ISO/IEC 42001 for AI vendors

What the international standard for artificial intelligence (AI) management systems asks of a company that builds or sells AI, how certification works and where to start when your customers ask.

Updated:

Why your customers ask for it

Enterprise customers send AI questionnaires before they sign: which models and tools you use, what customer data they see and who decides on each use. The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) publish a standard that gives you one structured way to answer: ISO/IEC 42001, with a management system that a third party can audit.

What the standard asks for

ISO/IEC 42001:2023 is the international standard for AI management systems, published jointly by ISO and IEC.

Like other management system standards, it is built on clauses 4 to 10: define the scope of the system, set a policy, assign roles, address risks, run internal audits and review the system at top-management level.

It also asks for an AI system impact assessment (clause 6.1.4) and a statement of applicability that lists the controls your company needs and justifies why each control is included or excluded (clause 6.1.3).

Annex A: controls chosen by risk

Annex A lists 38 reference controls across nine areas (A.2 to A.10). Your risk treatment determines which ones you need, and you compare that selection with Annex A so that no necessary control is left out (clause 6.1.3).

One area covers data for AI systems (A.7), including data quality, provenance and preparation; another covers the use of AI systems (A.9).

How certification works

Certification is granted by an accredited certification body that you choose, after it audits your management system. ISO/IEC 42006:2025 sets the requirements, on top of ISO/IEC 17021-1, for bodies that audit and certify ISO/IEC 42001, and accreditation bodies use it to accredit them.

Before it certifies, the body checks that your first internal audit and your first management review have been done: in the first stage of its audit, it evaluates whether both are planned and carried out (ISO/IEC 17021-1, 9.3.1.2.2 g).

The internal audit can be run by your own team or by an external party on your behalf, separate from the body that certifies you, with auditors who keep the audit objective and impartial (clauses 3.18 and 9.2.2; ISO/IEC 42006:2025, 5.2.2.3).

Other frameworks your customers mention

Your US customers may refer to the AI Risk Management Framework of the US National Institute of Standards and Technology (NIST AI RMF). It is voluntary and is organized in four functions, Govern, Map, Measure and Manage, each with its categories and subcategories. Certification is done against ISO/IEC 42001; NIST AI RMF gives you a second lens on the same gaps.

Your EU customers may ask about the EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744). It sets obligations by role and by category of AI system, including prohibited practices (art. 5), high-risk systems (art. 6) and systems with transparency obligations (art. 50), and separate obligations for providers of general-purpose AI models (Chapter V). The standard organizes how you manage AI; the regulation is checked use by use, so each AI use is classified against those categories.

Where to start

The first step is knowing which AI your company uses and what data it receives. From there:

  • List every AI tool and system in your company, who uses it and for what.
  • Map the data each AI use reads or receives, including personal data and your customers' data.
  • Assess the risks of each use and decide which Annex A controls you need.
  • Define the scope, the policy and the roles of the management system.
  • Plan your first internal audit and your first management review before you book the certification audit.

How we help

We assess how your company uses AI against ISO/IEC 42001 and NIST AI RMF, classify each AI use against the EU AI Act categories, and implement the AI management system with your team until it is ready for certification with the accredited body you choose.

Sources

These are the official sources for this guide, checked as of its update date. When a standard is sold by its publisher, we cite it by number and clause.

  1. ISO/IEC 42001:2023, clauses 3.18, 4 to 10 and Annex A (a paid standard; cited by clause number)
  2. ISO/IEC 42006:2025, clause 5.2.2.3 (a paid standard)
  3. ISO/IEC 17021-1:2015, clause 9.3.1.2.2 g (a paid standard)
  4. NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0)
  5. Regulation (EU) 2024/1689 (EU AI Act), Official Journal of the European Union
  6. Regulation (EU) 2026/1744, which amends the EU AI Act

Let's talk about your next step.

In 30 minutes we review where you stand and suggest where to start.