GLOSSARY · LEADERSHIP & GRC

ISO/IEC 42001

ISO/IEC 42001 is the international standard, published in 2023, for AI management systems: a certifiable framework for governing how an organization develops and uses AI responsibly.

It does for AI what ISO/IEC 27001 does for information security, defining policies, roles, risk processes, and continual improvement, and organizations can be audited and certified against it.

The value sits less in the content of the standard than in what certification signals. Most AI governance frameworks are voluntary and self-assessed, which makes them hard to point at in a procurement conversation. ISO/IEC 42001 is certifiable by an accredited body, so it answers the question enterprise buyers and regulators increasingly ask: not whether you have AI governance, but who checked.

Structurally it will feel familiar to anyone who has run a 27001 program, because it uses the same management system pattern. Define scope and context, set objectives, assign roles, run a risk assessment, apply controls, monitor, audit, improve. If you already hold 27001 the two integrate rather than duplicate, and much of the machinery you have built (internal audit, management review, corrective action) is reused directly. The AI-specific additions are an impact assessment for AI systems, controls covering data quality and provenance, and requirements for human oversight and transparency.

The honest caveat is cost and timing. Certification takes months and consumes real audit budget, so it earns its place when you sell AI-enabled products into regulated or enterprise markets, or when a customer has already asked for it. If nobody is asking yet, the NIST AI RMF gives you most of the same risk discipline at no cost and without the audit, and the work maps onto 42001 later if certification becomes necessary.