What ISO/IEC 42001 actually is — an AI management system in plain language
Most people meet ISO 42001 as a wall of clause numbers and assume it's a checklist. It isn't. It's a management system — a way of running AI so that good governance keeps happening after the launch-day enthusiasm fades. Once you see it that way, the rest of the standard falls into place.
A management system, not a one-off audit
Published in December 2023, ISO/IEC 42001 is the first international standard for an AI management system (AIMS). If you've come across ISO 27001 for information security, the shape is familiar: it doesn't tell you which AI you're allowed to build, it tells you how to govern whatever you build — set a policy, assess risk, assign ownership, keep evidence, review, improve. The point is repeatability. A certificate says an accredited body checked that this loop is actually running, not that someone wrote a nice document once.
The two halves: the clauses and Annex A
The standard has two parts that do different jobs. Clauses 4–10 are the management-system backbone — context and scope (4), leadership and policy (5), planning and risk (6), support and competence (7), operation (8), performance evaluation (9) and improvement (10). These are the verbs: what your organisation must actually do. Then Annex A is a catalogue of controls — the specific safeguards, grouped into areas covering things like AI policy, internal organisation, resources and data, the AI system life cycle, and information for interested parties. You choose which apply, justify the choice, and implement them.
A useful mental model: the clauses are the engine, Annex A is the parts list. Auditors read the clauses to see whether the system runs, and use Annex A to check whether the right safeguards are bolted on.
Why "risk-based" changes everything
ISO 42001 is deliberately risk-based, which is the feature teams most often miss. It never says "every company must do X." It says: understand how your AI could affect people and your organisation, then apply controls proportionate to that risk. A minimal-risk internal tool and a hiring model that ranks candidates are held to very different bars — correctly. This is liberating and demanding at once: liberating because you don't gold-plate low-risk systems, demanding because you have to be able to defend where you drew each line.
What it is not
Three honest clarifications. First, ISO 42001 is voluntary — it is a standard, not a law. The EU AI Act is the law; 42001 is the framework that helps you meet it and prove good practice to buyers. Second, being "audit-ready" is not the same as being certified: readiness is having the documented, evidenced system; certification is an accredited body confirming it through an independent audit. Third, it will not by itself make you AI Act compliant — but a well-run AIMS produces most of the evidence the Act asks for, which is why the two are best built together.
Educational orientation, not legal advice. ISO/IEC 42001 references current as of September 2026. Certification is performed by accredited bodies.