ISO/IEC 42001 is an international management system standard that specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system within an organization that provides or uses AI-based products or services. It was published in December 2023 by ISO/IEC Joint Technical Committee 1, SC 42 (Artificial intelligence), and is the first international AI-specific management system standard against which organizations can be certified.
| Published | December 2023 |
| Publisher | ISO/IEC Joint Technical Committee 1, SC 42 (Artificial intelligence) |
| Type | International management system standard (certifiable) |
Scope
The standard specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system within organizations that provide or use AI-based products or services. It is modeled on the ISO management-system family (ISO 9001, ISO 27001, ISO 14001) and follows the same Plan-Do-Check-Act structure.
Structure
Mandatory clauses (4–10)
ISO/IEC 42001 uses the standard Annex SL management-system structure across clauses 4 through 10:
- Clause 4 — Context of the organization
- Clause 5 — Leadership (AI policy, roles, responsibilities)
- Clause 6 — Planning (AI risk assessment, AI impact assessment, AI objectives)
- Clause 7 — Support (resources, competence, awareness, documentation)
- Clause 8 — Operation (AI life cycle, data management, third-party documentation)
- Clause 9 — Performance evaluation (monitoring, internal audit, management review)
- Clause 10 — Improvement (nonconformities, corrective actions, continual improvement)
Annex A — control objectives and controls
Annex A defines 39 controls grouped as follows:
- A.2–A.3 — AI policies, internal organization
- A.4 — Resources (data, tooling, system, human)
- A.5 — Impact assessment
- A.6 — AI life cycle (requirements, design, V&V, deployment, operation, monitoring)
- A.7 — Data management (acquisition, quality, provenance, preparation)
- A.8 — Information for interested parties (users, regulators, third parties)
- A.9 — Use of AI (responsible use, human oversight)
- A.10 — Third parties and customers
Annex B — implementation guidance
Annex B provides guidance notes for each Annex A control. Key subsections are:
- B.4 — Resource documentation (data provenance, labeling, retention, tooling, computing, human resources)
- B.5 — Impact assessment requirements and process
- B.6 — AI life cycle documentation (from requirements through operation and monitoring)
- B.7 — Data management (provenance, quality, preparation methods)
- B.8 — Third-party and user documentation, incident communication plans
- B.9 — Responsible-use documentation (human oversight objectives)
Key requirements for compliance
AI policy (5.2). The AI policy must include the organization's purpose, a framework for AI objectives, a commitment to requirements, a commitment to continual improvement, legal requirements, the risk environment, and principles for all AI activities.
AI risk assessment (6.1.2). The risk assessment must align with the AI policy, be consistent and comparable, assess consequences and likelihood, produce risk levels against criteria, and be repeatable.
AI impact assessment (6.1.4). The impact assessment must cover effects on individuals (fairness, accountability, transparency, security, privacy, safety, human rights) and effects on society (environmental sustainability, economic, health, norms/culture/values).
Documentation requirements span the full management system. Organizations must document the AI policy and objectives; AI risk criteria and risk tolerance; the risk assessment process and results; the risk treatment plan and residual risks; the impact assessment process, results, and reporting; AI resource documentation (data, tools, compute, people); AI life cycle documentation (requirements, design, V&V, deployment, operation); technical documentation for each interested-party category; event logs during all AI-use phases; nonconformities and corrective actions; and internal audit and management review results.
Certification
ISO/IEC 42001 is certifiable: organizations can undergo third-party audit and receive ISO 42001 certification. It is the first international AI-specific certifiable management system standard.
Relation to other frameworks
| Framework | Comparison to 42001 |
|---|---|
| NIST AI RMF (NIST AI Risk Management Framework (AI RMF 1.0)) | Voluntary US-only framework; complementary but not certifiable |
| EU AI Act (EU AI Act (Regulation 2024/1689)) | Regulatory; 42001 compliance may satisfy some but not all EU AI Act requirements |
| ISO/IEC 42005 (ISO/IEC 42005 — AI Impact Assessment) | Companion standard specifically for AI impact assessment process |
| Anthropic RSP (Anthropic's Responsible Scaling Policy (Version 3.1)) | Lab-specific; 42001 is organization-universal |
| OpenAI Preparedness (OpenAI Preparedness Framework V.2) | Capability-threshold-specific; 42001 is management-system-wide |
Adoption and legal status
ISO/IEC 42001 is the first certifiable international AI standard, and it is already cited in Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) and EU AI Act (Regulation 2024/1689) as a compliance-pathway reference. It provides documentation and process requirements for organizations building AI governance programs across regulatory regimes, and the 39-control structure in Annex A is used by AI governance practitioners as a compliance checklist.
FPF's 2026 analysis documents two pathways by which ISO 42001 compliance is moving from voluntary practice into legal obligation. The first is safe-harbor provisions: Texas TRAIGA conditions liability immunity on maintaining an ISO 42001-compliant AI risk management program. The second is judicial standards-of-care: New York courts are adopting ISO 42001's impact assessment and documentation controls as the benchmark for what a reasonable AI deployer does. Per the analysis, organizations that treated ISO 42001 certification as a marketing credential now face it as a threshold for legal protection.
Relationships
- supports: Algorithmic Accountability and Bias Audits, AI Compliance Industry / Regulatory Fragmentation, EU AI Act (Regulation 2024/1689), Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment).
- depends-on: ISO management-system Annex SL family.
- related: ISO/IEC 42005 — AI Impact Assessment, NIST AI Risk Management Framework (AI RMF 1.0), Frontier Compliance Framework (February 2026), Anthropic's Responsible Scaling Policy (Version 3.1), OpenAI Preparedness Framework V.2, AI Safety Cases and Frameworks.
Sources
- ISO/IEC 42001:2023 standard text
- CDT: "Best Practices in AI Documentation: The Imperative of Evidence from Practice"
- James Kavanagh: "Building your AI System Inventory" (Feb 11, 2025)
- Incentives or Obligations? The U.S. Regulatory Approach to Voluntary AI Governance Standards — FPF 2026 analysis documenting ISO 42001 embedding in binding law via Texas TRAIGA safe harbor and New York judicial standards-of-care