ISO/IEC 42001:2023 Information Technology — Artificial Intelligence — Management System
Framework reference — controls, obligations, and mapping to US state AI laws.
Last verified July 24, 2026
Overview
ISO/IEC 42001 is the world's first international standard for an Artificial Intelligence Management System (AIMS), published in December 2023 jointly by ISO and IEC. The standard specifies requirements for establishing, implementing, maintaining, and continually improving a management system for AI within an organization.
Like ISO 9001 (quality) and ISO 27001 (information security), 42001 follows the high-level structure for management-system standards (Annex SL) and is designed to be auditable and certifiable by third-party accredited bodies.
The standard includes core management-system clauses (context, leadership, planning, support, operation, performance evaluation, improvement) plus AI-specific Annexes:
- Annex A — reference controls covering policy, internal organization, AI resources, impact assessment, system lifecycle, third-party relationships, and use information
- Annex B — implementation guidance for the controls
- Annex C — AI-related organizational objectives and risk sources
- Annex D — domain or sector-specific use considerations
Certification provides a credible, internationally recognized signal of AI governance maturity that maps to obligations in the EU AI Act, NIST AI RMF, and emerging US state AI laws. Certification audits are typically conducted on a 3-year cycle.
The framework pairs naturally with the NIST AI RMF: teams often use NIST's GOVERN, MAP, MEASURE, and MANAGE functions to structure day-to-day risk work and ISO/IEC 42001 to obtain a transferable, audited certificate. For the operating-model view of committees, decision rights, and lifecycle gates, the AI governance guide is the companion reference.
ISO/IEC 42001 certification: how it works
ISO/IEC 42001 certification is voluntary, and ISO itself does not certify organizations. Certification is performed by independent certification bodies, which are typically accredited by a national accreditation body operating under the International Accreditation Forum framework — in the United States, the ANSI National Accreditation Board (ANAB) accredits certification bodies for ISO/IEC 42001. ISO/IEC 42006:2025 sets the additional requirements those bodies meet when auditing and certifying an Artificial Intelligence Management System, building on the general management-system certification standard ISO/IEC 17021-1. Sources: ISO — Certification, ISO/IEC 42006:2025, ISO/IEC 17021-1:2015, and ANAB ISO/IEC 42001 accreditation, retrieved 2026-05-29.
A typical initial certification runs as a two-stage audit:
- Stage 1 — a readiness and documentation review confirming the AI management system is designed, the scope and Statement of Applicability are defined, and the organization is ready for assessment.
- Stage 2 — an assessment of whether the management system is implemented and effective against ISO/IEC 42001 requirements and the selected Annex A controls.
After the certificate is issued it is maintained on a three-year cycle: surveillance audits (a smaller share of the initial audit effort) are normally conducted annually to confirm the system remains in conformance, and a recertification audit at the end of the cycle re-establishes the certificate. Source: ISO/IEC 17021-1:2015, retrieved 2026-05-29.
What an ISO/IEC 42001 certification audit reviews
Assessors evaluate management-system evidence rather than a single document, typically including:
- the AI policy, objectives, and the Statement of Applicability justifying which Annex A controls are included or excluded;
- AI system inventories and AI impact assessments for in-scope systems;
- system-lifecycle controls, data governance, and third-party or supplier relationships;
- monitoring, internal audit, and management review records demonstrating continual improvement.
ISO/IEC 42001 vs NIST AI RMF certification
The two are frequently confused, but only one results in an organizational certificate. ISO/IEC 42001 is certifiable through accredited certification bodies, so a procurement file can carry a certificate number, scope, certification body, and expiry date. The NIST AI RMF is a voluntary framework with no NIST-issued certification — organizations document alignment through a control map rather than a certificate. The practical pattern for teams that need both operational structure and transferable assurance is to run risk work against the NIST functions and pursue ISO/IEC 42001 certification when a customer, regulator, or board requires an audited credential.
Does ISO/IEC 42001 certification satisfy US state AI laws?
