ISO 42001

ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system

ISO/IEC 42001:2023 specifies requirements, with guidance, for establishing, implementing, maintaining, and continually improving an AI management system (AIMS) within an organization. It is the first international management-system standard written specifically for AI and is designed for any organization, of any size or sector, that provides or uses AI-based products or services. It addresses AI-specific concerns such as algorithmic bias, transparency, and lifecycle impacts rather than treating AI as generic IT.

Quick answer

ISO/IEC 42001:2023 is the first international management-system standard written specifically for AI, published December 2023. It requires an AI management system covering governance, risk assessment, and lifecycle controls, and is independently certifiable through accredited third-party auditors, unlike NIST's voluntary, non-certifiable framework.

Issuing body
International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC), developed by joint technical committee ISO/IEC JTC 1/SC 42
Official reference
www.iso.org/standard/42001

What it covers

  • Requires an AI management system (AIMS) structured across clauses 4 through 10: Context of the organization, Leadership, Planning, Support, Operation, Performance evaluation, and Improvement
  • Follows the Plan-Do-Check-Act (PDCA) continual-improvement cycle common to other ISO management-system standards such as ISO 9001 and ISO/IEC 27001
  • Annex A sets out AI-specific controls across control objectives including AI policy, internal organization, resources, AI system impact assessment, AI system life cycle, data for AI systems, and use of AI systems
  • Requires organizations to document which Annex A controls apply in a Statement of Applicability, selected in proportion to identified AI risks
  • Requires an AI system impact assessment addressing risks to individuals, groups, and society
  • Independently certifiable: accredited third-party certification bodies, not ISO itself, audit and certify conformance

Adoption status

Published December 2023 by ISO/IEC; adoption is voluntary and market-driven, with certification available through accredited certification bodies rather than ISO directly. It applies internationally with no single jurisdictional mandate, and certification against it is informational only, it does not by itself guarantee compliance with any specific law or regulation.

Reference only. This page explains what ISO 42001 covers; it is not a claim that Model Governance Index or any listed vendor satisfies it. Verify alignment directly against the issuing body's own current text before relying on it.

Sources. source 1 · source 2 · source 3. Data as of 2026-07-13. See methodology.

Related guides