Home Solutions Insights Case Studies About Book Discovery Call
Governance9 min read

What ISO/IEC 42001 Actually Requires — Clause by Clause, in Plain English

Dr. Mahdi Seify
Dr. Mahdi Seify
Founder & CAIO, VisionXY7 Ltd · Published 14 September 2026

PhD, AI-Driven Business Analytics · ISO/IEC 27001 Lead Auditor and Lead Implementer. Written from delivery, not from a summary of the standard.

In short: ISO/IEC 42001 is not a list of AI safety features to install. It is a management system standard — the same shape as ISO 9001 or ISO/IEC 27001 — which means it asks you to decide things, write them down, follow them, and show evidence you followed them. Clauses 4 to 10 are the obligations. Annex A's thirty-eight controls are the menu you choose from, and the Statement of Applicability is where you justify every choice, including the exclusions. Most organisations that fail a Stage 1 review fail on documents, not on technology.

The thing most people get wrong first

ISO/IEC 42001:2023 is an AI management system standard. That phrase does real work. It means the standard is not interested in whether your models are accurate, whether you use a particular architecture, or whether you have bought a particular tool. It is interested in whether your organisation has a repeatable, evidenced process for deciding how AI gets used, who is accountable, what could go wrong, and what happens when it does.

If you have been through ISO 9001 or ISO/IEC 27001, the shape will be immediately familiar — all three follow the same Annex SL structure. If you have not, the useful mental model is this: the standard asks you to decide something, write it down, do it, and keep the evidence you did it. Four steps, applied to about forty different questions.

Clauses 4 to 10, in plain terms

Clause 4 — Context and scope

Who you are, who cares about your AI (customers, regulators, employees, the people decisions are made about), and where the boundary of your management system sits. The scope statement is a real deliverable and a narrow one is not cheating — but you have to be able to defend where you drew the line.

Clause 5 — Leadership and policy

A published AI policy, signed off at the top, and named roles with real authority. The test an auditor applies is blunt: can you name the person who can stop an AI system, and do they know that is their job?

Clause 6 — Planning, risk and the Statement of Applicability

A documented risk methodology, a risk assessment actually carried out using it, an AI system impact assessment process, and the Statement of Applicability covering all thirty-eight Annex A controls with justification for what you included and what you excluded. This clause is where most of the audit time goes.

Clause 7 — Support

Resources, competence, awareness, and control of documented information. In practice: can the people using AI tell you what they are allowed to use them for, and has anyone been trained? Version control on the policy counts here too, unglamorously.

Clause 8 — Operation

The lifecycle: how an AI system gets proposed, assessed, approved, deployed, monitored and retired. Including the third-party systems you did not build, which is where most organisations discover their real estate is larger than they thought.

Clause 9 — Performance evaluation

Monitoring, internal audit, and management review. Three things that must have happened, with records. This is the clause you cannot fake in the fortnight before an audit, because the evidence is dated.

Clause 10 — Improvement

Nonconformity and corrective action. When something goes wrong, is it recorded, investigated, and does the system change as a result? An organisation with no recorded nonconformities is not a well-run one; it is one that is not looking.

The six documents a Stage 1 review opens with

A Stage 1 certification audit is largely a documentation review. In our experience the auditor reaches for the same six things, in roughly this order, and an organisation that has all six in a defensible state is in a fundamentally different conversation from one that does not:

  1. The scope statement — what is in the management system and what is deliberately outside it.
  2. The AI policy — approved, dated, and communicated to the people it binds.
  3. The Statement of Applicability — all thirty-eight controls, with justification for inclusion and exclusion.
  4. The risk methodology and the risk assessment produced with it — the method, and evidence it was used.
  5. The AI system impact assessment procedure — and at least one completed assessment.
  6. The internal audit programme and management review records — both of which must have actually taken place.

Notice what is not on that list: model performance metrics, technical architecture, the vendor you chose. Those matter to your business. They are not what Stage 1 is about.

Where the EU AI Act fits, and where it does not

These are different instruments and conflating them causes expensive confusion. ISO/IEC 42001 is a voluntary standard you can be certified against. The EU AI Act is law, and nobody certifies you against it in the same sense.

