ISO 42001, explained for teams building with AI

ISO/IEC 42001 is the first international standard for managing AI responsibly. Here is what it asks for, how certification works, and how it connects to ISO 27001 and the EU AI Act.

Assess ISO 42001 free

14 questions · about 10 min · no signup

Type
Certifiable standard
Published
December 2023
Annex A
38 controls, 9 objectives
Certificate
3 years, audited yearly

This guide is growing. A fuller ISO 42001 guide, with requirement-by-requirement detail and worked examples, is being written. Last updated 1st October 2026.

On this page
01

What is ISO 42001?

ISO/IEC 42001:2023 specifies the requirements for an AI management system, or AIMS: how an organization governs the AI systems it develops, provides or uses. It covers AI risk, the impact of AI on people and society, data, the AI life cycle and human oversight.

It follows the same high-level structure as ISO 27001, so a team that already runs an information security management system can extend much of it rather than start again.

02

Who asks for ISO 42001?

  • Companies building AI products, asked by enterprise customers how their AI is governed.
  • Companies that build on third-party AI models and need to show how they manage that dependency.
  • Teams preparing for the EU AI Act, since an AI management system supports much of the governance the Act expects.

Like ISO 27001, it is voluntary. Customers and partners are what usually make it a requirement.

03

What ISO 42001 requires

  • Context (clause 4): the AI systems in scope, and your role, such as developer, provider or user.
  • Leadership (clause 5): an AI policy and accountable roles.
  • Planning (clause 6): AI risk assessment, AI risk treatment and AI system impact assessment.
  • Support (clause 7): resources, competence and awareness.
  • Operation (clause 8): carrying out the risk treatment and impact assessments.
  • Performance evaluation (clause 9): monitoring, internal audit and management review.
  • Improvement (clause 10): corrective action and continual improvement.
04

The 38 Annex A controls

Annex A lists 38 reference controls under nine objectives. As with ISO 27001, you choose the ones that apply through your risk and impact assessments and justify the choice, rather than implementing every control by default.

Objective

A.2

Area

Policies related to AI

What it covers

An AI policy and how it fits with your other policies

Objective

A.3

Area

Internal organization

What it covers

Roles, responsibilities and reporting of concerns

Objective

A.4

Area

Resources for AI systems

What it covers

Data, tools, computing resources and people

Objective

A.5

Area

Assessing impacts of AI systems

What it covers

Effects on individuals, groups and society

Objective

A.6

Area

AI system life cycle

What it covers

Requirements, design, verification, deployment and monitoring

Objective

A.7

Area

Data for AI systems

What it covers

Data quality, provenance and preparation

Objective

A.8

Area

Information for interested parties

What it covers

Documentation and information for users

Objective

A.9

Area

Use of AI systems

What it covers

Responsible use within the intended purpose

Objective

A.10

Area

Third-party and customer relationships

What it covers

Suppliers and customers along the AI chain
05

How ISO 42001 certification works

  • Scope and gap assessment: decide which AI systems and activities the AIMS covers.
  • Build and run the AIMS: AI policy, risk and impact assessments, selected controls, and evidence that they operate.
  • Internal audit and management review.
  • Stage 1 and Stage 2 audits by an accredited certification body.
  • Certificate and surveillance: valid for three years, with yearly surveillance audits.
06

How ISO 42001 relates to the EU AI Act

The EU AI Act is law; ISO 42001 is a voluntary standard. An ISO 42001 certificate does not by itself make you compliant with the Act. They overlap heavily, though: risk management, data governance, documentation, transparency and human oversight appear in both, so work done for one carries over to the other.

07

Where teams usually fall short

  • No inventory of the AI systems in use, including third-party models and APIs.
  • No impact assessment before an AI system is deployed.
  • Training data with unknown provenance or licensing.
  • No monitoring for drift or unexpected behaviour after launch.
  • No defined human oversight for decisions the AI makes or supports.
08

What the free assessment covers

The free SwaSec ISO 42001 assessment asks 14 questions across 2 domains and takes about 10 minutes. It scores where you stand and ties each gap to the clause, control or article it relates to.

  • AIMS Clauses (4-10). AI management system requirements covering context, leadership, planning, support, and performance evaluation for AI governance.
  • Annex B Controls. AI-specific controls covering policies, governance, data, development, operations, third-party AI, and human oversight.

Start the ISO 42001 assessment. It is a self-assessment, not an audit or a certification.

09

How ISO 42001 overlaps with other frameworks

ISO 42001 shares 7 areas with the other frameworks SwaSec covers. Where it can, the assessment asks a shared area once, and the answer counts toward each framework.

  • Security Policy, shared with ISO 27001, SOC 2 and GDPR. Asked once.
  • Risk Assessment, shared with ISO 27001, SOC 2, GDPR and EU AI Act. Asked separately, because each framework wants something different.
  • Vendor/Supplier Management, shared with ISO 27001, SOC 2 and GDPR. Asked once.
  • Data Governance, shared with GDPR and EU AI Act. Asked separately, because each framework wants something different.
  • Human Oversight of AI, shared with EU AI Act. Asked once.
  • Change Management / Secure Development, shared with ISO 27001 and SOC 2. Asked once.
  • Training and Awareness, shared with ISO 27001 and SOC 2. Asked once.
10

Frequently asked questions

Is ISO 42001 mandatory?

No. It is a voluntary standard. It becomes a requirement when customers or partners ask for it.

What is the difference between ISO 42001 and ISO 27001?

ISO 27001 manages information security risk. ISO 42001 manages the risks and impacts of AI systems. They share the same management system structure, so many organizations run them together.

Does ISO 42001 make me compliant with the EU AI Act?

Not on its own. The Act sets legal obligations that depend on your AI system's risk level and your role. ISO 42001 gives you a management system that covers much of the same ground, which makes meeting those obligations easier.

What does the free SwaSec ISO 42001 assessment cover?

14 questions across 2 domains, taking about 10 minutes, with no signup. It gives you a score for ISO 42001, the gaps it found, and the clause, control or article each gap relates to.

11

Sources

This guide is general information, not legal advice. Last updated 1st October 2026.

The other frameworks