AI Governance Standards

What Is ISO 42001?

ISO 42001, formally ISO/IEC 42001:2023, is the international standard for an AI management system (AIMS): the policies, roles, risk and impact assessments, controls and reviews an organization uses to develop, provide or use AI responsibly. It was the first management system standard written for AI, and an accredited certification body can audit an organization against it and issue a certificate valid for three years.

  • Reliability & Governance
  • 11 min read
  • Updated October 2, 2026
  • VDF AI Team
01
In short

ISO 42001, formally ISO/IEC 42001:2023, is the international standard for an AI management system (AIMS): the policies, roles, risk and impact assessments, controls and reviews an organization uses to develop, provide or use AI responsibly. It was the first management system standard written for AI, and an accredited certification body can audit an organization against it and issue a certificate valid for three years.

Key takeaways

  • 01 ISO/IEC 42001:2023 was published in December 2023 by the joint ISO and IEC subcommittee on AI. It applies to any organization that provides or uses AI systems, whatever its size or sector.
  • 02 Its requirements sit in clauses 4 to 10, which share the harmonized structure of ISO/IEC 27001, and its reference controls sit in Annex A under nine objectives, A.2 to A.10.
  • 03 Certification is voluntary. An independent certification body runs a Stage 1 and a Stage 2 audit, followed by annual surveillance audits during a three-year cycle.
  • 04 Cost follows audit days, which ISO/IEC 42006 ties to the number of people doing AI work and the organization’s AI role, plus the internal effort of building and running the management system.
  • 05 A certificate is evidence of a working management system. On its own it does not show conformity with the EU AI Act, and it complements the NIST AI RMF rather than replacing it.
02

ISO 42001, defined

ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system, was published on 18 December 2023 by ISO/IEC JTC 1/SC 42, the joint subcommittee on artificial intelligence. It specifies requirements and gives guidance for establishing, implementing, maintaining and continually improving an AI management system, usually shortened to AIMS. ISO calls it the world’s first AI management system standard (ISO’s explainer, verified October 2026).

A management system is the organizational layer around the technology: who sets AI policy, how AI risks and impacts are assessed, which controls are chosen, how performance is monitored and how problems get corrected. The standard applies to organizations that develop AI, those that offer AI products or services, and those that only use AI supplied by others. Its single normative reference is ISO/IEC 22989:2022, the AI concepts and terminology standard, so terms such as AI system and interested party carry the meanings defined there.

03

Clauses 4 to 10: what ISO 42001 requires

Clauses 1 to 3 cover scope, references and terms. The auditable requirements live in clauses 4 to 10, and an organization seeking certification has to meet every one of them.

Clause 4, context of the organization. Understand internal and external issues and the needs of interested parties, then fix the scope of the AIMS: which AI systems, business units and AI roles it covers.

Clause 5, leadership. Top management commits to the AIMS, approves an AI policy and assigns roles, responsibilities and authorities.

Clause 6, planning. Plan actions for risks and opportunities, including an AI risk assessment (6.1.2), AI risk treatment (6.1.3) and an AI system impact assessment (6.1.4), then set AI objectives and plan any changes.

Clause 7, support. Provide resources, competence, awareness and communication, and control the documented information the system relies on.

Clause 8, operation. Run the planned processes and repeat the risk assessment, risk treatment and impact assessment as systems and circumstances change.

Clause 9, performance evaluation. Monitor and measure the AIMS, run an internal audit programme and hold management reviews.

Clause 10, improvement. Improve the system continually and deal with nonconformities through corrective action.

04

Annex A controls and the other annexes

Annex A is normative and lists reference control objectives and controls under nine headings: A.2 policies related to AI, A.3 internal organization, A.4 resources for AI systems, A.5 assessing impacts of AI systems, A.6 AI system life cycle, A.7 data for AI systems, A.8 information for interested parties, A.9 use of AI systems and A.10 third-party and customer relationships. Individual controls go down to items such as A.6.2.6, AI system operation and monitoring, and A.6.2.8, recording of event logs.

Annex A works as a catalogue to choose from. Risk treatment under clause 6.1.3 decides which controls apply, and certification auditors review a Statement of Applicability listing the controls that were chosen. Annex B, also normative, gives implementation guidance for each control; Annex C lists potential AI-related organizational objectives and risk sources; Annex D explains how the AIMS applies across domains and sectors.

