ISO/IEC 42001: the complete guide
Every clause and control of the first certifiable AI management system standard, in plain English. 7 auditable clauses plus Annex A: 38 controls under 9 objectives.
ISO/IEC 42001:2023, published in December 2023, is the world's first certifiable international standard for an AI management system. It sets out seven auditable clauses (4 to 10: context, leadership, planning, support, operation, performance evaluation and improvement) plus an Annex A of 38 reference controls under nine objectives, from which each organization selects and justifies its own set in a Statement of Applicability. Unlike the NIST AI RMF, it carries a real certification scheme: accredited certification bodies audit against it, and regulators and enterprise buyers increasingly ask for it by name.
Last verified against the published structure: August 25, 2026.
- Instrument
- ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system
- Issued by
- International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)
- Issue date
- December 2023 (first edition)
- Legal status
- Voluntary standard with a certification scheme; accredited bodies certify, ISO itself certifies no one
- Structure
- 7 auditable clauses (4 to 10) plus Annex A: 38 controls under 9 objectives (A.2 to A.10)
- Selection mechanism
- Statement of Applicability: controls chosen via risk assessment, exclusions justified
- Official source
- iso.org/standard/81230.html
- Last verified
- August 25, 2026
The seven auditable clauses
Clauses 1 to 3 are front matter (scope, references, terms) that every ISO management standard shares and no auditor tests. The requirements live in clauses 4 to 10, and they run on the Plan-Do-Check-Act loop: understand your context, lead, plan, support, operate, check, improve. An organization that already runs ISO 9001 or ISO/IEC 27001 will recognize the skeleton; what is new is everything the clauses demand about AI specifically.
Clause 4, Context of the organization
Know your situation before you write a single policy.
Read Clause 4, area by area →Clause 5, Leadership
AI governance fails from the top or it does not fail at all.
Read Clause 5, area by area →Clause 6, Planning
Decide what can go wrong, and what good looks like, before you build.
Read Clause 6, area by area →Clause 7, Support
The unglamorous clause that decides whether the policy is real.
Read Clause 7, area by area →Clause 8, Operation
Where the plan meets actual AI systems.
Read Clause 8, area by area →Clause 9, Performance evaluation
Check that the system works, on evidence, not vibes.
Read Clause 9, area by area →Clause 10, Improvement
The standard assumes you will get things wrong; it audits what you do next.
Read Clause 10, area by area →Annex A: 38 controls under 9 objectives
Annex A is the menu, not the mandate. Through the risk assessment in Clause 6, an organization chooses the controls that apply to it and records the choices, with a justification for every exclusion, in the Statement of Applicability. The SoA is the first document an auditor asks for, and the one that shows whether the risk work was real.
Policies related to AI
Give every later control a written foundation to stand on.
- A.2.2 AI policy
- A.2.3 Alignment with other organizational policies
- A.2.4 Review of the AI policy
Internal organization
Make accountability for AI a name and a desk, not a department of everyone.
- A.3.2 AI roles and responsibilities
- A.3.3 Reporting of concerns
Resources for AI systems
Know what your AI actually runs on: data, tools, compute and people.
- A.4.2 Resource documentation
- A.4.3 Data resources
- A.4.4 Tooling resources
- A.4.5 System and computing resources
- A.4.6 Human resources
Assessing impacts of AI systems
Look past the organization to the people the system can touch.
- A.5.2 AI system impact assessment process
- A.5.3 Documentation of AI system impact assessments
- A.5.4 Assessing AI system impact on individuals or groups of individuals
- A.5.5 Assessing societal impacts of AI systems
AI system life cycle
Govern the system from the first sketch to the last log line.
- A.6.1.2 Objectives for responsible development of AI system
- A.6.1.3 Processes for responsible design and development of AI systems
- A.6.2.2 AI system requirements and specification
- A.6.2.3 Documentation of AI system design and development
- A.6.2.4 AI system verification and validation
- A.6.2.5 AI system deployment
- A.6.2.6 AI system operation and monitoring
- A.6.2.7 AI system technical documentation
- A.6.2.8 AI system recording of event logs
Data for AI systems
Treat training and operating data as a governed asset, not plumbing.
- A.7.2 Data for development and enhancement of AI system
- A.7.3 Acquisition of data
- A.7.4 Quality of data for AI systems
- A.7.5 Data provenance
- A.7.6 Data preparation
Information for interested parties
Make the system legible to the people who have to live with it.
- A.8.2 System documentation and information for users
- A.8.3 External reporting
- A.8.4 Communication of incidents
- A.8.5 Information for interested parties
Use of AI systems
Govern the system in the hands of its users, not just in the lab.
