Ai Regulations
1899
UK AI Regulation Explained: How the UK Governs AI in 2026
Over half of UK adults and young people now use generative AI, and the large majority of UK businesses have...
ISO 42001 — formally ISO/IEC 42001:2023 — is the world's first international management system standard for artificial intelligence. Published in December 2023, it specifies the requirements for establishing, implementing, maintaining and continually improving an AI management system (AIMS): a structured, auditable way of governing how an organisation develops, provides or uses AI.
If your organisation already runs an ISO management system — 9001 for quality, 27001 for information security — the concept will feel immediately familiar, and that is by design. ISO/IEC 42001 follows the same harmonised structure as the standards you already operate, which means the question is rarely can we understand this? It is what does the AI version add, and is certification worth pursuing? This guide answers both, covering what the standard contains, how it compares with ISO 27001, how it relates to the EU AI Act, what certification involves, and how to decide whether it belongs on your roadmap.
ISO/IEC 42001 was developed jointly by the International Organization for Standardization and the International Electrotechnical Commission to fill a specific gap. Plenty of AI ethics principles and voluntary frameworks existed by 2023; what did not exist was a way for an organisation to prove, through independent audit, that it governs AI systematically. Among the major AI governance frameworks, ISO/IEC 42001 remains the only one that is certifiable, which is precisely what gives it commercial weight.
Three clarifications prevent the most common misunderstandings.
It certifies the organisation, not the AI. An AIMS certificate attests that your management system — your policies, risk assessments, roles, controls and improvement cycle — meets the standard. It does not certify that any individual AI model is accurate, unbiased or safe, in the same way that ISO 9001 certifies your quality system rather than guaranteeing every product is flawless.
It applies to users of AI, not only builders. The standard is written for any organisation that develops, provides or uses AI-based products and services. A logistics firm deploying vendor AI for routing, or a bank using a procured credit-scoring model, can implement and certify an AIMS just as a software company can.
It is voluntary. No law requires ISO/IEC 42001 certification. Its pull comes from the market — customer questionnaires, procurement requirements, regulatory expectations of "appropriate governance" — rather than from statute. How that voluntary standard interacts with binding law is covered in the EU AI Act section below.
The standard defines an AIMS, in essence, as the interconnected set of organisational elements — policies, objectives and processes — through which an organisation directs and controls its use of AI. In practice, an AIMS makes an organisation do five things continuously rather than once.
It makes you understand your context: which AI systems you have, who is affected by them, what stakeholders and regulators expect, and where AI sits in your strategy. It makes you assess risk and impact: ISO/IEC 42001 is notable for requiring not only conventional risk assessment but also AI system impact assessments that consider consequences for individuals, groups and society — a wider lens than most management standards demand. It makes you govern the lifecycle: applying controls from design or procurement through deployment, operation, monitoring and retirement, including oversight of third-party AI suppliers. It makes you assign accountability: leadership commitment, defined roles, competence and awareness requirements for the people who run AI. And it makes you improve: internal audits, management reviews, corrective action — the familiar plan-do-check-act engine that keeps the system honest as the technology and the rules change.
The recurring theme is proportionality. The standard does not prescribe one level of control for everything; it requires controls proportionate to the risks and impacts your own assessments identify — which is why two certified organisations can look quite different inside while both conforming.
ISO/IEC 42001 follows the harmonised high-level structure shared by modern ISO management system standards. Clauses 4 to 10 carry the requirements: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. If you hold ISO 27001:2022, the skeleton is identical — which is what makes integrated implementation realistic.
The substance specific to AI sits in the annexes. Annex A provides a reference set of 38 controls grouped under control objectives covering areas such as AI policy, internal organisation and accountability, resources for AI systems, impact assessment, the AI system lifecycle, data for AI, information for interested parties, AI use, and third-party relationships. As with ISO 27001's Annex A, organisations select and justify applicable controls through a statement of applicability rather than implementing everything blindly. Annex B offers implementation guidance for those controls; Annex C catalogues AI-related organisational objectives and risk sources to feed risk assessment; and Annex D addresses use of the AIMS across domains and sectors.
Two related standards are worth knowing because auditors and consultants will reference them: ISO/IEC 22989, which establishes AI terminology, and ISO/IEC 23894, which provides AI risk management guidance — both slot underneath 42001 rather than competing with it. A deliberate note on depth: this overview stays at the level of the standard's publicly available structure. The full text is copyrighted and must be purchased from ISO or a national standards body; the freely accessible foreword and introduction are viewable on the ISO Online Browsing Platform. Any implementation project needs the real document on the desk.

For most readers of this article, the practical question is how the AI standard differs from the information security standard they already run.

