ISO/IEC 42001: the AI management standard
ISO/IEC 42001 is the first international standard for an Artificial Intelligence Management System (AIMS) — a structured way to govern how you develop and use AI responsibly. It brings accountability, transparency, and AI-specific risk management under one certifiable framework, and it’s built on the same management-system backbone as ISO 27001, so the two fit together.
What it is
ISO/IEC 42001 defines an AI Management System (AIMS) — the policies, roles, risk processes, and controls for governing AI across its lifecycle. It’s the first management-system standard dedicated to artificial intelligence, and like ISO 27001 it can be independently certified.
Who needs it
Organizations that build, deploy, or depend on AI in ways that carry risk or scrutiny — AI-first products, enterprises embedding AI in decisions, and vendors whose customers now ask how their AI is governed. As AI regulation grows, it’s becoming the way to demonstrate responsible AI.
Governing AI you can trust
AI shapes decisions that affect real people. ISO 42001 turns responsible AI from a principle into an operating system.
Accountability by design
AI systems make or influence decisions that affect people. ISO 42001 asks you to define who is accountable, how risks are assessed, and how AI use aligns with your obligations.
Transparency & oversight
It pushes for documented purpose, data handling, and human oversight of AI — so you can explain what a system does and keep meaningful control over its outcomes.
Risk & trustworthiness
The standard frames AI-specific risks — bias, safety, misuse, model drift — as things to identify, treat, and monitor, the same way an ISMS treats information-security risk.
From policy to certification
Establish the AIMS
Define the scope of your AI Management System, set AI policy and objectives, and identify the AI systems and roles in play.
Assess AI risk & impact
Run AI risk assessments and impact assessments covering the people and outcomes your systems affect, then decide how to treat what you find.
Operate & document
Put controls, oversight, and records in place across the AI lifecycle — data, development, deployment, and monitoring — and keep the evidence.
Audit & improve
An accredited body can certify a conformant AIMS; internal audits and management review keep it improving as your AI use evolves.
How ISO 42001 complements ISO 27001
ISO 42001 and ISO 27001 share the same management-system backbone — scope, leadership, risk assessment, controls, internal audit, and continual improvement. If you already run an ISO 27001 ISMS, much of that structure carries straight over to an ISO 42001 AIMS; ISO 42001 then adds the AI-specific pieces like AI impact assessments and lifecycle oversight.
That shared backbone is the opportunity. Read our ISO 27001 guide to see the foundation, then let Komply map both standards onto a single control set so your security and AI governance run as one program.
ISO 42001 (AIMS) vs ISO 27001 (ISMS)
| ISO 42001 | ISO 27001 | |
|---|---|---|
| What it governs | AI systems & AI risk | Information security |
| Management-system model | ||
| Certifiable | ||
| AI-specific impact assessment | ||
| Best paired with | ISO 27001 | ISO 42001 |
ISO 42001, answered
Prove your AI is well-governed
Komply keeps your ISO 42001 AI-governance records alongside ISO 27001 in one control set — drafting policies, tracking evidence, and keeping you audit-ready.