ISO/IEC 42001:2023 — Artificial Intelligence Management

The first certifiable management system standard for artificial intelligence. It governs AI inventory, impact assessment, data provenance and human oversight.

International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC), through joint technical committee ISO/IEC JTC 1/SC 42. Certification is issued by accredited certification bodies.

What it is

ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence. Published in 2023 by ISO and IEC, it sets requirements for an Artificial Intelligence Management System — an AIMS — covering how an organisation develops, provides or uses AI responsibly.

It governs the risks conventional security standards do not reach. ISO 27001 manages information security risk very well, but it has nothing to say about whether a model is biased, whether anyone can account for the data it was trained on, or whether a human can meaningfully intervene in a decision it makes. Those are governance questions, and they are what 42001 addresses.

If you need a practical way to map AI risks before or alongside a certifiable management system, NIST AI RMF gives the team a governance framework to work from.

It follows the same Annex SL structure as other modern ISO standards — context, leadership, planning, support, operation, performance evaluation, improvement — so an organisation already running a management system is not starting from scratch. What changes is the subject matter.

Three requirements consistently catch organisations off guard:

  • The AI system inventory. You cannot govern what has never been enumerated, and most organisations are running more AI than they believe — embedded in SaaS products, vendor tools and individual team workflows.
  • AI system impact assessment. A structured evaluation of how a system affects individuals and society, not only how it affects the business.
  • Data provenance and human oversight. Demonstrating where training and input data came from, and showing a person can genuinely intervene in a consequential decision rather than being nominally "in the loop".

Who it's for

Certification is voluntary. The pressure to hold it is commercial, and it is arriving faster than most organisations expected.

Vendors selling AI-enabled products

Enterprise and government procurement now asks about AI governance by name. A paragraph in the acceptable use policy no longer clears that question, and the vendor without an answer loses time it cannot recover.

Organisations automating consequential decisions

Credit, hiring, triage, eligibility, pricing. Where a decision materially affects a person, the questions of who is accountable and how a human intervenes have regulators behind them, and the answers need to be documented rather than assumed.

Organisations deploying generative AI broadly

If staff are using AI tools across the business and nobody can produce a list of where it runs or what data reaches it, that is the gap. It is also the most common situation we encounter.

Suppliers to regulated entities

AI risk is being written into third-party risk assessments alongside security and privacy, particularly by APRA-regulated entities managing material service providers.

Choosing the right starting point

The right starting point follows the scale and consequence of AI use. An organisation beginning with a low-stakes pilot can establish its inventory, policy and governance foundations first. As AI becomes material to operations, affects consequential decisions or enters customer and procurement requirements, those foundations provide a direct path into a certifiable management system.

Why implement it

  • It answers the hardest question in AI procurement. "How do we know your AI is safe to buy?" is currently answered with assurances. A certificate answers it with independently assessed evidence.
  • It differentiates while adoption is low. Certification against 42001 remains uncommon. That follows the pattern of every management system standard: early certification is a competitive asset, late certification is a cost of entry. The window is open now.
  • It produces the inventory nobody has. Even setting certification aside, knowing exactly where AI runs in your business and what data reaches it is worth the exercise on its own.
  • It governs supplier AI risk. A vendor quietly changing the model behind an API is a real and under-managed exposure. The standard puts it inside supplier due diligence where it belongs.
  • It absorbs regulation rather than restarting for it. Obligations around automated decision-making and AI transparency are tightening in Australia and abroad. A management system already generating this evidence adapts; an organisation starting from nothing does not.

How implementation works

Five to eight months is typical. Where an ISO 27001 management system already exists, the shared Annex SL clauses are largely satisfied and the work concentrates on the AI-specific requirements.

1. Build the AI system inventory

Enumerate every AI system in use or development, including models embedded inside third-party products. This step routinely takes longer than planned and routinely surfaces systems the executive did not know were running. It is also the single most useful deliverable of the engagement, independent of certification.

2. Determine scope and role

The standard distinguishes between organisations that provide, produce and use AI systems, and obligations differ accordingly. Most organisations occupy more than one role at once.

3. Assess AI risk and run impact assessments

Assess risk to the organisation and, separately, impact on affected individuals and society. Impact assessments are performed for consequential systems and are the evidence an auditor will scrutinise most closely.

4. Build the controls

AI policy and acceptable use, the inventory as a maintained register, an impact assessment procedure, data provenance and quality controls, human oversight and escalation design, incident handling for AI failures, and AI-specific supplier due diligence.

5. Operate the system

Oversight has to be exercised, and it has to leave records. Expect an auditor to ask to see a specific decision where a human actually intervened. "A person reviews the output" is not evidence; a logged intervention is.

6. Internal audit and management review

Both mandatory before Stage 2, and the internal audit must be impartial.

7. Stage 1 and Stage 2 certification audit

Documentation and readiness first, then operating effectiveness against evidence.

How Soveriq helps

Soveriq builds the AI management system inside your existing environment, with AI risks entering the same register as security and privacy risks rather than sitting in a separate document. Where ISO 27001 is also in scope, AI suppliers pass through the existing due diligence pathway instead of a parallel one.

Engagements are scoped against published price floors.

On internal audit. Where Soveriq has built your management system, we do not then audit it and present that as an independent internal audit. What we provide is readiness validation — clearly labelled as such, and not a substitute for the impartial audit Clause 9.2 requires. Where an independent internal audit is needed after a Soveriq build, it is performed by someone independent of that build and the arrangement is disclosed in writing. The same applies to any retainer including an audit component.

Clear roles through certification. Soveriq prepares the AI management system, evidence and organisation for certification. The certificate and final certification decision come from an independent certification body, keeping implementation and certification roles clear. Soveriq supports your team through Stage 1 and Stage 2 without pre-empting that independent decision.

What the engagement looks like

ISO 42001 work follows the same five-module structure as every other Soveriq engagement.

  • Module 01 — Gap analysis. Including the AI system inventory, which is usually the most revealing part of the whole engagement.
  • Module 02 — Build. AI policy, inventory as a live register, impact assessment method, provenance and oversight controls, AI supplier due diligence.
  • Module 03 — Internal audit. The mandatory Clause 9.2 audit, subject to the impartiality position below.
  • Module 04 — Audit representation through Stage 1 and Stage 2.
  • Module 05 — Continuous compliance. Particularly relevant here, because AI estates change faster than the annual audit cycle.

Price floors for each module are published on the pricing page. Certification body fees are separate and paid directly to that body.

Where ISO 27001 is already in place or being built at the same time, the Annex SL clauses are shared and the AI work is a smaller increment rather than a second programme.

Common questions

Do we need ISO 27001 before ISO 42001?

No. ISO 42001 can be certified on its own. In practice most organisations building AI products also need 27001 for the same customers, and building both together is materially cheaper than building them separately, because they share Clauses 4 to 10.

We only use AI tools, we don't build models. Does it still apply?

Yes, and this is widely misunderstood. The standard covers organisations that use AI systems, not only those that develop them. If AI influences decisions that affect people, the governance obligations attach regardless of who trained the model.

Is this the same as the EU AI Act?

No. The EU AI Act is legislation with legal force in the European Union. ISO 42001 is a voluntary certifiable standard. They overlap substantially in what they ask for, so a certified AI management system is a good starting position for EU obligations, but certification is not legal compliance and should not be presented as such.

How do we handle AI embedded in vendor products?

It goes in the inventory like anything else, and the governance sits in supplier due diligence — what the vendor's model does, what data reaches it, and whether you are told when it changes. Most organisations find this is where the majority of their AI exposure actually lives.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope