International standard · certifiable
ISO/IEC 42001:2023 The management system for artificial intelligence.
ISO/IEC 42001 is the first certifiable standard for an artificial intelligence management system. It follows the harmonised structure of ISO management system standards and has its own controls for data, the life cycle and the impact assessment of AI systems.
At a glance
- Published
- December 2023
- Structure
- Clauses 4 to 10 (management system) and Annex A with 38 controls in 9 control objectives (A.2 to A.10)
- Distinctive feature
- AI system impact assessment: effects on individuals and society
- Certificate
- Issued by certification bodies accredited for ISO/IEC 42001; ISO/IEC 42006 sets the requirements for these bodies
Who ISO 42001 suits
- Organisations that develop, provide or use AI in their own operations.
- Companies preparing for the AI Act and looking for an orderly framework.
- Organisations that want to show customers or clients that they manage AI responsibly.

What ISO 42001 requires
- 01
AI policy and roles
A policy for AI, clear responsibilities and ways to raise concerns.
- 02
Impact assessment
Assess and document the effects of an AI system on individuals, groups and society.
- 03
Life cycle and data
Manage requirements, development, testing, operation and the provenance and quality of data.
- 04
Use and third parties
Intended use, information for those affected and rules for suppliers and customers.
Deadlines and dates
ISO/IEC 42001:2023 published
How UniqSuite helps
UniqSuite takes you through the requirements of the standard in plain questions. Your AI register from AI Governance serves as the evidence for the AI inventory. Where the same requirement also applies in another framework, your answer counts there too.
Frequently asked questions
Does ISO 42001 replace the AI Act?
No. The standard is voluntary, the AI Act is law. It does help to implement and evidence many AI Act obligations in an orderly way.
Do we need ISO 27001 for it?
No, ISO 42001 stands on its own. Both standards follow the same basic structure for management systems, so if you already have ISO 27001 you can share processes such as document control, internal audits and management review.
How do we recognise a suitable certification body?
Look for accreditation for ISO/IEC 42001. Since July 2025, ISO/IEC 42006 has set out the requirements that such bodies and their auditors must meet.
Which standards help with implementation?
ISO/IEC 42005 gives guidance on impact assessments for AI systems, and ISO/IEC 23894 on risk management for AI. Both are guidance documents that complement ISO 42001.
Where do we start?
First record your AI systems and define the scope. The AI policy, risk assessment and impact assessment build on this. The free UniqSuite quick check shows where you stand in about two minutes, with no sign-up.
See what is still open for you.
In half an hour we show you how UniqSuite organises the requirements, makes gaps visible and produces evidence.
