Skip to content
AIAC AI ASSURANCE COUNCIL

Framework

ISO/IEC 42001

The AI management system standard: what an organisation must establish, document and evidence to certify against it. Each page sets out a clause, the duty it creates, who it binds, and the artefacts an auditor asks to see — described in our own words, because the text is copyrighted.

§ 1 — Orientation

How the standard is put together

ISO/IEC 42001 is a management system standard, and almost every misunderstanding of it follows from forgetting that. It does not certify a model, it does not attest that any system performs as claimed, and it is not a conformity assessment under any regulation. What a certificate says is that an organisation had, at a point in time, a management system meeting the standard’s requirements — the governance around the AI, not the AI. That is a narrower claim than it is usually sold as, and it is also a genuinely useful one, because the requirements are specific about what has to exist and be shown.

It is voluntary, and nothing happens to an organisation that ignores it. There is no deadline, no penalty and no regulator; the only real consequence of failing it is that a certification body operating to ISO/IEC 42006 refuses or withdraws a certificate. Where these pages give dates they are edition and publication dates, never compliance dates — a distinction worth holding on to, because the standard is frequently written about as though it had statutory force it does not have. Its European adoption, BS EN ISO/IEC 42001:2026, carries no technical differences from the 2023 text.

Two structural points shape how the standard is read. Its clause numbering follows the harmonised structure common to every ISO management system standard, so a reader who knows ISO 27001 will recognise most of the skeleton and should be careful about assuming the AI-specific content sits where they expect — clause 4.1, for instance, adds a duty to determine the organisation’s own role in relation to AI systems, which has no analogue elsewhere. And both annexes are normative, not just Annex A, which is a common enough error to be worth stating plainly. These pages cite clause numbers and official titles and argue the substance in our own words; the normative text belongs to ISO and is not reproduced here.

§ 2 — Guides

Guides to this framework

Written about the instrument as a whole rather than provision by provision. Where an obligation page answers what one article requires, these answer what the thing is for and how it is adopted.