ISO/IEC 42001 Artificial Intelligence Management Systems
The world's first certifiable management system standard for artificial intelligence. It confirms that AI is developed, supplied and used responsibly.
This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →
What this certification proves
ISO/IEC 42001 does not assess whether your AI is clever. Performance is not its concern. What it examines is whether you worked out in advance who could be affected and how, and whether a person can intervene when something goes wrong.
One thing separates it decisively from every other management standard. Others assess risk to the organisation. This one adds the AI system impact assessment, which evaluates what happens to the people and society affected by the AI — not to the company using it. Does a recruitment model screen out a particular group? Can a credit model explain why it decided as it did?
The second thing to know is that using someone else's AI is enough to bring you into scope. If you have put a chatbot or a model API into your workflow, this standard applies to you.
Who this is for
- Organisations that build AI or embed it in a product or service
- Organisations that only use someone else's AI — chatbots, model APIs — in their operations
- Organisations preparing for the EU AI Act or Korea's AI Framework Act (in force 22 January 2026)
- Organisations whose customers ask how AI is governed during due diligence
🌱 How this relates to ESG
G GovernanceS SocialSpans G (Governance) and S (Social). The structure that governs AI is governance; the effect AI has on people is social.
- G — AI governance: AI policy, accountable owners, risk management and control of third-party model suppliers. Maps to «risk management» in governance frameworks
- S — impact on people: bias and discrimination, individual rights, explainability. The weight shifts to S wherever AI affects someone's opportunities — recruitment, credit, healthcare
- 🔴 Korea's AI Framework Act (in force 22 January 2026) — prior notification that AI is in use (§31①) and labelling of AI-generated output (§31②) are legal obligations, with penalties up to KRW 30 million. Annex A.8 (information for interested parties) is the control that manages them
- EU AI Act — organisations placing AI products or services on the European market carry high-risk obligations. 42001 is widely used as the compliance framework
- The first certifiable AI management system standard — for now it is the only structured answer available when a customer asks how AI is governed
What certification gives you
- The effect AI has on people is assessed in advance, preventing discrimination and malfunction incidentsSee the 8-step process →
- 🔴 Ensures AI use notification and AI-generated content labelling are not missed — legal obligations under Korea's AI Framework ActRequest audit duration and fees →
- Using someone else's AI puts you in scope too — supplier management procedures followCheck a certified organisation →
- Shares its skeleton with ISO/IEC 27001, so existing 27001 holders move much fasterSee ISO/IEC 27001 →
- Evidence for EU AI Act readiness and customer due diligenceCertification mark rules →
How the requirements are structured
This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.
| Clause | Title | In plain terms |
|---|---|---|
| 4 | Context | Determine whether you are a developer or a user of AI, identify applicable law, and set the scope. |
| 5 | Leadership | Top management sets the AI policy and appoints accountable owners. |
| 6 | Planning | AI risk assessment and AI system impact assessment; select controls from Annex A. |
| 7 | Support | Data, computing resources, specialist competence, awareness and documented information. |
| 8 | Operation | Manage the AI lifecycle — planning, development, testing, deployment, operation, retirement — and run the impact assessment in practice. |
| 9 | Performance evaluation | Monitor how AI systems behave and what effect they have; audit internally and review. |
| 10 | Improvement | Where incidents, complaints or bias appear, remove the cause and revise controls. |
| Annex A | 38 controls | Nine groups — AI policy · internal organisation · resources · impact assessment · lifecycle · data · information for interested parties · use of AI systems · third-party and customer relationships. |
※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.
Before you apply, please check
Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.
- Is there an inventory of AI in use — including AI you buy rather than build (chatbots, APIs)?
- Has each AI been classified as «we develop it» or «we use it»? The obligations differ by role
- 🔴 Is AI-generated content labelled and is AI use notified in advance on screen? These are legal obligations
- Is there a record of an AI system impact assessment? This is the first document an auditor asks for
- Where AI affects someone's qualifications, opportunities or money, is there a step where a person makes the final decision?
- Is there a rule preventing national ID numbers, account numbers and passwords entering AI training or input data?
- Do contracts with AI suppliers (model providers) define the boundaries of responsibility?
- Have you carried out at least one internal audit yourselves? (required before the audit)
You can apply for ISO/IEC 42001 certification here
Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.
Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317
※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.
Which audit division handles this
Audits against this standard are carried out by our 정보보안심사본부. See the organisation chart →
