Guides · ISO 42001

What ISO 42001 asks of an organisation

The standard behind the new line in supplier questionnaires is 51 pages long. Most of it is a structure shared with ISO 27001. The parts that are new for AI fit in a few sub-clauses and two annexes, and they ask for records rather than promises.

Published by Aitonomy We run agent workforces for companies. This is where we write down what that actually takes. What we do

Supplier questionnaires have gained a line this year: are you certified to ISO/IEC 42001, and if not, when? The standard behind the question is 51 pages long. This guide goes through what those pages ask an organisation to do, in business terms, and what the certificate does and does not prove.

We covered the broader picture in the rulebooks arriving around AI. This article takes the standard on its own, working from the part ISO publishes for free (foreword, scope, definitions and clause 4), the structure ISO shares across its management-system standards, accredited certification bodies and their auditors, and the announcements of organisations that have certified.

What does the standard certify?

ISO/IEC 42001:2023, published in December 2023, sets requirements for an AI management system. A management system is the set of policies, roles, processes and records through which an organisation runs something deliberately rather than by habit. ISO 9001 does this for quality and ISO 27001 for information security. ISO 42001 does it for the development, provision and use of AI.

The certificate therefore says something specific: an accredited auditor found that the organisation has defined which AI it governs, assessed its risks and impact, chosen controls, kept records, checked itself and corrected what it found. It does not say that any model is accurate or fair, or that the organisation complies with the EU AI Act, and it says nothing about AI outside the scope the organisation wrote down.

ISO 42001 is intended to cover the delta: the risks that are unique to AI. So think bias, transparency, responsible use, ethics and safety. Danny Manimbo, Schellman · ISO 42001 certification FAQ, February 2025

The standard names three roles, producer, provider and user, and one organisation can hold more than one: a company that runs agents on a bought platform is a user of the platform and may be a provider of the agent. The roles shape the scope, and the scope decides what the audit covers.

The certificate covers a scope, not a company

AWS’s certificate names four services. Microsoft’s names nine Copilot and Foundry products. IBM’s covers one model family. When a supplier says it is certified, ask: for which systems, and is the one we are buying inside that scope?

What is the shape of the standard?

Pages 1 to 16 hold the scope, 26 definitions and the requirement clauses 4 to 10. Annex A, four pages, lists 38 controls under nine objectives. Annex B, 25 pages and normative, gives implementation guidance per control. Annexes C and D are informative.

THE 51 PAGES OF ISO/IEC 42001 THE REQUIREMENT CLAUSES 4Context 5Leadership 6Planning 7Support 8Operation 9Evaluation 10Improvement AI-SPECIFIC TEXT: THE AI POLICY (5.2), RISK, TREATMENT AND IMPACT ASSESSMENT (6.1.2 TO 6.1.4, 8.2 TO 8.4) THE PAGES, IN PROPORTION Clauses 1 to 10 16 pp A · 4 Annex B, guidance per control 25 pp C D THE FREE PREVIEW ENDS AFTER CLAUSE 4, ON PAGE 6 A · 38 CONTROLS UNDER 9 OBJECTIVES (NORMATIVE) B · IMPLEMENTATION GUIDANCE PER CONTROL (NORMATIVE) C · OBJECTIVES AND RISK SOURCES (INFORMATIVE) D · INTEGRATION AND SECTORS (INFORMATIVE)
Half the document is guidance on the 38 controls. The requirement clauses take 16 pages, most of which is the structure every ISO management-system standard shares. Page numbers from the published table of contents.

Clauses 4 to 10 use what ISO calls the harmonised structure: identical clause numbers, titles and core text across all its management-system standards, so anyone who has run ISO 27001 will recognise nearly all of it. What is new for AI sits in a handful of sub-clauses, marked in the figure, and in the annexes. The full text costs CHF 225 from ISO or about EUR 250 excluding VAT from NEN, English only; the free preview stops at the end of clause 4.

What do clauses 4 to 10 require?

The table puts each clause in ordinary terms, with the records an auditor will look for. The right-hand column matters more than the middle one: a folder of policies with no records behind it fails the audit.

