What is ISO 42001?
ISO/IEC 42001:2023 is the international standard for an AI management system (AIMS): the policy, roles, risk and impact assessments, controls, monitoring and improvement an organisation uses to develop, provide or use AI responsibly. ISO and IEC published the first edition in December 2023, and organisations can be certified against it by accredited certification bodies.
Key facts
| Full reference | ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system |
|---|---|
| Published | December 2023, edition 1, 51 pages |
| Written by | ISO/IEC JTC 1/SC 42, the joint ISO and IEC committee on artificial intelligence |
| Certifiable | Yes, by accredited certification bodies (see ISO 42001 certification) |
| Rules for certifiers | ISO/IEC 42006:2025, published July 2025 |
| Where to get it | iso.org/standard/42001 or your national standards body |
How ISO/IEC 42001 is structured
Clauses 1 to 3 cover scope, references and terms. Clauses 4 to 10 are the requirements, and every one of them applies. Annex A lists 38 reference controls you select through risk treatment. Annex B gives guidance on implementing those controls, Annex C lists possible AI objectives and risk sources, and Annex D covers using the management system across domains and sectors.
| Part | What it covers (our summary) | Items in our gap assessment |
|---|---|---|
| Clause 4 | Context of the organisation: Your context and AI roles, interested parties, the scope of the system, and the system itself | 4 |
| Clause 5 | Leadership: Top management commitment, the AI policy, and roles and responsibilities | 3 |
| Clause 6 | Planning: Risks and opportunities, AI risk assessment and treatment, the Statement of Applicability, AI system impact assessment, AI objectives and planned changes | 6 |
| Clause 7 | Support: Resources, competence, awareness, communication and documented information | 5 |
| Clause 8 | Operation: Running the processes, and carrying out risk assessments, risk treatment and impact assessments | 4 |
| Clause 9 | Performance evaluation: Monitoring and measurement, internal audit and management review | 3 |
| Clause 10 | Improvement: Continual improvement, nonconformity and corrective action | 2 |
| A.2 | Policies related to AI | 3 |
| A.3 | Internal organisation | 2 |
| A.4 | Resources for AI systems | 5 |
| A.5 | Assessing impacts of AI systems | 4 |
| A.6 | AI system life cycle | 9 |
| A.7 | Data for AI systems | 5 |
| A.8 | Information for interested parties | 4 |
| A.9 | Use of AI systems | 3 |
| A.10 | Third-party and customer relationships | 3 |
| Total | 65 | |
Clause numbers and Annex A area names follow ISO/IEC 42001:2023; descriptions are our own.
Who it is for
Any organisation, of any size or sector, that develops, provides or uses AI systems. The standard asks you to state which of those roles you play for each AI system (clause 4.1), because a company that builds models faces different risks from one that buys an AI feature inside its CRM. The controls you select follow from that.
ISO 42001 and other AI frameworks
- ISO/IEC 27001: the same management system structure, so the two are often run together, with shared document control, internal audit and management review.
- EU AI Act: Regulation (EU) 2024/1689 is binding law with obligations that depend on the AI system's risk class and your role. Our German page maps its high-risk obligations to the clauses and controls.
- NIST AI RMF: the NIST AI Risk Management Framework is a voluntary US framework organised around govern, map, measure and manage. It isn't certifiable; ISO/IEC 42001 is.
Getting the ISO 42001 PDF
The official text is copyrighted and sold by ISO and national standards bodies as a PDF or print copy. ISO's page offers a preview of the opening pages. Copies offered free elsewhere are usually unauthorised, and they may be drafts rather than the published standard. Everything on this site describes the requirements in our own words, so you can start the work before you buy.
Where to start
- Score your gaps against every clause requirement and Annex A control.
- Work through the ISO 42001 checklist of documents, requirements and controls.
- Read the plain-language Annex A controls.
- Plan the audits and budget with ISO 42001 certification.
Questions
What is ISO/IEC 42001:2023?
The international standard for an AI management system, published by ISO and IEC in December 2023. It sets requirements for how an organisation governs the AI systems it develops, provides or uses, and organisations can be certified against it.
Is there a free ISO 42001 PDF?
No legitimate one. The standard is copyrighted and sold by ISO and national standards bodies; ISO's page lets you preview the opening pages. Free summaries, checklists and templates (like the ones on this site) describe it in their own words.
Who needs ISO 42001?
No one is required to have it by law. It suits any organisation that develops, provides or uses AI systems and wants a structured way to manage the risks, often because customers ask for evidence of responsible AI.
How is ISO 42001 different from ISO 27001?
Both are management system standards with the same clause 4 to 10 structure, so they combine well. ISO/IEC 27001 is about information security; ISO/IEC 42001 is about the responsible development, provision and use of AI, including impact assessments for people and society.
How does ISO 42001 relate to the EU AI Act and the NIST AI RMF?
The EU AI Act is law in the EU; the NIST AI RMF is a voluntary US framework; ISO/IEC 42001 is a certifiable international standard. A working AI management system supplies much of the risk, documentation and oversight evidence the other two expect, but it doesn't by itself show that you meet the AI Act.
Sources
- ISO/IEC 42001:2023 (ISO): edition 1, published December 2023, 51 pages, ISO/IEC JTC 1/SC 42.
- ISO/IEC 42006:2025 (ISO): edition 1, published July 2025, 31 pages; requirements for bodies that audit and certify AI management systems, building on ISO/IEC 17021-1.
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex: Official Journal of the EU.
- NIST AI Risk Management Framework: National Institute of Standards and Technology.
- Each source was opened and checked on 1 October 2026.