ISO 42001

ISO 42001

ISO 42001

TL;DR

TL;DR

ISO 42001 is the international standard for an AI management system, setting requirements for how an organization governs the AI it builds, deploys, and monitors across the full lifecycle.

ISO 42001 is the international standard for an AI management system, setting requirements for how an organization governs the AI it builds, deploys, and monitors across the full lifecycle.

What is ISO 42001?

ISO 42001 is the international standard specifying requirements for an artificial intelligence management system, or AIMS: the policies, roles, risk assessments, and lifecycle controls an organization uses to govern the AI systems it builds, buys, or deploys. ISO and IEC published it in December 2023.

It was the first standard of its kind, and it follows the same management-system blueprint as ISO 27001 for information security and ISO 9001 for quality: a documented scope, assigned ownership, recurring risk assessment, and independent audit. Its Annex A carries 38 controls that a certified organization must consider and justify.

How ISO 42001 works

An AI management system runs as a loop, Plan-Do-Check-Act, applied to AI-specific risk. In the plan phase an organization defines the scope of its AIMS, names the roles accountable for AI decisions, and writes an AI policy setting out which uses are permitted and which are prohibited. That scoping step decides everything downstream, because a control only reaches the systems inside the boundary.

The do phase is where operational controls live: a model and use-case inventory, a risk assessment per system, an AI impact assessment covering effects on individuals, and lifecycle procedures spanning data, development, testing, deployment, and retirement. This is the layer that turns AI compliance into a documented system with owners and dates attached to it.

Check and act close the loop through internal audit, management review, and corrective action. Because the standard shares clause structure with ISO 27001, teams already running an information security management system reuse most of the machinery, and the evidence collected for a SOC 2 Type II observation window frequently satisfies overlapping requirements.

What ISO 42001 requires

Annex A groups its 38 controls into themes. Five of those themes carry most of the audit weight.

  • AI policy: A documented policy stating permitted and prohibited uses, approved by leadership and reviewed on a fixed cycle, since an unreviewed policy fails on dates alone.

  • Internal roles: Named accountability for AI decisions, including who may approve a new use case and who holds authority to suspend a live system.

  • Resources for AI systems: A register of the data, tooling, compute, and human expertise each system depends on, which is where data provenance questions land.

  • AI system lifecycle: Requirements for design, verification, deployment, monitoring, and retirement, so a model whose behavior degrades has a defined response path.

  • Third-party relationships: Controls covering suppliers of models, data, and infrastructure, because most deployers inherit risk originating outside their own engineering.

ISO 42001 vs ISO 27001 vs SOC 2 Type II

Procurement teams often request all three at once and read them as a single trust signal, which is where the confusion starts. ISO 27001 certifies that an organization manages information security risk through a documented management system. SOC 2 Type II attests that a service organization's stated controls operated effectively across a monitored window of six to twelve months. ISO 42001 certifies that an organization manages the risks specific to AI: bias, opacity, model drift, and consequential automated decisions. The first two describe how data is protected; the third describes how the model itself is governed.


Who it binds

What it requires

How it is evidenced

ISO 42001

Any organization that develops, provides, or uses AI systems

An AI management system: policy, accountable roles, risk and impact assessment, lifecycle and supplier controls

Accredited certification audit in two stages, then periodic surveillance of live records

ISO 27001

Any organization holding information assets it must protect

An ISMS with a documented risk assessment and selected Annex A security controls

Accredited certification audit plus annual surveillance against the same scope

SOC 2 Type II

Service organizations handling customer data, mainly in the US market

Controls mapped to the trust services criteria the organization itself selects

Independent auditor report describing control operation over an observation period

If the concern is data handling and access control, ISO 27001 or a SOC 2 report answers it. If it is who decided what the model may do and what happens when the agent is wrong, ISO 42001 answers.

Why ISO 42001 matters for customer experience

Support automation touches money, health records, and account access, so the question a buyer is really asking is what governs the agent when it gets something wrong. Without a management system, the answer is a collection of individual assurances: an engineer's memory of how the model was tested, a screenshot of a prompt, a policy nobody has reviewed since launch. Vendor reviews stall there, and deals with compliance teams in regulated industries stall with them.

The standard replaces those assurances with a single source of truth for model inventory, risk classification, and incident response, which is precisely what a long security questionnaire is trying to reconstruct one question at a time. In healthcare workflows it sits alongside HIPAA compliance, which governs the data while the AIMS governs the decision made from it.

The tradeoff is real. The same documentation discipline that shortens a vendor review slows shipping, because every new use case now needs an impact assessment before it reaches a customer.

How is ISO 42001 measured?

There is no conformity score. An accredited certification body assesses the management system in two stages: a first-stage audit reviewing documentation, scope, and risk methodology, and a second-stage audit testing operational evidence by sampling actual risk assessments, approval records, incident tickets, and monitoring logs. Certification is then maintained through surveillance audits across a three-year cycle.

Internally, programs track a small set of operating measures: the share of live AI use cases with a completed impact assessment, the age of the oldest unreviewed risk assessment, and the elapsed time between an incident and its corrective action.

Several thresholds an AIMS must evidence are fixed elsewhere in regulation. Where an AI agent places automated calls or texts, the eCFR delivery restrictions rule sets a calling window of 8 a.m. to 9 p.m. local time and requires opt-out requests to be honored within 30 days, and an auditor will expect logs proving both.