- A.9.2 Processes for responsible use of AI systems
- A.9.3 Objectives for responsible use of AI system
- A.9.4 Intended use of the AI system
Third-party and customer relationships
Draw the responsibility line across the AI supply chain before something crosses it.
- A.10.2 Allocation of responsibilities
- A.10.3 Suppliers
- A.10.4 Customers
How certification actually works
This is where ISO/IEC 42001 parts company with the NIST AI RMF. The RMF certifies nothing; 42001 is built to be audited. An accredited certification body examines your AI management system against every clause, samples your evidence, and issues a certificate that enterprise procurement teams and regulators can take at face value. ISO itself certifies no one, and the certificate attests to the management system, never to the quality of a single model.
The companion standards matter here: ISO/IEC 42005 covers AI system impact assessment (the process Annex A.5 expects), and ISO/IEC 42006 sets the requirements for the bodies that audit and certify. The certificate is real, but it is not law: it does not by itself discharge EU AI Act obligations, and no honest auditor will tell you otherwise.
Where to go from reading to running it
Pair it with the NIST AI RMF
42001 supplies the auditable machinery; the AI RMF supplies the risk vocabulary that runs inside it. Most serious programs end up fluent in both.
Read the NIST AI RMF guideLearn it end to end, with a credential
AI Governance: Applied Mastery walks the whole discipline: 88 topics, every one gated by a mastery assessment, ending in a signed credential an employer can verify. $399 for an individual.
See the program, $399Frequently asked questions
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the first international management system standard for artificial intelligence, published in December 2023 by ISO and the IEC. It specifies what an organization must have in place to govern AI responsibly: a defined scope, leadership commitment, risk processes, lifecycle controls, and continual improvement. It follows the same Harmonized Structure as ISO 9001 (quality) and ISO/IEC 27001 (information security), so it bolts onto a management system an organization already runs.
Can an organization be certified against ISO/IEC 42001?
Yes, and that is what sets it apart from frameworks like the NIST AI RMF. Accredited certification bodies audit an organization's AI management system against the standard and issue certificates. Two honest caveats: ISO itself certifies no one (certification bodies do), and a certificate covers the management system, not the goodness of any single AI product.
Does ISO/IEC 42001 certification guarantee EU AI Act compliance?
No. The standard and the Act overlap heavily in spirit (risk management, documentation, lifecycle control), and running a certified AI management system puts much of the Act's expected machinery in place. But the Act is law with its own specific obligations and its own conformity procedures, and no ISO certificate discharges them. Treat 42001 as strong preparation, never as a legal safe harbor.
How does ISO/IEC 42001 relate to the NIST AI RMF?
They are different instruments that fit together. The NIST AI RMF is a voluntary risk framework: it tells you what good AI risk work looks like, in 72 subcategories, and certifies nothing. ISO/IEC 42001 is a certifiable management system standard: it tells you what organizational machinery must exist, and an auditor can attest that it does. Many organizations run the RMF's risk process inside a 42001 management system.
What is the Statement of Applicability?
The Statement of Applicability (SoA) is the document where an organization lists which of Annex A's 38 controls it has adopted, and justifies every exclusion. Annex A is a reference set, not a mandatory checklist: the controls you implement are chosen through your risk assessment (Clause 6.1), and the SoA is the record of that choice. Auditors read it first.
Who is ISO/IEC 42001 for?
Any organization that develops, provides or uses AI-based products or services, in any sector and at any size. The obligations scale with your role: a company building foundation models and a hospital deploying a triage model both run AI management systems, but the scope, risk profile and control selection differ. Clause 4 is where that scoping happens.
Why do the clauses start at 4 and the controls at A.2?
Clauses 1 to 3 are the standard's front matter (scope, normative references, terms) and are not auditable requirements; every Harmonized Structure standard works this way. Annex A.1 is the annex's introduction, so the nine control objectives run A.2 through A.10, and within each objective the first numbered entry is the objective itself, which is why the controls start at A.2.2.
Does GAGE certify organizations against ISO/IEC 42001?
No, and no training provider can. Certification is issued by accredited certification bodies after an audit of your management system. What a training program can do is build the competence the standard demands: Clause 7.2 makes competence an auditable requirement, and the AI Governance program exists to close exactly that gap.
Know the standard. Then prove you can run it.
38 controls is a catalogue, not a competence. Clause 7.2 makes competence an auditable requirement, which is exactly the gap a mastery-gated program closes.
Sources and verification
The standard's full text is copyrighted and sold by ISO; this guide publishes its structure (clause and control identifiers) exactly, with every explanation in our own plain-English words, verified against two independent enumerations of the published contents. It is not legal advice, and it is not affiliated with or endorsed by ISO or the IEC. Last verified: August 25, 2026.