Standards · ISO/IEC 42001
Certifiable since December 2023ISO/IEC 42001 from scope to certificate
The first international management system standard for AI, published December 2023 by ISO/IEC JTC 1/SC 42. Clauses 4 to 10 define the management system, Annex A carries the reference controls, and an accredited certification body audits the work and decides on the certificate. Modulos maps all of it in the governance graph.
ISO 42001 is a management system standard in the same family as ISO 9001 and ISO 27001, and holders of either will recognise the shape immediately. It expects an organisation to define a scope, set policies, identify and treat risks, operate controls, monitor performance, and continually improve. Annex A's controls are the reference set you start from; the management-system clauses are what certification audits.
The management-system backbone
Seven clauses define the AIMS. They are the certifiable core, and every audit works through them.
| Clause | Name | What it requires |
|---|---|---|
| 4 | Context | Define the AIMS scope, the internal and external context the organisation operates in, and the interested parties whose needs and expectations the system must address. |
| 5 | Leadership | Top management commitment, the AI policy, and the assignment of roles and responsibilities for AI governance. |
| 6 | Planning | AI risk assessment and treatment, AI system impact assessment, and the AI objectives that flow from them. |
| 7 | Support | Resources, competence, awareness, communication, and documented information. |
| 8 | Operation | Operational planning and control, plus the operational runs of AI risk assessment, risk treatment, and system impact assessment. The applicable Annex A controls operate here and auditors test their selection and operation. |
| 9 | Performance evaluation | Monitoring, measurement, internal audit, and management review. |
| 10 | Improvement | Nonconformity, corrective action, and continual improvement. |
Read the clauses as a Plan-Do-Check-Act cycle: plan (4–6), do (7–8), check (9), act (10). Holders of ISO 9001 or ISO 27001 will recognise the shape immediately; the Annex SL backbone is the same.
What clauses 5 and 7 hard-require of leadership
Clause 5.1
Top management commitment
Top management demonstrates leadership and commitment to the AIMS, sets direction, authorises resources, and owns outcomes.
Clause 5.2
An AI policy
Top management establishes an AI policy that frames objectives, accountability for the AIMS, and a commitment to continual improvement.
Clause 5.3
Defined responsibilities and authorities
Top management assigns and communicates responsibilities and authorities for roles relevant to the AIMS. The standard requires that roles be defined; it does not enumerate specific role names.
Clauses 7.2 & 7.3
Competence and awareness
Personnel whose work affects the AIMS must be competent (training, education, experience) and aware of the AI policy, their contribution to it, and the implications of not conforming.
The annexes and what is actually required
A and B are normative, so every AIMS must address them. C and D are informative. Most explainer pages get this distinction wrong.
Annex A
Normative
Reference control objectives and controls
The reference set of controls every AIMS is expected to address, selected and tailored through the risk assessment. The management-system clauses remain the certifiable core.
Annex B
Normative
Implementation guidance for Annex A
How the Annex A controls look in practice. It reads alongside Annex A as one set.
Annex C
Informative
Potential AI-related organisational objectives and risk sources
An idea bank for tailoring your risk register and objectives. Informative, so none of it is required.
Annex D
Informative
Using the AIMS across domains and sectors
Guidance on applying the management system in different industries and use cases, and it carries no requirements.
The certification path
Typical timelines run 6 to 9 months for organisations with existing ISO 27001 infrastructure and 9 to 15 months from scratch. Most of it is implementation and evidence, and the audit itself is the short part.
Gap analysis
Map current governance and AI practices against the standard. Identify what is already in place, what is missing, and what needs to be reworked. The output is a remediation plan and a rough timeline.
Implementation and evidence collection
Define scope, write or update policies, set up risk assessment and treatment, run the controls, and produce the records that prove all of this is happening. This is where the bulk of time goes, typically 60 to 80 percent of the total effort, and evidence collection is the bottleneck where software earns its keep.
Internal audit and management review
ISO management systems require both before the external audit. The internal audit checks conformance against the standard. Management review confirms leadership accountability and resource allocation.
