ISO/IEC 42001
ISO/IEC 42001 is an international standard that sets out how an organization should manage its use, development, or provision of artificial intelligence in a structured, governable way. It describes a management system approach so that AI-related activities can be directed, monitored, and improved over time. It is intended for organizations that develop, provide, or use AI and can be certified against by an accredited third party.
ISO/IEC 42001:2023, jointly issued by ISO and IEC, specifies requirements and provides guidance for establishing, implementing, maintaining, and continually improving an artificial intelligence management system (AIMS) within an organization's context. As a management-system standard, it addresses the governance structures, roles, and processes for directing AI-related activities rather than prescribing specific technical controls or model-level engineering methods. It applies to organizations that develop, provide, or use AI systems and, per the evidence, is a certifiable standard, meaning conformity may be assessed and certified by third parties. This entry does not cover clause-by-clause requirements, certification procedures, or how ISO/IEC 42001 interacts with jurisdiction-specific AI regulation, which vary by context.
Why it matters
Many organizations are adopting artificial intelligence more rapidly than they establish the structures to govern it. ISO/IEC 42001 addresses this gap by providing an internationally recognized, management-system approach to directing, monitoring, and improving AI-related activities. For governance professionals, it offers a recognizable reference point, analogous in form to other ISO management-system standards, for demonstrating that AI development, provision, or use is being managed in a structured and accountable way rather than on an ad hoc basis.
Because ISO/IEC 42001 is a certifiable standard, an organization may seek conformity assessment and certification from an accredited third party. This can support external assurance to customers, partners, regulators, and other stakeholders that defined governance processes for AI are in place and subject to continual improvement. Certification does not by itself guarantee that any particular AI system is safe, fair, or compliant with applicable law; it attests to the existence and operation of a management system, not to the technical performance of individual models.
The standard's relevance is heightened by the emergence of jurisdiction-specific AI regulation, though the way ISO/IEC 42001 interacts with such regulation varies by context and is not addressed in this entry. Organizations should treat the standard as a governance framework that complements, rather than substitutes for, applicable legal and regulatory obligations.
Who it's relevant to
Inside ISO/IEC 42001
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 42001.
