Most AI governance frameworks tell you what good practice looks like. ISO/IEC 42001 is the first that lets an external auditor put a certificate on the wall confirming you do it.

That distinction matters more than it sounds. Frameworks are self-assessed and therefore unfalsifiable from outside. A management system standard is audited, surveilled annually, and withdrawable. It converts governance from a claim into a verifiable status — which is precisely the transition the AI Human Proof standard argues the industry has to make.

The shape of the standard

ISO/IEC 42001:2023 follows the Harmonised Structure common to all modern ISO management system standards. If you have implemented ISO 27001 or ISO 9001, the skeleton is already familiar:

Clause 4 — Context. Determine internal and external issues, interested parties, and the scope of the AIMS. Crucially, determine the organisation’s role: are you an AI provider, producer, deployer, or user? Different roles pull in different controls.

Clause 5 — Leadership. Top management commitment, an AI policy, and assigned roles and responsibilities. The standard is explicit that accountability sits with leadership, not with a working group.

Clause 6 — Planning. AI risk assessment and risk treatment, plus the AI system impact assessment — the assessment of consequences for individuals and society, which is the clause that most distinguishes 42001 from its information-security sibling.

Clause 7 — Support. Resources, competence, awareness, communication, documented information.

Clause 8 — Operation. Operational planning and control; carrying out the risk treatment and impact assessments defined in Clause 6.

Clause 9 — Performance evaluation. Monitoring, measurement, internal audit, management review.

Clause 10 — Improvement. Nonconformity, corrective action, continual improvement.

Clauses 4–10 are mandatory. This is the part organisations underestimate: certification is not achieved by implementing controls. It is achieved by demonstrating a functioning management cycle around them.

The 38 controls

Annex A groups 38 controls under nine objectives:

Objective Concern
A.2 Policies related to AI
A.3 Internal organisation — roles, responsibilities, reporting of concerns
A.4 Resources — data, tooling, compute, human resources
A.5 Assessing impacts of AI systems on individuals and society
A.6 AI system life cycle — objectives, design, verification, deployment, operation
A.7 Data for AI systems — acquisition, quality, provenance, preparation
A.8 Information for interested parties — documentation, transparency, incident reporting
A.9 Use of AI systems — responsible use, intended purpose
A.10 Third-party and customer relationships — supplier obligations, allocation of responsibility

Controls are selected, not universally applied. The auditor’s question is whether your selection is justified by your risk assessment and whether omissions are defensible. A.10 is worth particular attention: most organisations deploying AI are consuming somebody else’s model, and the allocation of responsibility across that boundary is where governance most often falls through the gap.

How it sits alongside the EU AI Act

This is the question every European organisation asks, and the answer needs to be precise.

ISO/IEC 42001 is not a harmonised standard under the AI Act. Certification does not confer a presumption of conformity. Presumption of conformity will come from the European standards being developed by CEN-CENELEC JTC 21, the first of which are expected to publish during 2026.

What certification does give you:

  • Substantial coverage of Article 17’s quality management system requirement. A provider of a high-risk system must operate a QMS. A certified AIMS covers most of that ground.
  • Documented risk management and impact assessment, mapping onto Articles 9 and 27.
  • Data governance evidence, mapping onto Article 10.
  • An auditable trail — which is the practical difference between asserting compliance and demonstrating it to a market surveillance authority.

What it does not give you: conformity assessment, CE marking, EU database registration, or any relief from the deployer obligations in Article 26.

The sensible reading is that ISO/IEC 42001 is the stable foundation to build on while the harmonised standards are still in draft. The management system does not need to be rebuilt when JTC 21 publishes; the controls get mapped forward.

Where it overlaps with NIST AI RMF

The two are complementary rather than competing, and organisations operating on both sides of the Atlantic generally run them together.

NIST AI RMF is a process framework: GOVERN, MAP, MEASURE, MANAGE. It is rich on how to think about risk and deliberately silent on organisational machinery. ISO/IEC 42001 is a management system standard: it is prescriptive about the machinery — policy, roles, internal audit, management review — and comparatively light on risk methodology.

Run NIST AI RMF inside the Clause 6 and Clause 8 processes of an ISO/IEC 42001 AIMS and each covers the other’s weakness. NIST supplies the analytical depth; ISO supplies the auditable structure and the certificate.

What certification actually involves

A Stage 1 audit reviews documentation and readiness. A Stage 2 audit tests implementation — interviews, evidence sampling, walkthroughs of the AI system life cycle. Certification runs on a three-year cycle with annual surveillance audits.

The realistic prerequisite is that the AIMS has been operating long enough to have generated evidence: at least one internal audit, one management review, and a populated risk and impact assessment register. Organisations that treat certification as a documentation exercise fail Stage 2, because Stage 2 asks people what they actually do.

The honest assessment

ISO/IEC 42001 will not tell you whether your model is fair. No management system standard tells you that; it tells you whether you have a process for finding out, a record of having looked, and someone accountable for the answer.

That is a lower bar than “your AI is safe” — and it is a much higher bar than the published-ethics-principles posture most organisations currently occupy. For a deployer facing 2027 high-risk deadlines with harmonised standards still in draft, it is the most defensible position currently available.