Skip to main contentChat with us
AI Governance

Complete Guide to ISO 42001: AI Management System Standard

Surendra Pal SinghPublished Updated 16 min read
Complete Guide to ISO 42001: AI Management System Standard

TL;DR

  • ISO/IEC 42001:2023 is the world's first certifiable management system standard for AI — it governs how you develop, procure, and operate AI systems through an Artificial Intelligence Management System (AIMS).
  • It follows the same Clause 4–10 structure as ISO 27001, with 38 Annex A controls grouped into 9 themes (A.2–A.10) covering policies, impact assessment, the AI life cycle, data, and third parties.
  • Certification runs gap analysis → documentation → impact assessments → implementation → internal audit → Stage 1 → Stage 2. A focused scope takes roughly 3–6 months.
  • In India, consulting typically runs ₹1.5–5 Lakh depending on scope (indicative), with certification body fees separate.
  • ISO 42001 maps cleanly onto EU AI Act obligations — especially the Article 17 quality management system — but certification alone is not legal conformity.

ISO/IEC 42001 is the world's first certifiable management system standard for artificial intelligence: it tells you how to govern the development, procurement, and use of AI through an Artificial Intelligence Management System (AIMS), and an accredited certificate proves to customers and regulators that the governance actually operates. If ISO 27001 is how you demonstrate you manage information security, ISO 42001 is how you demonstrate you manage AI — its risks, its impacts on people, and its life cycle from design to retirement.

I've spent the last two years auditing and building AI management systems, and the pattern is familiar from the early days of ISO 27001: a standard arrives ahead of the market, enterprise procurement teams start asking for it, and organizations scramble to understand what an auditor will actually check. This guide is the answer to that question — clause by clause, control by control, with the nonconformities I see most often.

What Is ISO 42001, Exactly?

ISO/IEC 42001:2023, published in December 2023, defines requirements for establishing, implementing, maintaining, and continually improving an AIMS. The keyword is management system. This is not a model-testing standard, not a bias-measurement protocol, and not a technical benchmark. It is the organizational scaffolding around your AI: who is accountable, how risks and impacts are assessed, how systems move through their life cycle, where the data comes from, and what you tell the people affected.

Three things make it different from every AI ethics framework that preceded it:

  • It is certifiable. An accredited certification body audits you against it and issues a certificate on a three-year cycle with annual surveillance — the same machinery as ISO 27001. ISO/IEC 42006:2025 now sets the requirements certification bodies themselves must meet, which is tightening up the quality of audits in the market.
  • It is auditable. Every requirement is phrased so an auditor can ask for evidence. "We take AI ethics seriously" is not evidence. A completed impact assessment for a named system, signed off before deployment, is.
  • It is integrable. It follows the harmonized structure (Clauses 4–10) shared by ISO 27001, ISO 27701, and ISO 9001. If you already run an ISMS, roughly half of your AIMS plumbing — document control, internal audit, management review, corrective action — already exists.

Auditor's Note:

The most common misunderstanding I correct in opening meetings: ISO 42001 applies whether you build AI or merely use it. If your organization consumes third-party LLM APIs or has rolled out GenAI tools to staff, you have AI systems in scope. "We don't train models" is not an exemption — it just shifts the weight of your controls toward A.10 (third-party relationships) and A.9 (responsible use).

Who Actually Needs ISO 42001?

Nobody is legally required to hold an ISO 42001 certificate today. The demand is commercial and regulatory-adjacent, and it concentrates in three groups.

1. AI Product Companies

If AI is your product — you sell a model, an AI-powered SaaS, an agent platform, or AI-driven analytics — your enterprise customers' security questionnaires are already growing an AI governance section. ISO 42001 is becoming for AI products what SOC 2 became for SaaS: the document that ends the questionnaire. Indian AI startups selling into the US and EU are the single largest group asking us about this standard, because a certificate from an accredited body answers in one line what would otherwise take twenty pages of bespoke responses.

2. GenAI Adopters

Banks, insurers, healthcare groups, IT services companies — organizations that don't build models but have deployed copilots, chatbots, document-processing pipelines, or LLM-assisted decision support. Their boards are asking "who approved this, and what could go wrong?" An AIMS gives that question a structured answer: an AI system inventory, an approval gate with impact assessment, usage policies, and monitoring. For IT/ITES service providers, there's a second driver: clients are starting to flow AI governance clauses down into MSAs, and ISO 42001 is the cleanest way to satisfy them.

3. Enterprises Facing the EU AI Act

If you provide or deploy AI systems that touch the EU market, the EU AI Act's obligations are arriving in phases through 2026 and 2027 — and Article 17 requires providers of high-risk AI systems to operate a quality management system. ISO 42001 is the closest off-the-shelf management system to that requirement. It is not automatic legal conformity (more on that below), but it builds the documentation, risk management, and oversight machinery the Act expects, so you're assembling evidence once instead of twice.

