New · France 2027 presidential election: what the candidates propose on AI, quoted and sourced. Explore the tracker →

Last reviewed:

What is ISO/IEC 42001? Definition, certification and link with the AI Act

ISO/IEC 42001 is the international standard, published in December 2023 by ISO and IEC, that sets the requirements for an artificial intelligence management system (AIMS): policy, roles, risk and impact assessment, controls and continual improvement. It is voluntary and certifiable, but it is not a harmonised standard under the AI Act: an ISO 42001 certificate does not create a presumption of conformity with the EU regulation.

ISO/IEC 42001:2023 (first edition, December 2023) applies to AI the common structure of management system standards, the one used by ISO 9001 for quality and ISO/IEC 27001 for information security: context of the organisation, leadership, planning, support, operation, performance evaluation, improvement. It targets any organisation providing or using AI-based products or services, whatever its size. Its Annex A lists controls: AI policy, internal organisation, resources, impact assessment, system life cycle, data, information for interested parties, responsible use, third-party relationships. It can be certified by an accredited third party; AFNOR Certification is one of the bodies issuing it in France, for three years with annual surveillance audits. ISO/IEC 42006, published in 2025, sets the requirements for those certification bodies. The relationship with the AI Act is often misunderstood. Only European harmonised standards whose reference is published in the EU Official Journal give a presumption of conformity (Article 40). They are drafted by the CEN-CENELEC JTC 21 committee, not by ISO. For the quality management system required of high-risk system providers (Article 17), the reference standard is EN 18286, published by CEN-CENELEC in July 2026; its citation in the Official Journal is a Commission decision. An AIMS aligned with 42001 remains a useful basis for AI Act work, without guaranteeing compliance. The standard is sold in English and French by ISO and national bodies: there is no free official PDF.

Concrete example

Illustrative case. A 120-person SaaS vendor in Paris sells banks a module assessing the creditworthiness of individuals. In a tender, it is asked whether it is ISO 42001 certified. Already ISO/IEC 27001 certified, it reuses its structure (management review, internal audits, document control) and adds what is specific to AI: model inventory, impact assessments, rules on training data. But its module is high-risk (credit, Annex III of the AI Act): the certificate exempts it neither from the Article 17 quality system described by EN 18286, nor from the technical documentation due by 2 December 2027.

Comparison

ISO/IEC 42001, EN 18286 and the AI Act: who does what
FrameworkNatureMandatory?What it provides
AI Act (Regulation (EU) 2024/1689)EU lawYes, depending on role and risk levelThe obligations themselves
ISO/IEC 42001:2023International management standard, certifiableNoInternationally recognised AI governance framework
EN 18286:2026European quality system standard for the AI ActNo, but designed for Article 17Presumption of conformity once cited in the Official Journal
ISO/IEC 42006:2025Standard for certification bodiesFor certifiersGoverns how 42001 audits are conducted

FAQ

What is ISO 42001?

It is the first international standard for an artificial intelligence management system, published in December 2023. It describes how an organisation governs its AI use and development: policy, responsibilities, risk and impact assessment, controls, internal audits and continual improvement.

Is ISO 42001 certification mandatory?

No. No European or national law requires it. It is voluntary, and often requested by large clients or in tenders as evidence of AI governance maturity.

Is ISO 42001 a harmonised standard under the AI Act?

No. AI Act harmonised standards are European standards (EN) drafted by CEN-CENELEC, whose reference must be published in the EU Official Journal. ISO/IEC 42001 is not one of them: certification does not give a presumption of conformity. For the quality system of high-risk system providers, the European standard is EN 18286, published in July 2026.

Is there a free ISO 42001 PDF?

No. The standard is sold as a PDF or on paper by ISO (225 Swiss francs as of 30 September 2026) and by national standards bodies. There is no free official version; free copies circulating online are not authorised.

What is an ISO 42001 Lead Implementer?

It is a personal certification, issued by training organisations after a course and an exam, showing that a professional can implement an AI management system. It differs from certification of the organisation, issued after an audit by an accredited body. Lead Auditor is the equivalent for conducting audits.

What is the difference between ISO 42001 and ISO 27001?

ISO/IEC 27001 covers information security; ISO/IEC 42001 covers risks specific to AI (bias, transparency, impact on people, model life cycle). They share the same structure, so they can be combined in a single management system.

See also

Further reading

ISO/IEC 42006:2025, requirements for bodies certifying AI management systems (external resource)

Sources

  1. ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, ISO. https://www.iso.org/standard/42001 (accessed 2026-09-30)
  2. EN 18286 in the Spotlight: Supporting Compliance with the AI Act, CEN-CENELEC, July 2026. https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/ (accessed 2026-09-30)
  3. Regulation (EU) 2024/1689 on artificial intelligence (AI Act), Articles 17 and 40. https://eur-lex.europa.eu/eli/reg/2024/1689/oj (accessed 2026-09-30)
  4. ISO/IEC 42001 certification, AFNOR Certification. https://international.afnor.com/en/shop/type-of-service/management-system-certifications/iso-iec-42001-artificial-intelligence-management-system-certification/ (accessed 2026-09-30)

← Back to glossary

Address copied