What is ISO 42001?
ISO/IEC 42001:2023 specifies the requirements for an AI management system, or AIMS: how an organization governs the AI systems it develops, provides or uses. It covers AI risk, the impact of AI on people and society, data, the AI life cycle and human oversight.
It follows the same high-level structure as ISO 27001, so a team that already runs an information security management system can extend much of it rather than start again.
Who asks for ISO 42001?
- Companies building AI products, asked by enterprise customers how their AI is governed.
- Companies that build on third-party AI models and need to show how they manage that dependency.
- Teams preparing for the EU AI Act, since an AI management system supports much of the governance the Act expects.
Like ISO 27001, it is voluntary. Customers and partners are what usually make it a requirement.
What ISO 42001 requires
- Context (clause 4): the AI systems in scope, and your role, such as developer, provider or user.
- Leadership (clause 5): an AI policy and accountable roles.
- Planning (clause 6): AI risk assessment, AI risk treatment and AI system impact assessment.
- Support (clause 7): resources, competence and awareness.
- Operation (clause 8): carrying out the risk treatment and impact assessments.
- Performance evaluation (clause 9): monitoring, internal audit and management review.
- Improvement (clause 10): corrective action and continual improvement.
The 38 Annex A controls
Annex A lists 38 reference controls under nine objectives. As with ISO 27001, you choose the ones that apply through your risk and impact assessments and justify the choice, rather than implementing every control by default.
Objective
A.2Area
Policies related to AIWhat it covers
An AI policy and how it fits with your other policiesObjective
A.3Area
Internal organizationWhat it covers
Roles, responsibilities and reporting of concernsObjective
A.4Area
Resources for AI systemsWhat it covers
Data, tools, computing resources and peopleObjective
A.5Area
Assessing impacts of AI systemsWhat it covers
Effects on individuals, groups and societyObjective
A.6Area
AI system life cycleWhat it covers
Requirements, design, verification, deployment and monitoringObjective
A.7Area
Data for AI systemsWhat it covers
Data quality, provenance and preparationObjective
A.8Area
Information for interested partiesWhat it covers
Documentation and information for usersObjective
A.9Area
Use of AI systemsWhat it covers
Responsible use within the intended purposeObjective
A.10Area
Third-party and customer relationshipsWhat it covers
Suppliers and customers along the AI chainHow ISO 42001 certification works
- Scope and gap assessment: decide which AI systems and activities the AIMS covers.
- Build and run the AIMS: AI policy, risk and impact assessments, selected controls, and evidence that they operate.
- Internal audit and management review.
- Stage 1 and Stage 2 audits by an accredited certification body.
- Certificate and surveillance: valid for three years, with yearly surveillance audits.
How ISO 42001 relates to the EU AI Act
The EU AI Act is law; ISO 42001 is a voluntary standard. An ISO 42001 certificate does not by itself make you compliant with the Act. They overlap heavily, though: risk management, data governance, documentation, transparency and human oversight appear in both, so work done for one carries over to the other.
Where teams usually fall short
- No inventory of the AI systems in use, including third-party models and APIs.
- No impact assessment before an AI system is deployed.
- Training data with unknown provenance or licensing.
- No monitoring for drift or unexpected behaviour after launch.
- No defined human oversight for decisions the AI makes or supports.
What the free assessment covers
The free SwaSec ISO 42001 assessment asks 14 questions across 2 domains and takes about 10 minutes. It scores where you stand and ties each gap to the clause, control or article it relates to.
- AIMS Clauses (4-10). AI management system requirements covering context, leadership, planning, support, and performance evaluation for AI governance.
- Annex B Controls. AI-specific controls covering policies, governance, data, development, operations, third-party AI, and human oversight.
Start the ISO 42001 assessment. It is a self-assessment, not an audit or a certification.
How ISO 42001 overlaps with other frameworks
ISO 42001 shares 7 areas with the other frameworks SwaSec covers. Where it can, the assessment asks a shared area once, and the answer counts toward each framework.
- Security Policy, shared with ISO 27001, SOC 2 and GDPR. Asked once.
- Risk Assessment, shared with ISO 27001, SOC 2, GDPR and EU AI Act. Asked separately, because each framework wants something different.
- Vendor/Supplier Management, shared with ISO 27001, SOC 2 and GDPR. Asked once.
- Data Governance, shared with GDPR and EU AI Act. Asked separately, because each framework wants something different.
- Human Oversight of AI, shared with EU AI Act. Asked once.
- Change Management / Secure Development, shared with ISO 27001 and SOC 2. Asked once.
- Training and Awareness, shared with ISO 27001 and SOC 2. Asked once.
Frequently asked questions
Is ISO 42001 mandatory?
No. It is a voluntary standard. It becomes a requirement when customers or partners ask for it.
What is the difference between ISO 42001 and ISO 27001?
ISO 27001 manages information security risk. ISO 42001 manages the risks and impacts of AI systems. They share the same management system structure, so many organizations run them together.
Does ISO 42001 make me compliant with the EU AI Act?
Not on its own. The Act sets legal obligations that depend on your AI system's risk level and your role. ISO 42001 gives you a management system that covers much of the same ground, which makes meeting those obligations easier.
What does the free SwaSec ISO 42001 assessment cover?
14 questions across 2 domains, taking about 10 minutes, with no signup. It gives you a score for ISO 42001, the gaps it found, and the clause, control or article each gap relates to.
Sources
This guide is general information, not legal advice. Last updated 1st October 2026.