Skip to content
In this article

Rules and standards

ISO/IEC 42001

The management standard for how an organisation governs AI

Published 9 September 20262 min read

In one paragraph

ISO/IEC 42001 is an international standard for how an organisation governs artificial intelligence. Rather than judging any single model, it sets out what a management system for AI should contain: policies, defined roles, risk assessment specific to AI, and a cycle of monitoring and improvement. It is built to the same structure as ISO/IEC 27001, the well-established information security standard, so organisations that already hold one find the other familiar. Published in December 2023, it is open to any organisation, of any size or sector, that develops, provides or uses AI.

Who it applies to

Any organisation that develops, provides or uses AI, whatever its size or sector. It does not single out a particular industry or a particular kind of AI system, and it sits alongside sector-specific law rather than replacing it.

What it asks for

  • Documented policies covering how AI is chosen, developed, used, checked and retired.
  • Named roles and accountability across the whole AI lifecycle, not only at the point a system is built.
  • Risk assessment specific to AI, covering matters such as bias, safety and reliability, rather than generic information risk alone.
  • Continual monitoring, with the management system reviewed and improved over time rather than assessed once.
  • A structure that mirrors ISO/IEC 27001, so the two can be run, and where wanted certified, together.
  • Certification, for organisations that choose to seek it, carried out by accredited third-party certification bodies rather than by ISO itself, and covering the management system rather than the performance of any particular model.
  • Companion guidance in ISO/IEC 23894 on AI risk management specifically, which is not certifiable in its own right but feeds into the management system.

What it looks like in practice

An organisation that already holds an information security certification tends to arrive at this wanting the same discipline applied to AI. Much of the groundwork already exists: named owners, a review cycle, an audit trail. What is added is the AI-specific layer, a place to record how a model's risk was assessed, who signed off its use, and how it is monitored once it is running, built on the same structure the team already knows.

Where it stands now

ISO/IEC 42001:2023 was published in December 2023. It is a certifiable standard, assessed by accredited certification bodies rather than by ISO itself, and it carries no phased deadlines of its own; an organisation adopts it, and optionally certifies against it, whenever it chooses. ISO/IEC 23894:2023, the companion guidance on AI risk management, was published the same year. Dates change; the official text linked below is the authority.

How this connects to our work

Mapping your policies and controls to ISO/IEC 42001 sits alongside the policy, logging and access work that comes with a private AI setup, whether or not you intend to seek certification. The structure holds either way, and it keeps certification open to you if you later decide to pursue it.

Read the original

Every link goes to the publisher. Dates and status change; the text linked below is the authority.