
ISO 42001: The AI Certification That Structures Compliance
ISO 42001 is the first international AI management system standard. What certification actually changes for your company: governance, process, timeline and the key deadlines to mark on your calendar.
TL;DR: ISO/IEC 42001, published in December 2023, is the first internationally certifiable standard dedicated to AI management. It requires documented governance, risk assessment for each system, and a review of 38 AI-specific controls. Certification happens in two stages (documentation audit, then operational audit), is maintained through annual surveillance audits and renewed every 3 years. It does not replace the AI Act, but it serves as the working basis for the European harmonised standards: organisations that adopt it today will not start from scratch.
Your AI systems are deployed, your teams use them — and nobody can answer three simple questions: who is responsible for what, what risks each system carries, and how you prove it to a client, an auditor or an insurer. That is exactly the gap that the ISO 42001 standard structures.
Published on 18 December 2023, ISO/IEC 42001 is the first international management standard dedicated to artificial intelligence [iso.org]. It does more than recommend good practice: it is certifiable, like ISO 27001 or ISO 9001. This article explains what certification concretely changes inside a company, the path to obtaining it, and the deadlines to put on your calendar — including those of the AI Act.
ISO 42001: The First AI Management Standard
ISO/IEC 42001:2023 ("Information technology — Artificial intelligence — Management system") specifies the requirements for establishing, implementing, maintaining and continually improving an AI management system — the AIMS [iso.org]. It applies to any organisation that provides or uses AI-based products and services, regardless of sector or size: software vendor, integrator, manufacturer deploying predictive maintenance, or service company automating its processes.
Its method is the classic management-standard loop: the Plan-Do-Check-Act cycle. You define an AI policy, implement processes, measure results, improve. All of it, documented.
The Same Architecture as ISO 27001
ISO 42001 shares the common management-standard architecture (the "Annex SL" structure) with ISO 27001 and ISO 9001: clauses 4 to 10, from organisational context to continual improvement [certification.afnor.org]. Practical consequence: a company already certified to ISO 27001 already has part of the skeleton in place (document management, internal audits, management review). ISO 42001 grafts onto it instead of rebuilding everything from zero — AFNOR explicitly presents it as integrable with existing management systems.
Annex A: 38 AI-Focused Controls
Where ISO 27001 protects information, ISO 42001 governs the use of AI itself. Its Annex A brings together 38 AI-specific controls organised into 9 control objectives (AI policy, internal organisation, resources, impact assessment, system lifecycle, data, communication to interested parties, responsible use, relationships with third parties) [vanta.com] [arphie.ai]. Each organisation selects the controls that apply to its scope and justifies that choice in a statement of applicability (SoA) — the same mechanism as ISO 27001.
The standard is completed by a family of texts: ISO/IEC 23894 (AI risk management), ISO/IEC 42005:2025 (AI impact assessment) and ISO/IEC 42006:2025, which sets requirements for bodies authorised to audit and certify AIMS [iso.org — OBP].
What Certification Concretely Changes for Your Company
Certification is not a certificate to hang on the wall. It transforms four things in depth.
| Before | After |
|---|---|
| Nobody is designated as responsible for AI | Formalised roles: AIMS owner, owner of each system, reviewer of AI decisions |
| Nobody knows how many AI systems exist | A mandatory inventory of all AI systems and their use |
| AI risks are handled case by case | An impact assessment and risk mapping per system, aligned with ISO 23894 and ISO 42005 |
| Compliance relies on team memory | Documentation and an audit trail that can be verified: policies, registers, reviews, incidents |
| Oversight depends on goodwill | A control cycle: internal audits, management review, indicator measurement, continual improvement |
- Designated responsibilities. The standard requires naming who is responsible for what: governance, individual systems, decisions. No more "orphan AI", adopted by a department with no designated owner.
- An inventory and classification. Before any control, you must list the AI systems, their purpose, their data, their users, their lifecycle. Most companies discover "shadow AI" tools at this step that were never declared.
- Impact assessment and traced risks. Each system is analysed: potential biases, impacts on people, possible incidents. The treatments chosen are documented — this file is the evidence shown to an auditor.
- Selected and justified controls. Out of the 38 Annex A controls, the organisation keeps those that apply, through the statement of applicability. A justified choice beats "default" compliance.
- A permanent audit trail. Registers, review reports, measurements, incidents: everything is documented and retained. That is the difference between "we do responsible AI" and "we can prove it".
There is a commercial benefit too. Certification becomes a differentiating argument with large accounts and regulated sectors, which increasingly include AI governance in their purchasing criteria and tenders. Major players have already obtained it: Anthropic is among the first certified AI labs, an official announcement made in January 2025 [anthropic.com]. In France, AFNOR Certification issues the certification and documents the first certified companies [certification.afnor.org].
The Certification Path in 6 Steps
The journey follows a pattern proven by the other management standards. Here is the timeline, with verified orders of magnitude.
| Step | Content | Indicative duration |
|---|---|---|
| 1. Scoping | Define the organisation's role (provider, producer, user), the AIMS scope, the AI policy | 2-4 weeks |
| 2. Implementation | Objectives, procedures, risk and impact assessment, control selection, documentation | 2-6 months depending on maturity |
| 3. Internal audit | Verify that the system is actually applied, correct gaps | 1-2 weeks |
| 4. Stage 1 audit | The certification body reviews the documentation and AIMS design | 1-2 days |
| 5. Stage 2 audit | The body verifies operational effectiveness: processes, controls, risk management | 3-9+ days |
| 6. Maintenance | Annual surveillance audits, then recertification every 3 years | Ongoing |
Details of the schedule confirmed by practitioners [cloudsecurityalliance.org]:
- Certification audit happens in two stages. Stage 1 (1 to 2 days) verifies that documentation exists and holds up: scope, policies, risk management methodologies, statement of applicability. Stage 2 (3 to 9+ days, depending on headcount covered) verifies that what is written is actually applied: interviews, control testing, system supervision.
