ISO/IEC 42001, explained.
The international management-system standard for artificial intelligence — the certifiable framework for governing how a firm builds, buys and runs its AI, and the standard AIssure's ISO Deep Dive is built to prepare you for.
What ISO/IEC 42001 is
ISO/IEC 42001:2023 is the international management-system standard for artificial intelligence — it sets out the requirements for establishing, implementing, maintaining and continually improving an AI management system, or AIMS. It is the AI analogue of ISO/IEC 27001 for information security: not a checklist of controls but a structured, auditable management discipline for how an organisation governs the AI it develops, provides or uses.
Because it is a management-system standard, it is certifiable. An organisation can be assessed against it by an accredited certification body and, where it conforms, hold a certificate — the same mechanism that makes ISO 27001 certification meaningful to a counterparty or a supervisor.
The standards around it
ISO/IEC 42001 does not stand alone. Two related standards inform how a firm meets it:
- ISO/IEC 23894 — guidance on AI risk management: how to identify, assess and treat the risks an AI system carries.
- ISO/IEC 38507 — the governance implications of AI for the organisation and its governing body: what a board needs to understand and oversee when the firm uses AI.
ISO/IEC 42001 is the certifiable framework; 23894 and 38507 are the risk-management and governance guidance that sit beneath it. Read against each other, they describe a complete governance posture — which is why a serious readiness assessment maps across all three rather than treating 42001 in isolation.
Why it matters for regulated finance
For a bank, asset manager or insurer, a 42001 certificate is becoming the shorthand a procurement team, a counterparty or a regulator recognises: evidence that AI is governed under a recognised, independently audited system rather than by informal practice. It does not replace jurisdictional regulation — it is a management standard, not a supervisory rule — but it is the common language a certification body will hold you to.
How AIssure maps to it
AIssure's ISO Standards Deep Dive is a 275-question assessment mapped to ISO/IEC 42001, 23894 and 38507. It works through the requirements of the standard the way a certification audit does — but ahead of it — and produces two things the audit expects to see: an evidence base assembled against each clause, and a gap-remediation plan ranked by where you fall short of conformity.
Every finding is traced to the provision it was tested against, on a regulatory knowledge graph — so when the certification body asks you to show your working, the citation trail is already there. The result is a defensible, point-in-time picture of readiness, comparable across engagements and reproducible at re-performance.
Certification-ready, not certified
An assessment prepares you for certification; it does not grant it. Accredited ISO/IEC 42001 certification is issued only by accredited certification bodies such as BSI, Schellman or A-LIGN. AIssure produces the evidence base and remediation plan a certification audit expects — so we say certification-ready, never "certified." Independence is the reason: the firm preparing your evidence cannot also be the body that certifies it.
The primary source
The definitive text is published by ISO. Read it at ISO/IEC 42001:2023, and see how it sits alongside the jurisdictional regimes in AIssure's regulatory coverage.
Related
ISO Standards Deep Dive
275 questions across ISO/IEC 42001, 23894 and 38507.
→ CoverageRegulations & standards
The eight jurisdictions and the instruments within them.
→ The moatThe regulatory knowledge graph
How the citation trail is built, versioned and verified.
→ The categoryThe AI governance audit
The productised, point-in-time assessment, explained.
→ISO/IEC 42001 — the questions we get.
What buyers, compliance teams and AI assistants ask about the AI management-system standard and readiness for it.
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the international management-system standard for artificial intelligence — it specifies the requirements for an AI management system (an AIMS). It is the AI analogue of ISO/IEC 27001 for information security: a structured, auditable way to govern how an organisation develops, provides or uses AI. It is certifiable by accredited certification bodies.
Does AIssure certify us to ISO 42001?
No. AIssure delivers a certification-ready assessment; it does not certify. Accredited ISO/IEC 42001 certification is issued only by accredited certification bodies such as BSI, Schellman or A-LIGN. AIssure produces the evidence base and gap remediation those bodies expect to see — the language is deliberately 'certification-ready', never 'certified'.
How do ISO 23894 and ISO 38507 relate to ISO 42001?
They are complementary. ISO/IEC 23894 gives guidance on AI risk management, and ISO/IEC 38507 addresses the governance implications of AI for the organisation and its governing body. ISO/IEC 42001 is the certifiable management-system standard; 23894 and 38507 inform how you meet it. AIssure's ISO Deep Dive maps across all three.
How does AIssure prepare us for a 42001 audit?
The 275-question ISO Standards Deep Dive maps to ISO/IEC 42001, 23894 and 38507 and produces the evidence base plus a gap-remediation plan a certification audit expects — every finding traced to the clause it was tested against. You walk into the certification body's audit with the documentation already assembled.
Start with a thirty-minute read on your readiness.
A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.