External audit, Stage 1 and Stage 2
Stage 1 is a documentation review: the auditor checks that the AIMS is in place and ready. Stage 2 is the implementation audit: the auditor verifies the AIMS is actually being run as documented, Annex A control selection and operation included. Nonconformities get resolved, the certification body takes its certification decision, and the certificate follows. Annual surveillance audits then run.
The common failure mode is treating certification as a documentation sprint rather than a governance program. Cramming policies for the audit produces a certificate that decays the moment policies change. The point is durable governance, and audits are won on records: decisions, approvals, dated evidence, traceability. That is what surveillance audits check between certifications.
ISO/IEC 42001 certificates are issued by independent accredited certification bodies, and the choice of auditor is yours, driven by scope, geography, and existing certification relationships. Modulos is auditor-agnostic: the platform manages your AIMS records regardless of which accredited body you select. Verify accreditation through your national accreditation body or the International Accreditation Forum directory.
The regimes overlap where the controls live
ISO/IEC 42001 sits in the framework library as 42 requirements mapped onto shared controls beside NIST AI RMF and the EU AI Act. The AIMS is the certifiable wrapper; where another framework shares a control, the evidence behind it is written once and reused, with each framework keeping its own scope.
Framework library v1.0.28
Frequently asked questions
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the first international management system standard for artificial intelligence, published in December 2023 by ISO/IEC JTC 1/SC 42. It specifies how an organisation should govern its AI systems across the entire lifecycle. It applies to any organisation that develops, deploys, or uses AI, regardless of industry or size.
When was ISO/IEC 42001 published?
ISO/IEC 42001 was published in December 2023 by ISO/IEC JTC 1/SC 42, the joint ISO and IEC committee responsible for AI standards. It is the first edition of the standard.
What is ISO/IEC 42001 certification?
Certification means an accredited third-party certification body has audited an organisation’s AI Management System (AIMS) and confirmed it meets the requirements of ISO/IEC 42001. There is also a separate concept of product conformity certification, where the platform or tool itself is certified against the standard. Modulos holds CertX product conformity certificate 213-001/24, the first issued under the CertX-AI V1.0 scheme.
What does ISO/IEC 42001 cover?
The standard covers clauses 4 through 10 of the harmonised ISO management-system structure: context, leadership, planning, support, operation, performance evaluation, and improvement. Annexes A and B (normative) provide reference controls and implementation guidance. Annexes C and D (informative) cover risk sources, organisational objectives, and sector adaptation.
How many controls are in ISO/IEC 42001 Annex A?
Annex A of ISO/IEC 42001:2023 contains a reference set of AI-specific controls grouped under control objectives covering policies, internal organisation, resources, impact assessment, lifecycle, data, third-party use, and customer expectations. Verify the exact count against the published standard at iso.org, as readers should not rely on a marketing-page number for compliance scoping.
What roles does ISO/IEC 42001 require?
ISO 42001 mandates top management commitment (clause 5.1), an AI policy (5.2), and defined responsibilities and authorities for roles relevant to the AIMS (5.3). It also requires competence and awareness for personnel whose work affects the AIMS (clauses 7.2 and 7.3). The standard does not enumerate specific role names. Organisations typically stand up an AI policy or AIMS owner, AI risk owners, and AI system owners as practical implementations.
How does ISO/IEC 42001 compare to ISO/IEC 27001?
ISO/IEC 27001 covers information security; ISO/IEC 42001 covers AI management. They share the same harmonised ISO management-system structure, so organisations operating 27001 can re-use document control, internal audit, management review, and corrective action processes. AI-specific governance such as AI risk assessment and lifecycle controls sits on top.
How does ISO/IEC 42001 compare to SOC 2?
SOC 2 is a US attestation against the AICPA Trust Services Criteria for service organisations. ISO/IEC 42001 is an international management system standard for AI specifically. They serve different audiences (US enterprise customers vs international markets) and different scopes (general security and availability vs AI). Many organisations carry both.
How does ISO/IEC 42001 relate to the EU AI Act?
