Framework
ISO/IEC 42001
The AI management system standard: what an organisation must establish, document and evidence to certify against it. Each page sets out a clause, the duty it creates, who it binds, and the artefacts an auditor asks to see — described in our own words, because the text is copyrighted.
§ 1 — Orientation
How the standard is put together
ISO/IEC 42001 is a management system standard, and almost every misunderstanding of it follows from forgetting that. It does not certify a model, it does not attest that any system performs as claimed, and it is not a conformity assessment under any regulation. What a certificate says is that an organisation had, at a point in time, a management system meeting the standard’s requirements — the governance around the AI, not the AI. That is a narrower claim than it is usually sold as, and it is also a genuinely useful one, because the requirements are specific about what has to exist and be shown.
It is voluntary, and nothing happens to an organisation that ignores it. There is no deadline, no penalty and no regulator; the only real consequence of failing it is that a certification body operating to ISO/IEC 42006 refuses or withdraws a certificate. Where these pages give dates they are edition and publication dates, never compliance dates — a distinction worth holding on to, because the standard is frequently written about as though it had statutory force it does not have. Its European adoption, BS EN ISO/IEC 42001:2026, carries no technical differences from the 2023 text.
Two structural points shape how the standard is read. Its clause numbering follows the harmonised structure common to every ISO management system standard, so a reader who knows ISO 27001 will recognise most of the skeleton and should be careful about assuming the AI-specific content sits where they expect — clause 4.1, for instance, adds a duty to determine the organisation’s own role in relation to AI systems, which has no analogue elsewhere. And both annexes are normative, not just Annex A, which is a common enough error to be worth stating plainly. These pages cite clause numbers and official titles and argue the substance in our own words; the normative text belongs to ISO and is not reproduced here.
§ 2 — Guides
Guides to this framework
Written about the instrument as a whole rather than provision by provision. Where an obligation page answers what one article requires, these answer what the thing is for and how it is adopted.
ISO/IEC 42001 explained for practitioners
What ISO/IEC 42001 actually requires, what an auditor looks for, what it costs in effort, and the three things organisations consistently get wrong about it.