The AI management standard
ISO 42001, explained by practitioners
ISO 42001 is the international management system standard for artificial intelligence, published in December 2023. It sets out how an organisation that develops or uses AI must govern it, through an artificial intelligence management system (AIMS): an AI policy, assigned accountability, risk and impact assessments, and lifecycle controls. Accredited certification bodies audit against it and issue certificates.
What it requires
A management system for AI, not a technical checklist
ISO 42001 does not tell you which model to use or how to write a prompt. It requires you to run AI the way ISO 27001 taught the world to run information security: decide what is in scope, put leadership's name on a policy, assess the risks and impacts of every AI system you build or buy, control each system through its lifecycle, and keep records that prove all of it happened. That framework of policy, process and evidence is the AIMS, the artificial intelligence management system the standard is built around.
The distinctive part is the impact assessment. Beyond asking what could go wrong for your organisation, the standard requires you to assess what your AI could do to the people and groups it touches. That is the piece regulators and enterprise buyers now look for, and the piece most internal AI policies miss. If you are building broader AI governance rather than chasing a certificate, our AI governance framework guide shows where the standard fits alongside NIST AI RMF and UK guidance.
The clause structure
- Clause 4: context, and which AI systems the AIMS covers
- Clause 5: leadership, an AI policy and assigned roles
- Clause 6: risk and AI impact assessment, with objectives
- Clause 7: resources, competence, awareness and documentation
- Clause 8: operational controls over the AI lifecycle
- Clause 9: monitoring, internal audit and management review
- Clause 10: nonconformity handling and continual improvement
Clauses 4 to 10 follow the same harmonised structure as ISO 27001 and ISO 9001, which is why organisations holding either start a long way ahead.
Who needs it
Who ISO 42001 is actually for
The standard applies to any organisation that develops, provides or uses AI systems. In practice, three groups are driving UK adoption.
You build AI into your product
Software firms shipping models, LLM features or agents to customers. Enterprise buyers have started writing ISO 42001 into procurement questionnaires the way they did with ISO 27001 a decade ago, and a certificate answers the question once instead of per deal.
You deploy AI inside the business
Organisations rolling out copilots, chatbots or decision-support models against their own data. The standard forces the questions that internal rollouts skip: who approved this use, what was the impact assessment, and who is accountable when the output is wrong.
You sit in a regulated or exposed sector
Financial services, health, legal, recruitment and anyone in scope of the EU AI Act. An AIMS gives regulators and clients a recognised, auditable answer to how AI is governed, rather than a policy document nobody can evidence.
Weighing the standard against European regulation? Our EU AI Act guide for UK companies and its supporting articles compare the two in depth, so this page can stay focused on the standard itself.
How to get certified
The ISO 42001 certification process, step by step
One point before the steps, because the industry blurs it: consultancies, including us, deliver readiness, implementation and audit support. The certificate itself is only ever issued by an accredited certification body that you appoint, after its own independent audits.
Step 1
Scope the AIMS
Decide which AI systems, teams and sites the management system covers. Scoping too wide is the most common early mistake; the certificate only needs to cover what your customers and regulators care about.
Step 2
Run a gap analysis
Measure current practice against every clause and control before building anything. This is the step we productise as a fixed-price engagement, and it produces the costed plan for everything below.
Step 3
Build the AIMS
Write the AI policy, run risk and impact assessments on each in-scope system, implement the Annex A controls that apply, and generate the records that prove it all happens in practice.
Step 4
Internal audit and management review
The standard requires you to audit your own AIMS and put the results in front of leadership before any external auditor arrives. Skipping this is a guaranteed stage 1 finding.
Step 5
Stage 1 certification audit
An accredited certification body you appoint reviews your documentation and readiness. In the UK, look for a body accredited by UKAS. The body is independent of any consultancy that helped you prepare.
Step 6
Stage 2 audit and certificate
The certification body tests whether the AIMS operates in practice, not just on paper. Pass, and it issues the certificate, valid for three years with surveillance audits in between.
