Q&A

Frequently asked questions

The most frequently asked questions about ISO 42001, the AI Management System, the certification process and the EU AI Act. Can't find your question? The pages The Standard and Our Services cover the subject in greater depth.

The standard

What is ISO 42001?

ISO/IEC 42001:2023 is the first global, certifiable standard for an AI Management System (AIMS). The standard provides a methodology for managing the use and development of AI within your organisation in a structured, controllable, and auditable way, from risk analysis to policy and continuous improvement.

When was ISO 42001 published and by whom?

ISO/IEC 42001:2023 was published in December 2023 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It is the first certifiable AI standard in the world. In the Netherlands, the standard is available through NEN.

What is an AI Management System (AIMS)?

An AIMS is the totality of policies, processes, roles, and controls with which your organisation manages AI responsibly. It is anchored in the High-Level Structure (HLS) and the Plan-Do-Check-Act (PDCA) cycle, allowing it to seamlessly integrate with existing management systems such as ISO 27001 and ISO 9001.

What are the Annex A controls?

Annex A of ISO 42001 contains 38 controls, divided across 9 domains (such as AI policy, roles and responsibilities, data for AI systems, and information for interested parties). You select which controls apply on a risk-based basis and document this in a Statement of Applicability.

What is an AI System Impact Assessment (AISIA)?

The AI System Impact Assessment (AISIA) evaluates the potential consequences of an AI system for individuals, groups, and society, not just for the organisation itself. This assessment goes beyond a traditional risk analysis and is a distinguishing element of ISO 42001. Read more on The Standard.

Which organisations is ISO 42001 relevant for?

ISO 42001 is relevant for any organisation that develops, procures, or deploys AI and wants or needs to demonstrate governance to customers, partners, or regulators. The standard is scalable, from startups and SMEs to large enterprises, and applies in particular to organisations that fall under the EU AI Act or sector-specific requirements.

The certification process

What does the certification process look like?

We follow a proven process in four phases: (1) strategic intake and gap analysis, (2) risk and impact assessment and system design, (3) implementation of the AIMS, and (4) internal audit and guidance through to certification. The external certification then proceeds via a two-stage audit (Stage 1 and Stage 2). See the details on our Services page.

What is the difference between a Stage 1 and Stage 2 audit?

The external audit consists of two stages. In Stage 1, the auditor assesses the design and documentation of your AIMS (policy, risk methodology, Statement of Applicability); this typically takes 1 to 2 days and can often be conducted remotely. In Stage 2, the auditor tests the practical operation through interviews, observations, and records; this usually takes place on-site and typically lasts 2 to 5 days.

How long does ISO 42001 certification take?

That depends on your starting position. Starting from scratch, a process typically takes 9 to 18 months; with an existing ISO 27001 or ISO 9001 management system, often 6 to 9 months. The certification audit itself typically takes 2 to 5 days.

How long is the certificate valid?

An ISO 42001 certificate is valid for three years. During that period, an annual surveillance audit takes place to verify that the AIMS continues to comply, and in the third year a recertification follows for a new three-year cycle.

Which certification bodies are available?

Certification is performed by an accredited certification body. In the Netherlands, DNV and BSI have held RvA accreditation for ISO 42001 since January 2025; parties such as Kiwa, TÜV, and LRQA also offer certification. We are independent of the certification body and guide you through to the audit.

Can the audit be conducted remotely?

Partially. The Stage 1 audit (documentation and design) is often conducted remotely; the Stage 2 audit (testing of operations) typically takes place wholly or partially on-site, depending on the certification body and the scope.

We are already ISO 27001 certified. Do we need ISO 27001 first?

No, ISO 27001 is not a prerequisite for ISO 42001. However, if you are already ISO 27001 or ISO 9001 certified, that is an ideal starting point: ISO 42001 shares the same High-Level Structure, so we integrate the AIMS into your existing management system and avoid duplication of effort.

The EU AI Act

How does ISO 42001 relate to the EU AI Act?

The EU AI Act sets legal, risk-based requirements for AI systems. ISO 42001 is an important instrument to demonstrably meet those requirements: a certified AIMS provides the structured evidence (risk analyses, documentation, oversight) that regulators expect. See also our explanation on The Standard page.

Is ISO 42001 certification equivalent to EU AI Act compliance?

No. ISO 42001 is not (yet) a harmonised standard under the EU AI Act and therefore does not provide an automatic ‘presumption of conformity’. The standard covers an estimated 40 to 70% of the organisational requirements and forms a strong foundation, but specific legal obligations (such as risk classification, CE marking, registration in the EU database, and the technical documentation required by Annex IV) fall outside its scope and require additional steps.

Is ISO 42001 mandatory?

Formally, ISO 42001 is voluntary. In practice, it is increasingly expected through procurement processes, customers, and partners. For high-risk AI, the EU AI Act furthermore requires a quality management system (Article 17); an ISO 42001 AIMS can contribute significantly to meeting that requirement.

Practical & about us

How do I determine our role: provider, developer, or deployer?

Your role in relation to an AI system (provider, developer, or deployer) determines the scope and obligations of your AIMS. Establishing that role for each in-scope AI system is one of the first steps; we map this out together with you during the intake phase.

Why ISO42001.nl?

ISO42001.nl is an initiative of NeoSecurity, with more than 15 years of experience in ISO 27001, NEN 7510, and ISO 9001. We combine deep technical AI knowledge with the pragmatic approach of an experienced ISO consultant. Read more on About Us.

Last updated: July 2026. Mentioned timelines and accreditations are indicative and based on public sources (2025–2026).

Have a question about your situation?

Every organisation is different

Discover how ISO 42001 applies to your specific context and what the process looks like.