42001
ISO/IEC 42001:2023 · Artificial intelligence management system

ISO/IEC 42001AIMS

The first certifiable management system for artificial intelligence. Proof that your AI is developed and used responsibly — for clients, regulators and the EU AI Act.

SCHEME CARD · INFORMATION SECURITY
ISO/IEC 42001Artificial intelligence management system · 2023
Who it's for
IT & software, AI product companies and more
Audit model
Stage 1 + Stage 2 + surveillance
Certificate validity
3 years
Typical timeline
8–12 weeks
Listed in public registerCombines with ISO/IEC 27001, ISO/IEC 27701
3 yrscertificate validity, with annual surveillance audits
2audit stages — documentation review, then on-site assessment
8–12weeks from application to certificate, typical timeline
1business day to a fixed offer after your application
Why companies certify

Who needs ISO/IEC 42001— and when

ISO/IEC 42001 sets out how an organisation governs the AI systems it develops, provides or uses: AI policy, risk and impact assessment, data quality, transparency, human oversight and monitoring across the AI life cycle. Certification shows clients and regulators that AI risks are managed systematically, not case by case.

Requested in procurement for AI-enabled products and services, and increasingly used as evidence of good practice under the EU AI Act.

INDUSTRIES WE CERTIFY TO ISO/IEC 42001

IT & softwareAI product companiesFintech & insuranceHealthcare & medtechTelecomPublic sector
Not sure whether ISO/IEC 42001 fits? Our auditors run a short diagnostic review and suggest the scheme — or a combination of two or three — that answers your customers' requirements.
Inside the standard

What the audit examines

01AI policy & roles

Objectives, accountability and responsible-AI principles defined.

02AI risk assessment

Risks to individuals, society and the organisation assessed and treated.

03AI impact assessment

Consequences of AI systems for people and groups evaluated.

04Data for AI

Quality, provenance and suitability of training and operational data.

05AI life cycle

Design, verification, deployment, monitoring and retirement controlled.

06Third parties

Suppliers of models, data and AI services managed.

What the audit covers

Requirements,clause by clause

ISO/IEC 42001 is audited against these requirement areas. Open each one to see what auditors look for in your company.

Clause 4Context of the organisation+
Interested parties, internal and external issues, and how the scope of the system is defined.
Clause 5Leadership+
Top management commitment, a policy that fits the business, roles and responsibilities.
Clause 6Planning+
Risks and opportunities identified and addressed; measurable objectives with plans to reach them.
Clause 7Support+
Resources, competence and awareness, communication, control of documented information.
Clause 8Operation+
How processes are planned, controlled and delivered day to day.
Clauses 9–10Evaluation & improvement+
Monitoring, internal audits, management review — and how nonconformities become corrective actions.
Benefits

What ISO/IEC 42001certification gives you

  • Trust of clients and partners in your AI products
  • Structured basis for EU AI Act readiness
  • AI risks managed systematically, not case by case
  • Clear accountability and human oversight
  • Faster vendor due diligence for AI services
  • Integrates with ISO/IEC 27001 and ISO/IEC 27701
Integrated audit

Hold more than one standard? One audit.

ISO/IEC 42001 shares its structure with ISO/IEC 27001, ISO/IEC 27701. We audit them together — one team, one visit, one report.

−25%audit days on average
1lead auditor for all standards
The path to certificate

Five steps from application to ISO/IEC 42001

Scroll the steps — the bar shows where you are in the process. Every step has a named coordinator and a fixed timeline.

STEP 1 / 5 · Application & offer
STEP 11 business day
Application & offer

You send a short application; a coordinator sizes the audit and sends a fixed offer.

→ Offer with audit plan
STEP 21–2 days
Stage 1 audit

Documentation review and readiness check — remote or on site. Gaps are listed, not penalised.

→ Readiness report
STEP 3By calculation
Stage 2 audit

On-site assessment of implementation and effectiveness with a team that knows your sector.

→ Audit report
STEP 45–10 days
Decision & certificate

Independent certification decision; the certificate is issued and entered into the public register.

→ ISO/IEC 42001 certificate
STEP 5Annual
Surveillance & renewal

Annual surveillance keeps the certificate in force; re-certification in year three.

→ Certificate maintained
Readiness check

Are you readyfor Stage 1?

Tick what you already have. You do not need a perfect system to apply — you need a working one.

Your readiness
0%

Based on the items ticked on the left. Indicative — the Stage 1 audit gives the formal picture.

Apply for ISO/IEC 42001 →
FAQ · ISO/IEC 42001

Questions companiesask before certifying

Did not find yours? Call us — a coordinator answers within the same business day.

+38 (044) 332-30-76
Is ISO/IEC 42001 the same as EU AI Act compliance?+
No. The AI Act is legislation; ISO/IEC 42001 is a management system that helps you meet its governance, risk and transparency expectations and demonstrate them with a certificate.
We only use AI tools from vendors — is it relevant?+
Yes. The standard covers organisations that use AI as well as those that develop it; the scope is then focused on selection, oversight and supplier control.
Can it be combined with ISO/IEC 27001?+
Yes. Both follow the same High Level Structure, and most clients audit them together to save audit days.
Related schemes

Often certifiedtogether

Get certifiedto ISO/IEC 42001

Send an application — we define scope and audit duration, and issue a fixed offer within one business day.

  • Auditors with experience in your industry
  • Fixed price — no surprises after Stage 1
  • Certificate listed in the public register
By sending the form you agree to the processing of the data for preparing a quotation.