How Is the Standard Structured? Clauses 4–10

Like every modern ISO management system standard, the certifiable requirements live in Clauses 4 through 10:

  • Clause 4 — Context of the organization. Define your role in the AI value chain (provider, deployer, both), the internal and external issues that matter, interested parties, and the scope of the AIMS. Scope is where audits are won or lost: a scope that quietly excludes your highest-risk AI system will be challenged.
  • Clause 5 — Leadership. Top management must own the AI policy, assign roles and responsibilities, and demonstrate commitment. Auditors interview leadership; a CEO who cannot articulate the organization's AI risk appetite is a finding waiting to happen.
  • Clause 6 — Planning. The engine room. It requires an AI risk assessment (6.1.2 — what could harm the organization), an AI system impact assessment (6.1.4 — what could harm individuals, groups, and society), risk treatment with a Statement of Applicability against Annex A, and measurable AIMS objectives. Note that risk assessment and impact assessment are two distinct exercises — merging them into one spreadsheet is one of the most common Stage 1 findings I raise.
  • Clause 7 — Support. Resources, competence (can your team actually evaluate model behavior?), awareness, communication, and documented information.
  • Clause 8 — Operation. Execute the plans: operational controls over the AI life cycle, and re-running risk and impact assessments at planned intervals and on significant change.
  • Clause 9 — Performance evaluation. Monitoring and measurement, internal audit of the AIMS, and management review with AI-specific inputs.
  • Clause 10 — Improvement. Nonconformity handling and corrective action, including for AI incidents like hallucination-driven errors, drift, or misuse.

Annex A of ISO/IEC 42001 contains the 38 reference controls. Annex B gives implementation guidance for each, Annex C catalogs AI-specific objectives and risk sources (useful when building your risk methodology), and Annex D points to sector standards.

What Do the 9 Annex A Control Themes Cover?

The 38 controls group into nine themes, A.2 through A.10. You select and justify them via your Statement of Applicability — and unlike a policy document, each selected control must produce operating evidence. Here's each theme and what I actually ask for when auditing it:

Annex A Theme What It Requires What an Auditor Checks
A.2 — AI policies A management-approved AI policy, aligned with other org policies, reviewed at planned intervals Approval and version history; whether the policy reflects your actual AI use (a generic template that never mentions your products is a red flag); evidence of review after major changes like adopting a new foundation model
A.3 — Internal organization Defined AI roles and responsibilities; a channel for reporting AI concerns Named owners for each AI system (not "the data science team"); whether staff know how to escalate a concern about model behavior — I ask engineers directly
A.4 — Resources for AI systems Documented data, tooling, system/compute, and human resources for each AI system An AI system inventory with its dependencies: which models, which datasets, which GPUs/cloud services, which skill sets. If you can't list your AI systems, nothing downstream can work
A.5 — Impact assessment A formal process for assessing impacts on individuals, groups, and society across the AI life cycle Completed assessments for real systems, done before deployment, covering affected people (not just business risk); reassessment triggers on significant change; sign-off by someone accountable
A.6 — AI system life cycle Objectives for responsible development; requirements, design, verification & validation, deployment, operation, technical documentation, and event logging Stage gates with evidence: test results before release, documented acceptance criteria, rollback plans, model/system documentation, and logs that let you reconstruct what the system did and when
A.7 — Data for AI systems Data management across acquisition, provenance, quality, and preparation for AI Where training/fine-tuning/RAG data came from, under what rights; quality criteria; how personal data is handled (this is where I cross-check against DPDP/GDPR obligations); documented preparation steps
A.8 — Information for interested parties System documentation and information for users; external reporting; incident communication Do users know they're interacting with AI? Are limitations disclosed? Is there a working process to notify affected parties when an AI incident occurs — and has it been tested?
A.9 — Responsible use Defined intended use, objectives for responsible use, and human oversight A written intended-use statement per system (and prohibited uses); where the human is in the loop, what they can override, and whether they're trained to do it — "human oversight" that's just a dashboard nobody watches gets written up
A.10 — Third-party relationships Allocating AI responsibilities across suppliers, partners, and customers Contracts and assessments for model/API providers (OpenAI, Anthropic, cloud ML services): who handles incidents, data use rights, change notification. Consuming a frontier model API does not outsource your accountability

What Does the Certification Process Look Like?

The path to certificate is the same choreography as ISO 27001, with AI-specific artifacts. For a focused scope — say, a SaaS company with three to five AI systems — expect 3 to 6 months end to end. Larger enterprises with sprawling AI estates should plan for 9–12 months.

