ISO 42001
FRAMEWORK · ISO/IEC 42001

ISO/IEC 42001: the AI management system, as a programme

ISO/IEC 42001 is the international standard for an AI management system — the policies, roles, risk method, impact assessments and reviews an organisation runs around the AI it develops or uses. It is voluntary: nobody is required to adopt it, and it is not a harmonised standard under the EU AI Act. Organisations adopt it because customers, boards and procurement ask for a certifiable way to show AI is governed, and because it shares its structure with ISO/IEC 27001.

Last reviewed · against the consolidated text and Commission guidance

65
clauses and controls
27
programme steps, each producing a record
6
gate-locked phases
14
records shared with the sibling programme
Legal basis
ISO/IEC 42001:2023
Published by
ISO and IEC
Status
Voluntary · certifiable
WHO IT APPLIES TO

Who adopts it

Nobody is required to. These are the organisations for which the standard answers a question someone is already asking.

Providers and developers of AI

Organisations that build models or AI products and want a certifiable governance system their customers can rely on — the Annex A controls cover the AI lifecycle, data and third parties.

Deployers with a portfolio

Companies using several AI systems across functions, where an inventory, an impact-assessment method and a review cycle need an owner.

Organisations already on ISO 27001

The two standards share the Annex SL clause structure, so an ISMS already answers the context, leadership, support and evaluation clauses — one management system, two scopes.

KEY DATES · STATUS

The dates that matter

Certified by an accredited certification body — never by Veritome (ISO/IEC 17021-1 §5.2.5 keeps the consultant and the certifier apart).

DateEventWhat it means
18.12.2023PublishedFirst edition of ISO/IEC 42001, the first certifiable AI management system standard.
01.08.2024EU AI Act in forceRegulation (EU) 2024/1689 entered into force; harmonised standards for it are drafted separately by CEN-CENELEC and none is cited in the Official Journal yet.
02.12.2027EU AI Act Annex IIIThe date most Annex III high-risk duties apply from. An AI management system organises the work; it gives no presumption of conformity today.
WHAT IT ASKS

65 requirements, in the shape the framework gives them

The standard follows the Annex SL structure every modern ISO management system uses — context, leadership, planning, support, operation, performance evaluation, improvement — and adds AI-specific requirements: an AI risk assessment, an AI system impact assessment, and an Annex A of controls on policy, roles, resources, lifecycle, data, information for interested parties, responsible use and third parties. Veritome's catalogue paraphrases every clause and control; the standard's own text is licensed and is never reproduced.

27
clause requirements (clauses 4–10)
38
Annex A controls
  • Clause 4Context of the organisation4
  • Clause 5Leadership3
  • Clause 6Planning6
  • Clause 7Support5
  • Clause 8Operation4
  • Clause 9Performance evaluation3
  • Clause 10Improvement2
  • A.2Policies for AI3
  • A.3Internal organisation2
  • A.4Resources for AI systems5
  • A.5Impacts of AI systems4
  • A.6AI system life cycle9
  • A.7Data for AI systems5
  • A.8Information for interested parties4
  • A.9Use of AI systems3
  • A.10Third parties and customers3
HOW VERITOME RUNS IT

27 steps, 6 phases, one record each

6 phases: Establish · Plan · Support · Operate · Evaluate & improve · Certification audit. Each phase opens when the one before it is complete, the same gate rule the EU AI Act journey uses. 14 of the 27 steps are one record shared with the ISO/IEC 27001 programme — context, interested parties, roles, risk method, objectives, change, competence, awareness, documented information, operational control, monitoring, internal audit, management review and corrective action — written once, credited in both. The Statement of Applicability is a view over the programme, not a second form: exclusions need a written justification. The certification phase is optional and records the arrangements with your certification body.

