ISO/IEC 42001:2023
ISO 42001 Artificial Intelligence Management Systems
Govern AI you build or buy, before regulators and customers ask how.
AI policy
Leadership, Clause 5
Data
Provenance
Model
Design and verify
Impact assessment
Clause 6 gate
Approved
Deploy
Clause 8
Human oversight
Annex A control
Monitor
Clause 9 review
Retrain returns to Data
Trustworthy AI
Evidence on demand
SYS/05 · Governed lifecycle
AI lifecycle stages loop through impact and oversight gates under a leadership policy, yielding trustworthy AI.
What ISO 42001 is
ISO/IEC 42001 is the first certifiable management-system standard for artificial intelligence. It requires organizations that develop, provide or use AI to govern it responsibly: impact assessments, lifecycle controls, data quality, transparency and human oversight, structured through the familiar Annex SL clauses.
CORE audits ISO 42001 against the AI systems you actually run. Your auditor starts with the inventory and your declared role in the value chain, then tests whether risk and impact assessments were completed before deployment rather than after, whether human oversight exists where the system affects people, and whether data provenance, evaluation and monitoring records support the claims made in your system documentation. Because the standard is young, the findings raised most often concern inventories that miss AI embedded in purchased tools, impact assessments treated as a one-off sign-off, and monitoring that watches uptime rather than behaviour.
Who it is for
- Software companies whose customers now require an AI-governance certificate alongside ISO 27001
- Enterprises deploying third-party AI in decisions affecting people and facing contractual governance clauses
- Organizations whose tenders or regulators expect independently audited AI management
- Certified organizations transferring an active ISO 42001 certificate from another certification body
- Data and platform teams that want responsible-AI practice assessed rather than asserted
Business outcomes
What leadership should expect the system to change, in operational terms.
Defensible AI decisions
Documented impact assessments and oversight for every consequential AI system.
Procurement advantage
A certificate of registration answers the AI-governance questions now appearing in enterprise contracts.
Regulatory preparation
A management system aligned to the direction of AI regulation across major markets.
Controlled innovation
Clear criteria for what may ship, with which data, under whose accountability.
Benefits beyond the certificate
Inventory and ownership
Every AI system, model and use case catalogued with a named owner and risk tier.
Lifecycle discipline
Controls across design, data, verification, deployment and monitoring rather than one-off ethics reviews.
Transparency artifacts
System documentation and user information prepared once, reused for every stakeholder.
Integration with 27001
Shares structure with information security, so one system governs data and AI together.
Trust signal
An audited certificate differentiates in markets where AI claims are cheap and unverified.

The main requirements
The themes your auditor will examine, in plain language. The full clause detail is worked through at Stage 2.
01
Context and role (Clause 4)
Determine your role across the AI value chain: developer, provider, user, or several at once.
02
Leadership and policy (Clause 5)
An AI policy with commitments to responsible development and use, and assigned accountability.
03
Risk and impact assessment (Clause 6)
AI risk assessment plus AI system impact assessment considering individuals and society.
04
Support (Clause 7)
Competence, awareness and documented information for the AIMS.
05
Operation (Clause 8)
Operational planning, AI system lifecycle controls and third-party AI management.
06
Annex A controls
Reference controls covering policies, impact assessment, lifecycle, data, transparency and use.
07
Evaluation and improvement (Clauses 9 and 10)
Monitoring, internal audit, management review and continual improvement of the AIMS.
What each requirement buys you
Select a requirement theme to see the business outcomes it chiefly drives. The mapping reflects where audit sampling concentrates, not a normative ISO table.
Requirement themes
Context and role (Clause 4) chiefly drives 2 of 4 ISO 42001 outcomes.
Outcomes it drives
Defensible AI decisions
Documented impact assessments and oversight for every consequential AI system.
Procurement advantage
A certificate of registration answers the AI-governance questions now appearing in enterprise contracts.
