Fast-Track · Weeks, Not Months

ISO 42001

Artificial Intelligence Management System Certification

ISO/IEC 42001:2023 is the first certifiable standard for AI management systems (AIMS). Praxis-Q delivers end-to-end certification - gap analysis through Stage 2 audit - and maps it onto your existing ISO 27001 ISMS so one governance system covers both.

ISO/IEC 42001:2023 is the first certifiable management system standard for artificial intelligence. Published in December 2023, it defines requirements for establishing, implementing, maintaining and continually improving an AI Management System (AIMS), and applies to any organisation that develops, provides or uses AI systems - not only to model builders. The standard follows the same Annex SL harmonised structure as ISO 27001, with clauses 4 to 10 covering context, leadership, planning, support, operation, performance evaluation and improvement, plus an Annex A of 38 controls grouped under nine objectives spanning AI policy, internal organisation, resources, impact assessment, system lifecycle, data, information for interested parties, use of AI systems, and third-party relationships. Praxis-Q delivers the full path - scoping, AI risk and impact assessment, AIMS documentation, internal audit, and Stage 1 and Stage 2 certification support - and integrates it with an existing ISO 27001 ISMS wherever one is already in place, so governance is extended rather than duplicated.

At a Glance

DeliveryWeeks
Controls38 Annex A
Valid3 years
Published2023

ISO 42001

ISO 42001

Artificial Intelligence Management System Certification

The Problem

Enterprise buyers and regulators now ask how your AI is governed. Without a certified AI management system, AI features stall in procurement review and EU AI Act questions have no defensible answer.

What We Do

  • Scope & Gap Analysis
  • AI Risk & Impact Assessment
  • AIMS Documentation
  • Internal Audit
  • Certification

What You Get

  • First certifiable AI governance standard
  • Answers enterprise AI procurement questionnaires
  • Structures EU AI Act readiness work
  • Shares Annex SL structure with ISO 27001
  • Covers AI developers, providers and deployers
  • Evidences responsible-AI claims to customers
  • Reduces model, data and third-party AI risk
  • Differentiates in AI-enabled product tenders

Who ISO 42001 Applies To

The standard is deliberately role-aware. It covers AI developers and providers who build or supply models and AI-enabled products, and equally the deployers who put third-party AI to work inside their own processes. If you fine-tune a model, embed a vendor API in a customer-facing product, or use AI in decisions that affect people, you are in scope. Praxis-Q begins every engagement by fixing the AI system inventory and the role you occupy for each, because scope drives which of the 38 Annex A controls are applicable and what your Statement of Applicability has to justify.

The 38 Annex A Controls and the Statement of Applicability

Annex A organises 38 controls under nine objectives - policies related to AI, internal organisation, resources for AI systems, assessing impacts of AI systems, AI system lifecycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. As with ISO 27001, controls are selected and justified in a Statement of Applicability rather than applied wholesale. Annex B gives implementation guidance, Annex C catalogues AI-specific risk sources, and Annex D addresses sector and domain use. We work control by control, producing the artefacts an auditor asks to see.

AI Risk Assessment and AI System Impact Assessment

ISO 42001 requires two distinct exercises that organisations often conflate. AI risk assessment looks inward at risks to the organisation and its objectives. The AI system impact assessment looks outward at consequences for individuals, groups and society - fairness, transparency, safety, and the effect of automated decisions on people. Both must be documented, repeatable and revisited as systems change. Praxis-Q supplies the methodology, runs the first cycle with your teams, and leaves you able to run subsequent cycles unaided.

ISO 42001 and the EU AI Act

The two are frequently mentioned together and should not be confused. ISO 42001 is a voluntary standard you can certify against; the EU AI Act is binding law with obligations that vary by risk classification. Certification does not confer a legal presumption of conformity. What it does is produce the governance spine - risk management, data governance, technical documentation, human oversight, lifecycle records - that Act readiness work draws on, which is why organisations preparing for the Act frequently start here. We are explicit about the boundary rather than selling certification as legal cover.

Integrating With an Existing ISO 27001 ISMS

If you already hold ISO 27001, most of the management system machinery is reusable. Annex SL means the clause structure, internal audit programme, management review cadence, corrective action process and document control can be extended to cover AI rather than duplicated. What is genuinely new is the AI-specific content: the AI policy, the system inventory, impact assessment, data provenance and quality controls, and third-party AI supplier management. Praxis-Q runs combined engagements so a single audit cycle and a single evidence set serve both certificates.

Frequently Asked Questions

Is ISO 42001 the same as the EU AI Act?
No. ISO 42001 is a voluntary certifiable management standard; the EU AI Act is law. A certified AIMS produces much of the governance evidence the Act expects, but it is not a legal presumption of conformity.
We already hold ISO 27001 - does that help?
Considerably. Both use the Annex SL harmonised structure, so scope, risk process, internal audit and management review can be extended rather than rebuilt.
What is ISO/IEC 42001:2023?
It is the first international certifiable standard for AI management systems, published in December 2023. It specifies requirements for an AI Management System (AIMS) across clauses 4 to 10 and an Annex A of 38 controls, and applies to organisations that develop, provide or use AI systems.
How long does ISO 42001 certification take?
Timeline depends on the number of AI systems in scope and whether an ISO 27001 management system already exists. Organisations with a mature ISMS move considerably faster because the shared Annex SL clauses are already operating; those starting without one need longer for the management system foundations.
Does ISO 42001 make us EU AI Act compliant?
No. The Act is law and ISO 42001 is a voluntary standard, and certification is not a legal presumption of conformity. A certified AIMS does produce much of the risk management, data governance, documentation and oversight evidence that Act readiness requires, so it is a substantial head start rather than a substitute.
We only use third-party AI - are we still in scope?
Yes. The standard covers deployers as well as developers. If you embed a vendor model in your product or use AI in decisions affecting people, the impact assessment, use-of-AI and third-party relationship controls apply to you.
How does ISO 42001 differ from ISO 27001?
ISO 27001 governs information security; ISO 42001 governs artificial intelligence. They share the Annex SL structure, so they integrate cleanly, but the AI standard adds impact assessment on affected individuals, AI lifecycle controls, data provenance and quality requirements, and transparency obligations that have no ISO 27001 equivalent.

Ready to Get Started?

Free gap analysis · Proposal in 24hrs · Delivery in weeks