Requirements and controls
The Annex A control themes, summarised
Alongside the management clauses, ISO 42001's Annex A supplies a reference set of AI-specific controls grouped under nine themes. You justify which apply to your systems in a statement of applicability, exactly as ISO 27001 does for security controls.
| Control theme | What it covers |
|---|---|
| Policies related to AI | A management-approved AI policy, kept current and aligned with your other organisational policies. |
| Internal organisation | Defined roles, responsibilities and reporting lines for AI, so accountability for each system has a name against it. |
| Resources for AI systems | Documenting the data, tooling, compute and human expertise each AI system depends on. |
| Assessing impacts of AI systems | Formal impact assessments covering individuals, groups and society, not just the organisation's own risk. |
| AI system lifecycle | Requirements, design, verification, deployment, operation and retirement managed as controlled stages. |
| Data for AI systems | Provenance, quality, preparation and management of the data used to train and run each system. |
| Information for interested parties | What you tell users, customers and regulators about your AI systems, including incident reporting routes. |
| Use of AI systems | Defining responsible use, setting intended-use boundaries and stopping systems drifting beyond them. |
| Third-party relationships | Governing suppliers, model providers and customers in the AI supply chain, and allocating responsibility between you. |
The gap analysis measures you against every theme above, clause by clause, and tells you which controls genuinely apply to your systems. See what it covers.
What it costs
What ISO 42001 certification costs
Published certification market guides put a total ISO 42001 project, consultancy and certification body fees combined, at roughly £8,000 to £15,000 for organisations up to 50 staff, £15,000 to £30,000 for 51 to 250 staff, and £30,000 to £50,000 or more above that. Two variables move you within those bands: how many AI systems sit in scope, and how much management system machinery you already have.
Our part of that equation is fixed rather than estimated: the gap analysis is priced inside the published £8,500 to £16,700 readiness range, ISO 42001 compliance can be delivered and then run for you from £1,850 a month, and every package is priced on our published pricing page before you commit to anything. Certification body fees are set by the body you appoint and paid to them directly; the gap analysis report includes them in the costed roadmap so the full picture is on one page.
Already hold ISO 27001?
ISO 27001 does a large share of the work for you
Because the two standards share the harmonised clause structure, an operating ISMS already gives you document control, internal audit, management review, supplier management and improvement processes that an AIMS can extend rather than duplicate. Published certification market guides suggest an existing ISO 27001 certification cuts the ISO 42001 effort by 30 to 40 percent, and that matches what we see: the genuinely new work is the AI-specific layer of impact assessments, lifecycle controls and data provenance.
Many organisations run the two together or add 42001 at their next 27001 surveillance point. Our sister practice at ISO 27001 Certification UK handles the information security side, and the two teams scope combined engagements as one project. Wherever you start, the gap analysis accounts for what your ISMS already covers, so you never pay to build the same control twice.
Quick answers
ISO 42001 questions, answered
What is ISO 42001?
ISO/IEC 42001 is the international standard for managing artificial intelligence, published in December 2023. It defines the requirements for an artificial intelligence management system (AIMS): the policies, impact assessments, lifecycle controls and oversight an organisation needs to develop or use AI responsibly. It is certifiable, meaning an accredited body can audit you against it and issue a certificate.
How do you get ISO 42001 certified?
Scope the management system, gap-assess against the standard, build and operate the AIMS, then complete an internal audit and management review. After that, an accredited certification body of your choosing conducts a stage 1 documentation audit and a stage 2 implementation audit, and issues the certificate if you pass. Consultancies like ours get you ready for those audits; only the accredited body can certify you.
Is ISO 42001 worth it for a business our size?
It depends on who is asking you about AI. If enterprise customers, regulators or investors want evidence of AI governance, certification usually pays for itself in shortened due diligence. If nobody is asking yet, aligning with the standard without certifying still gives you the risk and impact assessment discipline at a fraction of the cost, and leaves you ready to certify when a contract demands it.
Do we need certification, or just alignment?
Certification is worth it when an external party needs proof: procurement questionnaires, regulator expectations or a competitive tender. Alignment, meaning you implement the AIMS but skip the external audit, suits organisations that want the governance benefit without the audit overhead. A gap analysis serves both routes, because it tells you the distance to travel either way.
What is an AIMS?
An artificial intelligence management system is the framework of policies, processes, roles and records through which an organisation directs and controls its AI. It is the AI equivalent of the ISMS that sits behind ISO 27001: not a piece of software, but a documented, auditable way of deciding which AI systems you run, assessing their risks and impacts, and proving they stay within the boundaries you set.
From reading to readiness
Find out how far you are from certifiable
A scoping call costs nothing: we map your AI systems against the standard, flag the likely gaps and put a fixed figure on closing them.