← Back to blog

ISO/IEC 42001: The Complete Guide to the AI Management System Standard

ISO/IEC 42001: The Complete Guide to the AI Management System Standard

What ISO 42001 is, how the standard is built, and how organizations get certified — the definitive starting point, with links to every part of the framework.

By Sakthi Thangavelu, CEO, AramGRC·September 2026 · AI Governance Insights·September 18, 2026·12 min read

ISO/IEC 42001:2023 is the world's first certifiable management-system standard for artificial intelligence. Published on 18 December 2023 by ISO and IEC, it specifies how an organization establishes, implements, maintains, and continually improves an AI management system (AIMS) — a structured way to govern the AI it develops, provides, or uses. Any organization can be independently audited and certified against it, in the same way ISO/IEC 27001 certifies information security.

This guide is the hub of our ISO 42001 cluster. It explains the standard end to end and links to a dedicated deep-dive on each part — from what the standard is, through its clauses and Annex A controls, to certification, cost, training, and what it means for Indian businesses.

What is ISO 42001 in one sentence?

ISO 42001 is the international standard that defines the requirements for an AI management system: a governance framework built on the Plan-Do-Check-Act cycle that lets an organization manage AI-specific risks — bias, opacity, safety, security, and misuse — with the same rigor it already applies to quality or information security. It was developed by ISO/IEC JTC 1/SC 42, the joint subcommittee responsible for AI standards.

Why ISO 42001 matters now

AI governance has moved from voluntary good practice to a procurement and regulatory expectation. Enterprise buyers now ask vendors how their AI is governed; regulators from the EU to India expect demonstrable, not aspirational, controls. ISO 42001 gives an organization one certifiable framework that answers the question every board is now asking — “how do we know our AI systems are under control?” — with independent evidence rather than a policy statement. We explore that business case in AI governance as competitive advantage and the ROI of ISO/IEC 42001.

How the standard is structured

ISO 42001 follows ISO's Harmonized Structure (the shared skeleton also used by ISO 27001 and ISO 9001), which is why it integrates cleanly with management systems you may already run. The auditable requirements sit in Clauses 4 to 10, supported by Annex A controls.

ClauseWhat it requires
4 — ContextDetermine internal/external issues, interested parties, and the scope of the AIMS; define your role (developer, provider, or user of AI).
5 — LeadershipTop-management commitment, an AI policy, and clearly assigned roles and responsibilities.
6 — PlanningAI risk assessment and treatment, AI system impact assessment, and measurable AI objectives.
7 — SupportResources, competence, awareness, communication, and documented information.
8 — OperationPut the risk and impact assessments into practice across the AI lifecycle.
9 — Performance evaluationMonitoring, measurement, internal audit, and management review.
10 — ImprovementContinual improvement and corrective action for nonconformities.

Our requirements and clauses guide walks through each clause in detail.

The Annex A controls

Annex A of ISO 42001 sets out 38 controls organized under 9 control objectives (categories A.2 through A.10), covering AI policies, internal organization, resources, impact assessment, the AI system lifecycle, data, information for interested parties, use of AI systems, and third-party relationships. Annex B gives implementation guidance, Annex C catalogues AI risk sources, and Annex D covers sector use. See the full Annex A controls breakdown.

How ISO 42001 certification works

An organization is certified through a two-stage audit by an accredited certification body: Stage 1 reviews whether the AIMS is designed and documented, and Stage 2 verifies it is genuinely operating. Certificates run on a three-year cycle with annual surveillance audits and a recertification audit at the end. ISO/IEC 42006:2025 sets the competence requirements for the certification bodies themselves. Full detail is in our certification process guide and what auditors actually look for.

Organizations get certified; individuals get trained. A company earns an ISO 42001 certificate for its management system. People earn professional credentials — Foundation, Lead Implementer, or Lead Auditor — that qualify them to build or audit one. Don't confuse the two; see ISO 42001 training and certification for individuals.

