[email protected]
Accredited Certification Body · IAS & IAF Member · Certificates Verifiable Online
HomeStandardsISO/IEC 42001

Get Your ISO/IEC 42001 Quote

Takes 30 seconds · a specialist responds within 2 business hours
Step 1 of 2
CertificationTrainingCompliance Audits
Not sure - guide me
ISO/IEC 42001
No spam. No obligation. A clear quote.
15,000+Certified Clients
30+Countries Served
IAS · IAFAccredited
ISO/IEC 42001:2023 · Artificial Intelligence Management

Certified governance for the AI you build and deploy so procurement stops stalling

ISO/IEC 42001 certifies that an organisation manages its AI systems deliberately: an inventory of what is deployed, an assessment of who the outputs affect, controls over training data and model change, and named humans accountable for oversight. It is what enterprise buyers, regulators and boards now ask for when AI sits inside a product or a decision.

You need ISO/IEC 42001 if…

  • !A customer’s procurement team has sent an AI governance questionnaire and your answers are currently verbal.
  • !You are shipping a product with a model inside it into the European market.
  • !The board has asked who signed off the model now making credit, pricing or eligibility decisions.
  • !An internal team adopted a third-party model and nobody can say what data it sees.
  • !A regulator or ombudsman questioned an automated decision and you have no impact assessment on file.
  • !You already hold ISO/IEC 27001 and the same buyers are now asking about AI specifically.
What it is

A management system standard for organisations that develop, supply or use artificial intelligence. It asks you to know which AI systems you run, judge the harm they could cause, control the data and models behind them, and keep people answerable for the outputs.

Who issues it

ISO/IEC 42001 is certified by an accredited certification body such as SIS after a two-stage audit. It is not a self-declaration and not a product approval.

Validity

The certificate runs three years, with a surveillance audit each year and a full recertification audit before it expires.

Who gets asked for it

Software vendors, banks, insurers, health and public bodies, and manufacturers embedding models in products or in release and pricing decisions.

8of 25 industries

Where this certification is demanded

ISO/IEC 42001 is applicable across 8 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.

Public SectorTelecommunication IndustryElectricals and Electronics IndustryEducation IndustryInformation Technology IndustryAutomotive Industry+2 more

What ISO/IEC 42001 Actually Requires

The backbone an implementer has to build, in the order it usually gets built.

1
AI role & scope

Decide whether you develop, supply or use each AI system, list them all, and set the boundary of the management system accordingly.

2
Policy & accountability

Top management signs an AI policy, allocates budget and names who owns each model, including who has authority to stop it running.

3
Risk & impact assessment

Assess risk to the organisation and, separately, the impact on individuals and society, then record which Annex A controls apply and why.

4
Data & competence

Document the provenance, quality and labelling of training and input data, and show the people reviewing model outputs are competent to do it.

5
Lifecycle controls

Set design objectives, validate before release, control model and prompt changes, keep human oversight, and hold suppliers of models to the same terms.

6
Monitoring & improvement

Track performance and drift in live use, log AI incidents and complaints, audit internally, and take the findings to management review.

How ISO/IEC 42001 Certification Works

No black box. A defined, time-bound route from first call to certificate in hand.

Application & Proposal

We scope by counting AI systems, not headcount alone: which models you build versus buy, whether decisions are automated or advisory, and how many sites and development teams are involved.

1–2 days

Gap Review & Readiness

A model gets retrained on Friday to fix a complaint, and by Monday it is scoring applications differently. Nobody wrote that down. That absence is what stalls a Stage 2.

1–2 weeks

Stage 1 + Stage 2 Audit

Stage 1 checks scope, AI policy, Statement of Applicability and the impact assessment method. Stage 2 traces a live system end to end, from data source to human override.

Scheduled around operations

Certificate Issued

The certificate names your AI scope. Surveillance is where it bites: the auditor returns to a different inventory and asks what governance ran on the systems added since.

Valid 3 years
Eight to sixteen weeks is typical, though a tender date named at application lets SIS compress the audit schedule, and the real driver is how many AI systems sit in scope.

Industries That Need ISO/IEC 42001

🏛️
Public Sector
Open full page →
Why it applies hereGovernments deploying AI in benefits assessment, policing, revenue and public service delivery face acute fairness, transparency and accountability scrutiny. ISO/IEC 42001 provides governance over AI system inventory, impact assessment, data quality and human oversight, letting a department demonstrate responsible deployment before public and parliamentary review.Typical trigger: AI deployment governance; public scrutiny
📡
Telecommunication Industry
Open full page →
Why it applies hereOperators deploy AI in network optimisation, fraud detection, churn prediction and customer service. ISO/IEC 42001 provides governance over AI system inventory, data quality, bias assessment and human oversight, which matters where automated decisions affect subscriber pricing, credit or service access.Typical trigger: AI in network and customer decisions
🔌
Electricals and Electronics Industry
Open full page →
Why it applies hereManufacturers embedding AI in products, and those using AI in inspection, yield prediction and quality decisions, need governance over data quality, model change and human oversight. ISO/IEC 42001 provides that framework and supports the AI-related conformity questions now appearing in European product regulation.Typical trigger: AI-enabled products; AI in quality decisions
🎓
Education Industry
Open full page →
Why it applies hereInstitutions deploying AI in admissions, proctoring, grading and learning personalisation face fairness and transparency questions with direct consequences for students. ISO/IEC 42001 provides governance over AI inventory, impact assessment, data quality and human oversight, allowing the institution to defend automated decisions.Typical trigger: AI in admissions and assessment
💻
Information Technology Industry
Open full page →
Why it applies hereFirms building or deploying AI face customer and regulatory demands for demonstrable governance. ISO/IEC 42001 covers AI system inventory, impact assessment, data quality, model change control and human oversight, and is emerging as the certification enterprise buyers request when procuring AI-enabled products.Typical trigger: AI product procurement; EU AI Act readiness
🚗
Automotive Industry
Open full page →
Why it applies hereAI is now embedded in driver assistance, quality inspection and predictive maintenance. ISO/IEC 42001 provides governance over AI system inventory, data quality, model change control and human oversight, supporting the safety argument and the regulatory scrutiny that automated driving features attract.Typical trigger: ADAS and AI inspection governance
🏦
Banking and Finance
Open full page →
Why it applies hereAI now drives credit decisioning, fraud detection, collections and customer servicing, where automated outcomes affect access to finance and attract fairness scrutiny. ISO/IEC 42001 provides governance over model inventory, data quality, bias assessment and human oversight, supporting explainability to regulators and customers.Typical trigger: Credit decisioning; model governance
🏭
Manufacturing Industries
Open full page →
Why it applies hereManufacturers using AI for visual inspection, predictive maintenance, scheduling and yield optimisation need governance over data quality, model change and human oversight, particularly where AI decides whether product is released. ISO/IEC 42001 provides that framework and supports AI-related questions in customer and regulatory assessments.Typical trigger: AI-based inspection and release decisions

