ISO 42001Foundations

What ISO/IEC 42001 actually is — an AI management system in plain language

Most people meet ISO 42001 as a wall of clause numbers and assume it's a checklist. It isn't. It's a management system — a way of running AI so that good governance keeps happening after the launch-day enthusiasm fades. Once you see it that way, the rest of the standard falls into place.

A management system, not a one-off audit

Published in December 2023, ISO/IEC 42001 is the first international standard for an AI management system (AIMS). If you've come across ISO 27001 for information security, the shape is familiar: it doesn't tell you which AI you're allowed to build, it tells you how to govern whatever you build — set a policy, assess risk, assign ownership, keep evidence, review, improve. The point is repeatability. A certificate says an accredited body checked that this loop is actually running, not that someone wrote a nice document once.

The two halves: the clauses and Annex A

The standard has two parts that do different jobs. Clauses 4–10 are the management-system backbone — context and scope (4), leadership and policy (5), planning and risk (6), support and competence (7), operation (8), performance evaluation (9) and improvement (10). These are the verbs: what your organisation must actually do. Then Annex A is a catalogue of controls — the specific safeguards, grouped into areas covering things like AI policy, internal organisation, resources and data, the AI system life cycle, and information for interested parties. You choose which apply, justify the choice, and implement them.

A useful mental model: the clauses are the engine, Annex A is the parts list. Auditors read the clauses to see whether the system runs, and use Annex A to check whether the right safeguards are bolted on.

Why "risk-based" changes everything

ISO 42001 is deliberately risk-based, which is the feature teams most often miss. It never says "every company must do X." It says: understand how your AI could affect people and your organisation, then apply controls proportionate to that risk. A minimal-risk internal tool and a hiring model that ranks candidates are held to very different bars — correctly. This is liberating and demanding at once: liberating because you don't gold-plate low-risk systems, demanding because you have to be able to defend where you drew each line.

What it is not

Three honest clarifications. First, ISO 42001 is voluntary — it is a standard, not a law. The EU AI Act is the law; 42001 is the framework that helps you meet it and prove good practice to buyers. Second, being "audit-ready" is not the same as being certified: readiness is having the documented, evidenced system; certification is an accredited body confirming it through an independent audit. Third, it will not by itself make you AI Act compliant — but a well-run AIMS produces most of the evidence the Act asks for, which is why the two are best built together.

The practical takeaway. Don't start by collecting control numbers. Start by writing a two-page policy and an honest inventory of where you use AI. The management system grows from those two things — everything in Annex A hangs off knowing your scope and your risk.
BJ

Former IBM and Deloitte strategy consultant, now advising mid-market companies on AI governance. Founder of Govern42.

Questions about your ISO 42001 or EU AI Act programme? Email me directly: bigjay11@gmail.com

Educational orientation, not legal advice. ISO/IEC 42001 references current as of September 2026. Certification is performed by accredited bodies.