Regulatory preparation
A management system aligned to the direction of AI regulation across major markets.
Controlled innovation
Clear criteria for what may ship, with which data, under whose accountability.
How CORE audits ISO 42001
Step 1
Stage 1 reviews role, inventory and scope
Your auditor confirms the role you have declared across the AI value chain, tests the AI system inventory against what the organization actually deploys, reads the AI policy, the risk and impact assessment method and the applicability of the Annex A controls, and checks that internal audit and management review have taken place.
Step 2
Stage 2 examines the AI lifecycle in practice
The audit samples individual AI systems from the inventory and follows them through: the completed impact assessment and its timing, data sources and provenance, evaluation and testing evidence, release criteria and approvals, human oversight arrangements, transparency and user information, third-party AI supplier controls, and post-deployment monitoring.
Step 3
Surveillance samples new systems and drift
Year 1 and Year 2 audits sample AI systems added or materially changed since the last visit, re-assessment of impact where use or model changed, AI incidents and complaints, monitoring output and the action taken on it, competence of the people exercising oversight, and the closure of previous findings.
Step 4
Recertification revisits the whole cycle
In Year 3 the audit reviews the AI management system across the full period: whether the inventory stayed complete, whether impact assessment became routine rather than exceptional, whether oversight held as deployment scaled, and whether the declared role and scope still describe what the organization does.
What your auditor expects to see
Before Stage 2 can proceed, the system needs to have run long enough to have produced its own evidence.
01Internal AIMS audit completed
A full internal audit of the clauses and applicable Annex A controls with evidence sampling across real AI systems, run by auditors independent of the teams that built them.
02Management review held
Minuted review covering AI incidents, monitoring results, impact assessment outcomes, supplier performance and objectives, with decisions and owners recorded.
03Records covering a meaningful period
Completed impact assessments, evaluation and test results, release approvals, monitoring output and oversight logs spanning enough time to show the system governing deployment rather than documenting intent.
04Corrective actions closed
AI incidents, complaints and audit findings showing root-cause analysis, the change made to the lifecycle control, and evidence that the change is operating.
05Competence demonstrable
Records connecting named people to defined AI responsibilities: risk owners, system owners, and anyone exercising human oversight over a consequential decision.
06Inventory and scope defined
A written scope naming the AI systems, roles and locations to be certified, matched by an inventory that includes AI embedded in purchased products.
Certification decision
With that evidence in place, Stage 1 and Stage 2 can run. The decision that follows is taken by a reviewer who was not on your audit team.
CORE is the certification body. We assess and certify management systems. We do not build them — that separation is what makes the certificate worth holding. We do not design, document or implement the systems we audit, and we do not run your internal audits. If you need that work done, our directory of independent consultants is a starting point, and engaging one has no bearing on the decision. More on how we keep the audit and the decision separate.
The optional pre-assessment
Before Stage 1 you can ask for an optional pre-assessment: an audit-style review of your AI activities and governance against ISO/IEC 42001:2023. It tests the inventory, samples completed impact assessments, and examines the applicable Annex A controls, returning a written report of where the evidence would not currently satisfy an auditor.
The report reports; it does not resolve. CORE will not build your inventory, write your impact assessment method or select your controls, because a certification body may not audit work it produced. Because the standard is recent, many organizations use the pre-assessment simply to see how a certification auditor reads their existing governance. Where implementation support is needed, see /resources/find-a-consultant.
What you receive
- Findings against each clause of the standard
- Where the evidence is missing or incomplete
- Whether Stage 2 could proceed on today's records
- The same sampling method a certification audit uses
Training for ISO 42001
Courses that teach how the standard is written and how it is audited.
ISO 42001 questions, answered straight
Related standards
Ready to certify to ISO 42001?
Tell us your standards, scope, effective headcount and sites. You will get a scope statement and a fixed quotation, with audit duration calculated from the accreditation body's mandatory formula.