06

How ISO 42001 certification works

Certification is voluntary. Independent certification bodies carry it out, and national accreditation bodies can accredit them; ISO presents certification as the route for organizations that want independent confirmation that their AIMS meets the standard. In the UK, UKAS assesses certification bodies against ISO/IEC 42001, ISO/IEC 17021-1 and ISO/IEC 42006, and granted its first AIMS accreditation, to BSI, on 15 January 2026. Before choosing an auditor, check that its accreditation scope includes ISO/IEC 42001.

The audit runs in two stages. Schellman, a certification body, describes its process as follows (verified October 2026). Stage 1 reviews readiness, including scope, policies, the risk methodology and the Statement of Applicability, and typically takes one to two days. Stage 2 usually follows four to twelve weeks later, and no more than six months later, and tests whether policies, controls, monitoring, internal audit, management review and corrective action actually operate; it lasts from three to nine or more days. The certificate is valid for three years, with a surveillance audit each year at roughly a third of the initial audit time.

07

ISO 42001 certification cost: what drives it

The certification body’s fee is driven by audit days. ISO/IEC 42006 makes audit time a normative calculation in its Annex A, based mainly on how many people do AI-related work and on the organization’s AI role, with worked examples in Annex B. Audit firm Sensiba’s summary of that table puts an AI producer with one to ten such people at 5.0 auditor days and a developer, provider or user of the same size at 3.5 days, rising to 13 and 9 days at 126 to 175 people (Sensiba, verified October 2026). Multiply by the body’s day rate and add Stage 1, two surveillance audits and recertification in year three.

The other drivers sit on your side of the table: how many AI systems and sites are in scope, whether the AIMS is audited together with an existing ISO/IEC 27001 system, and how much evidence already exists. Internal effort covers AI risk and impact assessments, documented information, operating the Annex A controls you select, staff awareness, and a full internal audit and management review before Stage 2. Consultants and governance software are optional extras. Ask for quotes in auditor days, so offers from different bodies can be compared like for like.

08

ISO 42001, the EU AI Act and the NIST AI RMF

The EU AI Act is binding law, and a 42001 certificate is not, on its own, evidence of conformity with it. Article 17 requires providers of high-risk AI systems to run a quality management system, and Article 40 grants a presumption of conformity only for harmonised standards whose references are published in the Official Journal, and only as far as they cover the requirements. In July 2026 CEN and CENELEC published EN 18286:2026, a quality management system standard written for AI Act purposes (verified October 2026). Under the Digital Omnibus, Regulation (EU) 2026/1744, high-risk obligations apply from 2 December 2027 for Annex III systems and from 2 August 2028 for AI in products covered by Annex I.

42001 still earns its place. Its risk assessment, impact assessment, documented information, monitoring and corrective action produce many of the records the Act asks for, and it covers every AI system in scope, not only the high-risk ones.

The NIST AI RMF 1.0 is voluntary, is organized into Govern, Map, Measure and Manage, and is being revised under the White House AI Action Plan. It describes outcomes, while 42001 sets requirements an auditor can test. NIST’s AI Resource Center hosts a crosswalk to the draft (FDIS) text of 42001 that maps, for example, GOVERN 1.6 on inventorying AI systems to the resource documentation guidance, and MEASURE 2.4 on production monitoring to clause 9.1 and event-log recording. For one control set that serves all three references, see the AI governance framework crosswalk.

09

How it works

  1. 01

    Set the scope and the roles

    Decide which AI systems, units and AI roles the AIMS covers, name an owner for each system, and have top management approve the AI policy.

  2. 02

    Assess risks and impacts

    Run the AI risk assessment and the AI system impact assessment for every system in scope; ISO/IEC 23894 and ISO/IEC 42005 are useful method guides.

  3. 03

    Select controls

    Treat each risk by choosing Annex A controls and any others you need, and record the choices in a Statement of Applicability.

  4. 04

    Operate and keep evidence

    Run the controls long enough to produce records: logs, approvals, assessments, training records, supplier reviews and incident handling.

  5. 05

    Audit yourself first

    Complete an internal audit and a management review, and close the nonconformities they raise.

  6. 06

    Book Stage 1 and Stage 2

    An accredited certification body reviews readiness, then tests effectiveness; the certificate follows a successful Stage 2.

10

ISO 42001 vs EU AI Act vs NIST AI RMF

How the three most cited AI governance references differ. Status and dates verified October 2026.