  1. Gap analysis (Weeks 1–2). Inventory every AI system (including the shadow GenAI tools nobody admits to), map current practices against Clauses 4–10 and Annex A, and define a defensible scope. This is also where you decide whether to integrate with an existing ISMS — if you hold ISO 27001, integration cuts the work substantially.
  2. AIMS documentation (Weeks 3–6). AI policy, roles, risk and impact assessment methodologies, life cycle procedures, data management procedures, and the Statement of Applicability. Documentation should describe what you actually do — auditors test reality against paper, and the gap between them is where audits stumble.
  3. Risk and impact assessments (Weeks 5–8). Run the Clause 6.1.2 risk assessment and the 6.1.4 impact assessment for each in-scope system. This is the intellectually honest part of the project: a real impact assessment names the people who could be harmed and how, not just "reputational risk: medium."
  4. Implementation (Weeks 8–16). Close the gaps: stand up the AI inventory, build life cycle stage gates into your development process, fix logging, paper the supplier relationships, train staff, and define human oversight per system.
  5. Internal audit and management review (Weeks 14–18). A full internal audit of the AIMS by someone independent of its implementation, then a management review with documented decisions. Certification bodies will not proceed without both.
  6. Stage 1 audit. The certification body reviews your documentation and readiness, usually remotely. You'll get a findings list; plan 2–4 weeks to close it.
  7. Stage 2 audit. The real exam: interviews with leadership, engineers, and system owners; sampling of impact assessments, life cycle evidence, logs, and supplier files. Pass, and the certificate is issued for three years with annual surveillance audits.

Auditor's Note:

Don't schedule Stage 1 until your impact assessments are genuinely complete for every in-scope system. Half-finished impact assessments are the single most common reason Stage 2 dates slip — they cascade into the Statement of Applicability, risk treatment, and life cycle evidence, so one gap becomes four findings.

What Does ISO 42001 Certification Cost in India?

Two separate budget lines, and keep them separate when comparing quotes:

  • Consulting and implementation: ₹1.5–5 Lakh (indicative), depending on scope — number of AI systems, whether you're a provider or deployer, whether an existing ISO 27001 ISMS can be extended, and how much of the documentation and assessment work you want done for you versus guided. At TCSA, every certification engagement we run comes in under ₹5 Lakh.
  • Certification body fees: separate and paid directly to the body. These vary with organization size, scope, and the body's accreditation, and cover Stage 1, Stage 2, and annual surveillance across the three-year cycle. Get this quoted in writing before you start — a consultant who blends it into one opaque number is hiding margin somewhere (indicative market practice varies widely).

If you're already ISO 27001 certified, ask about an integrated audit: shared clauses (document control, internal audit, management review) are assessed once, which reduces both consulting effort and audit days.

How Does ISO 42001 Map to the EU AI Act?

Carefully — and the precision matters. The EU AI Act is law with its own conformity assessment regime; ISO 42001 is a voluntary management system standard. Certification does not grant presumption of conformity with the Act. What it does is build, in one pass, most of the organizational machinery the Act demands of providers and deployers of high-risk systems:

  • Article 9 (risk management system) ↔ Clauses 6.1.2 and 8: a documented, iterative AI risk process operating across the life cycle.
  • Article 10 (data and data governance) ↔ A.7: provenance, quality, and preparation controls for training, validation, and testing data.
  • Article 11 + Annex IV (technical documentation) ↔ A.6.2.7: system documentation produced as a life cycle deliverable, not reverse-engineered later.
  • Article 12 (record-keeping/logging) ↔ A.6.2.8: event logs sufficient to reconstruct system behavior.
  • Article 13 (transparency to deployers/users) ↔ A.8: information for interested parties, limitations, instructions for use.
  • Article 14 (human oversight) ↔ A.9.4: defined, trained, empowered human oversight per system.
  • Article 17 (quality management system for providers of high-risk AI) ↔ the AIMS as a whole — this is the strongest alignment, and the reason EU-exposed providers are certifying now rather than waiting.

The honest framing I give clients: ISO 42001 gets you perhaps 60–70% of the organizational evidence the Act will ask of you (indicative — the harmonized European standards that will define formal conformity are still being finalized). Build the AIMS now, and the delta becomes a legal-and-product exercise instead of a from-scratch program under deadline.

What Nonconformities Do Auditors Actually Raise?

