ISO/IEC 42001: What Your Function Must Demonstrate

ISO/IEC 42001 is the first international management-system standard for artificial intelligence, and it is quickly becoming the badge firms reach for when a customer, a board or a regulator asks “how do you govern your AI?” Published in 2023, it does for AI what ISO 27001 did for information security: it defines a management system — an AI Management System, or AIMS — that an accredited body can certify. For a firm whose AI is becoming a selling point or a scrutiny point, the question is no longer whether AI governance matters, but whether to demonstrate it through a recognised certification.

What the standard actually asks for

ISO 42001 follows the familiar management-system structure, so anyone who has been through ISO 27001 will recognise the shape: leadership commitment, defined scope, risk and impact assessment, objectives, operational controls, and continual improvement on a plan-do-check-act cycle. What is distinctive is the AI-specific content. It requires an organisation to assess not just risks to itself but impacts on individuals and society, to manage the full AI lifecycle from data to deployment to decommissioning, and to maintain the governance, documentation and human-oversight arrangements appropriate to the systems it runs. The Annex A controls span data governance, transparency, accountability and lifecycle management — the areas an auditor will expect to see evidenced, not just described.

Why it is worth considering now

Two forces make ISO 42001 more than a nice-to-have. The first is commercial: enterprise buyers and procurement teams are beginning to ask AI suppliers for governance assurance, and a certification answers that question in a way a policy document does not. The second is regulatory adjacency. The EU AI Act imposes real obligations on high-risk and general-purpose AI, and while ISO 42001 is not the AI Act and certification does not equal legal compliance, a well-built AIMS produces much of the governance, risk-assessment and documentation the Act expects. Building the management system once, to a recognised standard, is an efficient way to be ready for both the buyer’s question and the regulator’s.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

What “demonstrate” really means

The word that trips firms up is demonstrate. Certification is not achieved by writing policies; it is achieved by showing the management system operating — risk assessments actually performed, controls actually running, oversight actually exercised, with records to prove it. The common failure is treating ISO 42001 as a documentation exercise and discovering at audit that the auditor wants evidence of practice, not intent.

  • Start with scope. Define which AI systems and processes the AIMS covers; an honest, bounded scope is easier to certify than an aspirational one.
  • Assess impact, not just risk. The standard’s distinctive requirement is considering effects on people, not only on the business.
  • Build the evidence trail as you go. The management system has to be lived, not assembled the month before the audit.

For a firm serious about AI as part of its offering, ISO 42001 is the clearest way to turn “we govern our AI responsibly” from a claim into something a customer or regulator can verify.

Who this is for

This reading is for:

  • CTOs and heads of AI asked to “get certified” for AI governance
  • Compliance leads deciding whether ISO 42001 is worth pursuing
  • Firms using AI Act readiness as a commercial differentiator
  • Boards wanting external assurance that AI is under control

Sixteen Pillars builds the AI management system to ISO 42001 as a lived, evidenced capability, positioned so it also answers much of what the EU AI Act expects. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming