AI . Jul 2026

ISO/IEC 42001: The AI Standard Your Business Needs

Share this Article

twitterlogofacebooklogolinkedinlogo

A few years ago, when a client asked about your AI systems, a short paragraph in a proposal was usually enough. That has changed. Procurement teams now send detailed questionnaires about how AI models are trained, who reviews their output, and what happens when they get things wrong. Some have started asking a more pointed question: are you certified to ISO/IEC 42001?


If you haven't come across it yet, here is what the standard is, why it exists, and what it takes to get certified.


So what exactly is ISO/IEC 42001?

ISO/IEC 42001 was published in December 2023 and is the first international management system standard written specifically for artificial intelligence. It sets out how an organisation should establish and run an Artificial Intelligence Management System, or AIMS.


Anyone who has worked with ISO 9001 or ISO 27001 will recognise the shape of it. The clauses cover context, leadership, planning, support, operation, performance evaluation and improvement, and the whole thing runs on the familiar Plan-Do-Check-Act cycle. What's new is the subject matter. Instead of quality or information security in general, the standard deals with the particular problems that come with building or using AI.


It applies to any organisation, in any sector, of any size. You don't have to be an AI company. A bank using a credit scoring model, a hospital using a diagnostic tool, or a retailer running a recommendation engine all fall within scope.

Doesn't ISO 27001 already cover this?

It's a fair question, and the honest answer is no.


ISO 27001 protects information. It makes sure data is kept confidential, accurate and available. What it doesn't do is tell you whether your hiring model is quietly rejecting candidates from a particular background, or whether your chatbot is inventing answers with complete confidence, or who is responsible when an automated decision harms someone. These are AI problems, not information security problems, and they need their own controls.


The good news for ISO 27001-certified organisations is that the two standards share a lot of structural DNA. Your document control, internal audit and management review processes carry over, and industry estimates suggest that head start can cut the implementation effort substantially.

What the standard asks of you

Stripped of the formal language, ISO 42001 asks a handful of reasonable questions:


Does leadership actually own this? The standard requires a formal AI policy and named responsibilities. AI governance can't live in a slide deck that nobody revisits.


Do you know what AI you have? Certification requires a proper inventory of every AI system you build or use, with its purpose, data sources and current lifecycle stage recorded. Most organisations are surprised by what turns up once they start looking.


Have you thought about who could be affected? This is where 42001 goes further than most standards. AI System Impact Assessments look beyond business risk to the effect a system could have on individuals and society. For a loan approval model, that means asking who gets refused and why, not just whether the server stays up.


Are the controls in place across the lifecycle? Annex A of the standard lists controls that run from data acquisition and model development through deployment, monitoring and eventual retirement.


Do you keep improving? Internal audits, management reviews and corrective actions apply here just as they do in every other ISO management system. Given how quickly AI changes, this part matters more than usual.


One clarification worth making early, because it prevents awkward conversations later: certification does not mean an auditor has verified that your model is accurate or unbiased. It means an independent body has verified that your organisation governs its AI through a sound, documented, repeatable process. That distinction is exactly what buyers and regulators are looking for.

The regulatory backdrop

The EU AI Act came into force in August 2024 and becomes fully applicable in August 2026, with rules for high-risk systems already being enforced. Other countries are drafting their own versions, and companies operating across borders are starting to feel the weight of overlapping requirements.


ISO 42001 doesn't replace any of these laws. What it does is give you one coherent framework to build on, so you're not reinventing your governance for every jurisdiction. Organisations that put the framework in place now will have a much easier time than those who wait for a regulator or a lost deal to force the issue.


The commercial pressure is arguably moving faster than the legal one. Microsoft and other major vendors have already been certified, and large enterprises have begun writing ISO 42001 into their vendor requirements. It's likely to trickle down the supply chain the same way ISO 27001 did a decade ago.

Getting started

There's no secret to the implementation path. It looks like this:

  1. Run a gap assessment against the standard, taking credit for anything your existing certifications already cover.
  2. Build the AI inventory.
  3. Carry out impact assessments for your significant systems.
  4. Write the policy, assign ownership and put the lifecycle controls in place.
  5. Operate the system for a period and audit it internally.
  6. Bring in an accredited certification body for the formal audit.

For a mid-sized organisation with an existing management system, this is typically a matter of months rather than years. Without one, budget for longer and start with the basics.

A closing thought

Every wave of technology eventually produces a standard that separates organisations that take it seriously from those that don't. For information security it was ISO 27001. For AI, ISO/IEC 42001 is shaping up to play that role. Getting certified won't make your AI perfect, but it will mean you can answer hard questions about it honestly, with evidence, at a time when more and more people are asking them.


And even if certification isn't on your roadmap yet, the principles behind the standard — knowing what AI you run, assessing who it affects, keeping a human in the loop — are simply good engineering. The organisations that build AI this way from the start will find certification, whenever it comes, far less painful.

Work with Pirai Infotech

At Pirai Infotech, responsible AI isn't an afterthought — it's how we build. From AI-powered solutions like Contract Genie and Pirai Invoice AI to our quality engineering and application services, we design systems with the transparency, oversight and documentation that frameworks like ISO/IEC 42001 expect. If you're planning your next AI initiative and want it built right the first time, talk to our team.

Picture of the author

Recent Articles:

Accelerate Your Success
With Us

Pirai Enquiry Form
Phone

Subject