The headline difference is the impact assessment. ISO 27001 asks what could happen to our information? ISO/IEC 42001 also asks what could our AI do to people? — fairness, transparency, safety and societal consequences enter the management system as first-class concerns. The headline similarity is everything else: shared clause structure, shared audit logic, shared documentation discipline. Organisations with a functioning 27001 system typically extend it rather than building a parallel one, reusing their risk methodology, document control, internal audit programme and management review with AI-specific additions.
The standard and the EU AI Act are natural companions, but the relationship is often overstated, so it pays to state it precisely.
What 42001 genuinely does for Act readiness. The Act's high-risk regime demands exactly the kind of machinery an AIMS institutionalises: a risk management system, data governance, documentation, human oversight arrangements, post-market monitoring and accountability. An organisation operating a serious ISO/IEC 42001 system will have built most of the organisational scaffolding the Act expects, will have the evidence trail regulators ask for, and will find conformity work a matter of mapping and gap-closing rather than starting cold.
What 42001 does not do. Certification does not constitute EU AI Act compliance, and it does not currently grant a legal presumption of conformity. The Act's presumption mechanism works through harmonised European standards — being developed by the European standards bodies CEN and CENELEC at the European Commission's request — and those are distinct documents, even though they draw on international work including ISO/IEC 42001. Treat the standard as a strong foundation for Act compliance, not a substitute for it.
The honest summary for planning purposes: if the EU AI Act applies to you, ISO/IEC 42001 is one of the best structural investments you can make; it simply is not a certificate you can wave at a market-surveillance authority in place of conformity assessment. The same complementary logic applies to the voluntary NIST AI Risk Management Framework: NIST helps you think the risks through, 42001 systematises and certifies the management of them, and the Act sets the binding floor.
Certification follows the path familiar from other ISO management standards, with AI-specific content at each step.
Implementation. The organisation scopes its AIMS, performs risk and impact assessments, selects Annex A controls, produces the statement of applicability and required documentation, and runs the system long enough to generate evidence — internal audit results, management review minutes, monitoring records. For organisations extending an existing 27001 system, this phase commonly takes several months; greenfield implementations take longer.
Stage 1 audit. An accredited certification body reviews documentation and readiness — essentially checking that a system exists on paper and is plausibly operating.
Stage 2 audit. The certification audit proper: auditors test whether the system works in practice, sampling processes, interviewing staff and examining evidence against the standard's requirements.
Certification and surveillance. A successful stage 2 yields a certificate, typically valid for three years, with annual surveillance audits in between and full recertification at the end of the cycle.

One practical caution when choosing an auditor: the certification market for AI is young, so verify that your certification body is accredited for ISO/IEC 42001 by a recognised national accreditation body rather than merely offering the service. Accredited certification arrived quickly after publication — BSI, for example, holds UKAS, RvA and ANAB accreditations for ISO/IEC 42001 certification — and a supporting standard, ISO/IEC 42006, now sets the requirements for bodies auditing and certifying AI management systems. An unaccredited certificate is worth considerably less to the customers and regulators you are trying to convince.
Certification is an investment — standard purchase, implementation effort, audit fees, ongoing surveillance — so the decision deserves more rigour than "everyone seems to be doing it". Four questions sort most organisations.
Do your customers ask? If AI governance questionnaires are appearing in your sales cycles and procurement processes, certification converts a recurring, bespoke evidence exercise into a single credential. Demand-side pressure is the strongest business case, and it is the path large providers have already taken — Microsoft publishes ISO/IEC 42001 compliance documentation for its AI services precisely because enterprise customers expect it.
Is AI close to your core offering or your highest risks? An organisation whose product is AI, or whose AI decisions materially affect people, gains more from systematised governance than one using AI peripherally.
Does regulation loom? Organisations in scope of the EU AI Act's high-risk obligations get double value: the AIMS does real compliance groundwork while also producing a market-facing credential.
Do you already run ISO systems? Existing 27001 or 9001 machinery cuts the marginal cost of 42001 substantially — often the deciding factor for mid-sized organisations.
If most answers are no, a sensible middle path is to implement without certifying: build the AIMS, skip the audit, and keep certification as an option once customer or regulatory pressure justifies it. The governance benefit comes from the system, not the certificate; the certificate monetises the system.
ISO/IEC 42001 marks the moment AI governance grew up: from principles and pledges to a management system an independent auditor can verify. For ISO-experienced organisations, it is less a leap than an extension — the discipline you already apply to quality and security, pointed at the technology that now needs it most.
No. It is a voluntary standard — no jurisdiction legally requires certification. In practice, however, it is becoming a contractual and procurement expectation in AI-heavy supply chains, and for organisations facing the EU AI Act it doubles as structured preparation for obligations that are mandatory.
It depends on scope, AI footprint and existing management systems. Organisations extending a mature ISO 27001 system commonly reach certification readiness in roughly six to twelve months; organisations starting without any ISO infrastructure should expect longer. The audit itself (stages 1 and 2) is measured in weeks; building and evidencing the system is what takes the time. Treat any provider promising certification in a few weeks with scepticism.
Yes — it is explicitly designed for this. The standard shares the harmonised high-level structure used by ISO 27001, 9001 and peers, so clauses on leadership, planning, support, internal audit and management review can be operated as one integrated system. Most adopters with existing certifications run integrated audits covering multiple standards in a single cycle, which reduces both cost and audit fatigue.
Ai Regulations
1899
Over half of UK adults and young people now use generative AI, and the large majority of UK businesses have...
Ai Governance
3439
What Is an AI Governance Framework? An AI governance framework is a structured system of rules, responsibilities, processes, and controls...
319
Responsible AI is the practice of designing, deploying and managing artificial intelligence in a way that is fair, transparent, accountable...