They do overlap usefully: an organisation with a working AIMS will find much of what the Act asks for — risk management, data governance, human oversight, logging, transparency — already sitting in its management system. Holding ISO/IEC 42001 does not make you compliant with the Act, and no auditor will tell you it does.

On timing, as of September 2026: general-purpose AI obligations have been in force since 2 August 2026. Under the Digital Omnibus agreement, obligations for stand-alone high-risk systems now apply from 2 December 2027, and for high-risk systems embedded in products from 2 August 2028. Those are fixed dates — the co-legislators rejected making them conditional on harmonised standards being ready, specifically so organisations could plan against them.

And the Act applies on the basis of where the output is used, not only where the provider sits. A UK organisation whose AI output reaches people in the EU can be in scope. In the UK itself there is no AI statute and the approach is regulator-led — ICO, MHRA, FCA, CQC, GDC. No statute does not mean no obligations.

What this costs you, honestly

The expensive part of ISO/IEC 42001 is almost never the certification fee. It is the six to twelve months of operating a management system so that there is evidence to audit, and the organisational work of getting an approval gate used rather than routed around.

Which is why the first question worth answering is not “how do we certify” but “where are we now”. That is a fifteen-minute question, and it is free to answer.

This article is general information, not legal advice, and not an audit. Certification against ISO/IEC 42001 is issued only by a certification body accredited under ISO/IEC 42006. VisionXY7 Ltd prepares organisations for certification audits and reviews their systems independently; it does not perform them. Dr. Mahdi Seify is an ISO/IEC 27001 Lead Auditor and Lead Implementer and applies that methodology to the AI standards; he is not an ISO/IEC 42001 Lead Auditor and is not ISO/IEC 42001 certified.

The service behind this article
ISO/IEC 42001 Audit Readiness

A free 15-question Quick Check scores you against the eight domains and the eight Stage 1 gates in about eight minutes. The Gap Review then examines the evidence behind your answers.

See the assessment →

Frequently Asked

Is ISO/IEC 42001 mandatory?

No. It is a voluntary standard. What is increasingly not voluntary is being able to answer a customer, insurer or regulator who asks how your AI is governed — and ISO/IEC 42001 has become the shorthand for that answer. It is appearing in tenders and supplier questionnaires well ahead of any legal requirement to hold it.

How long does certification take?

For an organisation starting from no formal AI governance, six to twelve months is realistic before a Stage 1 review, and the constraint is almost never the technology. It is the evidence: a management system has to have been operating long enough to have produced records — a risk assessment that was actually done, an internal audit that actually happened, a management review with minutes. You cannot compress the passage of time.

We already hold ISO/IEC 27001. Does that help?

Considerably. Both follow the same Annex SL management system structure, so your scope statement, risk methodology, internal audit programme, management review cycle and corrective action process already exist and mostly extend rather than get rebuilt. The genuinely new work is AI-specific: the system inventory, impact assessment against ISO/IEC 42005, data governance for training and input data, and the human oversight decisions.

What is the difference between Clause 6.1.3 and Annex A?

Annex A is the catalogue of thirty-eight controls. Clause 6.1.3 is the obligation to go through that catalogue, decide which controls apply to you, and record the justification for both inclusions and exclusions in a Statement of Applicability. Annex A tells you what is available; Clause 6.1.3 makes you own the choice. An auditor reads the Statement of Applicability before almost anything else.

Does VisionXY7 certify us?

No, and no consultancy can. Certification against ISO/IEC 42001 is issued only by a certification body accredited under ISO/IEC 42006. A firm that both built your management system and certified it would not be independent, which is exactly why the separation exists. VisionXY7 prepares organisations for that audit and reviews their systems independently beforehand.

Could You Stand Up
An Audit Today?

Fifteen questions, about eight minutes, and your result on screen immediately — a maturity index against the structure of ISO/IEC 42001, and the status of all eight Stage 1 gates. Free, no account, no sales call to receive it.

Start the free Quick Check