DimensionISO/IEC 42001:2023EU AI ActNIST AI RMF 1.0
TypeCertifiable management system standardBinding regulation, (EU) 2024/1689Voluntary framework
Applies toAny organization that develops, provides or uses AIProviders, deployers and other operators of AI placed on the EU market or used in the EUAny organization that chooses to adopt it
Core structureClauses 4 to 10 plus Annex A controlsRisk tiers: prohibited, high-risk, transparency and minimalFour functions: Govern, Map, Measure, Manage
Independent checkAccredited certification body; Stage 1 and 2; three-year certificateConformity assessment for high-risk systems; market surveillance authoritiesNone built in; self-assessment
Risk and impactAI risk assessment (6.1.2) and AI system impact assessment (6.1.4)Risk management system (Art. 9); fundamental rights impact assessment for some deployers (Art. 27)MAP and MEASURE functions
Records and logsDocumented information (7.5); event-log control in Annex AAutomatic logging (Art. 12); deployers keep logs at least six months (Art. 26(6))Documentation outcomes across the functions
Key datesPublished December 2023Prohibitions since 2 Feb 2025; Art. 50 since 2 Aug 2026; high-risk from 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I)Released January 2023; revision under way
Consequence of failureSuspension or withdrawal of the certificateFines under Art. 99None
11
How VDF AI fits

From concept to a governed, on-premise reality

ISO/IEC 42001 certifies an organization’s management system, not a software product. VDF AI does not hold an ISO/IEC 42001 certificate; it is software that runs inside your environment, under your controls and your audits, and its part in an AIMS is producing evidence. The trust center describes an AI system inventory with owner, purpose, model, tool and data-source metadata, approval gates and role-scoped permissions for high-impact workflows, and run logs that show the prompt, retrieval, model route, tool call, response and reviewer action.

Those records line up with what auditors sample. The inventory supports scoping and resource documentation; run logs and audit events streamed to your SIEM support monitoring under clause 9.1 and event-log recording in Annex A; approval gates support oversight of AI use; an approved model catalog with version history and evaluation records supports life-cycle control. Policy, risk acceptance and management review stay with your organization, and the governance and security handbook lists the controls and evidence in one place.

12

Frequently asked questions

What is ISO 42001?

ISO 42001, published as ISO/IEC 42001:2023, is the international standard for an AI management system. It sets requirements for the policies, roles, risk assessments, impact assessments, controls, monitoring and improvement processes an organization uses to develop, provide or use AI responsibly. It follows the same harmonized clause structure as ISO/IEC 27001, lists reference controls in Annex A, and an accredited certification body can audit an organization against it.

Is ISO 42001 certification mandatory?

No. ISO describes certification against ISO/IEC 42001 as voluntary, chosen by organizations that want independent confirmation that their AI management system meets the standard. Customers, partners or regulators may still ask for it, so it can become a commercial requirement. It is separate from legal duties: under the EU AI Act, a presumption of conformity comes from harmonised standards published in the Official Journal, not from a 42001 certificate.

How much does ISO 42001 certification cost?

The certification fee is driven mainly by audit days. ISO/IEC 42006 sets audit time from the number of people doing AI-related work and the organization’s AI role; one published summary of its table starts at 3.5 auditor days for a small AI developer, provider or user and 5.0 for a small AI producer. Add the Stage 1 review, two annual surveillance audits and recertification after three years, plus the internal effort of running risk and impact assessments, controls, an internal audit and a management review.

How long does ISO 42001 certification take?

The audits themselves are short; preparation takes longer. One certification body describes a Stage 1 readiness review of one to two days, a Stage 2 audit of three to nine or more days, and a gap of four to twelve weeks between them that should not exceed six months. Before Stage 2 the management system needs to have run long enough to produce records, including completed risk and impact assessments, an internal audit and a management review.

What is the difference between ISO 42001 and ISO 27001?

ISO/IEC 27001 is about information security: preserving the confidentiality, integrity and availability of information. ISO/IEC 42001 is about governing AI systems across their life cycle, including risk, impact on people, data, transparency, responsible use and suppliers. Both use the same harmonized clause structure, so an organization with a 27001 system can reuse document control, internal audit, management review and corrective action, and both can be audited together. Neither certificate substitutes for the other.

Does ISO 42001 cover the EU AI Act?

Partly. Its risk assessment, impact assessment, documented information, monitoring and corrective action produce much of the evidence the AI Act expects, but it was not written to the Act’s articles and it is not a harmonised standard under the Act. Providers of high-risk systems still need the specific records the Act names, such as technical documentation and automatic logs. CEN and CENELEC published EN 18286:2026 in July 2026 as a quality management system standard written for AI Act purposes.

See it in your environment

Put these concepts to work on infrastructure you control.

VDF AI runs governed agents, private retrieval, and model routing inside your own cloud, data center, or air-gapped network — or start free in our managed cloud today. Book a walkthrough mapped to your stack.