ISO/IEC 42001 (AI management system)
What is ISO/IEC 42001?
ISO/IEC 42001 is the first international standard for an AI management system. ISO and IEC published it on 18 December 2023, the document runs to 51 pages, and it is still in its first edition. What it describes is not a technology and not a test of a model. It is a way of organising the work around AI: who decides, what gets written down, which risks you looked at, and what you did about them.
A management system standard says nothing about how good any particular model is. ISO 9001 does not tell a customer that your product is good, only that you run a process that notices when the product is bad. ISO/IEC 42001 works the same way for AI. A company can hold the certificate while running a model that performs poorly, as long as it knows that, has weighed it, and acts on the answer.
It is written for any organisation that develops, provides or uses AI-based products or services, which is the wording NBN, the Belgian standards body, puts on its own page about the standard. The company that only buys AI is in scope too. Using it is enough.
What the standard asks for
ISO/IEC 42001 follows the harmonized structure ISO uses across its management system standards, so the requirements sit in clauses 4 to 10 and run on the plan-do-check-act cycle.
Context and scope. Clause 4 asks you to write down what your organisation does with AI, who has an interest in it (customers, staff, regulators, the people a system decides about), and where the boundary of the management system runs. Scope shapes everything after it, and it can cover one product line rather than the whole company.
Leadership and an AI policy. Clause 5 puts the duty on top management rather than on a working group, and asks for a written AI policy with roles and responsibilities assigned to named people.
Risk assessment and risk treatment. Clause 6.1 asks for a repeatable way to assess AI risks and to treat them. Clause 6.1.3 then requires a Statement of Applicability: for every control in Annex A, whether you apply it and why, with the exclusions justified in writing. Anyone who has done ISO/IEC 27001 has met that document before.
An impact assessment on people. Clause 6.1.4 is the part the older standards have no equivalent for. Next to the risks a system creates for you, you assess what it does to individuals, to groups and to society. ISO/IEC 42005, published in May 2025, is the companion standard on how to run one.
Competence and documented information. Clause 7 covers the people: who needs to know what, what training they were given, and which records the system produces. This is the clause that quietly decides how much work the whole thing turns into.
Monitoring, internal audit and management review. Clause 9 asks you to measure whether the management system is working, to audit yourself against the standard (9.2) and to review the results at top management level (9.3). The management review is where the system produces a decision instead of a report.
Improvement. Clause 10 asks what you do with a nonconformity once you find one. An auditor comes back to an open finding at the next surveillance audit, so this is the clause where the paperwork has to turn into a change.
Annex A carries 38 controls in nine groups, numbered A.2 to A.10: policies related to AI, internal organisation, resources for AI systems, assessing impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. Annex B is normative as well and carries the implementation guidance for each of those controls. Annexes C and D are informative: a catalogue of AI-related objectives and risk sources, and notes on using the management system across domains or sectors.
Why companies go for the certificate, and what it takes
Three reasons come up. A customer or a tender asks for it, often the same customer who asked for ISO/IEC 27001 two years earlier. It gives shape to work you would otherwise improvise from week to week. And it is something to put on the table when a regulator or a large client asks how you govern AI.
Certification goes through an accredited body, auditing against ISO/IEC 17021-1 plus ISO/IEC 42006:2025, the standard that sets the extra competence and audit-time rules for AI auditors. The audit comes in two stages: stage 1 reads your documentation and the design of the system, stage 2 goes looking for evidence that it actually runs. The certificate lasts three years, with a lighter surveillance audit in each of the two years in between and a full recertification at the end.
The cost that hurts is not the auditor's invoice. It is the months of evidence in front of it. Stage 2 wants a risk assessment with dates on it, an internal audit that was performed, a management review with minutes, and a nonconformity somebody actually closed. None of that can be produced in the week before the audit, so what you are really booking is a named owner and several months of running the system first.
How the large providers did it sets the expectation for what a certificate covers. AWS was certified in November 2024 for four named services, Amazon Bedrock, Amazon Q Business, Amazon Textract and Amazon Transcribe, and passed its first surveillance audit in November 2025. Anthropic announced certification of its AI management system in January 2025, audited by Schellman under ANAB accreditation. Microsoft holds certificates for a set of named Copilot and Foundry services. The scope is written on the certificate every time, and it pays to read it before treating a supplier's badge as cover for the product you buy.
ISO 42001 versus the AI Act
The AI Act is European law. It applies to you whether you have heard of it or not, its obligations hang off the risk class of the system, and breaking it carries fines. ISO/IEC 42001 is a voluntary standard. Nobody has to hold it, and nothing in the regulation asks for it. NBN puts it plainly: the AI Act imposes rules, ISO/IEC 42001 is voluntary, and it is a good first step towards compliance rather than the compliance itself.
The legal mechanism behind that distinction is Article 40 of the AI Act. A high-risk system that conforms to a harmonised standard is presumed to conform to the corresponding requirements of the regulation, but only for standards developed on a Commission request and then cited in the Official Journal of the European Union. ISO/IEC 42001 is not one of them, and European adoption did not change that. CEN approved the identical European version, EN ISO/IEC 42001:2026, on 13 March 2026 and made it available on 18 March 2026, which turns it into a national standard in Belgium through NBN but not into a harmonised one.
The harmonised track runs separately, at CEN-CENELEC's JTC 21, under the Commission's standardisation request. The first standard out of it, EN 18286:2026 on the quality management system for EU AI Act regulatory purposes, was approved on 12 July 2026 and covers the quality management system that Article 17 requires from providers of high-risk systems. That is the closest AI Act counterpart to ISO/IEC 42001, and even it carries no presumption of conformity yet, because that starts only once the reference appears in the Official Journal.
So certification helps and discharges nothing. The evidence you assemble for a 42001 audit, the inventory, the risk files, the oversight arrangements, is largely the evidence an AI Act question would ask for. Your obligations under Article 4, Article 26 and Article 50 stay exactly where they were.
If you already hold ISO 27001 or ISO 9001
Then you add rather than start over. The harmonized structure means clauses 4 to 10 are the same skeleton you already run, so your document control, your competence records and your audit programme extend to cover AI instead of being rebuilt.
Two things genuinely differ. The Annex A controls reach ground information security never touched: the life cycle of an AI system, where the training data came from, and what you tell the people who live with the result. And clause 6.1.4 turns the risk question outward. ISO/IEC 27001 asks what could happen to your organisation. ISO/IEC 42001 also asks what your system could do to somebody else, which is a different assessment with different people in the room.
What a Belgian SME should borrow instead of buy
For a company of thirty people with a Copilot licence and two AI features inside software it already pays for, the certificate is the wrong purchase. The checklist behind it is not. Three parts carry almost all of the value, and none of them needs an auditor.
An AI inventory. Every AI system in use, what it is for, who owns it, whether you are provider or deployer, and which data it touches. That is clause 4 in practice, and it is the same list the agent registry entry describes for agents. Nothing else here works without it.
A risk assessment per system, not per company. One page each. What can go wrong, how bad that would be, what you have done about it, who signed. Add the clause 6.1.4 question: who is on the receiving end of what this system decides or suggests, and what happens to them when it is wrong. That question turns a technical risk log into something you can put in front of a customer.
A management review. An hour a quarter, with somebody in the room who can actually decide. What ran, what went wrong, what changed at the suppliers, what we stop doing. Written down. This is the part that gets skipped, and the cheapest of the three.
Put an AI usage policy next to those and you have the working half of a management system without an audit budget. The day a tender does ask for the certificate, you start from a running system rather than a blank page, and that is where most of the project time goes.