ClauseWhat it asksWhat you need to be able to show
4
Context
Work out what affects your use of AI (your role, legal and ethical factors, who has a stake) and decide which AI systems the management system coversA written scope. A list of interested parties and what they expect. Clause 4.1 also asks whether climate change is a relevant issue
5
Leadership
Top management commits, issues an AI policy and assigns responsibilitiesAn AI policy approved at the top. Named owners for AI risk, impact assessment and the system as a whole
6
Planning
Define how you will assess AI risk, treat it and assess the impact on people. Set measurable AI objectivesA risk assessment method with criteria set in advance. A risk treatment plan and a Statement of Applicability. An impact assessment process. Objectives with owners
7
Support
Provide resources and competent people, make staff aware, communicate, and control your documentsEvidence of competence. Versioned, controlled documents
8
Operation
Run the processes. Carry out the assessments at planned intervals and when something significant changesThe results of each assessment. Evidence that processes ran as planned and that changes were reviewed
9
Evaluation
Monitor and measure, audit yourself, and have management review the resultsMonitoring results. An internal audit programme and its findings. Management review records
10
Improvement
Fix nonconformities, address their causes, and keep improving the systemA record of each nonconformity, the corrective action and whether it worked
This is where you need objective evidence that your AI management system is working and it’s not just intentions. Ali Moshayedi, ISO 42001 auditor, BSI · on clause 9, BSI webinar, March 2026

What is specific to AI?

Three processes, defined in clause 6 and carried out in clause 8.

AI risk assessment (6.1.2, 8.2). Identify what the organisation’s AI systems could do to its own objectives, using criteria fixed in advance. Annex C offers a menu of risk sources.

AI risk treatment (6.1.3, 8.3). Decide which controls address those risks and record the decision in a Statement of Applicability: “documentation of all necessary controls and justification for inclusion or exclusion of controls”. It is the first thing an auditor reads.

AI system impact assessment (6.1.4, 8.4). Assess the consequences of developing, providing or using an AI system for individuals, groups and society. A risk assessment looks inward, at the organisation. An impact assessment looks outward, at the people the system touches.

TWO ASSESSMENTS, TWO DIRECTIONS THE ORGANISATION and the AI systems it develops, provides or uses AI RISK ASSESSMENT 6.1.2 · 8.2 · LOOKS INWARD What could our AI do to our own objectives? AI SYSTEM IMPACT ASSESSMENT 6.1.4 · 8.4 · LOOKS OUTWARD What could our AI do to individuals, groups and society? BOTH FEED THE RISK TREATMENT PLAN AND THE STATEMENT OF APPLICABILITY (6.1.3 · 8.3) REPEATED AT PLANNED INTERVALS AND WHEN A SYSTEM CHANGES SIGNIFICANTLY
The impact assessment is the outward-facing addition. Most management-system standards already carry a risk assessment. ISO 42001 adds a second one, aimed at the people affected. ISO/IEC 42005:2025 gives guidance on what it should contain: why the system exists, who is affected, the foreseeable impacts and how they are addressed.

The nine control objectives

Annex A groups its 38 controls under nine objectives. You select the ones your risk treatment needs, may add your own, and justify every inclusion and exclusion in the Statement of Applicability.

ObjectiveControlsWhat it covers, in plain terms
A.2 Policies for AI3An AI policy, aligned with your other policies, reviewed on a schedule
A.3 Internal organisation2Who is responsible for what, and how staff raise concerns about AI
A.4 Resources5Documenting the data, tools, computing and people each AI system depends on
A.5 Impact assessment4A process for assessing impact on individuals, groups and society, and records of having done it
A.6 Life cycle9Responsible design, verification and validation, deployment, operation and monitoring, documentation, event logs
A.7 Data5Where data comes from, its quality, its provenance, and how it is prepared
A.8 Information for interested parties4What users are told, external reporting, communicating incidents
A.9 Use of AI3Processes for responsible use, and a defined intended use for each system
A.10 Third parties and customers3Allocating responsibility across the supply chain, managing suppliers, duties to customers

Five of the nine are new territory compared with an information-security standard: A.5 to A.9, on impact, life cycle, data, information and use. That is where the work goes.

What does certification involve?

Certification comes from a certification body that is itself accredited for ISO 42001 under ISO/IEC 42006:2025. In the Netherlands the RvA accredited BSI and DNV in January 2025 and TÜV NORD in February 2026. Some early certificates were issued under other schemes, so the accreditation mark on a certificate is worth checking.