From AIMS audits and readiness assessments to date, the recurring findings — write these on a whiteboard before you start:

  1. No complete AI system inventory. Marketing's GenAI content tool and the support team's chatbot pilot are AI systems. Scoping them out silently is a Stage 1 finding; not knowing they exist is worse.
  2. Impact assessment confused with risk assessment. One spreadsheet, business-risk language only, nothing about affected individuals or groups. Clause 6.1.4 is its own discipline.
  3. Template documentation that doesn't match reality. An AI policy referencing "the AI Ethics Board" that has never met. Auditors check meeting minutes.
  4. Human oversight defined nowhere. The SoA claims A.9.4, but no one can say who can override the model, on what authority, with what training.
  5. No data provenance for training or RAG data. "We scraped it" is an answer; it's just not a passing one. A.7 wants acquisition records and rights.
  6. Third-party model providers treated as out of scope. No supplier assessment, no contractual allocation of AI responsibilities, no change-notification process for model updates that silently alter behavior. A.10 exists precisely for this.
  7. Logging that can't reconstruct an AI decision. Application logs exist; prompt/response/version trails don't. When the first AI incident hits, the investigation dies here.

Frequently Asked Questions

Is ISO 42001 mandatory?

No. It's voluntary, like ISO 27001. The pressure is commercial — enterprise customers, investors, and procurement teams — and regulatory-adjacent, as evidence of responsible AI governance under regimes like the EU AI Act.

We only use third-party AI tools like ChatGPT and Copilot. Does ISO 42001 still apply?

Yes. The standard covers use of AI, not just development. Your AIMS would lean on usage policies (A.2), responsible use and oversight (A.9), and supplier controls (A.10) rather than model development controls — a lighter implementation, but a real one.

How long does ISO 42001 certification take?

For a focused scope with management attention, 3–6 months from gap analysis to Stage 2. Existing ISO 27001 certification shortens it; a large, undocumented AI estate lengthens it.

How much does it cost in India?

Indicatively, ₹1.5–5 Lakh for consulting and implementation depending on scope, plus certification body fees, which are quoted separately based on your size and scope. TCSA engagements stay under ₹5 Lakh.

Do we need ISO 27001 before ISO 42001?

No, it's not a prerequisite. But the two share the Clause 4–10 skeleton, and most organizations buying AI products also ask about information security — so we usually recommend implementing them together or extending an existing ISMS. See our guide on AI security risks and mitigation for the security side of the picture.

Does ISO 42001 certification mean we comply with the EU AI Act?

No. It builds most of the management system the Act expects — risk management, data governance, documentation, logging, human oversight — but legal conformity is a separate assessment against the Act itself. Treat the AIMS as the foundation, not the finish line.

How many controls are in ISO 42001 Annex A?

38 controls across 9 themes (A.2–A.10). You justify inclusion or exclusion of each in your Statement of Applicability — and every included control must produce evidence an auditor can sample.


Surendra Pal Singh is CISO & DPO at Tranquility Cybersecurity and a certified ISO 27001, ISO 27701, and ISO 42001 Lead Auditor (CISA). Talk to us about scoping your AIMS.

Frequently Asked Questions

Is ISO 42001 mandatory?

No. It's voluntary, like ISO 27001. The pressure is commercial — enterprise customers, investors, and procurement teams — and regulatory-adjacent, as evidence of responsible AI governance under regimes like the EU AI Act.

We only use third-party AI tools like ChatGPT and Copilot. Does ISO 42001 still apply?

Yes. The standard covers use of AI, not just development. Your AIMS would lean on usage policies (A.2), responsible use and oversight (A.9), and supplier controls (A.10) rather than model development controls — a lighter implementation, but a real one.

How long does ISO 42001 certification take?

For a focused scope with management attention, 3–6 months from gap analysis to Stage 2. Existing ISO 27001 certification shortens it; a large, undocumented AI estate lengthens it.

How much does it cost in India?

Indicatively, ₹1.5–5 Lakh for consulting and implementation depending on scope, plus certification body fees, which are quoted separately based on your size and scope. TCSA engagements stay under ₹5 Lakh.

Do we need ISO 27001 before ISO 42001?

No, it's not a prerequisite. But the two share the Clause 4–10 skeleton, and most organizations buying AI products also ask about information security — so we usually recommend implementing them together or extending an existing ISMS.

Does ISO 42001 certification mean we comply with the EU AI Act?

No. It builds most of the management system the Act expects — risk management, data governance, documentation, logging, human oversight — but legal conformity is a separate assessment against the Act itself. Treat the AIMS as the foundation, not the finish line.

How many controls are in ISO 42001 Annex A?

38 controls across 9 themes (A.2–A.10). You justify inclusion or exclusion of each in your Statement of Applicability — and every included control must produce evidence an auditor can sample.

Ready to Start Your Compliance Journey?

Get a complimentary readiness assessment and customized implementation roadmap from our compliance experts.

Free Assessment

No obligation, no sales pitch

Custom Roadmap

Tailored to your organization

Expert Guidance

500+ successful audits

Book Free Consultation