How AI agents change ISO 42001

The standard was written for organizations that build or deploy AI, and a support agent resolving tickets autonomously is squarely a deployment. What changes in practice is the pace of the lifecycle. A model version, a retrieval index, a prompt, and a set of tool permissions can all change inside a week, so lifecycle controls have to run continuously, on a release cadence an auditor can actually see.

Autonomy raises the stakes on two controls in particular. Impact assessment matters more because an agent that issues refunds or changes account settings acts on a customer directly. Monitoring matters more because degradation surfaces as a confident wrong answer. Runtime constraints do the enforcement, which is why AI guardrails in support automation belong in the evidence file: a policy stating the agent may never quote a medical dosage is auditable once a control blocks it.

The consequence for buyers is that a certificate dated eighteen months ago describes a system since rebuilt, so ask what the most recent surveillance audit covered.

What to look for in an ISO 42001 program

Start with scope. A certificate covers only the systems named in the statement of scope, so read that document before you read the certificate: an AIMS scoped to one internal model tells you nothing about the agent handling your customers.

Then integration surface and ownership. Ask who signs off on a new use case, how long that approval takes, and whether risk classification lives as a field in a system of record. Ask how supplier controls reach the foundation model provider, since every deployer inherits behavior it cannot inspect.

On certifications, check whether the AIMS shares evidence with the information security certification a buyer already recognizes; teams comparing ISO 27001 certified support platforms are effectively testing for that overlap. Financial services buyers add DORA compliance, which pulls an AI vendor into ICT third-party risk reporting.

The constraint that bites hardest is evidence freshness: surveillance audits sample recent records, so documentation generated in the month before an audit fails on timestamps.

ISO 42001 and AI agent certification

ISO 42001 certifies the organization, describing how a company governs AI in general. Buyers evaluating one specific agent often want something narrower, which is the gap AIUC-1 addresses by certifying an agent's safety, security, reliability, and privacy behavior directly. The two answer different questions and are usually presented together: the management system explains the process, the agent certification describes the product.

Neither displaces the sector rules already binding the workflow. An AIMS supplies the classification and the review trail those sector obligations depend on.

What does ISO 42001 mean in plain terms?

Think of it as a driving licence for the organization behind the AI. ISO stands for the International Organization for Standardization and IEC for the International Electrotechnical Commission, the two bodies that publish it jointly as ISO/IEC 42001, and AIMS is the shorthand for the artificial intelligence management system it describes. The certificate makes no promise that the model is accurate. It promises that somebody decided what the model is allowed to do, wrote that down, checked it, and can show the checking to a stranger.

A company without one can still be careful. That care lives in individual people, so it leaves when they do, and no customer or auditor can tell careful from lucky.

The tradeoff is bureaucracy. Every impact assessment is real work, and a team that treats the paperwork as the goal ends up with a well-documented system nobody improves.

Common ISO 42001 mistakes

Scoping the AIMS around the easy systems. A narrow scope certifies faster and satisfies nobody, because it excludes the customer-facing agent the buyer was asking about. The mechanism is that scope is chosen by the applicant, so it drifts toward whatever documentation already exists.

Treating the impact assessment as a launch gate. Completed once at deployment and never revisited, it describes a system that no longer exists, since the model, the retrieval sources, and the tool permissions all move after go-live.

Copying the ISMS wholesale. Reusing ISO 27001 clause structure is efficient; reusing its risk register yields a document about confidentiality and availability that never mentions bias, drift, or automated decisions affecting individuals.

Buying the certificate as a marketing asset. When ownership sits with the compliance team alone, the engineers changing model behavior weekly never enter the loop, and the surveillance audit finds a management system that stopped managing anything.

Frequently Asked Questions

What does ISO 42001 certification actually cover?

ISO 42001 certification covers an organization's AI management system, meaning its policy, accountable roles, risk and impact assessments, lifecycle procedures, and supplier controls for the AI systems named in its statement of scope. It certifies governance quality across those systems. It makes no claim about the accuracy of any individual model or agent.

What is the difference between ISO 42001 and ISO 27001?

ISO 42001 and ISO 27001 share a clause structure and a certification process, but govern different risks. ISO 27001 covers information security: confidentiality, integrity, and availability of data. ISO 42001 covers AI-specific risk such as bias, opacity, drift, and automated decisions affecting people. Most organizations certify both, reusing audit machinery across the two.

ISO 42001 vs SOC 2 Type II: which do buyers ask for?

ISO 42001 and SOC 2 Type II get requested for different reasons. SOC 2 Type II is an auditor report on whether selected controls operated effectively over an observation period, widely expected by US buyers. ISO 42001 is an accredited certification of an AI management system. Regulated AI buyers increasingly ask for both.

Is ISO 42001 mandatory?

ISO 42001 is voluntary. No jurisdiction requires the certificate itself, and organizations adopt it because procurement teams, enterprise security reviews, and regulated-industry buyers want structured evidence of AI governance. In practice it functions as a commercial requirement long before it becomes a legal one, particularly in healthcare, financial services, and public sector purchasing.

What are the Annex A controls in ISO 42001?

Annex A controls in ISO 42001 number 38 and are grouped by theme: AI policy, internal organization and roles, resources supporting AI systems, AI system lifecycle, data management, information for interested parties, third-party relationships, and impact assessment. An organization must consider each control and document why it applies or does not.

How does ISO 42001 apply to AI customer support agents?

ISO 42001 applies to support agents as deployed AI systems requiring inventory, risk classification, impact assessment, and monitoring. Practically that means documenting which actions the agent may take, who approved them, how escalation to a human works, and what evidence exists that runtime guardrails blocked prohibited behavior in production.

Learn More

Learn More