The audit follows the ISO 27001 pattern: a Stage 1 documentation review in one or two days, a Stage 2 test of whether the system operates over one to three weeks, then a three-year certificate with annual surveillance. Those durations are Schellman’s published experience; the same firm quotes year-one audit fees from the low to the mid tens of thousands of US dollars. Stage 2 looks for records, so the system has to have run before the audit; implementers quote six to twelve months from a standing start, three to six where an ISO 27001 system exists. Treat all of these as one body’s or one trade’s figures. The larger cost is internal: the inventory, the assessments and the records.

If your scope is not 100% clear, your governance and your audit will fail. Fran Caballero, ISO 42001 auditor, BSI · BSI webinar with Darktrace, May 2026

Caballero names three failures BSI sees: scope that does not say where the AI starts and ends; metrics borrowed from ordinary IT that say nothing about drift, fairness or data accuracy; and policies downloaded to pass an audit. Before any of that comes the inventory: an auditor’s first request is a list of the AI systems in scope with their intended use.

How have the first certified organisations done it?

OrganisationCertifiedScopeWhat stands out
AWSNov 2024, SchellmanBedrock, Q Business, Textract, TranscribeGovernance organised along the seven AI life-cycle stages of ISO/IEC 22989. First surveillance audit, Nov 2025, no findings
AnthropicJan 2025, SchellmanAI products and services, including the Claude modelsLinks the management system to its Responsible Scaling Policy
MicrosoftMar 2025, recertified May 2026Nine named Copilot and Foundry productsA risk-tiered review so senior oversight goes to higher-impact systems. Scope grew from two to three systems in year two
DarktraceJul 2025, BSIIts AI-driven security productsBuilt on an existing ISO 27001 and 27018 system. Every AI change now passes an impact assessment before production
Metyis, AmsterdamJul 2025, DNVIts AI management systemFirst ISO 42001 certificate issued in the Netherlands, under RvA accreditation

Google Cloud, Workday, Snowflake, Salesforce, SAP, IBM (for its Granite models), KPMG in the US and BCG have also announced certificates; BCG counted itself in January 2026 among the first 100 organisations worldwide. As far as we could establish, no Dutch bank, insurer or public body had announced one by September 2026.

When we change an AI system, what happens is now it goes through AI impact assessments covering data quality, bias, risk and customer impact before it’s actually deployed into production. Darktrace compliance team · BSI webinar, May 2026

Three patterns run through these accounts. The scope is narrow and named. The system is built on existing ISO 27001 machinery, with the AI assessments and the five new control areas added; Darktrace’s team said it “didn’t build ISO 42001 from scratch”. And the visible operational change is a gate: an impact assessment before an AI system, or a change to one, reaches production.

The commercial effect is already visible. Microsoft’s supplier programme, SSPA, requires ISO 42001 certification for suppliers whose AI use it classes as sensitive or high-risk, according to Schellman. For a vendor, the cost of not having the certificate, or a dated plan for one, is a longer questionnaire now and exclusion from some work later. For a buyer, asking for it is the cheapest check that a supplier keeps an inventory, assesses impact and monitors after release.

How does it sit next to the EU AI Act?

ISO 42001 is not a harmonised standard under the AI Act, and certification gives no presumption of conformity. CEN-CENELEC JTC 21 wrote its own quality-management standard for Article 17, EN 18286, approved in July 2026, because Article 17 attaches to each high-risk system as a product while 42001 governs an organisation. As of September 2026 no AI Act harmonised standard has been cited in the Official Journal. 42001 was adopted as a European standard in 2026; adoption is not harmonisation.

EU AI ActISO/IEC 42001
What it isLaw, in force in stages from 2025 to 2028A voluntary standard you can be certified against
Who it bindsProviders and deployers, by role and by risk tierWhoever chooses it, within the scope they define
The unitEach AI system, classified by its intended purposeThe organisation’s management system
What it provesThat the obligations for that system were metThat an accredited auditor found a working management system
Where they overlapRisk management, data governance, documentation and logging, human oversight, monitoring after release, supplier management, communicating incidents
What 42001 does not coverConformity assessment, CE marking and the declaration of conformity; registration in the EU database; the Article 27 fundamental rights impact assessment; Article 73 incident-reporting deadlines; the Annex IV technical file per system
It doesn’t mean that you’re automatically compliant, but it does mean it’s your first rung on the ladder. It’s your first step into compliance. Will Booth, Director of Cybersecurity Compliance, Darktrace · on the AI Act, BSI webinar, May 2026

The practical arrangement, for an organisation that faces both, is one management system and one file per AI system. The management system carries the policy, the assessments, the audits and the reviews; the per-system file carries what the Act asks for that system, which we set out in what the AI Act asks of a deployer.