No. ISO/IEC 42001 is a voluntary management-system standard, not a statute. A certificate is useful evidence of governance maturity and due care, but it does not by itself discharge binding obligations under US state and sector law — for example the Colorado AI Act, Texas TRAIGA, NYC Local Law 144, Illinois HB 3773, the Utah AI Policy Act, and the California AI laws, nor HIPAA or FCRA where they apply. Certified organizations still maintain a separate statutory-evidence file mapping each applicable law's duties to specific controls and artifacts.
Frequently asked questions
Is ISO/IEC 42001 certification mandatory?
No. ISO/IEC 42001 certification is voluntary. Organizations pursue it to obtain independent, internationally recognized confirmation that their AI management system meets the standard, often because a customer, regulator, or board requests audited assurance.
Who can certify an organization to ISO/IEC 42001?
Independent certification bodies perform the audit and issue the certificate; ISO does not certify organizations itself. Certification bodies are typically accredited by a national accreditation body — in the United States, ANAB — and meet the requirements of ISO/IEC 42006:2025 and ISO/IEC 17021-1.
What are the ISO/IEC 42001 clauses?
ISO/IEC 42001 follows the Annex SL management-system structure: context of the organization, leadership, planning, support, operation, performance evaluation, and improvement, paired with the AI-specific controls in Annex A and guidance in Annexes B through D.
How long does ISO/IEC 42001 certification last?
A certificate is normally maintained on a three-year cycle, with annual surveillance audits to confirm continued conformance and a recertification audit before the cycle ends.
Certification
ISO/IEC 42001 is certifiable via Accredited certification bodies under ISO/IEC 17021-1. Certification typically requires a documented AI management system, internal audit, and external assessment by an accredited certification body.
Core controls & obligations
Specific controls and obligations from ISO/IEC 42001, with section references where available.
- GovernanceRole: bothClauses 4-5
Establish, implement, maintain, and continually improve an AI management system (AIMS) covering policies, leadership commitment, roles, and integration with other management systems.
- Risk assessmentRole: bothClause 6 + Annex A.5
Conduct AI system impact assessments and risk assessments addressing intended uses, deployment context, affected stakeholders, and mitigation of identified risks per Annex A.5 controls.
- DocumentationRole: bothClause 8 + Annex A.6
Maintain documentation throughout the AI system lifecycle including data management, system development, verification and validation, and deployment per Annex A.6 controls.
- TransparencyRole: deployerClause 8 + Annex A.8
Provide information to users and affected stakeholders about the AI system's intended use, capabilities, limitations, and how to interpret outputs per Annex A.8 controls.
Mapped to US state laws
Common controls in ISO/IEC 42001 that satisfy or overlap with US state AI law obligations. Mapping strength indicates how closely the framework control corresponds to the statutory requirement.
- California Generative AI: Training Data Transparencypartial mapping
- Transparency in Frontier Artificial Intelligence Act (TFAIA)strong mapping
- Colorado Artificial Intelligence Actstrong mapping
- NYC Local Law 144 (Automated Employment Decision Tools)partial mapping
- Texas Responsible Artificial Intelligence Governance Act (TRAIGA)partial mapping
- Utah Artificial Intelligence Policy Actweak mapping
Related comparisons
Use the side-by-side comparisons to place this framework against adjacent US AI laws and standards.
- NIST AI RMF vs ISO/IEC 42001
Compare framework scope, evidence expectations, and implementation context.
- Texas TRAIGA vs ISO/IEC 42001
Compare the law and framework records using the same source-backed entity data.
Related compliance guides
Apply ISO/IEC 42001 alongside these implementation guides that connect the framework to operating models and statutory obligations.
- AI compliance framework: the regulatory control map — map ISO/IEC 42001 controls onto a reusable, multi-law control set.
- NIST AI RMF playbook: official guide, actions & PDF — the actionable companion to the NIST AI Risk Management Framework.
- AI governance: building an AI compliance program — turn framework functions into decision rights, committees, and lifecycle gates.
- California AI Transparency Act for healthcare — apply framework controls to the Act's healthcare content-provenance and disclosure workflow.
- Utah AI Policy Act for financial services — apply framework controls to high-risk generative-AI interactions involving financial data.
- Florida AI laws for hiring and HR — map framework role, governance, and evidence controls onto Florida hiring workflows.
Sources
Last reviewed July 24, 2026. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.
We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.