The Standard

From abstract principle to demonstrable governance

The exponential adoption of Artificial Intelligence is no longer a technological trend, but a fundamental shift in the economic paradigm. ISO 42001 makes that shift governable.

ISO/IEC 42001:2023

What is ISO 42001? The first certifiable standard for an AI management system

The abstract discussion about "responsible AI" is over. The market, legislators and society demand demonstrable, auditable evidence. ISO/IEC 42001:2023 is the definitive answer: the first global, certifiable standard that provides a methodology for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System (AIMS).

The standard is anchored in the internationally recognised High-Level Structure (HLS) and follows the proven Plan-Do-Check-Act (PDCA) cycle, enabling seamless integration with ISO 27001 and ISO 9001.

ISO/IEC 42001EU AI ActISO/IEC 27001ISO 9001

Seamless integration

The AIMS integrates within existing governance frameworks such as ISO 27001 and ISO 9001. This maximises the value of prior compliance investments and prevents isolated "compliance silos".

Continuous maturity

The PDCA cycle transforms AI governance into a living process of continuous improvement, remaining agile in the face of new technology and regulation such as the EU AI Act.

Market access & trust

A certificate becomes a license to operate and a competitive differentiator in tenders and towards regulators.

In essence, ISO 42001 translates the complex ethical and technical risks of AI into a structured, manageable and auditable business process, so you can innovate with confidence, accelerate market access and create lasting value for stakeholders.

EU AI Act

How does ISO 42001 relate to the EU AI Act?

The EU AI Act is the world's first comprehensive AI legislation. It classifies AI systems based on risk and imposes strict requirements on high-risk systems. ISO 42001 serves as a key instrument to demonstrate compliance with these requirements.

Unacceptable risk

Prohibited applications, such as government social scoring and manipulative systems that cause harm.

High risk

Strict obligations: risk management, data quality, technical documentation, logging and human oversight.

Limited risk

Transparency obligations, such as making chatbots identifiable and labelling AI-generated content.

Minimal risk

No specific obligations. Voluntary codes of conduct are encouraged for responsible use.

A certified AIMS under ISO 42001 provides the structured evidence (risk analyses, policies, documentation and oversight) that regulators expect under the EU AI Act. This way, you turn a legal obligation into a demonstrable competitive advantage.

ISO/IEC 42001AI Management SystemEU AI ActRisk-based requirementsISO/IEC 27001Information securityISO 9001Quality management

Have questions? See our frequently asked questions.

Turn strategy into action

From standard to demonstrable certification

Discover how our structured implementation process guides your organisation towards successful certification.