offers naming an "ISO 42001:2026" mean something else. It is not that. Knowing precisely what it is, and what the EU AI Act does and does not accept as proof, saves an expensive detour.

The official title is "Information technology — Artificial intelligence — Management system". It sets requirements for establishing, implementing, maintaining and continually improving an AI management system, commonly abbreviated to AIMS, and it addresses any organisation that offers or uses products or services involving AI systems, irrespective of size, type or sector.

Why AI needed a standard of its own

Anyone already running an ISMS will recognise the structure: context, leadership, planning, support, operation, performance evaluation, improvement. ISO/IEC 42001 follows the harmonised structure ISO uses for management system standards, so it combines with an existing system rather than displacing it.

The questions are different, though. An ISMS asks about confidentiality, integrity and availability. An AI management system also asks about the purpose and the limits of a model, about data provenance and data quality, about the traceability of decisions, about human oversight, about effects on the people a system touches, and about how the system behaves across its whole lifecycle.

The three pieces that carry the work

A dependable inventory of the AI systems in use. Without an answer to which systems are running, for what purpose and on what data, every subsequent assessment is speculation. This step is routinely harder than expected, because AI features arrive inside purchased software and reach business units without passing anyone's approval.

An assessment that goes beyond conventional risk thinking. Alongside risk to the organisation, the standard requires a view of impacts on individuals and groups. Both belong in the documentation and in the treatment.

Clear roles across the lifecycle. Who owns purpose definition, data selection, training or configuration, release, monitoring in operation and decommissioning? Without named owners, the documentation has no consequences.

Where the overclaiming happens

The EU AI Act is Regulation (EU) 2024/1689. It is a legal act imposing obligations; ISO/IEC 42001 is a voluntary management system standard. A management system standard is not a route to conformity with a regulation.

That is not pedantry; it follows from how the Regulation is built. The presumption of conformity attaches to harmonised standards whose references have been published in the Official Journal of the European Union. Those standards are developed at CEN and CENELEC, in Joint Technical Committee 21. ISO/IEC 42001 is not among them and therefore triggers no presumption of conformity.

What the standard genuinely delivers is the organisational foundation (inventory, roles, assessment procedures, documentation, monitoring) on which regulatory obligations can be met and evidenced at all. Running an AI management system makes that work easier. It does not make you compliant.

The AI Act timeline, briefly

General applicability of the AI Act arrived on 2 August 2026 and was not postponed; the transparency obligations under Article 50 have applied ever since. What Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus for AI, postponed were the obligations for high-risk systems: under the recast Article 113(c), Chapter III sections 1, 2 and 3 apply to standalone systems under Annex III from 2 December 2027, and to systems embedded in products under Annex I from 2 August 2028. This distinction is frequently reported wrongly. The postponement concerns the high-risk obligations, not general applicability.

Running it alongside an existing ISMS

If you already work to ISO/IEC 27001, do not build a second, separate system. Context, leadership, competence, documented information, internal audit and management review can be run jointly; what differs is mainly the subject of the assessment and the specialists who have to take part in it. It pays to link the inventory of AI systems to the existing asset inventory, and to attach the impact assessment where data protection and information security are already assessed.

The division of responsibility for purchased systems matters just as much. An organisation using a vendor's model or service still owns purpose definition, data selection, release and monitoring in its own deployment context. That allocation belongs in the contract documents and in the supplier assessment, not in a general policy.

Certification

As a management system standard, ISO/IEC 42001 is certifiable in principle, and the process resembles that of other management system standards, with a review of the documentation and a review of implementation. A certificate is evidence towards customers and partners about the management system. It is not a statement by a market surveillance authority about the legal conformity of any individual AI system. Anyone buying a certificate, or being shown one, should nonetheless look at the accreditation behind it, because its basis is young: ISO/IEC 42006:2025 has, since July 2025, set the requirements for bodies that audit and certify AI management systems. It supplements ISO/IEC 17021-1 and serves expressly as the criteria document for accreditation. So ask not only for the certificate, but for the body behind it, and who accredited that body.

ISO/IEC 42001 in Rizzqo

ISO/IEC 42001 is supported in Rizzqo. Its control catalogue is imported when a customer needs it, and its requirements then attach to the AI systems they concern, each answered by a named owner and evidenced at the point of implementation. For the EU AI Act, the platform carries a taxonomy for classifying those systems.

The inventory side comes first, and for AI systems it matters unusually much. An AI system is an asset in Rizzqo like a business process, and the models, data sources, training and operating environments and the providers involved are the supporting objects beneath it, each with a category and a named owner. Which categories of personal data reach into such a system follows from the primary assets above it and is passed along the chain.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework