Examples
Worked examples
- Is an instance
An enterprise pursuing ISO/IEC 42001 certification across its AI portfolio.
- Is an instance
A consultancy mapping ISO/IEC 42001 controls to EU AI Act provider obligations.
Counter-examples
Looks similar, but isn't
- Not an instance
A single model card.
- Not an instance
ISO/IEC 27001 (information security, not AI).
Editorial commentary
ISO/IEC 42001 is an international standard, published in 2023, specifying requirements for establishing, implementing, maintaining, and continually improving an AI management system within an organisation — structured analogously to ISO 9001 (quality management) and ISO/IEC 27001 (information-security management), which it deliberately shares a common high-level structure with to ease integrated audits.
What it governs
ISO/IEC 42001 is organisation-level governance scaffolding, not a per-system compliance check: it specifies requirements across leadership commitment, planning (including AI risk assessment and treatment), support (resources, competence, awareness), operation (AI system lifecycle controls), performance evaluation, and continual improvement of an organisation’s AI management practices as a whole. It is the first certifiable international standard specifically for AI management, meaning an organisation can be audited and formally certified against it by an accredited certification body, the way organisations already are for ISO 9001 or ISO/IEC 27001.
How this differs from a conformance assessment or an evaluation card
ISO/IEC 42001 certifies an organisation’s overall governance processes — does this organisation have adequate AI risk management, oversight, and continual-improvement practices in place? — which is a different question from an AI conformance assessment, which certifies that one specific AI system meets one specific law’s requirements before that system reaches the market. It is also broader than an AI evaluation card, which documents a single evaluation exercise rather than an organisation’s management system. ISO/IEC 42001 is expected to interact with, and potentially streamline, EU AI Act conformity-assessment routes for organisations that already hold it, though the Act’s own conformity-assessment requirements remain the legally binding path.
Sources
ISO/IEC 42001:2023, “Information technology — Artificial intelligence — Management system.”
Also known as
ISO 42001 · AIMS standard
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="ISO/IEC 42001 (AI management system)"
vocab-term-identifier="https://casrai.org/dictionary/term/iso-iec-42001-ai-management-system" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/iso-iec-42001-ai-management-system",
"name": "ISO/IEC 42001 (AI management system)",
"identifier": "https://casrai.org/dictionary/term/iso-iec-42001-ai-management-system",
"description": "An international standard, published in 2023, specifying requirements for establishing, implementing, maintaining, and continually improving an AI Management System within an organisation, structured analogously to ISO 9001 (quality) and ISO/IEC 27001 (information security).",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/ai-ml-research-outputs#set",
"url": "https://casrai.org/dictionary/term/iso-iec-42001-ai-management-system",
"sameAs": [
"ISO 42001",
"AIMS standard"
],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"author": {
"@id": "https://casrai.org/#editorial-team"
},
"datePublished": "2026-05-21T02:22:50",
"dateModified": "2026-08-22T14:39:33",
"inLanguage": "en-GB",
"isAccessibleForFree": true
}