Commonly taken alongside

AI governance sits on top of information security and privacy, so organisations usually certify ISO/IEC 27001 and 27701 alongside 42001 and have SIS audit them together, which removes a duplicated set of interviews and evidence requests on audit day.

Not Sure Which Certification You Need?

Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.

Question 1 of 3

Which sector best describes your organisation?

How many of your models have a named owner?

Two numbers matter. How many models are in production, and how many have an impact assessment written before deployment? An ISO/IEC 42001 audit starts with the gap between them.

Get My Free Quote →

What ISO/IEC 42001 Changes for Your Business

Certification is not a certificate on the wall. It is a working system that pays for itself.

📄

Answers the AI questionnaire

Procurement questionnaires stop being a scramble. The inventory, impact assessments and oversight records already exist, so responses take days rather than weeks.

🧭

Shadow AI comes into view

Building the inventory surfaces the models teams adopted without review, and the data those models have been reading. The list is usually longer than the one IT keeps.

📐

Groundwork for AI regulation

Risk classification, technical documentation, logging and human oversight are what emerging AI law asks for, so the same evidence serves both purposes.

🔁

Model changes stop surprising you

Version control, retraining triggers and release approval mean a model does not quietly change behaviour between a demonstration and a production decision.

🏛️

Something to show the board

Directors asking who is accountable for AI get a named owner, a risk register and an audit report from an independent body.

🌐

Accepted without a second audit

An accredited certificate carries through the IAF arrangement, so a buyer in another country accepts it without commissioning an audit of its own.

Knowledge Base - Downloads

Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.

PDF GUIDE

ISO/IEC 42001 implementation guide for AI teams

Clause-by-clause walkthrough with the Annex A controls explained in plain terms, and worked examples for a developer and a deployer.

TEMPLATE

AI system inventory and impact assessment

A working register covering purpose, role, data sources, affected groups, oversight owner and review date, ready to populate.

CHECKLIST

Pre-audit readiness check for AIMS

Fifty questions an auditor is likely to ask, arranged by clause, with the record each one expects to see.

WHITEPAPER

Where 42001 meets AI regulation

How management system evidence maps onto the risk classification, technical documentation and human oversight duties appearing in new AI legislation.

🔒 Documents are locked. Fill the form once to unlock every download.

Frequently Asked Questions

Straight answers to what buyers ask before they commit to ISO/IEC 42001.

Does ISO/IEC 42001 certify our AI model, or the organisation?
The organisation. Certification covers the management system that governs AI across its lifecycle, not the accuracy or safety of any single model. An auditor will sample specific systems to test whether the controls operate, but the certificate is issued against a scope of activity and sites. No certification body can certify a model as fair, safe or correct.
We only use AI bought from vendors. Does the standard still apply?
Yes. ISO/IEC 42001 distinguishes roles, and a deployer or user of AI has obligations of its own: knowing what the system does, assessing impact on the people affected, checking what the supplier commits to, keeping human oversight, and monitoring outputs in live use. Many certified organisations build nothing and buy everything.
Does certification make us compliant with the EU AI Act?
No, and be wary of anyone who says it does. Certification against a management system standard does not confer legal conformity or a presumption of it. What it does is build the underlying machinery the law expects, such as risk classification, technical documentation, logging, data governance and human oversight, so the compliance work has somewhere to sit.
Can we add 42001 to an existing ISO/IEC 27001 certificate?
They remain separate certificates, but they integrate well. Both use the same harmonised management system structure, so context, leadership, competence, internal audit and management review can be run once and audited once. SIS can combine the audits, which typically saves audit days and stops the same evidence being requested twice.
What does the AI impact assessment actually have to cover?
Who the system affects, how badly it could affect them, and what happens if it is wrong. That means identifying the individuals or groups subject to the outputs, the potential harms including bias and loss of access to a service, the data the system relies on, the oversight in place, and the point at which a human intervenes.
How long is the certificate valid and what happens each year?
Three years. A surveillance audit takes place each year, and it will look at what changed: new models deployed, retraining events, incidents logged, complaints about automated outputs, and whether the inventory was kept current. Before the third year ends, a recertification audit reviews the whole system again and a new certificate is issued.
Email Us
✉ EmailGet Quote