Compliance Guide
ISO/IEC 42001:2023 AI Management System
ISO/IEC 42001:2023 is the world's first international, certifiable standard for an Artificial Intelligence Management System (AIMS). Published by ISO and IEC, it provides a structured framework to responsibly develop, deploy, and manage AI systems - with a focus on accountability, transparency, traceability, and risk management for AI-specific risks like bias, data quality, explainability, and societal impact.

Key Components of ISO/IEC 42001
Built around the Plan-Do-Check-Act (PDCA) cycle, the standard requires organizations to establish, implement, maintain, and continually improve an AIMS. It follows the same High-Level Structure as ISO 27001, ISO 9001, and ISO 27701 - making integration straightforward.
Scope
Applies to any organization that develops, provides, or uses AI systems - regardless of size or industry.
Risk Assessment
Mandatory systematic identification, analysis, and treatment of AI-specific risks and opportunities.
Leadership & Commitment
Top management must demonstrate leadership, establish an AI policy, and define roles and objectives.
Annex A Controls
38 reference controls across 9 control objectives. Selected and implemented via a Statement of Applicability tailored to your AI risk profile.
Not sure if ISO 42001 applies to your AI use cases?
A short scoping call clarifies which AI systems fall in scope, which Annex A controls are relevant, and how 42001 maps to standards you already follow.
Why ISO/IEC 42001 Certification Matters
Competitive Advantage
Positions your organization as a leader in responsible AI and differentiates you from competitors.
Regulatory Alignment
Prepares you for emerging global regulations including the EU AI Act, demonstrating proactive compliance.
Trust & Reputation
Builds stakeholder confidence by proving ethical, transparent, and reliable AI practices.
Risk Reduction
Systematically mitigates AI-specific risks before they become costly issues.
Operational Efficiency
Integrates seamlessly with existing management systems, reducing duplication and audit fatigue.
Responsible AI
Embeds bias mitigation, explainability, and human oversight into every stage of the AI lifecycle.
ISO/IEC 42001 is not a one-time certification - it is an ongoing management system that requires continual improvement and annual surveillance audits.
Common Controls Tested in an ISO 42001 Audit
Certification bodies assess both the AIMS requirements (Clauses 4-10) and the selected Annex A controls. Key focus areas include:
- AI governance, leadership, and policy
- Risk management and impact assessments
- AI system lifecycle (design, development, deployment, monitoring)
- Data governance and quality for AI systems
- Transparency, explainability, and human oversight
- Third-party and supply chain management
- Incident management and continual improvement
The ISO/IEC 42001 Certification Process
Certification is performed by an accredited certification body and follows a two-stage audit process - identical to other ISO management system standards. Successful certification is valid for 3 years, with surveillance audits required annually.
Stage 1 Audit
Typically 1-2 days
Reviews your policies, procedures, AIMS documentation, and risk management framework.
Stage 2 Audit
Typically 3-9+ days
Tests the operational effectiveness and implementation of controls in practice. Duration depends on scope.
Maintenance
3-year cycle
Annual surveillance audits required, with a full recertification audit in Year 3.
Preparing for ISO/IEC 42001 in 2026: Step-by-Step Checklist
A practical, phased roadmap used by organizations implementing an AIMS.
Phase 1 - Planning & Scoping
- Inventory all AI systems and use cases in scope.
- Secure leadership commitment and designate an AI governance lead (often the CISO or Chief AI Officer).
- Define the AIMS scope and boundaries.
- Engage an accredited certification body early for guidance.
Phase 2 - Gap Assessment & Remediation
- Conduct a gap analysis against the standard and Annex A controls.
- Perform an AI risk assessment and impact analysis.
- Develop or update required policies, procedures, and controls.
- Implement technical and operational safeguards, including data quality processes and human oversight mechanisms.
Phase 3 - Evidence, Internal Audit & Certification
- Build a centralized evidence repository.
- Deliver AI-specific training and awareness programs.
- Conduct an internal audit and management review.
- Undergo the two-stage external audit and address any nonconformities.
Need an experienced AIMS implementer?
We deliver gap analyses, policy packs, evidence collection automation, and audit support so your team can focus on building AI - not chasing documentation.
Typical ISO/IEC 42001 Certification Timeline (2026 Averages)
Total time from kickoff to certificate typically ranges from 6-12 months depending on scope and maturity.
| Phase | Duration |
|---|---|
| Planning & Gap Analysis | 1-2 months |
| Policy & Control Implementation | 2-4 months |
| Operation & Internal Audit | 1-2 months |
| Certification Audits & Reporting | 4-8 weeks |
Pro Tip: If you already hold ISO 27001 certification, you can reuse approximately 50% of existing controls and documentation, shortening the timeline by 40-50%. Our compliance automation platform can reduce manual effort by up to 80% through automated evidence collection, risk tracking, and pre-built AIMS templates.
Required Policies and Procedures for ISO/IEC 42001
The standard requires documented information to support the AIMS. Policies must be living documents, reviewed annually, and tailored to your AI risk profile.
Core Governance & Leadership
- AI Policy (overall commitment and objectives).
- Information Security Policy (extended for AI).
- Risk Management & AI Impact Assessment Policy.
- Roles, Responsibilities, and Authorities for AIMS.
Operational & Technical
- AI System Lifecycle Management Policy.
- Data Governance & Quality Policy for AI Systems.
- Transparency, Explainability & Human Oversight Policy.
- Change Management & Configuration Policy for AI Systems.
- Incident Response & AI Incident Management Plan.
Third-Party & Continual Improvement
- Third-Party / Supplier AI Risk Management Policy.
- Monitoring, Measurement, Analysis & Evaluation Procedures.
- Nonconformity, Corrective Action & Continual Improvement Policy.
Our AI Transparency Guarantee
Artificial Intelligence (AI) Usage and Accountability
Brent Norris utilizes Artificial Intelligence (AI) and Large Language Models (LLMs) to accelerate engineering processes, structure compliance strategies, and draft technical blueprints. AI models do not possess professional licenses, certified security auditor credentials, or legal authority. Any architectural plans, code generation, or technical recommendations produced with AI assistance are treated as advanced drafts. Brent Norris assumes complete and final human accountability for all deployed systems. AI is not utilized as a replacement for certified security professionals or compliance officers. No client data or Protected Health Information (PHI) is ever entered into unauthorized or public AI models.
Annex A: 9 Control Objectives
Annex A provides 38 controls across 9 objectives. Organizations select those applicable to their AI systems via a Statement of Applicability. These controls must demonstrate both design and operational effectiveness during the Stage 2 audit.
| Control Objective | Focus Areas |
|---|---|
| Internal Organization | Roles, responsibilities, and AI governance. |
| Resources for AI Systems | Data, tools, and human resources. |
| AI System Impact Assessment | Risk and societal impact evaluations. |
| AI System Life Cycle | Design, development, deployment, and monitoring. |
| Data for AI Systems | Quality, traceability, and management. |
| Information for Interested Parties | Transparency and communication. |
| Responsible Use of AI Systems | Ethical use and human oversight. |
| Third-Party & Customer Relationships | Supply chain and external AI dependencies. |
| AI Incident Management | Response and continual improvement. |
Ready to operationalize Annex A?
We translate the 9 control objectives into a tailored Statement of Applicability and turn each control into automated, audit-ready evidence.
Frequently asked questions
Build Trustworthy AI - and Prove It
ISO/IEC 42001 turns "responsible AI" from a marketing claim into an audited, certifiable practice. We help you get there with practical, automated, and integrated implementations that respect the work you've already done in SOC 2, HIPAA, HITRUST, and ISO 27001.