The thing most people get wrong first
ISO/IEC 42001:2023 is an AI management system standard. That phrase does real work. It means the standard is not interested in whether your models are accurate, whether you use a particular architecture, or whether you have bought a particular tool. It is interested in whether your organisation has a repeatable, evidenced process for deciding how AI gets used, who is accountable, what could go wrong, and what happens when it does.
If you have been through ISO 9001 or ISO/IEC 27001, the shape will be immediately familiar — all three follow the same Annex SL structure. If you have not, the useful mental model is this: the standard asks you to decide something, write it down, do it, and keep the evidence you did it. Four steps, applied to about forty different questions.
Clauses 4 to 10, in plain terms
Who you are, who cares about your AI (customers, regulators, employees, the people decisions are made about), and where the boundary of your management system sits. The scope statement is a real deliverable and a narrow one is not cheating — but you have to be able to defend where you drew the line.
A published AI policy, signed off at the top, and named roles with real authority. The test an auditor applies is blunt: can you name the person who can stop an AI system, and do they know that is their job?
A documented risk methodology, a risk assessment actually carried out using it, an AI system impact assessment process, and the Statement of Applicability covering all thirty-eight Annex A controls with justification for what you included and what you excluded. This clause is where most of the audit time goes.
Resources, competence, awareness, and control of documented information. In practice: can the people using AI tell you what they are allowed to use them for, and has anyone been trained? Version control on the policy counts here too, unglamorously.
The lifecycle: how an AI system gets proposed, assessed, approved, deployed, monitored and retired. Including the third-party systems you did not build, which is where most organisations discover their real estate is larger than they thought.
Monitoring, internal audit, and management review. Three things that must have happened, with records. This is the clause you cannot fake in the fortnight before an audit, because the evidence is dated.
Nonconformity and corrective action. When something goes wrong, is it recorded, investigated, and does the system change as a result? An organisation with no recorded nonconformities is not a well-run one; it is one that is not looking.
The six documents a Stage 1 review opens with
A Stage 1 certification audit is largely a documentation review. In our experience the auditor reaches for the same six things, in roughly this order, and an organisation that has all six in a defensible state is in a fundamentally different conversation from one that does not:
- The scope statement — what is in the management system and what is deliberately outside it.
- The AI policy — approved, dated, and communicated to the people it binds.
- The Statement of Applicability — all thirty-eight controls, with justification for inclusion and exclusion.
- The risk methodology and the risk assessment produced with it — the method, and evidence it was used.
- The AI system impact assessment procedure — and at least one completed assessment.
- The internal audit programme and management review records — both of which must have actually taken place.
Notice what is not on that list: model performance metrics, technical architecture, the vendor you chose. Those matter to your business. They are not what Stage 1 is about.
Where the EU AI Act fits, and where it does not
These are different instruments and conflating them causes expensive confusion. ISO/IEC 42001 is a voluntary standard you can be certified against. The EU AI Act is law, and nobody certifies you against it in the same sense.
They do overlap usefully: an organisation with a working AIMS will find much of what the Act asks for — risk management, data governance, human oversight, logging, transparency — already sitting in its management system. Holding ISO/IEC 42001 does not make you compliant with the Act, and no auditor will tell you it does.
On timing, as of September 2026: general-purpose AI obligations have been in force since 2 August 2026. Under the Digital Omnibus agreement, obligations for stand-alone high-risk systems now apply from 2 December 2027, and for high-risk systems embedded in products from 2 August 2028. Those are fixed dates — the co-legislators rejected making them conditional on harmonised standards being ready, specifically so organisations could plan against them.
And the Act applies on the basis of where the output is used, not only where the provider sits. A UK organisation whose AI output reaches people in the EU can be in scope. In the UK itself there is no AI statute and the approach is regulator-led — ICO, MHRA, FCA, CQC, GDC. No statute does not mean no obligations.
What this costs you, honestly
The expensive part of ISO/IEC 42001 is almost never the certification fee. It is the six to twelve months of operating a management system so that there is evidence to audit, and the organisational work of getting an approval gate used rather than routed around.
Which is why the first question worth answering is not “how do we certify” but “where are we now”. That is a fifteen-minute question, and it is free to answer.
This article is general information, not legal advice, and not an audit. Certification against ISO/IEC 42001 is issued only by a certification body accredited under ISO/IEC 42006. VisionXY7 Ltd prepares organisations for certification audits and reviews their systems independently; it does not perform them. Dr. Mahdi Seify is an ISO/IEC 27001 Lead Auditor and Lead Implementer and applies that methodology to the AI standards; he is not an ISO/IEC 42001 Lead Auditor and is not ISO/IEC 42001 certified.