Last reviewed:
What is ISO/IEC 42001? Definition, certification and link with the AI Act
ISO/IEC 42001 is the international standard, published in December 2023 by ISO and IEC, that sets the requirements for an artificial intelligence management system (AIMS): policy, roles, risk and impact assessment, controls and continual improvement. It is voluntary and certifiable, but it is not a harmonised standard under the AI Act: an ISO 42001 certificate does not create a presumption of conformity with the EU regulation.
ISO/IEC 42001:2023 (first edition, December 2023) applies to AI the common structure of management system standards, the one used by ISO 9001 for quality and ISO/IEC 27001 for information security: context of the organisation, leadership, planning, support, operation, performance evaluation, improvement. It targets any organisation providing or using AI-based products or services, whatever its size. Its Annex A lists controls: AI policy, internal organisation, resources, impact assessment, system life cycle, data, information for interested parties, responsible use, third-party relationships. It can be certified by an accredited third party; AFNOR Certification is one of the bodies issuing it in France, for three years with annual surveillance audits. ISO/IEC 42006, published in 2025, sets the requirements for those certification bodies. The relationship with the AI Act is often misunderstood. Only European harmonised standards whose reference is published in the EU Official Journal give a presumption of conformity (Article 40). They are drafted by the CEN-CENELEC JTC 21 committee, not by ISO. For the quality management system required of high-risk system providers (Article 17), the reference standard is EN 18286, published by CEN-CENELEC in July 2026; its citation in the Official Journal is a Commission decision. An AIMS aligned with 42001 remains a useful basis for AI Act work, without guaranteeing compliance. The standard is sold in English and French by ISO and national bodies: there is no free official PDF.
Concrete example
Illustrative case. A 120-person SaaS vendor in Paris sells banks a module assessing the creditworthiness of individuals. In a tender, it is asked whether it is ISO 42001 certified. Already ISO/IEC 27001 certified, it reuses its structure (management review, internal audits, document control) and adds what is specific to AI: model inventory, impact assessments, rules on training data. But its module is high-risk (credit, Annex III of the AI Act): the certificate exempts it neither from the Article 17 quality system described by EN 18286, nor from the technical documentation due by 2 December 2027.
Comparison
| Framework | Nature | Mandatory? | What it provides |
|---|---|---|---|
| AI Act (Regulation (EU) 2024/1689) | EU law | Yes, depending on role and risk level | The obligations themselves |
| ISO/IEC 42001:2023 | International management standard, certifiable | No | Internationally recognised AI governance framework |
| EN 18286:2026 | European quality system standard for the AI Act | No, but designed for Article 17 | Presumption of conformity once cited in the Official Journal |
| ISO/IEC 42006:2025 | Standard for certification bodies | For certifiers | Governs how 42001 audits are conducted |
FAQ
What is ISO 42001?
It is the first international standard for an artificial intelligence management system, published in December 2023. It describes how an organisation governs its AI use and development: policy, responsibilities, risk and impact assessment, controls, internal audits and continual improvement.
Is ISO 42001 certification mandatory?
No. No European or national law requires it. It is voluntary, and often requested by large clients or in tenders as evidence of AI governance maturity.
Is ISO 42001 a harmonised standard under the AI Act?
No. AI Act harmonised standards are European standards (EN) drafted by CEN-CENELEC, whose reference must be published in the EU Official Journal. ISO/IEC 42001 is not one of them: certification does not give a presumption of conformity. For the quality system of high-risk system providers, the European standard is EN 18286, published in July 2026.
Is there a free ISO 42001 PDF?
No. The standard is sold as a PDF or on paper by ISO (225 Swiss francs as of 30 September 2026) and by national standards bodies. There is no free official version; free copies circulating online are not authorised.
What is an ISO 42001 Lead Implementer?
It is a personal certification, issued by training organisations after a course and an exam, showing that a professional can implement an AI management system. It differs from certification of the organisation, issued after an audit by an accredited body. Lead Auditor is the equivalent for conducting audits.
What is the difference between ISO 42001 and ISO 27001?
ISO/IEC 27001 covers information security; ISO/IEC 42001 covers risks specific to AI (bias, transparency, impact on people, model life cycle). They share the same structure, so they can be combined in a single management system.
See also
Further reading
ISO/IEC 42006:2025, requirements for bodies certifying AI management systems
Sources
- ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, ISO. https://www.iso.org/standard/42001
- EN 18286 in the Spotlight: Supporting Compliance with the AI Act, CEN-CENELEC, July 2026. https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/
- Regulation (EU) 2024/1689 on artificial intelligence (AI Act), Articles 17 and 40. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- ISO/IEC 42001 certification, AFNOR Certification. https://international.afnor.com/en/shop/type-of-service/management-system-certifications/iso-iec-42001-artificial-intelligence-management-system-certification/