- Between the two, allow 4 to 12 weeks (6 months maximum) to correct the gaps found at stage 1.
- The certificate is valid for 3 years, maintained by annual surveillance audits (roughly one third of the initial audit time), then recertification at the end of the cycle [nqa.com].
- The most variable stage is step 2 (implementation): a company already equipped with a management system (ISO 27001, ISO 9001) reuses its skeleton and moves significantly faster than an organisation starting from zero.
Documentation is the classic bottleneck of this journey. It is also where automation changes the game: collecting registers, tracking controls, producing audit evidence — tasks that AI-powered document tools complete far faster than spreadsheets, as we detail on our Automated Regulatory Compliance page.
ISO 42001 and the AI Act: What Certification Covers, and What It Does Not
The question always comes back: does ISO 42001 make you AI Act compliant? Short answer: no, but it prepares the ground better than any other approach.
The AI Act is a directly applicable European regulation, in force since 1 August 2024, with progressive application [digital-strategy.ec.europa.eu]. To date: the transparency obligations (Art. 50) have been in application since 2 August 2026; obligations for stand-alone high-risk systems arrive on 2 December 2027; those for systems embedded in regulated products arrive on 2 August 2028 — a timeline postponed by the Digital Omnibus on AI, in force since 27 July 2026 [eur-lex.europa.eu]. For the details of risk classification, see our article AI Act 2026: Industrial AI Compliance.
Where does ISO 42001 fit into this framework?
- What it covers. Governance, risk management, data quality, human oversight, documentary transparency: the requirements imposed by certification largely overlap with those the AI Act addresses for high-risk systems — including the quality management system requirement (Article 17) for providers.
- What it does not cover. A voluntary standard is not legal compliance: registration of systems in the EU database, product conformity assessment, rules specific to GPAI models — certification does not dispense you from any regulatory obligation.
- The bridge ahead. The European Commission has mandated CEN/CENELEC to develop the harmonised standards of the AI Act; one of them will cover the management system of the companies concerned, and ISO 42001 serves as the working basis for its development [certification.afnor.org]. When these standards are published in the Official Journal of the EU, organisations already structured around ISO 42001 will have a largely convertible foundation — instead of building everything in a rush.
Getting certified now is buying time. The certification cycle (3 years) stretches beyond the AI Act high-risk deadlines (December 2027, August 2028): a company certified from 2026 approaches those deadlines with a documented, audited, proven management system.
The Deadlines to Remember
| Date | Deadline |
|---|---|
| 18 December 2023 | Publication of ISO/IEC 42001:2023 |
| 2 August 2026 | AI Act — transparency obligations (Art. 50): already in application |
| 2026-2027 | CEN/CENELEC harmonised standards under development — ISO 42001 as the basis |
| 2 December 2027 | AI Act — stand-alone high-risk systems |
| 2 August 2028 | AI Act — high-risk systems embedded in regulated products |
| Every year | ISO 42001 surveillance audit (certificate maintenance) |
| Every 3 years | ISO 42001 recertification |
FAQ — ISO 42001 and AI Certification
What is the ISO 42001 standard? ISO/IEC 42001:2023 is the first international certifiable standard dedicated to AI management. It specifies the requirements of an AI management system (AIMS): governance, risk assessment, specific controls and continual improvement.
Who is ISO 42001 certification for? Any organisation that provides or uses AI-based products or services: software vendors, integrators, manufacturers, service companies. There is no size threshold.
What is the difference between ISO 42001 and ISO 27001? ISO 27001 protects information (confidentiality, integrity, availability). ISO 42001 governs the use of AI: responsibilities, impacts, lifecycle, third-party relationships. Both share the same architecture and are cumulative — ISO 42001 certification integrates with existing management systems.
Does ISO 42001 replace the AI Act? No. The AI Act is a binding European regulation; ISO 42001 certification is voluntary. It covers part of the requirements (governance, risks, data, oversight) and serves as the basis for the European harmonised standards under preparation, but it does not dispense you from any legal obligation.
How long does ISO 42001 certification last? The certificate is valid for 3 years, maintained by annual surveillance audits, then renewed through a recertification audit. The time from launch to certificate depends on maturity: a few months for an organisation already structured (ISO 27001), longer otherwise.
Is ISO 42001 certification mandatory? No. It is voluntary, in France and across the EU. However, it is becoming an increasingly requested commercial differentiator, and a direct preparation for AI Act obligations.
Conclusion: AI Compliance Is Built Before the Constraint Arrives
ISO 42001 certification changes a company in depth: designated responsibilities, inventoried systems, documented risks, retained evidence. It does not replace the AI Act — but it provides a method to get there, a common language with auditors, and a head start on the European harmonised standards.
The first step requires no tooling: map your AI systems. How many are deployed? Who uses them? What risk do they carry? From that inventory, you can select the Annex A controls that apply to you and cost your certification journey.
👉 Request an AI compliance diagnostic — Map your systems, identify the applicable ISO 42001 controls and get an action plan within 48 hours.
Article published on 18 August 2026 by Damien Godard — ISO/IEC 42001:2023 published by ISO; certification process and timeline according to AFNOR Certification and the Cloud Security Alliance; AI Act deadlines verified on EUR-Lex (Regulation EU 2024/1689, Digital Omnibus (EU) 2026/1744).
