GuideGlobalISO/IEC 42001

ISO/IEC 42001 Compliance

Conformance means the artificial intelligence management system (AIMS) fulfils the ISO/IEC 42001:2023 requirements that apply within its defined scope.

Show both design and operation: clause ownership, risk and impact methods, the statement of applicability, operating records, monitoring, internal audit, management review, and corrective action. Certification is voluntary and does not replace legal analysis.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this guide to assess , prepare an internal claim, answer customer assurance questions, or prepare for third-party certification. First define the AIMS scope. Then map every requirement in Clauses 4-10 to an accountable process and evidence that the process operates. Treat applicable laws, regulations, contracts, and sector rules as separate requirements: ISO/IEC 42001 can organise that work, but the standard does not prove those obligations have been met.

Section 1

What does ISO/IEC 42001 compliance mean?

ISO/IEC 42001 defines as fulfilment of a requirement. A conformance assessment therefore asks whether the scoped AIMS fulfils the standard's requirements and whether its processes are effectively implemented and maintained. It does not ask whether one model passed a product test.

Decide which assurance outcome is needed. An organisation can assess itself, ask a customer or other second party to assess it, or seek voluntary certification from an independent certification body. ISO does not certify organisations. Accreditation is separate recognition of a certification body's competence and is not compulsory.

State every claim precisely. Name the edition, the organisational and activity scope, the type of assessment, the assessor or certification body where applicable, and the current status. Do not describe readiness work or an internal assessment as certification.

  • Internal conformance: the organisation evaluates its own AIMS against defined criteria and retains the assessment method, evidence, findings, and approvals.
  • Customer assurance: provide evidence within the agreed scope and contract while protecting confidential or sensitive information.
  • Third-party certification: an independent certification body audits the management system and issues the certificate if its requirements are met.
  • Legal compliance: separately identify each applicable legal duty, responsible actor, jurisdiction, deadline, and required evidence.
Section 2

Which evidence shows that Clauses 4-10 operate?

Build an evidence map from each requirement to its owner, process, controlled document, operating record, and review method. Evidence must match the defined AIMS scope and the organisation's actual roles in developing, providing, or using AI systems.

Some requirements call for documented information explicitly, while others can be demonstrated through records of an operating process. Clause 7.5 also requires the organisation to control required AIMS information for availability, protection, access, storage, change, retention, and disposition. Keep the amount of documentation needed for the standard and effective operation, but make it traceable and current.

  • Context and leadership: context analysis, interested-party requirements, documented scope, AI policy, objectives, assigned roles, and evidence of top-management decisions and resources.
  • Planning: AI risk criteria, repeatable risk-assessment method, risk results, impact-assessment method and results, statement of applicability, treatment plan, residual-risk acceptance, objectives, and planned changes.
  • Support and operation: competence evidence, awareness and communications, controlled documented information, operational criteria, selected control records, supplier controls, change records, and retained risk, treatment, and impact results.
  • Performance and improvement: monitoring methods and results, internal-audit programme and reports, management-review inputs and decisions, nonconformity records, cause analysis, corrective actions, effectiveness reviews, and AIMS changes.
Section 3

How should risk treatment and Annex A be assessed?

Assess the Clause 6.1.3 decision process, not only the final control list. The organisation must use its risk-assessment results to select treatment options, determine all necessary controls, compare them with Annex A so necessary controls are not omitted, consider relevant Annex A controls and Annex B guidance, and identify additional controls where needed.

The statement of applicability must list the necessary controls and justify inclusion and exclusion. Annex A is normative, but it is a reference set rather than a universal checklist: the standard allows controls to be excluded when they are not necessary and additional controls to be designed or taken from other sources. Annex B is also normative, but its implementation guidance does not have to be included or excluded in the statement of applicability and may be adapted when it is not suitable or sufficient.

Check that designated management approved the treatment plan and accepted residual AI risks, and that the selected controls are implemented, monitored, and reviewed for effectiveness.

  • Trace each necessary control to a risk, objective, external requirement, or other documented reason.
  • Record why each Annex A control is included or excluded and identify any additional control.
  • Link the statement of applicability to the current risk treatment plan, residual-risk approval, owner, and operating evidence.
  • Reassess treatment when significant changes occur, new risks are found, or a treatment option proves ineffective.
Section 4

What should internal audit and management review test?

Internal audits must occur at planned intervals and determine whether the AIMS conforms both to the organisation's own requirements and to ISO/IEC 42001, and whether it is effectively implemented and maintained. The audit programme must define frequency, methods, responsibilities, planning, reporting, and the objectives, criteria, and scope of each audit. Auditors must be selected and audits conducted to preserve objectivity and impartiality.

Top management must review the AIMS at planned intervals. Inputs include earlier actions, changes in context and interested-party needs, trends in nonconformities, corrective actions, monitoring, measurement, and audit results, plus opportunities for improvement. The review must produce decisions on improvement opportunities and needed AIMS changes.

Use representative operating samples across the scope. A policy's existence does not show that risk assessments, impact assessments, supplier controls, monitoring, incident handling, or corrective actions work.

  • Keep audit criteria separate from consultancy or readiness advice so findings remain objective.
  • Record each nonconformity, its evidence, correction, cause analysis, corrective action, owner, due date, and effectiveness review.
  • Escalate overdue or ineffective corrective actions to management review.
  • Retain the audit programme, audit results, management-review inputs, decisions, and follow-up actions as documented information.
Section 5

How should teams prepare for certification without overstating it?