Explore the full ISO 42001 cluster

Related standards in the ISO 42001 family

ISO 42001 does not stand alone. ISO/IEC 42005:2025 (published 28 May 2025) gives the methodology for the AI system impact assessment that Annex A requires. ISO/IEC 23894:2023 provides AI risk-management guidance, and ISO/IEC 22989:2022 defines the AI terminology the whole family uses. ISO/IEC 42006:2025 governs the bodies that certify you.

Who needs ISO 42001?

Any organization that builds, sells, or relies on AI is in scope, but adoption is fastest where AI touches customers, regulated decisions, or enterprise procurement: cloud and AI providers, B2B SaaS, healthcare, financial services, HR and recruiting tech, legal tech, and government suppliers. Amazon Web Services was among the first to achieve accredited certification and has publicly reported passing its first surveillance audit — a signal that ISO 42001 is following ISO 27001's path from differentiator to baseline expectation.

Frequently asked questions

What is ISO/IEC 42001?+

ISO/IEC 42001:2023 is the international standard specifying requirements for an AI management system (AIMS). Published in December 2023, it is the first certifiable AI standard, letting organizations be independently audited on how they govern the AI they develop, provide, or use.

Is ISO 42001 mandatory?+

No. ISO 42001 is a voluntary standard, but it is increasingly required in enterprise procurement and used as evidence of readiness for regulations such as the EU AI Act and India's AI governance guidelines.

How many controls does ISO 42001 have?+

Annex A of ISO 42001 contains 38 controls grouped under 9 control objectives (categories A.2 to A.10), supported by implementation guidance in Annex B.

How long does ISO 42001 certification take?+

For an organization with an existing management system, a realistic path runs about 6 months from gap assessment to the Stage 2 certification audit; organizations starting from scratch should budget longer. Certificates then run on a 3-year cycle with annual surveillance audits.

What is the difference between ISO 42001 and ISO 42005?+

ISO 42001 is the certifiable management-system standard; ISO 42005:2025 is guidance on how to conduct an AI system impact assessment, which is one of the activities ISO 42001's Annex A requires.

Related reading

ISO/IEC 42001AI management systemISO 42001 certificationAI governanceAIMS

The ISO 42001 series

ISO 42001 Certification

Start here — what ISO 42001 is, what it requires, costs, and how to get certified.

ISO/IEC 42001: The Complete Guide to the AI Management System Standard

The world's first certifiable AI management system standard — requirements, Annex A controls, certification, cost, training and India relevance.

You're here

What Is ISO/IEC 42001? The AI Management System Standard Explained

The standard explained in plain language.

ISO 42001 Requirements

The clauses and Annex A controls ISO 42001 asks for.

ISO 42001 Annex A Controls: All 38 Controls Across 9 Objectives

The 38 AI controls across 9 objectives (A.2–A.10), and how you select which apply.

ISO 42001 Certification Cost

What ISO 42001 certification costs, including in India.

ISO 42001 Checklist

A step-by-step readiness checklist for certification.

ISO 42001 Documentation & Toolkit: Mandatory Policies, Templates & Records

The mandatory policies, procedures and records — and what a good ISO 42001 toolkit includes.

ISO 42001 vs ISO 27001

How the AI and information-security standards differ.

How to Get ISO 42001 Certified

The certification process, step by step.

ISO 42001 Lead Auditor

Courses and credentials for individuals.

ISO 42001 Lead Implementer: Role, Training & Certification

The role that builds and runs the AIMS — course, exam and how it differs from Lead Auditor.

ISO 42001 Certification in India: One AIMS for DPDP, MeitY and RBI FREE-AI

DPDP Act, MeitY guidelines and RBI FREE-AI, mapped to one AIMS.

ISO 42001 vs NIST AI RMF vs the EU AI Act: How They Map

A standard, a voluntary framework and a law — how they fit together.

ISO 42001 for Startups & SMEs: A Right-Sized Path to AI Governance

How smaller AI companies scope, cost and pursue certification proportionately.

ISO 42001 Certified Companies: Who's Certified & Why It Matters

Who is certifying, why the list is growing, and how to verify a certificate.

WhatsApp