7 min read

What Is ISO 42001? AI Management System Standard

Featured Image

Quick Answer: ISO 42001 is the international standard for AI management systems. It was published in December 2023. Certification proves an accredited third party has audited how your organization governs AI. It applies to any organization that builds, provides or uses AI systems. That includes companies deploying models built by someone else.

Your last three enterprise deals came with a security questionnaire. The newest version has a section that did not exist eighteen months ago.

It asks how you govern AI. Who approved the model. What happens when it produces a wrong answer. Whether anyone reviews training data. Procurement wants a document, not a paragraph about your values.

That is the pressure driving interest in ISO/IEC 42001:2023. No law compels it in the United States. Customers do.

Here we cover what the standard requires, who it applies to, and what certification takes. We also talk about the part the explainers skip: the operating work that follows the certificate.

Key Takeaways

  • ISO 42001 defines an AI management system. That means the policies, roles, risk processes and evidence governing AI across its lifecycle.
  • It applies to organizations that develop AI, resell it, or use bought-in AI features.
  • It is the only AI governance standard an accredited body can certify you against.
  • Annex A contains 38 controls across 9 control objectives. You select from them rather than implementing all of them.
  • Most teams underestimate the continuous load. Inventory upkeep, repeated impact assessments, monitoring evidence.
  • BEMO implements the AI management system, from AI inventory scoping through the certification audit.

What ISO 42001 Covers

The ISO 42001 standard builds an AI management system, abbreviated AIMS. Think of it as the governance layer sitting above every AI system you run.

It follows the same plan-do-check-act structure as ISO 27001 and ISO 9001. If you have run a management system before, the shape is familiar.

Clauses 4 through 10 define the system itself. Context and scope. Leadership and policy. Planning and risk. Support and competence. Operation. Performance evaluation. Improvement. These clauses are mandatory.

Annex A is different. It holds 38 AI-specific controls grouped under 9 control objectives, numbered A.2 through A.10. The objectives cover AI policy, internal organization, resources and impact assessment. They also cover the AI system lifecycle and data. The last three cover transparency, responsible use and third-party relationships.

Annex A is a reference set, not a checklist. Our ISO 42001 requirements checklist works through every control area with the evidence each expects. You choose which controls apply based on your risk and impact assessments. A Statement of Applicability records every inclusion and every exclusion, with justification.

Annex B gives implementation guidance for each control. It is informative rather than mandatory, but auditors read it. Annexes C and D add risk-source ideas and sector-specific notes.

Two companion standards matter here. ISO/IEC 42005:2025 covers AI system impact assessment. ISO/IEC 23894:2023 covers AI risk management guidance. Neither is certifiable on its own.

Who Needs ISO 42001

Three groups are being asked for it right now:

  1. Companies that build AI products. If your model shapes a decision your customer relies on, you are in scope.
  2. Companies that embed third-party models. You call an API, wrap it in your product, and ship it. Buying the model does not move the governance obligation. You are still accountable for how it behaves in your product.
  3. Companies that sell into regulated buyers. Healthtech, fintech, government contractors and enterprise SaaS all sit here. Their customers have compliance teams, and those teams write questionnaires.

The pattern worth naming: AI vendors now get AI governance questions. They arrive in the same security review that asks for SOC 2. Two years ago that section was blank. Now it has weight in the scoring.

ISO 42001 compliance also matters for internal AI use. If your finance team runs a model that flags invoices, it sits inside the boundary. So do AI features that arrived inside SaaS tools nobody catalogued.

That last category is where scoping gets uncomfortable. Most organizations cannot name every AI system in use.

How ISO 42001 Relates to ISO 27001, SOC 2 and the NIST AI RMF

Short version: they do different jobs and share evidence.

ISO 27001 secures the data. ISO 42001 governs the decisions a model makes with that data. An encrypted training set can still produce a discriminatory output. ISO 27001 has nothing to say about that.

SOC 2 is an attestation against trust services criteria, not a certification against a standard. It covers security and availability. It does not cover model behavior, training data provenance, or explainability.

The NIST AI Risk Management Framework is the closest in subject matter. It is voluntary US guidance, published as NIST AI 100-1 in January 2023. It has four functions: Govern, Map, Measure and Manage. It produces no certificate, but our compliance practice helps if you are weighing several frameworks.

That distinction decides the answer for most buyers. If a customer asks for proof, only one of these gives you something to send.

Work overlaps more than the documents suggest. Your existing risk methodology, internal audit program and management review cadence carry across. If you already hold ISO 27001, the path to a second certification is shorter.

What Certification Actually Requires

Certification is a two-stage audit performed by an accredited certification body, and our step-by-step certification roadmap walks the full sequence. ISO/IEC 42006:2025 sets the rules those bodies follow, including how audit time is calculated.

Here is what the full sequence produces.

