Regulations & standards

ISO/IEC 42001, explained.

The international management-system standard for artificial intelligence — the certifiable framework for governing how a firm builds, buys and runs its AI, and the standard AIssure's ISO Deep Dive is built to prepare you for.

Scope
International standard
Body
ISO/IEC
Applies to
Any organisation operating AI
Status
Certifiable (2023)

What ISO/IEC 42001 is

ISO/IEC 42001:2023 is the international management-system standard for artificial intelligence — it sets out the requirements for establishing, implementing, maintaining and continually improving an AI management system, or AIMS. It is the AI analogue of ISO/IEC 27001 for information security: not a checklist of controls but a structured, auditable management discipline for how an organisation governs the AI it develops, provides or uses.

Because it is a management-system standard, it is certifiable. An organisation can be assessed against it by an accredited certification body and, where it conforms, hold a certificate — the same mechanism that makes ISO 27001 certification meaningful to a counterparty or a supervisor.

The standards around it

ISO/IEC 42001 does not stand alone. Two related standards inform how a firm meets it:

  • ISO/IEC 23894 — guidance on AI risk management: how to identify, assess and treat the risks an AI system carries.
  • ISO/IEC 38507 — the governance implications of AI for the organisation and its governing body: what a board needs to understand and oversee when the firm uses AI.

ISO/IEC 42001 is the certifiable framework; 23894 and 38507 are the risk-management and governance guidance that sit beneath it. Read against each other, they describe a complete governance posture — which is why a serious readiness assessment maps across all three rather than treating 42001 in isolation.

Why it matters for regulated finance

For a bank, asset manager or insurer, a 42001 certificate is becoming the shorthand a procurement team, a counterparty or a regulator recognises: evidence that AI is governed under a recognised, independently audited system rather than by informal practice. It does not replace jurisdictional regulation — it is a management standard, not a supervisory rule — but it is the common language a certification body will hold you to.

How AIssure maps to it

AIssure's ISO Standards Deep Dive is a 275-question assessment mapped to ISO/IEC 42001, 23894 and 38507. It works through the requirements of the standard the way a certification audit does — but ahead of it — and produces two things the audit expects to see: an evidence base assembled against each clause, and a gap-remediation plan ranked by where you fall short of conformity.

Every finding is traced to the provision it was tested against, on a regulatory knowledge graph — so when the certification body asks you to show your working, the citation trail is already there. The result is a defensible, point-in-time picture of readiness, comparable across engagements and reproducible at re-performance.

Certification-ready, not certified

An assessment prepares you for certification; it does not grant it. Accredited ISO/IEC 42001 certification is issued only by accredited certification bodies such as BSI, Schellman or A-LIGN. AIssure produces the evidence base and remediation plan a certification audit expects — so we say certification-ready, never "certified." Independence is the reason: the firm preparing your evidence cannot also be the body that certifies it.

The primary source

The definitive text is published by ISO. Read it at ISO/IEC 42001:2023, and see how it sits alongside the jurisdictional regimes in AIssure's regulatory coverage.

FAQ

ISO/IEC 42001 — the questions we get.

What buyers, compliance teams and AI assistants ask about the AI management-system standard and readiness for it.

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the international management-system standard for artificial intelligence — it specifies the requirements for an AI management system (an AIMS). It is the AI analogue of ISO/IEC 27001 for information security: a structured, auditable way to govern how an organisation develops, provides or uses AI. It is certifiable by accredited certification bodies.

Does AIssure certify us to ISO 42001?

No. AIssure delivers a certification-ready assessment; it does not certify. Accredited ISO/IEC 42001 certification is issued only by accredited certification bodies such as BSI, Schellman or A-LIGN. AIssure produces the evidence base and gap remediation those bodies expect to see — the language is deliberately 'certification-ready', never 'certified'.

How do ISO 23894 and ISO 38507 relate to ISO 42001?

They are complementary. ISO/IEC 23894 gives guidance on AI risk management, and ISO/IEC 38507 addresses the governance implications of AI for the organisation and its governing body. ISO/IEC 42001 is the certifiable management-system standard; 23894 and 38507 inform how you meet it. AIssure's ISO Deep Dive maps across all three.

How does AIssure prepare us for a 42001 audit?

The 275-question ISO Standards Deep Dive maps to ISO/IEC 42001, 23894 and 38507 and produces the evidence base plus a gap-remediation plan a certification audit expects — every finding traced to the clause it was tested against. You walk into the certification body's audit with the documentation already assembled.

Next step

Start with a thirty-minute read on your readiness.

A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.