Where does Aitonomy fit?

Most of what clauses 8 and 9 and the life-cycle controls ask for is operating evidence: what each AI system is for, who oversees it, what it did, what was checked and what changed. For an agent workforce, that is the record Aitonomy Control keeps.

What Control holds for an auditor

Per agent role · six kinds of evidence

  1. Intended use and scope.Each agent has a defined job, a named human owner and explicit limits on what it may do. The Scan produces the inventory of the work and systems involved before anything runs. (A.9.4; clause 4.3.)
  2. Human oversight.Every capability runs at a supervision level, Suggests, Drafts or Auto, promoted on evidence and reduced by rule. Each approval is recorded with its reason. (A.9.2; clause 5.3.)
  3. Operation, monitoring and event logs.Every action in production is recorded with the checks that ran, the reviewer and the outcome, and governance changes sit in the same history. (A.6.2.6; A.6.2.8; clause 9.1.)
  4. Verification and validation.A model change sends the agent back to its held-out test cases before it keeps its level; exceptions, policy breaches and quality gates are tracked over time. (A.6.2.4.)
  5. Third-party models.Each role uses an approved model from a provider you can change; every connection to your systems shows how it is secured. (A.10.3; A.4.)
  6. Correction and improvement.Accepted human corrections become proposed changes to the role; every applied change is visible and reversible. (Clause 10.)

What Control does not do is write the management system. The AI policy, the scope, the assessments, the internal audit, the management review and the Statement of Applicability remain the organisation’s own documents, and they are the ones a certification body reads first. Where an impact assessment is needed before an agent goes live, we prepare the operational input: the agent’s purpose, the data it touches, its limits and the supervision it will run under; the decision to accept the impact belongs to the customer’s accountable process owner. Aitonomy does not hold an ISO 42001 certificate and does not certify anyone; the mapping above is ours, not an auditor’s.

Take one AI system you already run and ask the standard’s questions of it. What is it for, who owns it, what could it do to the people on the other end, what did it do last week, and who checked? If the answers exist as records, certification is a question of scope and an audit date. If they do not, that is the work, worth doing whether or not a questionnaire ever asks.

Common questions

What is ISO 42001, in plain terms?+
ISO/IEC 42001:2023 is the international standard for an AI management system: the policies, roles, assessments, records and reviews through which an organisation governs the AI it develops, provides or uses. It shares its structure with ISO 27001, adds AI risk and impact assessments, and lists 38 controls to choose from. An accredited body can certify an organisation against it.
Does ISO 42001 certification mean compliance with the EU AI Act?+
No. ISO 42001 is not a harmonised standard under the AI Act and gives no presumption of conformity. It covers much of the same ground but not the Act’s product-level duties such as conformity assessment, CE marking, registration or the fundamental rights impact assessment. It is a useful base for AI Act work, not a substitute for it.
Do you need ISO 27001 before ISO 42001?+
No. The standard states that it does not require any other management system to be implemented or certified first. In practice most early adopters built on an existing ISO 27001 system and added the AI-specific assessments and controls on top.

Sources and scope

Watch and listen

Mik Nijhuis

Co-founder and Chief AI Officer

Mik has architected enterprise systems for ABN AMRO, Aegon and Shell. He builds agent systems that add throughput without removing the controls complex organisations need.

Aitonomy builds and runs agent roles for recurring business work, supervised in production and measured against a baseline agreed before the first live case.What we do

All insights

Fieldwork

How an agent workforce is actually run. The roles we put into production, and the evidence behind the decisions.

Ready when you are

Bring one workflow.
Leave with a business case.

Bring us the work that slows your teams down. We will map it, count what it costs today, and select the first role only when the numbers support it.