ISO/IEC 42001 Certification: What It Is, Who Needs It and How to Get Certified

ISO/IEC 42001 certification and AI governance

ISO/IEC 42001 is the international standard for an artificial intelligence management system (AIMS). It sets out how an organization that develops, provides or uses AI systems should govern them. This guide explains what the standard covers, who it is for, how an organization gets certified and which personal certifications exist.

Key points

  • ISO/IEC 42001 was published in December 2023. It is the first management system standard for AI that an organization can be certified against.
  • It applies to any organization that develops, provides or uses AI systems, whatever its size or sector.
  • There are two kinds of certification: an organization is certified by a certification body after an audit, and an individual earns a personal credential by passing an exam.
  • Certification does not prove compliance with the EU AI Act, but the management system helps you organize and evidence that work.

What ISO/IEC 42001 covers

The standard follows the same clause structure as ISO/IEC 27001 and ISO 9001. Clauses 4 to 10 set the requirements: understanding the organization’s context, leadership and an AI policy, planning, support, operation, performance evaluation and improvement.

What makes it specific to AI is the work it asks for inside that structure:

  • AI risk assessment and treatment. Identify the risks that your AI systems create for the organization and decide how to treat them.
  • AI system impact assessment. Assess the consequences an AI system may have for individuals, groups and society.
  • Controls. Annex A lists reference controls. You select the ones that apply and justify the choice in a Statement of Applicability.
  • Life cycle management. Set requirements for how AI systems are designed, developed, verified, deployed, monitored and retired.

The Annex A controls are grouped into nine areas: AI policies, internal organization, resources for AI systems, assessing impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships.

Who needs it

ISO/IEC 42001 is voluntary. Organizations usually adopt it for one of these reasons:

  • They build or sell AI products and customers ask how the AI is governed.
  • They use AI in decisions that affect people, such as hiring, lending, healthcare or public services.
  • They operate in a regulated sector and need a documented, auditable approach to AI risk.
  • They already run ISO/IEC 27001 or ISO 9001 and want AI governance in the same system.

ISO/IEC 42001 and the EU AI Act

The EU AI Act is a law. It places obligations on providers and deployers of AI systems according to the risk category of each system. ISO/IEC 42001 is a voluntary standard for a management system. The two are different things, and a certificate is not proof of legal compliance.

They do support each other. An AIMS gives you an inventory of AI systems, assigned responsibilities, risk and impact assessments, and records. That is much of the evidence you need when you work out and demonstrate what the law requires of you.

How an organization gets certified

  1. Define the scope. Decide which parts of the organization and which AI systems the AIMS covers.
  2. Gap analysis. Compare current practice with the requirements.
  3. Build the system. Write the AI policy, run the risk and impact assessments, select controls and produce the Statement of Applicability.
  4. Operate it. Run the processes long enough to produce records.
  5. Internal audit and management review. Check the system yourself and fix what you find.
  6. Certification audit. A certification body audits in two stages: a review of the documented system, then an audit of how it works in practice.
  7. Keep it. The certification body returns for surveillance audits, and the certificate is renewed through recertification.

Horus Academy trains the people who do this work. It does not certify organizations.

Personal certification: Foundation, Lead Implementer, Lead Auditor

PECB offers personal credentials for ISO/IEC 42001. You take a course, pass the PECB exam and apply for the credential.

Course Length Who it is for
ISO/IEC 42001 Foundation 2 days, 14 CPD credits People who need a working knowledge of the standard
ISO/IEC 42001 Lead Implementer 5 days, 31 CPD credits People who set up and run an AIMS
ISO/IEC 42001 Lead Auditor 5 days, 31 CPD credits People who audit an AIMS

Passing the Lead Implementer exam qualifies you for one of four credentials, depending on your experience:

Credential Professional experience AIMS project experience
Provisional Implementer None None
Implementer Two years, at least one in artificial intelligence At least 200 hours
Lead Implementer Five years, at least two in artificial intelligence At least 300 hours
Senior Lead Implementer Ten years, at least seven in artificial intelligence At least 1,000 hours

All credentials also require you to sign the PECB Code of Ethics. If your main concern is AI risk rather than a full management system, look at Lead AI Risk Manager.

How ISO/IEC 42001 relates to ISO/IEC 27001

ISO/IEC 27001 protects information. ISO/IEC 42001 governs AI systems. They share the same clause structure, so policies, internal audit, management review and document control can be run once for both. The risk assessments differ: ISO/IEC 42001 adds the impact of AI systems on individuals and society, which an information security risk assessment does not cover.

Where to start

If you are new to the standard, start with the Foundation course. If you are responsible for putting it in place, take Lead Implementer. If you will assess it, take Lead Auditor. All AI courses are listed on one page.

Sources: ISO/IEC 42001:2023, AI management systems (ISO) and Regulation (EU) 2024/1689, the EU AI Act (EUR-Lex).

Frequently asked questions

Is ISO/IEC 42001 certification mandatory?

No. ISO/IEC 42001 is a voluntary standard. Organizations adopt it to show customers, regulators and partners that they govern AI in a structured way. Some customers may ask for it in contracts.

Does ISO/IEC 42001 certification mean we comply with the EU AI Act?

Not by itself. The EU AI Act sets legal obligations that depend on the risk category of each AI system. ISO/IEC 42001 gives you a management system for governing AI, which helps you organize and evidence that work, but certification is not proof of legal compliance.

Can an individual be certified in ISO/IEC 42001?

Yes. Organizations are certified by a certification body after an audit. Individuals earn a personal credential, such as PECB Certified ISO/IEC 42001 Lead Implementer or Lead Auditor, by passing an exam and meeting the experience requirements.

Do we need ISO/IEC 27001 before ISO/IEC 42001?

No. The two standards are independent. They share the same clause structure, so an organization that already runs an ISO/IEC 27001 management system can reuse much of it.

Leave a Reply

Your email address will not be published. Required fields are marked *