ISO/IEC 42001: The Complete Guide to the AI Management System Standard

What ISO 42001 is, how the standard is built, and how organizations get certified — the definitive starting point, with links to every part of the framework.

What ISO 42001 is, how the standard is built, and how organizations get certified — the definitive starting point, with links to every part of the framework.
ISO/IEC 42001:2023 is the world's first certifiable management-system standard for artificial intelligence. Published on 18 December 2023 by ISO and IEC, it specifies how an organization establishes, implements, maintains, and continually improves an AI management system (AIMS) — a structured way to govern the AI it develops, provides, or uses. Any organization can be independently audited and certified against it, in the same way ISO/IEC 27001 certifies information security.
This guide is the hub of our ISO 42001 cluster. It explains the standard end to end and links to a dedicated deep-dive on each part — from what the standard is, through its clauses and Annex A controls, to certification, cost, training, and what it means for Indian businesses.
ISO 42001 is the international standard that defines the requirements for an AI management system: a governance framework built on the Plan-Do-Check-Act cycle that lets an organization manage AI-specific risks — bias, opacity, safety, security, and misuse — with the same rigor it already applies to quality or information security. It was developed by ISO/IEC JTC 1/SC 42, the joint subcommittee responsible for AI standards.
AI governance has moved from voluntary good practice to a procurement and regulatory expectation. Enterprise buyers now ask vendors how their AI is governed; regulators from the EU to India expect demonstrable, not aspirational, controls. ISO 42001 gives an organization one certifiable framework that answers the question every board is now asking — “how do we know our AI systems are under control?” — with independent evidence rather than a policy statement. We explore that business case in AI governance as competitive advantage and the ROI of ISO/IEC 42001.
ISO 42001 follows ISO's Harmonized Structure (the shared skeleton also used by ISO 27001 and ISO 9001), which is why it integrates cleanly with management systems you may already run. The auditable requirements sit in Clauses 4 to 10, supported by Annex A controls.
| Clause | What it requires |
|---|---|
| 4 — Context | Determine internal/external issues, interested parties, and the scope of the AIMS; define your role (developer, provider, or user of AI). |
| 5 — Leadership | Top-management commitment, an AI policy, and clearly assigned roles and responsibilities. |
| 6 — Planning | AI risk assessment and treatment, AI system impact assessment, and measurable AI objectives. |
| 7 — Support | Resources, competence, awareness, communication, and documented information. |
| 8 — Operation | Put the risk and impact assessments into practice across the AI lifecycle. |
| 9 — Performance evaluation | Monitoring, measurement, internal audit, and management review. |
| 10 — Improvement | Continual improvement and corrective action for nonconformities. |
Our requirements and clauses guide walks through each clause in detail.
Annex A of ISO 42001 sets out 38 controls organized under 9 control objectives (categories A.2 through A.10), covering AI policies, internal organization, resources, impact assessment, the AI system lifecycle, data, information for interested parties, use of AI systems, and third-party relationships. Annex B gives implementation guidance, Annex C catalogues AI risk sources, and Annex D covers sector use. See the full Annex A controls breakdown.
An organization is certified through a two-stage audit by an accredited certification body: Stage 1 reviews whether the AIMS is designed and documented, and Stage 2 verifies it is genuinely operating. Certificates run on a three-year cycle with annual surveillance audits and a recertification audit at the end. ISO/IEC 42006:2025 sets the competence requirements for the certification bodies themselves. Full detail is in our certification process guide and what auditors actually look for.
Organizations get certified; individuals get trained. A company earns an ISO 42001 certificate for its management system. People earn professional credentials — Foundation, Lead Implementer, or Lead Auditor — that qualify them to build or audit one. Don't confuse the two; see ISO 42001 training and certification for individuals.
The standard explained in plain language.
Part 2The Stage 1 / Stage 2 process and how to get certified.
Part 3What certification costs in India and globally.
Part 4Foundation, Lead Implementer and Lead Auditor credentials.
Part 5The clauses and 38 Annex A controls, explained.
Part 6A step-by-step readiness checklist.
Part 7The certification process, step by step.
Part 8How the two standards differ and integrate.
Part 9Mapping to global AI regulation.
Part 10DPDP Act, MeitY guidelines, RBI FREE-AI.
ISO 42001 does not stand alone. ISO/IEC 42005:2025 (published 28 May 2025) gives the methodology for the AI system impact assessment that Annex A requires. ISO/IEC 23894:2023 provides AI risk-management guidance, and ISO/IEC 22989:2022 defines the AI terminology the whole family uses. ISO/IEC 42006:2025 governs the bodies that certify you.
Any organization that builds, sells, or relies on AI is in scope, but adoption is fastest where AI touches customers, regulated decisions, or enterprise procurement: cloud and AI providers, B2B SaaS, healthcare, financial services, HR and recruiting tech, legal tech, and government suppliers. Amazon Web Services was among the first to achieve accredited certification and has publicly reported passing its first surveillance audit — a signal that ISO 42001 is following ISO 27001's path from differentiator to baseline expectation.
ISO/IEC 42001:2023 is the international standard specifying requirements for an AI management system (AIMS). Published in December 2023, it is the first certifiable AI standard, letting organizations be independently audited on how they govern the AI they develop, provide, or use.
No. ISO 42001 is a voluntary standard, but it is increasingly required in enterprise procurement and used as evidence of readiness for regulations such as the EU AI Act and India's AI governance guidelines.
Annex A of ISO 42001 contains 38 controls grouped under 9 control objectives (categories A.2 to A.10), supported by implementation guidance in Annex B.
For an organization with an existing management system, a realistic path runs about 6 months from gap assessment to the Stage 2 certification audit; organizations starting from scratch should budget longer. Certificates then run on a 3-year cycle with annual surveillance audits.
ISO 42001 is the certifiable management-system standard; ISO 42005:2025 is guidance on how to conduct an AI system impact assessment, which is one of the activities ISO 42001's Annex A requires.
Start here — what ISO 42001 is, what it requires, costs, and how to get certified.
The world's first certifiable AI management system standard — requirements, Annex A controls, certification, cost, training and India relevance.
You're here
The standard explained in plain language.
The clauses and Annex A controls ISO 42001 asks for.
The 38 AI controls across 9 objectives (A.2–A.10), and how you select which apply.
What ISO 42001 certification costs, including in India.
A step-by-step readiness checklist for certification.
The mandatory policies, procedures and records — and what a good ISO 42001 toolkit includes.
How the AI and information-security standards differ.
The certification process, step by step.
Courses and credentials for individuals.
The role that builds and runs the AIMS — course, exam and how it differs from Lead Auditor.
DPDP Act, MeitY guidelines and RBI FREE-AI, mapped to one AIMS.
A standard, a voluntary framework and a law — how they fit together.
How smaller AI companies scope, cost and pursue certification proportionately.
Who is certifying, why the list is growing, and how to verify a certificate.