ISO/IEC 42001 and the EU AI Act sit at different levels. ISO 42001 is an organisation-level AI Management System. The EU AI Act regulates specific AI systems, with obligations on providers and deployers of high-risk systems. ISO 42001 is not being adopted as a harmonised standard under the Act, so 42001 certification does not give a presumption of conformity. It is valuable as governance scaffolding around your AI portfolio, but does not substitute for the Act’s system-level requirements.
How does ISO/IEC 42001 relate to the EU Machinery Regulation?
For AI in safety-critical machinery, ISO/IEC 42001 helps structure the governance and documentation that the Machinery Regulation conformity assessment requires. The Canton of Zurich Innovation Sandbox for AI report (2025) shows how a single integrated AIMS can address both regimes simultaneously rather than running parallel processes.
How does ISO/IEC 42001 relate to NIST AI RMF?
NIST AI RMF is a voluntary US framework focused on AI risk practices. ISO/IEC 42001 is a certifiable international management system. Many organisations use NIST AI RMF as a risk-practice library and ISO/IEC 42001 as the certifiable management system that wraps around it. They complement each other.
How do you get ISO/IEC 42001 certification?
A four-step process: gap analysis against the standard, implementation and evidence collection, internal audit and management review, then external audit (Stage 1 documentation review and Stage 2 implementation audit). After Stage 2, nonconformities get resolved and the certification body takes its certification decision; the certificate follows. Annual surveillance audits then run. Evidence collection is the bottleneck and where software solves time.
How long does ISO/IEC 42001 certification take?
Typical timelines run 6 to 9 months for organisations with existing ISO 27001 infrastructure and 9 to 15 months from scratch. The audit itself is short. The bulk of time goes into implementation, evidence collection, and management review cycles. With Modulos, Xayn reached audit-readiness in four weeks, becoming the first German company to achieve ISO/IEC 42001 certification, audited by SGS.
How much does ISO/IEC 42001 certification cost?
Total cost is a mix of audit fees paid to the certifying body (scope-dependent), implementation cost (internal time plus tooling), and ongoing surveillance audits each year. Audit fees vary widely by scope, organisation size, and chosen body. Most of the cost in practice is internal effort: scoping, evidence collection, internal audit, and management review.
Who can certify our organisation against ISO/IEC 42001?
Independent accredited certification bodies issue ISO/IEC 42001 certificates. The choice of auditor is yours, driven by scope, geography, and any existing certification relationships. Modulos is auditor-agnostic: the platform manages your AIMS records regardless of which accredited body you select. Verify accreditation through your national accreditation body or the International Accreditation Forum (IAF) directory.
How does Modulos help with ISO/IEC 42001 certification?
Modulos automates evidence collection and audit preparation across clauses 4 to 10 and Annex A controls. AI agents (Scout, Evidence Agent, Control Assessment Agent) reduce manual work. Modulos holds CertX product conformity certificate 213-001/24, the first issued under the CertX-AI V1.0 scheme; was selected by the Canton of Zurich Innovation Sandbox; and powered Xayn’s 4-week certification.

The Modulos AI Governance Platform holds the first product conformity certification for an AI governance platform against ISO/IEC 42001:2023, issued by the accredited body CertX (certificate 213-001/24).
“Modulos AI Governance Platform streamlined our process. Without it, we would have spent twice the amount of time manually creating control lists from ISO 42001 annexes and linking subpages. What stood out with Modulos was the intuitive, guided approach. The platform's built-in guidance made the process seamless, and the ability to easily re-share and follow controls in the order provided was very efficient.” Leif-Nissen Lundbaek, CEO & Co-Founder, Xayn, Xayn
See ISO/IEC 42001 mapped in the governance graph
Talk to an expert
A demo walks the AIMS clauses and Annex A controls on your scope, on the governance graph your certification evidence would live in.
Request a demo →Keep exploring on your own
The NIST AI RMF page covers the risk operating model many programs run inside the AIMS, and the compliance guide covers the regulatory picture around the standard.