International standard · certifiable

ISO/IEC 42001:2023 The management system for artificial intelligence.

ISO/IEC 42001 is the first certifiable standard for an artificial intelligence management system. It follows the harmonised structure of ISO management system standards and has its own controls for data, the life cycle and the impact assessment of AI systems.

At a glance

Published
December 2023
Structure
Clauses 4 to 10 (management system) and Annex A with 38 controls in 9 control objectives (A.2 to A.10)
Distinctive feature
AI system impact assessment: effects on individuals and society
Certificate
Issued by certification bodies accredited for ISO/IEC 42001; ISO/IEC 42006 sets the requirements for these bodies

Who ISO 42001 suits

  • Organisations that develop, provide or use AI in their own operations.
  • Companies preparing for the AI Act and looking for an orderly framework.
  • Organisations that want to show customers or clients that they manage AI responsibly.
Two colleagues working together on a laptop

What ISO 42001 requires

  • 01

    AI policy and roles

    A policy for AI, clear responsibilities and ways to raise concerns.

  • 02

    Impact assessment

    Assess and document the effects of an AI system on individuals, groups and society.

  • 03

    Life cycle and data

    Manage requirements, development, testing, operation and the provenance and quality of data.

  • 04

    Use and third parties

    Intended use, information for those affected and rules for suppliers and customers.

Deadlines and dates

  1. ISO/IEC 42001:2023 published

111testable requirements in UniqSuite

How UniqSuite helps

UniqSuite takes you through the requirements of the standard in plain questions. Your AI register from AI Governance serves as the evidence for the AI inventory. Where the same requirement also applies in another framework, your answer counts there too.

Frequently asked questions

Does ISO 42001 replace the AI Act?

No. The standard is voluntary, the AI Act is law. It does help to implement and evidence many AI Act obligations in an orderly way.

Do we need ISO 27001 for it?

No, ISO 42001 stands on its own. Both standards follow the same basic structure for management systems, so if you already have ISO 27001 you can share processes such as document control, internal audits and management review.

How do we recognise a suitable certification body?

Look for accreditation for ISO/IEC 42001. Since July 2025, ISO/IEC 42006 has set out the requirements that such bodies and their auditors must meet.

Which standards help with implementation?

ISO/IEC 42005 gives guidance on impact assessments for AI systems, and ISO/IEC 23894 on risk management for AI. Both are guidance documents that complement ISO 42001.

Where do we start?

First record your AI systems and define the scope. The AI policy, risk assessment and impact assessment build on this. The free UniqSuite quick check shows where you stand in about two minutes, with no sign-up.

See what is still open for you.

In half an hour we show you how UniqSuite organises the requirements, makes gaps visible and produces evidence.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy policy.