Stage

What you do

What it produces

Scope definition

Decide which AI systems and business units sit inside the boundary

A documented scope statement with justified exclusions

AI system inventory

Catalogue every AI system, including embedded SaaS features

A maintained inventory with owners

Risk and impact assessment

Assess risk to the organization and impact on individuals and society

Risk register and AI system impact assessment records

Control selection

Choose applicable Annex A controls and justify exclusions

Statement of Applicability

Implementation

Build policy, lifecycle controls, data governance and monitoring

Operating controls with evidence

Internal audit

Audit your own system against the standard

Internal audit report and findings

Management review

Leadership reviews performance and resourcing

Documented review with decisions

Stage 1 audit

Certification body reviews documentation

Readiness findings, gaps to close

Stage 2 audit

Certification body tests implementation

Certificate, or nonconformities to fix

 

Two things surprise teams here:

  • The AI system impact assessment has no ISO 27001 equivalent. It asks who the system affects and how, not just what it risks for you. That is new work with new inputs.

  • The gap between Stage 1 and Stage 2 has a ceiling. Leave it too long and Stage 1 gets repeated. Confirm the current window with your certification body before you plan around it.

After certification, the cycle continues. Surveillance audits run annually. Recertification follows on a three-year cadence.

Where AI Governance Programs Stall

Most ISO 42001 AI management system projects do not fail at the audit. They stop months earlier, and always in the same places.

The inventory is the first casualty. Teams list the models they built. They miss AI features that arrived inside tools they already pay for. A note-taker, a support triage bot, a resume screener in the recruiting platform. Nobody catalogued them because nobody bought them as AI.

Then ownership blurs. Model risk sits between engineering, legal, product and security. The gap assessment gets completed. It names twenty gaps. It names no owner for any of them.

Impact assessments get treated as a document rather than a process. Somebody writes one, files it, and moves on. Then the model gets retrained and the behavior changes. The assessment now describes a system that no longer exists.

Monitoring is where audits actually fail. The standard expects continuous operation. The auditor asks for six months of evidence that somebody watched model behavior. Most teams can produce a policy saying they would. They cannot produce the logs.

The staffing math is the honest part. Running an AIMS is a fraction of a role, forever. It is not a project with an end date. The median US wage for an information security analyst was $124,910 in May 2024. AI governance skills sit above that. Hiring for it takes months you do not have.

Microsoft 365 and Azure AI Relevance

If you run on Microsoft, much of the evidence layer already exists. It is usually just not configured or retained:

  • AI systems you build in Azure. Microsoft Foundry provides content filtering and evaluations. Microsoft renamed it from Azure AI Foundry, so both names circulate.
  • Data governance. Microsoft Purview handles classification, sensitivity labels and DLP. Applied to prompts and outputs, it answers what data can reach a model.
  • Access. Entra ID conditional access controls who reaches AI tooling and under what conditions. Privileged Identity Management covers who can change model configuration.
  • Logging. The unified audit log captures interactions, but retention is a configuration choice. Default retention is often shorter than your audit window. Set it deliberately.
  • Microsoft 365 Copilot. The data boundary and tenant grounding rules matter, and your impact assessment describes them. Microsoft also publishes an ISO/IEC 42001 assessment template in Purview Compliance Manager.
  • Shadow AI. Defender for Cloud Apps surfaces the AI services your people already use. That is your inventory starting point, not a spreadsheet.

How BEMO Implements ISO 42001

Many vendors here explain the standard, then sell a course or an audit. BEMO does the implementation.

We own the AI system inventory rather than asking you to produce one. We run the risk and impact assessments. We write the Statement of Applicability that an auditor will accept.

We also configure the Microsoft surfaces that produce your evidence: Purview policies, conditional access, log retention, and Foundry evaluations wired to run on a schedule.

Then we operate it. Monitoring output gets collected. Impact assessments get repeated when models change. Internal audit runs before the certification body arrives.

BEMO stays through Stage 2 and past it, because surveillance audits are part of the engagement rather than a handoff. That is how the AI compliance work is structured, and the wider AI managed services sit alongside it.

Answering the Questionnaire with a Certificate

The AI governance section of a security review is not going away. It is getting longer.

Right now most vendors answer it with a paragraph about responsible AI principles. That is a paragraph competing against a certificate.

An AI management system takes months to build and staff you probably do not have. It also takes continuous operation once it exists. That is the part catching teams out.

BEMO builds it, runs it, and owns the outcome through the audit. Book a gap assessment to see where your AI systems stand today.

Frequently Asked Questions

Is ISO 42001 mandatory?

No US law requires ISO 42001 today. The pressure is commercial. Enterprise customers, procurement teams and partners increasingly ask for AI governance evidence. This is the only certifiable answer available.

How long does ISO 42001 certification take?

Most organizations should plan for several months from gap assessment to certificate. Teams with a mature ISO 27001 system move faster. Risk processes and audit habits already exist. Starting cold with no AI inventory takes considerably longer.

Can we certify if we only use third-party AI models?

Yes. The standard applies to organizations that provide or use AI systems. Building them is not required. Your controls focus on supplier assessment, use governance and monitoring rather than model development.

Does ISO 27001 already cover AI?

No. ISO/IEC 27001:2022 has 93 controls across 4 themes, all focused on information security. It does not address model behavior, training data provenance, explainability or impact on affected individuals.

Who audits ISO 42001?

An accredited certification body. ISO/IEC 42006:2025 sets the competence and audit-time requirements those bodies must meet. Confirm current accreditation status directly with any body you shortlist.

Leave us a comment!