ISO 42001: what an AI management system actually requires

7 min read

ISO/IEC 42001 specifies requirements for an AI management system: the governance structure an organisation puts around AI, rather than the properties of any individual model. It follows the familiar management-system pattern, so if you hold ISO 27001 the shape is recognisable. The novel parts are the AI-specific impact assessment and the requirement to maintain a current inventory of AI systems and their purposes.

What kind of standard this is

ISO 42001 is a management-system standard, in the same family as 27001 for information security and 9001 for quality. That determines what it audits. Certification does not assert that your models are accurate, fair or safe. It asserts that you have a defined system for governing them, that the system is operating, and that you can produce evidence of both.

This distinction disappoints people expecting a seal of approval on model behaviour, and it is what makes the standard practical. Auditable claims are claims about process, because process is what an auditor can observe.

Where it overlaps 27001, and where it does not

The management-system scaffolding is shared: leadership commitment, scope definition, risk process, documented objectives, competence, internal audit, management review, continual improvement. An organisation with a working ISMS can reuse most of that structure and should.

The AI-specific additions are where the work is. The standard expects an AI system impact assessment that considers effects on individuals and society, not only on the organisation, which is a wider frame than a security risk assessment. It expects lifecycle controls covering data provenance, model development and post-deployment monitoring. And it expects a maintained record of the AI systems in scope, their purposes and their classifications.

The inventory requirement is the hard one

Most of the clauses can be satisfied by writing and approving documents. The inventory cannot, because it has to be true on the day the auditor asks, and it decays continuously as teams ship.

This is the clause that most often exposes the gap between the governance programme and the organisation. A register maintained by asking teams to self-declare is complete only to the extent that teams remember and comply. Registers built that way are routinely missing the systems that matter most, because unsanctioned deployments are precisely the ones nobody declares.

The durable approach is to derive the inventory from observation rather than attestation, then use the declared register as a reconciliation target: anything running that is not registered is a finding, and finding it is the point.

Evidence a certification audit asks for

Beyond the documented policies, expect requests for operational records:

  • The current AI system inventory, with owners and stated purposes.
  • Impact assessments for systems in scope, with dates and named assessors.
  • Records of decisions to deploy, including what was considered and rejected.
  • Evidence that post-deployment monitoring runs and that someone reviews its output.
  • Incident records, including AI-specific incidents and what changed afterwards.
  • Internal audit results and management review minutes covering the AIMS.

How it relates to the EU AI Act

They are different instruments. ISO 42001 is a voluntary certifiable standard; the AI Act is law with penalties. Certification does not confer legal compliance, and no auditor will tell you it does.

The relationship is that the evidence substantially overlaps. An organisation running a functioning AIMS is generating most of what AI Act obligations require: an inventory, risk assessments, oversight records and monitoring. Building for one and treating the other as a mapping exercise is considerably cheaper than running two programmes.

Frequently asked

Do we need ISO 42001 if we already have ISO 27001?

27001 does not cover AI-specific risks such as model behaviour, data provenance or societal impact. If AI is material to what you sell or how you operate, 42001 addresses the gap, and you can extend your existing management system rather than building a separate one.

How long does certification take?

It depends far more on how much of the management-system scaffolding you already have than on the AI-specific work. Organisations extending a mature ISMS move considerably faster than those building a management system from scratch.

Does ISO 42001 certification satisfy the EU AI Act?

No. It is a voluntary standard, not a legal conformity route, and certification is not a defence. It is useful because the evidence it makes you produce is largely the evidence the Act asks for.

What is the most common reason organisations fail the audit?

An inventory that does not match reality. Policies are straightforward to write and easy to approve; a live, accurate register of every AI system in the organisation is the control that requires the programme to actually function.

Bulwark does this in production

Agent registry, scope enforcement, human approvals and a hash-chained evidence trail you can verify without trusting us. Free Developer tier, 100,000 governed decisions a month, no card required.

Related guides