Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is ISO/IEC 42001 and what is an AIMS?
Last verifiedISO/IEC 42001:2023 is the international management-system standard for governing AI. An AIMS is policies, roles, and controls; certification is optional third-party attestation. Not legal advice.
ISO 42001 overview, last verified 10 September 2026 against ISO/IEC 42001:2023 clauses 4–10 and Annex A/B, ISO/IEC 22989, and ISO/IEC 17021-1. This page does not determine that 42001 applies to YOU, does not issue certificates, and is not legal advice.
AIMS vs certification vs conformity
An AI management system (AIMS) is the organisational system in clauses 4–10: context, leadership, planning, support, operation, performance evaluation, and improvement. Conformity means YOUR organisation believes it meets those requirements. Certification is when an accredited certification body audits that AIMS and issues a certificate under ISO/IEC 17021-1 — a voluntary market signal, not a Union regulation and not a product CE mark. Last verified 10 September 2026.
- Legal requirement: none for ISO 42001 itself — it is a voluntary international standard.
- Professional standard: ISO/IEC 42001:2023 clauses 4–10 and Annex A control objectives (via Statement of Applicability).
- Guidance: Annex B implementation guidance; ISO/IEC 42005 and ISO/IEC 23894 are advisory.
- 42001 governs how YOU manage AI — it is not a product safety mark under product legislation.
Clauses 4–10 at a glance
| Clause | Theme | Kind of text |
|---|---|---|
| 4 | Context and scope of the AIMS | Standard requirement |
| 5 | Leadership and AI policy | Standard requirement |
| 6 | Planning, risks, objectives, SoA | Standard requirement |
| 7 | Support and documented information | Standard requirement |
| 8 | Operation — impact assessment, lifecycle | Standard requirement |
| 9 | Performance evaluation — audit, review | Standard requirement |
| 10 | Improvement — corrective action | Standard requirement |
Annex A — nine control areas
Annex A lists nine control areas. YOUR Statement of Applicability records which apply. Control objectives are required when applicable; implementation approach is the organisation's choice.
- Policies related to AI — Annex A control area.
- Internal organization — roles and reporting for AI.
- Resources for AI systems — data, tooling, computing, people.
- Assessing impacts of AI systems — AI system impact assessment.
- AI system life cycle — design through operation.
- Data for AI systems — provenance, quality, governance.
- Information for interested parties — transparency documentation.
- Use of AI systems — responsible operation and monitoring.
- Third-party and customer relationships — supplier and customer duties.
What to do now
- Read the controls-explained page for Annex A themes before scoping an AIMS.
- Inventory AI systems YOU actually develop or use — scope follows facts.
- Ask leadership whether certification, self-attestation, or readiness-only is the goal.
Checklist
- ☐ AIMS scope defined (which AI systems, which sites)?
- ☐ Leadership commitment and AI policy drafted?
- ☐ Annex A SoA started with justified exclusions?
- ☐ Distinction clear: voluntary standard vs EU AI Act legal duties?
Where this shows up in ShipReady Metrics
Signed-in app → Compliance → AI governance holds the AI inventory and AI risk register. The 24-framework crosswalk includes ISO 42001 with a crosswalk-density honesty layer (coverage, not a pass). Marking iso_42001 in-scope on the obligation map is not a determination that the standard applies. This product does not certify and does not replace an accredited audit.