01

Establish

5 steps
  1. Context of the organisation
    Shared record
  2. Interested parties and their requirements
    Shared record
  3. Scope of the AI management system
  4. Leadership commitment and AI policy
  5. Roles, responsibilities and authorities
    Shared record
02

Plan

5 steps
  1. Risk methodology and AI risk assessment
    Shared record
  2. Risk treatment and Statement of Applicability
  3. AI system impact assessment
    Per system
  4. AI objectives and planning to achieve them
    Shared record
  5. Planning of changes
    Shared record
03

Support

3 steps
  1. Resources and competence
    Shared record
  2. Awareness and communication
    Shared record
  3. Control of documented information
    Shared record
04

Operate

8 steps
  1. Operational planning and control
    Shared record
  2. AI risk assessment and treatment in operation
  3. AI system impact assessment in operation
  4. Data for AI systems
    Per system
  5. Information for interested parties
    Per system
  6. Responsible use of AI systems
    Per system
  7. Third parties and customers
  8. Statement of Applicability gap review (dynamic)
05

Evaluate & improve

4 steps
  1. Monitoring, measurement, analysis and evaluation
    Shared record
  2. Internal audit
    Shared record
  3. Management review
    Shared record
  4. Nonconformity, corrective action and continual improvement
    Shared record
06

Certification audit

2 steps
  1. Certification readiness review (optional workflow)
  2. Certification arrangements and outcome (optional)
ISO 42001ISO 42001 programme
27 steps · 27 records · 14 shared
01Establish
5 steps · Complete
02Plan
5 steps · In progress
03Support
3 steps · Locked
04Operate
8 steps · Locked
05Evaluate & improve
4 steps · Locked
06Certification audit
2 steps · Locked
Plan · the steps
  1. 01Risk methodology and AI risk assessmentShared recordApproved
  2. 02Risk treatment and Statement of ApplicabilityIn draft
  3. 03AI system impact assessmentPer systemTo do
  4. 04AI objectives and planning to achieve themShared recordTo do
Phases and steps as the product generates them · progress shown is illustrative
WHERE IT OVERLAPS

Credited in both, or only related

The 14 shared records are the only place two frameworks credit the same evidence in Veritome — the owner's verified matrix checked those clauses against both standards. Everything else that connects ISO/IEC 42001 to the EU AI Act, the GDPR or the NIST AI RMF is a related link: shown beside the step as supporting reading, never counted as coverage.

WithRecords credited in bothRelated only — shown, never creditedPage
EU AI Act034EU AI Act
GDPR016GDPR
ISO 270011418ISO 27001
NIST AI RMF023NIST AI RMF

13 of the 27 steps carry a related link to an EU AI Act article. A related link is a supporting candidate the owner's verified matrix did not check against source text; the product shows it beside the step and never counts it as coverage. The full matrix for all five frameworks is on the frameworks page; the EU AI Act itself, article by article, is at /eu-ai-act.

The coverage matrix in Veritome — one row per requirement, one column per framework, credited cells apart from related ones
QUESTIONS PEOPLE ASK

ISO/IEC 42001, answered plainly

The answers below are the ones the page marks up for search engines and AI assistants — the same text, nothing hidden.

What is ISO/IEC 42001?

The first international standard for an AI management system, published by ISO and IEC in December 2023. It specifies how an organisation establishes, runs and improves the governance of the AI it develops or uses — policy, roles, risk and impact assessment, lifecycle controls, review — and it can be certified by an accredited body.

Is ISO/IEC 42001 mandatory under the EU AI Act?

No. It is voluntary, and it is not a harmonised standard under the Act. The European harmonised standards are being drafted by CEN-CENELEC's JTC 21 and none has been cited in the Official Journal, so no standard gives a presumption of conformity today. ISO/IEC 42001 organises the management-system half of the work; it does not discharge an Art. 9 or Art. 17 obligation on its own.

How many controls does ISO/IEC 42001 have?

38 Annex A controls, alongside 27 clause requirements in clauses 4 to 10 — 65 requirements in Veritome's catalogue. The controls are applied through the Statement of Applicability: each is included or excluded with a justification.

Can ISO/IEC 42001 and ISO/IEC 27001 share one management system?

Yes — both follow the Annex SL clause structure, so the context, leadership, support and evaluation clauses are answered once. Veritome shares 14 records between the two programmes: one record, both programmes, credit in both.

What is the Statement of Applicability?

The document that lists every Annex A control and says whether it is included, and why any is excluded. In Veritome it is a view over the programme — the SoA steps open pre-filled from the records already written, and an exclusion needs a justification sentence before it saves.

Does Veritome certify ISO/IEC 42001?

No. Certification is issued by an accredited certification body after its own audit, and ISO/IEC 17021-1 keeps the party that helped build the system apart from the party that certifies it. Veritome runs the programme and produces the records; the certification phase records the arrangements with the body you choose.

The other four