ISO 42001
ISO 42001:2023 is the management system standard for artificial intelligence. It is what customers and procurement teams increasingly ask for when you build AI into a product, and what boards ask for when the organization starts adopting AI internally. Like the privacy extension, it builds on an ISO 27001 ISMS.
AI governance, with the systems inventory to back it
How an ISO 42001 program runs
Establish the ISMS
ISO 42001 requires ISO 27001 as its foundation, so the information security management system comes first.
Inventory your AI systems
Register the AI systems you develop, procure or embed, with their purpose, owner and the data they use.
Impact assessments
Assess each system's impact across the affected domains and record the outcome as the standard expects.
Controls and integrated documentation
Work through the 38 AI controls and generate the 40-document integrated library.
AI management as part of the same system
ISO 42001 extends ISO 27001 rather than standing beside it. Enabling it moves the library from 36 documents to 40; enabling privacy as well takes it to 42. One management system, one set of records, one audit trail.
ISO 42001 FAQ
Can we certify to ISO 42001 without ISO 27001?
No. ISO 42001 is an extension and requires ISO 27001 as its foundation. Complyanz blocks enabling the AI module on its own.
Does this apply if we only use third-party AI?
Yes. The standard covers AI systems you procure or embed as well as ones you build. The inventory records the systems in use and the impact assessment asks the same questions regardless of who trained the model.
What is an AI impact assessment?
A structured assessment of how an AI system could affect the people and interests it touches, recorded per system. Complyanz provides the templates and keeps the completed assessments alongside the system inventory.
How does this relate to the EU AI Act?
ISO 42001 is a management system standard, not legislation. Organizations use it as the operational framework for AI governance, which supports but does not replace a legal assessment of your obligations under any specific regulation.
Govern the AI you build and buy
Enable ISO 42001 alongside ISO 27001 and the AI controls, system inventory and impact assessments are ready to work with.