Certification · ISO 27001 extension

ISO 42001

ISO 42001:2023 is the management system standard for artificial intelligence. It is what customers and procurement teams increasingly ask for when you build AI into a product, and what boards ask for when the organization starts adopting AI internally. Like the privacy extension, it builds on an ISO 27001 ISMS.

What you get

AI governance, with the systems inventory to back it

38AI management controls covering the AI lifecycle
40documents in the integrated library when AI is added to the ISMS
1inventory for every AI system you build, buy or embed
42documents when privacy and AI are both integrated
In the platform

How an ISO 42001 program runs

Step 1

Establish the ISMS

ISO 42001 requires ISO 27001 as its foundation, so the information security management system comes first.

Step 2

Inventory your AI systems

Register the AI systems you develop, procure or embed, with their purpose, owner and the data they use.

Step 3

Impact assessments

Assess each system's impact across the affected domains and record the outcome as the standard expects.

Step 4

Controls and integrated documentation

Work through the 38 AI controls and generate the 40-document integrated library.

Going further

AI management as part of the same system

ISO 42001 extends ISO 27001 rather than standing beside it. Enabling it moves the library from 36 documents to 40; enabling privacy as well takes it to 42. One management system, one set of records, one audit trail.

Questions

ISO 42001 FAQ

Can we certify to ISO 42001 without ISO 27001?

No. ISO 42001 is an extension and requires ISO 27001 as its foundation. Complyanz blocks enabling the AI module on its own.

Does this apply if we only use third-party AI?

Yes. The standard covers AI systems you procure or embed as well as ones you build. The inventory records the systems in use and the impact assessment asks the same questions regardless of who trained the model.

What is an AI impact assessment?

A structured assessment of how an AI system could affect the people and interests it touches, recorded per system. Complyanz provides the templates and keeps the completed assessments alongside the system inventory.

How does this relate to the EU AI Act?

ISO 42001 is a management system standard, not legislation. Organizations use it as the operational framework for AI governance, which supports but does not replace a legal assessment of your obligations under any specific regulation.

Govern the AI you build and buy

Enable ISO 42001 alongside ISO 27001 and the AI controls, system inventory and impact assessments are ready to work with.