QAnswer
QAnswer

QAnswer AI Search

⌘K
Try for Free
Back to Blog

Published August 21, 2026

News

ISO 42001: What the AI Management Standard Actually Requires

9 min read

Samir Yacini

Samir Yacini

Growth Marketer

ISO 42001: What the AI Management Standard Actually Requires
QAnswer

AI Summary by QAnswer

ISO/IEC 42001 is the first certifiable management-system standard for artificial intelligence. Published in late 2023, it does for AI what ISO 27001 did for information security: it defines how an organisation governs the thing, not how the thing is built.

That distinction confuses most people on first contact, and it is the whole point. ISO 42001 does not certify that your model is accurate or unbiased. It certifies that you have a system for identifying AI risks, deciding what to do about them, and proving you did it.

We went through the certification ourselves, so this guide covers what the standard actually requires, the Annex A controls, how the audit works, what it costs in effort, and how it relates to the EU AI Act.

What Is ISO 42001?

ISO/IEC 42001 specifies the requirements for establishing, implementing, maintaining and continually improving an AI management system — an AIMS. It is the AI counterpart to ISO 27001 for security and ISO 9001 for quality, and it follows the same structural logic, which makes it familiar if you already hold either.

It applies to any organisation that develops, provides or uses AI systems. That last word matters: you do not need to build models to be in scope. An organisation deploying someone else's AI across its operations has AI risks to govern.

What it does not certify

Worth being blunt, because vendors blur this. ISO 42001 is not a stamp saying your AI is accurate, fair or safe. No standard can certify that — accuracy is a property of a specific model on a specific task, and it changes with every update.

What certification tells a buyer is that you have identified where your AI can cause harm, put controls in place proportionate to that risk, and submitted the whole arrangement to an external auditor. It is evidence of governance maturity, not of model quality.

The Structure: Clauses 4 to 10

The requirements sit in clauses 4 through 10, and they mirror every other ISO management standard.

iso-42001-clauses.txt
4  Context            scope, interested parties, role in the AI value chain
5  Leadership         AI policy, responsibilities, management commitment
6  Planning           risk assessment, impact assessment, objectives
7  Support            competence, awareness, documented information
8  Operation          running the controls you selected
9  Evaluation         monitoring, internal audit, management review
10 Improvement        nonconformities, corrective action

If you hold ISO 27001, this shape is already familiar and much of clause 7 and 9 can be shared. That is the single biggest saving available: run one integrated management system rather than two parallel ones.

The AI system impact assessment

This is the requirement with no equivalent in ISO 27001, and the one that takes the most thought. Where security risk assessment asks what could happen to the organisation, the AI impact assessment asks what the AI could do to people — individuals, groups and society.

Concretely: who is affected by this system's outputs, what happens when it is wrong, who can contest a decision, and what is the consequence of the system being unavailable. It has to be done before deployment, and revisited when the system changes materially.

Annex A: The Controls

Annex A provides a catalogue of around 40 controls grouped into roughly ten areas. You do not implement all of them. You select the ones relevant to your risks and record the decision — including the exclusions and why — in a Statement of Applicability.

The areas that generate the most work in practice:

  • AI data management — provenance, quality, labelling, bias. Where did the training or retrieval data come from, and are you allowed to use it?
  • Impact assessment — the analysis described above, documented and dated.
  • Lifecycle — how systems are specified, tested, released, monitored and retired.
  • Third parties — what you require from model providers and subprocessors, and how you verify it.
  • Information for users — telling people they are interacting with AI, and what its limits are.

A note on the number: published sources give 38 or 39 controls depending on how they count sub-controls. Use the standard itself as the authority, not a blog post — including this one.

How the Audit Works

Certification follows the standard two-stage external audit model, performed by an accredited certification body.

certification-path.txt
# 1. Gap analysis
   Current practice measured against the requirements. Reveals the real workload.

# 2. Build the AIMS
   Policy, risk and impact assessments, Statement of Applicability, procedures.

# 3. Stage 1 audit
   The auditor reviews documentation and design. Are you ready to be audited?

# 4. Stage 2 audit
   Operational effectiveness: evidence, interviews, observation. Does it actually run?

# 5. Certificate + surveillance
   Valid three years, with annual surveillance audits in between.

Stage 2 is where organisations get caught out. A beautiful policy nobody follows fails. Auditors ask to see the impact assessment for a specific system, the record of who approved it, and the log of what changed since. If those artefacts do not exist, the documentation does not save you.

