
ISO/IEC 42001 is the international standard for an AI management system, the AI equivalent of ISO 27001. Published in December 2023, it is certifiable: an accredited auditor can attest that your organisation governs its AI responsibly, using Annex A controls that cover the AI lifecycle, impact assessments and supplier management.
What does ISO 42001 require?
Two things: a management system built on the standard's clauses, and a set of controls selected from Annex A, which contains 38 of them. The clauses follow the same Harmonised Structure as every modern ISO management standard, so the skeleton will look familiar to anyone who has been near ISO 27001.
A management system, in plain English, is a documented way of running something: who is responsible, what gets checked, how often, and what happens when a check fails. ISO 42001 points that machinery at AI. It does not tell you which models to use or avoid; it tells you to know what AI you have and what it could do to the people on the receiving end, then be ready to prove both on demand.
| Clause | What it asks for |
|---|---|
| 4 · Context | Work out what role AI plays in your organisation and who is affected by it |
| 5 · Leadership | An AI policy owned at the top, not delegated to a working group |
| 6 · Planning | Risk assessments and AI impact assessments, with measurable objectives |
| 7 · Support | People, competence and documentation to keep the system running |
| 8 · Operation | The controls applied in practice across development and use |
| 9 · Performance evaluation | Monitoring, internal audit and management review |
| 10 · Improvement | Fixing nonconformities; improving the system over time |
| Annex A | 38 controls covering the AI lifecycle, impact assessments and supplier management |
Annex A is where the AI substance lives. The impact assessment controls in particular ask you to look outward at the people affected by an AI system, rather than only inward at organisational risk. For teams arriving from security standards, that outward look is the biggest cultural adjustment the standard demands. The supplier management controls matter more than they look, too, because most organisations' AI risk arrives through suppliers rather than through anything built in-house.
Who should get certified first?
AI vendors selling into enterprise and government. If your buyers have procurement teams and security questionnaires, a certificate answers in one document the questions you are currently answering forty times a year by hand.
The logic is commercial rather than regulatory. Nothing forces certification on anyone. But an enterprise buyer weighing two AI vendors, one holding an accredited certificate and one offering a policy PDF, has an easy tiebreaker. Certification also front-loads the pain usefully: you build the management system once, then reuse the same evidence for every deal that follows. Timing follows the sales cycle, not the calendar year: if the certificate must exist when a tender closes, the management system has to exist well before that, because auditors want to see a system operating rather than one founded last month.
If you are not selling AI, the calculus changes. An organisation that only consumes AI can usually get what it needs from a lighter internal programme, and save certification for the day a regulator or a flagship customer makes it worth the fees.
What does certification cost and how long does it take?
It runs on the same three-year cycle as ISO 27001: an initial certification audit, surveillance audits in each of the following two years, then recertification. Build time before that first audit depends almost entirely on how much management-system machinery you already have in place.
Hard numbers vary by certification body, headcount and how many AI systems sit in scope, so a quoted range means little until your scope is fixed.
The cost that surprises people is internal time rather than auditor fees. Someone has to write the impact assessments, chase the supplier evidence and sit in the management reviews, and that someone usually has another job. Budget for the calendar as much as for the invoice. Scope is the lever you control: certification attaches to a defined scope, and a first certificate covering one product line costs less and teaches more than an everything-at-once attempt.
How does it relate to ISO 27001?
They share the Harmonised Structure, so the clause skeleton is identical. An existing ISMS is a head start, and a large one. Document control, internal audit, management review, corrective action: the machinery you built for 27001 extends to cover the AI management system instead of being built twice.
In practice many organisations run the two as one integrated system, with a single document set and one audit calendar. The AI-specific work that remains is real (the impact assessments and the Annex A controls have no 27001 equivalent), but it lands on rails that already exist. Starting 42001 from a functioning ISMS and starting it from nothing are different projects with different budgets. If 27001 is on your roadmap anyway, build whichever comes first as a system you intend to live in, and the second becomes an extension rather than a project.
One warning. An ISMS that only ever existed to pass its own audit will transfer its bad habits to the AIMS. Paper systems replicate fast.
Zavior maps your existing ISO 27001 controls against the 42001 requirements, so the gap list is real before an auditor ever quotes you.
Frequently asked questions
Is ISO 42001 mandatory anywhere?
It is a voluntary standard; certifying is a commercial decision, not a legal duty. Contracts are the practical exception. Enterprise and government buyers can write the standard into procurement requirements, and once it sits in a signed contract it is mandatory for you regardless of what any statute says.
Can you self-attest?
You can implement the standard and declare conformity yourself, and for internal discipline that has genuine value. It is not certification. "Certified" means an accredited certification body audited you, which is the entire reason the certificate carries weight with buyers who will never inspect your system personally.
Is it feasible for an SME?
Yes. Management system standards scale with scope, and a small organisation with a handful of AI systems has a genuinely smaller system to build and audit. An existing ISO 27001 ISMS shortens the path further, because the shared Harmonised Structure means half the machinery already exists.
Zavior · AI Governance
An AI management system is only worth certifying if it runs after the auditor leaves. Zavior finds the AI already in use across the business, puts the usage rules, training and monitoring around it that Annex A asks for, and keeps the impact assessments and supplier evidence current, so the system an auditor reviews in Singapore or Australia is the one your teams actually use, not a binder assembled the month before.
Book a free 30-minute business assessment →This is general information, not legal advice.