ISO/IEC 42001 Artificial Intelligence Management Systems

The world's first certifiable management system standard for artificial intelligence. It confirms that AI is developed, supplied and used responsibly.

ITS own scheme

This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →

What this certification proves

ISO/IEC 42001 does not assess whether your AI is clever. Performance is not its concern. What it examines is whether you worked out in advance who could be affected and how, and whether a person can intervene when something goes wrong.

One thing separates it decisively from every other management standard. Others assess risk to the organisation. This one adds the AI system impact assessment, which evaluates what happens to the people and society affected by the AI — not to the company using it. Does a recruitment model screen out a particular group? Can a credit model explain why it decided as it did?

The second thing to know is that using someone else's AI is enough to bring you into scope. If you have put a chatbot or a model API into your workflow, this standard applies to you.

Who this is for

  • Organisations that build AI or embed it in a product or service
  • Organisations that only use someone else's AI — chatbots, model APIs — in their operations
  • Organisations preparing for the EU AI Act or Korea's AI Framework Act (in force 22 January 2026)
  • Organisations whose customers ask how AI is governed during due diligence

🌱 How this relates to ESG

G GovernanceS Social

Spans G (Governance) and S (Social). The structure that governs AI is governance; the effect AI has on people is social.

  • G — AI governance: AI policy, accountable owners, risk management and control of third-party model suppliers. Maps to «risk management» in governance frameworks
  • S — impact on people: bias and discrimination, individual rights, explainability. The weight shifts to S wherever AI affects someone's opportunities — recruitment, credit, healthcare
  • 🔴 Korea's AI Framework Act (in force 22 January 2026)prior notification that AI is in use (§31①) and labelling of AI-generated output (§31②) are legal obligations, with penalties up to KRW 30 million. Annex A.8 (information for interested parties) is the control that manages them
  • EU AI Act — organisations placing AI products or services on the European market carry high-risk obligations. 42001 is widely used as the compliance framework
  • The first certifiable AI management system standard — for now it is the only structured answer available when a customer asks how AI is governed

What certification gives you

How the requirements are structured

This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.

ISO/IEC 42001Artificial Intelligence Management SystemsP · 조항 4 · 5 · 6PlanSet the AI policy;assess AI risk and…D · 조항 7 · 8 · Annex ADoOperate the selectedcontrols across…C · 조항 9CheckMeasure AIperformance and…A · 조항 10ActRemove causes ofincidents and bias;…
계획 → 실행 → 점검 → 개선이 한 번으로 끝나지 않고 계속 돕니다. 심사에서 보는 것도 «이 바퀴가 실제로 도는가» 입니다.
ClauseTitleIn plain terms
4ContextDetermine whether you are a developer or a user of AI, identify applicable law, and set the scope.
5LeadershipTop management sets the AI policy and appoints accountable owners.
6PlanningAI risk assessment and AI system impact assessment; select controls from Annex A.
7SupportData, computing resources, specialist competence, awareness and documented information.
8OperationManage the AI lifecycle — planning, development, testing, deployment, operation, retirement — and run the impact assessment in practice.
9Performance evaluationMonitor how AI systems behave and what effect they have; audit internally and review.
10ImprovementWhere incidents, complaints or bias appear, remove the cause and revise controls.
Annex A38 controlsNine groups — AI policy · internal organisation · resources · impact assessment · lifecycle · data · information for interested parties · use of AI systems · third-party and customer relationships.

※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.

Before you apply, please check

Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.

  • Is there an inventory of AI in use — including AI you buy rather than build (chatbots, APIs)?
  • Has each AI been classified as «we develop it» or «we use it»? The obligations differ by role
  • 🔴 Is AI-generated content labelled and is AI use notified in advance on screen? These are legal obligations
  • Is there a record of an AI system impact assessment? This is the first document an auditor asks for
  • Where AI affects someone's qualifications, opportunities or money, is there a step where a person makes the final decision?
  • Is there a rule preventing national ID numbers, account numbers and passwords entering AI training or input data?
  • Do contracts with AI suppliers (model providers) define the boundaries of responsibility?
  • Have you carried out at least one internal audit yourselves? (required before the audit)
See the 8-step certification process →

You can apply for ISO/IEC 42001 certification here

Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.

Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317

※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.

Which audit division handles this

Audits against this standard are carried out by our 정보보안심사본부. See the organisation chart →