Confirm the intended certificate scope with candidate certification bodies before the audit and ask what accreditation covers their AIMS certification service. Verify the body's identity and accreditation status through the relevant accreditation body or recognised database where applicable. ISO recommends evaluating more than one certification body and checking the relevant -assessment standard and accreditation.

Before the external audit, complete the organisation's internal audit and management review, close or control known nonconformities, and confirm that records represent normal operation. Do not create a separate audit-only process. After certification, continue planned monitoring, internal audits, management reviews, corrective action, and change control.

Describe the certificate as assurance about the named management system and scope. Do not claim that ISO certified the organisation, that the certificate covers systems outside its stated scope, or that it proves every AI system is safe, accurate, unbiased, or legally compliant.

  • Check the certificate's standard edition, organisation name, sites or units, activity scope, certification body, issue date, validity information, and accreditation mark where used.
  • Route scope changes, significant AI changes, acquisitions, supplier changes, and major incidents through the AIMS change process and notify the certification body when required by its terms.
  • Keep legal and regulatory mappings current even when the certificate remains valid.
Primary sources

References and citations

iso.org
Referenced sections
  • ISO states that certification is voluntary, is performed by independent certification bodies, and does not replace laws or regulations.
iso.org
Referenced sections
  • Official ISO guidance on choosing and checking a certification body, the role of accreditation, certificate verification, and the fact that ISO does not certify organisations.
iso.org
Referenced sections
  • Clauses 9.2, 9.3, and 10.2 of the licensed standard establish internal-audit, management-review, nonconformity, and corrective-action requirements.
Related guides

Explore more topics

ISO/IEC 42001 AI Impact Assessment Template
ISO/IEC 42001 AI-system impact assessment template for consequences, affected people, foreseeable misuse, context, evidence, approval, and reassessment.
ISO/IEC 42001 AI Management FAQ
Plain-language ISO/IEC 42001 FAQ covering scope, policy, Annex controls, risk and impact assessment, suppliers, monitoring, certification, and legal limits.
ISO/IEC 42001 AI Policy FAQ
ISO/IEC 42001 AI policy requirements, approval, communication, evidence, alignment with other policies, and review triggers.
ISO/IEC 42001 AI System Inventory Guide
Build an ISO/IEC 42001 AI inventory covering purpose, owners, lifecycle roles, data, resources, suppliers, impacts, risks, controls, and monitoring.
ISO/IEC 42001 AI System Inventory Workflow
ISO/IEC 42001 workflow for creating, approving, maintaining, changing, and retiring AI-system inventory records with accountable evidence.
ISO/IEC 42001 AIMS Scope Decision Guide
Define an auditable ISO/IEC 42001 AIMS boundary across organisational units, AI activities, products, services, interfaces, suppliers, and customers.
ISO/IEC 42001 AIMS Scope Decision Workflow
ISO/IEC 42001 AIMS scope workflow for context, interested parties, AI activities, external dependencies, boundary approval, and change review.
ISO/IEC 42001 Certification FAQ
ISO/IEC 42001 certification scope, readiness evidence, internal audit, management review, corrective action, and claim limits.
ISO/IEC 42001 Controls and Governance Model Guide
ISO/IEC 42001 governance model linking leadership, policy, risk and impact assessment, Annex controls, lifecycle roles, monitoring, audit, and improvement.
ISO/IEC 42001 Generative AI FAQ
Apply ISO/IEC 42001 to generative AI development, procurement, integration, employee use, supplier evidence, impacts, controls, and monitoring.
ISO/IEC 42001 High Risk AI FAQ
Separate ISO/IEC 42001 organisational risk criteria from legal high-risk AI classifications, with evidence, approval, and reassessment triggers.
ISO/IEC 42001 Human Oversight FAQ
Design and evidence effective human oversight under ISO/IEC 42001, including competence, information, intervention authority, testing, and review.
ISO/IEC 42001 Model Monitoring Evidence Guide
ISO/IEC 42001 monitoring evidence for AIMS performance, AI-system outcomes, impacts, control effectiveness, supplier signals, escalation, and correction.
ISO/IEC 42001 Post Market Monitoring FAQ
Distinguish ISO/IEC 42001 operational monitoring from legal post-market monitoring and connect real-world evidence to risk, review, incidents, and correction.
ISO/IEC 42001 Provider and Deployer Roles FAQ
Map ISO/IEC 42001 lifecycle responsibilities across developers, users, suppliers, customers, and third parties while keeping legal operator roles separate.
ISO/IEC 42001 Requirements Guide
ISO/IEC 42001:2023 requirements explained across Clauses 4-10, Annex A controls, Annex B guidance, evidence, audit, review, and improvement.
ISO/IEC 42001 Risk Controls FAQ
Select, justify, approve, operate, and review ISO/IEC 42001 risk controls, including Annex A comparison, the statement of applicability, residual risk, and evidence.
ISO/IEC 42001 vs EU AI Act Comparison
Compare voluntary ISO/IEC 42001 AIMS certification with binding EU AI Act roles, classifications, duties, evidence, dates, and enforcement.
ISO/IEC 42001 vs ISO/IEC 23894 Comparison
Compare certifiable ISO/IEC 42001 AIMS requirements with ISO/IEC 23894 AI risk-management guidance and see how to integrate their evidence.
ISO/IEC 42001 vs NIST AI RMF Comparison
Compare ISO/IEC 42001 AIMS requirements with the voluntary NIST AI RMF GOVERN, MAP, MEASURE, and MANAGE functions and evidence.