ISO 42001
ISO/IEC 42001:2023
The first international standard for managing artificial intelligence responsibly.
Issuer
ISO / IEC
Region
Global
Published
December 2023
Outcome
Accredited certification
Overview
What is ISO 42001?
ISO/IEC 42001:2023 is the world's first certifiable standard for an Artificial Intelligence Management System (AIMS). Published in December 2023, it gives organizations a structured way to develop, deploy, and govern AI systems responsibly.
It follows the same management-system structure as ISO 27001, so if you already run an ISMS, much of the governance scaffolding carries over. It's quickly becoming the credential for companies that build or rely on AI and want to prove it's well-governed.
Who needs it: Any organization that develops, provides, or uses AI systems — and wants to demonstrate responsible AI governance to customers, partners, and regulators ahead of laws like the EU AI Act.
Inside the framework
What an AI Management System covers
AI policy & governance
Leadership-approved objectives, roles, and accountability for how AI is built and used.
AI risk & impact assessment
Systematic assessment of risks and impacts to individuals and society across the AI lifecycle.
The AI system lifecycle
Responsible design, development, verification, deployment, and monitoring of AI systems.
Data for AI
Governance of the data used to build and run AI — quality, provenance, and appropriate use.
Transparency & third parties
Information for affected parties, and managing suppliers and components in your AI supply chain.
With RegShield
Get ISO 42001-ready in a fraction of the time
AI evidence mapping
Upload a policy, screenshot, or config and RegShield maps it to the right ISO 42001 controls in seconds — with confidence scores you can defend in front of an auditor.
Reuse across frameworks
Evidence you collect for ISO 42001 is automatically reused across every other framework you've activated — so the work compounds instead of repeating.
Gaps & audit-ready reports
See your ISO 42001 readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.
FAQ
Common questions
Who needs ISO 42001?
Any company building products on AI or LLMs, or deploying AI in regulated workflows, that wants a recognized governance credential.
Does it overlap with ISO 27001?
Yes — the management-system clauses are shared. An existing ISMS gives you a big head start on the AIMS, and RegShield reuses that evidence.
How does it relate to the EU AI Act?
ISO 42001 is voluntary, but its governance practices map closely to what the EU AI Act expects, making it a practical way to prepare.