What it actually costs in effort

The honest answer is that it depends far more on your starting point than on your size. An organisation already certified to ISO 27001, with change control and documented procedures, is adding a risk domain to an existing system. An organisation with no management system is building one from scratch, and that is the expensive path — the standard is not the hard part, the discipline is.

ISO 42001 and the EU AI Act

These are different instruments and it is worth keeping them apart. ISO 42001 is a voluntary international standard you choose to certify against. The AI Act is binding EU law that applies whether you like it or not.

They fit together well, though. Much of what the AI Act demands — risk management, technical documentation, human oversight, post-market monitoring — maps onto clauses and controls you implement for ISO 42001. Certification is not automatic compliance, and nobody should sell it as such. But an organisation with a working AIMS has already built most of the evidence machinery the regulation asks for.

On timing: general-purpose AI model obligations have applied since 2 August 2025, Article 50 transparency duties since 2 August 2026, and the high-risk obligations were deferred to 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI in already-regulated products. We cover the wider regulatory picture in our guide to digital sovereignty.

Why It Matters Commercially

Two reasons, and the second is the one people underestimate.

The first is procurement. Public bodies and regulated industries increasingly ask for evidence of AI governance in tenders. A certificate answers in one line what would otherwise be a fifty-question security review.

The second is internal. Going through the process forces an organisation to write down what its AI systems actually do, who owns them and what happens when they fail. Most teams discover during the gap analysis that they have more AI in production than they thought, and less documentation than they assumed.

How This Applies at QAnswer

QAnswer holds both ISO 27001 and ISO 42001, which is still uncommon — most platforms hold the security certification alone. We wrote about the ISO 27001 certification when we obtained it.

Holding both matters for a specific reason. If you deploy an AI assistant over your own documents, your auditors will ask about the security of the data and the governance of the AI — two separate questions. A vendor certified on both answers both.

It also compounds with architecture. Because QAnswer runs on-premise or in a private cloud and every answer cites the source it came from, the evidence an auditor wants — where the data sits, who can reach it, why the system said what it said — is a property of the system rather than something reconstructed after the fact.

Our full posture is documented in the Trust Center.

Frequently Asked Questions

What is ISO 42001 in simple terms?

A certifiable standard for how an organisation governs artificial intelligence. It requires you to identify AI risks and impacts, apply proportionate controls, and prove to an external auditor that the system works.

Is ISO 42001 mandatory?

No. It is a voluntary standard. The EU AI Act is the mandatory instrument, and certification helps demonstrate readiness for it without replacing it.

How long does ISO 42001 certification take?

It depends almost entirely on your starting point. With an existing ISO 27001 management system you are extending something that works; without one you are building the discipline itself, which is the longer road.

How long is the certificate valid?

Three years, with annual surveillance audits in between to confirm the system is still operating.

What is the difference between ISO 42001 and ISO 27001?

ISO 27001 governs information security — protecting data. ISO 42001 governs AI — including harms the AI could cause to people, which security standards do not address. They share structure, so running them together is far cheaper than running them apart.

Does ISO 42001 certify that an AI is unbiased?

No, and any vendor implying otherwise is overselling. It certifies that you have a system for identifying and managing bias risk, not that a given model is free of bias.

Does it apply if we only use third-party AI?

Yes. The standard covers organisations that use AI systems, not only those that build them. Deploying someone else's model across your operations creates governance obligations of its own.

The Bottom Line

ISO 42001 is a governance standard, not a quality mark. Its value is that it makes AI risk management legible — to auditors, to buyers, and above all to yourself.

If you are evaluating AI vendors, asking for it is a fast filter. If you are considering certification, the gap analysis alone is worth doing: it tells you how much AI you are already running without governing.

Deploy AI on your own data, on infrastructure you control, with QAnswer — ISO 27001 and ISO 42001 certified. Explore our governance features and AI Assistants.

Learn more at www.qanswer.ai

Questions about our certifications? Contact us or email info@the-qa-company.com


Back to Blog

Share this article:

The AI platform that works.

Try for free today