What ISO/IEC 42001 actually is
ISO/IEC 42001 is the first international, certifiable management system standard for artificial intelligence. Published in December 2023, it does for AI what ISO 27001 did for information security: it defines what a managed, auditable approach looks like — an AI management system, or AIMS — and allows an accredited third party to certify that you operate one.
It is a standard about how an organisation governs AI, not about how any single model behaves. Certification does not say your AI is safe or accurate. It says something narrower and, to a board or a procurement team, more useful: this organisation knows what AI it runs, has decided who is accountable for it, assesses the impact on people before and during deployment, and can evidence all of it on demand.
Structurally it follows the same harmonised skeleton as ISO 27001 and ISO 9001 — seven clause families plus an annex of AI-specific controls, each included or excluded with a written justification in a statement of applicability. If you already hold a management system certification, the shape will be familiar. The content will not.
Who should care — and who can wait
Three groups have a live reason to take ISO 42001 seriously now. Regulated organisations — firms supervised by the FCA or PRA, practices regulated by the SRA, providers answerable to the CQC, and anyone processing personal data under the ICO’s remit — because supervisors increasingly expect AI to sit inside a documented management system, even where no rule names the standard. Suppliers into large enterprises, because procurement questionnaires have started asking for it the way they asked for ISO 27001 a decade ago. And organisations in scope of the EU AI Act, because although certification does not by itself demonstrate conformity with the Act, the risk management, documentation and oversight habits the standard builds are the same habits the Act demands.
Who can wait? Organisations with a genuinely small AI footprint and no external pressure to certify. Even there, the readiness work — inventory, accountability, impact assessment — is worth doing on its own merits. It is the certificate that can wait, not the discipline.
The seven clause families, in plain English
The standard’s requirements sit in clauses 4 to 10, and they read more plainly than their headings suggest.
- Context (clause 4). Know your ground: what AI you operate, who it affects, which external obligations apply, and precisely what your management system covers. Scope is decided here — and audited later.
- Leadership (clause 5). Top management owns the system. A signed policy is not enough; the standard expects direction, resourcing and visible accountability from the executive, not delegation to a compliance inbox.
- Planning (clause 6). Assess AI risks and — distinctively — the impact of your systems on individuals and society, then set measurable objectives and decide how each risk will be treated.
- Support (clause 7). The evidence layer: competent people, adequate resources, awareness across the organisation, and documented information that is controlled and current.
- Operation (clause 8). The controls actually running in the AI lifecycle — the difference between a policy and a practice, and where most audit findings arise.
- Performance evaluation (clause 9). Monitoring, internal audit and management review: proving to yourselves that the system works before an external auditor asks.
- Improvement (clause 10). When something fails — and something will — nonconformities are recorded, corrected and fed back into the system.
Annex A adds a catalogue of AI-specific controls, from data governance through the AI lifecycle to third-party relationships. Auditors read your justifications for including or excluding each one closely.
Readiness maps to work you have already done
ISO 42001 readiness is often presented as a fresh mountain to climb. For an organisation already running a serious governance programme, it is mostly a mapping exercise. A complete AI inventory — including the shadow AI that never went through procurement — answers most of clause 4. An accountability map with named owners answers much of clause 5. Risk classification and impact assessment against recognised frameworks — the EU AI Act’s risk tiers, the NIST AI RMF — is clause 6 in different clothing. Live monitoring, review records and incident learning are clauses 8, 9 and 10 in operation.
This is how we approach it. A Sentinel engagement produces the inventory, risk classification and accountability map; Citadel then keeps the evidence current — the monitoring records, review logs and controlled documentation that clauses 7 and 9 expect an auditor to find. Our Enterprise AI Lab maintains an active research line mapping ISO 42001 requirements against the Sentinel programme, so certification builds on work already done rather than duplicating it.
The honest gap for most organisations is not controls but evidence: things done well once, undocumented, unrepeatable. A management system is the habit of keeping receipts.
Realistic timelines
Certification follows the standard two-stage pattern: a stage 1 audit reviewing documentation and readiness, then a stage 2 audit testing the system in operation, followed by annual surveillance audits and recertification on a three-year cycle. The detail that catches organisations out is that auditors expect to see the system running, not freshly printed — typically at least one completed internal audit, one management review, and months of operating evidence before stage 2.
That drives the arithmetic. For a mid-market organisation starting from a partial baseline — some policies, an incomplete inventory, no formal impact assessment — readiness is realistically a six-to-twelve-month programme. With an existing certified management system and a complete AI inventory it can be materially shorter; from a standing start, longer. Build in time for the market, too: accredited ISO 42001 certification is still young and audit capacity is uneven, so slots need booking well ahead. The organisations that certify smoothly are the ones that treated the operating period as the point, not the delay.
Where readiness efforts fail
The failure modes repeat across organisations, and most are visible months before an audit exposes them. The commonest is treating the standard as a writing project: a full set of handsome documents describing a system that does not operate. Stage 2 audits test practice, and no auditor is persuaded by a policy with no records behind it.
The second is scoping the system around the AI you know about. If the inventory is incomplete — and unmanaged, team-adopted AI tools mean it usually is — the management system governs a fiction, and every downstream assessment inherits the gap. The third is treating ISO 42001 as an ISO 27001 bolt-on. The overlap in structure is real; the overlap in substance is partial. AI impact assessment — the effect of a system on the people subject to it — is a different discipline from information security risk, and it is the requirement auditors most often find missing.
The rest are quieter: leadership engagement that amounts to a signature; a certified scope drawn so narrowly the certificate says less than procurement assumes; monitoring that logs findings nobody corrects. Each is the same error at root — pursuing the certificate instead of the system.