ISO/IEC 42001:2023 — AI Management Systems
ISO 42001 — the certification
standard for AI governance.
ISO/IEC 42001:2023 is the international standard for AI Management Systems. It gives organisations a structured, auditable framework for governing AI responsibly — and a certification that proves it. Endaxi AIG implements the complete standard, out of the box.
The Standard
What ISO/IEC 42001 is, and why it matters now.
ISO/IEC 42001:2023 — published in December 2023 — establishes requirements for an Artificial Intelligence Management System (AIMS): the policies, processes, controls, and evidence that an organisation uses to manage AI responsibly throughout its lifecycle. Think of it as ISO 27001, but for AI governance specifically.
What it covers
ISO 42001 follows the standard high-level structure (HLS) shared by ISO 27001, ISO 9001, and other management system standards. It covers:
- Understanding the context in which AI is used in your organisation
- Leadership, accountability, and AI policy
- Risk assessment and treatment specific to AI
- Operational controls — 32 controls across 8 domains in Annex A
- Impact assessments — societal, fundamental rights, and safety
- Internal audit, management review, and continual improvement
- Nonconformity management and corrective action
Who it applies to
ISO 42001 applies to any organisation that:
- Develops, provides, or uses AI systems
- Wants to demonstrate responsible AI governance to customers, regulators, or partners
- Is seeking to meet enterprise procurement requirements that demand an AI governance framework
- Is pursuing EU AI Act compliance and wants a supporting management system
There is no minimum size threshold. ISO 42001 is designed to scale from a small organisation with a handful of AI tools to a large enterprise with complex AI programmes.
Why Certify
Why ISO 42001 certification is becoming non-negotiable.
Certification is not yet a legal requirement for most organisations — but the commercial and regulatory pressure to certify is accelerating faster than most compliance teams anticipated.
Enterprise procurement gates
Large enterprises and public bodies are increasingly requiring suppliers to demonstrate AI governance maturity. ISO 42001 certification — like ISO 27001 before it — is becoming a standard procurement condition. Early certification gives you a competitive advantage and avoids losing contracts.
EU AI Act synergy
ISO 42001 and the EU AI Act share significant structural overlap. An ISO 42001-certified AI management system provides much of the governance infrastructure the Act requires — risk management, technical documentation, human oversight, and post-market monitoring. Building both simultaneously is the most efficient path to compliance with either.
Regulator and board confidence
Certification by an accredited third-party body is the most credible way to demonstrate to regulators, insurers, and your own board that AI governance is not just documented on paper but embedded in operating practice. It provides independent assurance that your AIMS is functioning as intended.
Customer trust and differentiation
As AI concerns grow among end customers, ISO 42001 certification — like a privacy seal or ISO 27001 — signals that your organisation takes AI responsibility seriously. For B2B vendors in particular, it is increasingly a differentiator in sales conversations.
Insurance and liability
Cyber and technology liability insurers are beginning to ask about AI governance practices. An ISO 42001-aligned programme — whether certified or not — provides evidence of due diligence that is relevant to underwriting assessments and claims handling.
Internal discipline
Beyond external drivers, ISO 42001 provides a structured discipline for managing AI consistently across an organisation — clear ownership, documented controls, regular review cycles, and a corrective action programme. Organisations that implement it report cleaner AI decision-making and fewer governance surprises.
The AIMS Lifecycle
ISO 42001 is not a one-time exercise. It is a managed system.
Like all ISO management system standards, ISO 42001 follows a Plan–Do–Check–Act cycle. Your AIMS must be continually maintained, audited, and improved — not just documented once. Endaxi AIG implements every stage of the cycle.
1
Define scope
Establish your AIMS boundaries, AI roles (provider/deployer), and interested parties
2
Set policy
Document your AI policy, measurable objectives, and KPIs with ownership
3
Assess risk
Classify and risk-assess every AI system; complete impact assessments for high-risk systems
4
Implement controls
Apply Annex A controls; build evidence; track implementation and test dates
5
Audit & review
Internal audit against all clauses; management review with documented inputs and outputs
6
Improve
Log nonconformities; root cause analysis; corrective actions with effectiveness review
Platform Modules
Ten modules. Every clause of ISO 42001 implemented.
Endaxi AIG implements the full ISO/IEC 42001:2023 standard across ten dedicated modules — from AIMS scope through to CAPA. Each module maps directly to the relevant clauses and, where applicable, to the corresponding EU AI Act articles.
A
Clause 4 — Context
AIMS Scope & Context
Versioned scope statements defining your AI Management System boundaries, in-scope business units, AI role declaration (Provider, Deployer, Importer, Distributor), internal and external issues register with climate change relevance tracking, and full version history.
B
Clause 4.2 — Interested Parties
Interested Parties & Requirements
Structured tracking of stakeholder expectations across seven party types — Internal, External, Regulator, Customer, Supplier, Employee, Public — with AIMS-addressed flags for traceability to controls and objectives.
C
Clauses 5 & 6.2 — Leadership
AI Policy & Objectives
Versioned AI Policy with approval workflow — only one version current at a time. Measurable AI Objectives with KPI, target value, current value, status tracking (On Track, At Risk, Behind, Achieved), and named owner accountability.
D
Articles 5, 6, 50, 5
EU AI Act Classification Engine
Guided classification wizard applying the Act’s precedence logic. Generates a Legal Classification Certificate with rationale, assessor identity, and timestamp. Omnibus-current — updated for May 2026 amendments. Covers all 5 risk tiers and GPA.
E
Clause 6.1 — Risk & Impact
Risk & Impact Assessment Framework
Pre-seeded 5×5 risk criteria matrix with three appetite levels. Eight AI-specific risks pre-loaded. Per-system risk assignment with treatment type, residual scoring, and accepted-by tracking. Includes FRIA (Art. 27) and ASIA (Art. 9) assessment modules.
F
Clause 6.1 + Annex A
Statement of Applicability
All 32 ISO/IEC 42001:2023 Annex A controls pre-seeded, each cross-referenced to the relevant EU AI Act articles. Implementation status, justification, and exclusion rationale tracked per control. SoA JSON export for certifying bodies.
G
Clause 8 — Operations
Controls Library & Assessment Engine
Ten pre-seeded AI-specific controls mapped to Annex A and EU AI Act articles. Per-system control assignment with implementation status, test dates, and owner. Four assessment templates: Intake, Security Review, Annual Review, Change Triggered.
H
Clauses 9.2 & 9.3 — Evaluation
Internal Audit & Management Review
Internal audit module with lead auditor assignment, finding severity classification (Observation, Minor NC, Major NC, OFI), and full lifecycle. Management Review with required inputs (previous actions, AIMS performance, risk updates, audit results) and structured output recording.
I
Clause 10.1 — Improvement
Nonconformity & CAPA
Full corrective action lifecycle: Open → Root Cause Analysis → Corrective Action Planned → In Progress → Effectiveness Review → Closed. ISO clause and EU article cross-referencing. Overdue corrective action alerting. Ownership chain: raised by, owner, closed by.
J
Articles 72–73 — Monitoring
Post-Market Monitoring & Regulatory Reporting
Monitoring plans with KPI tracking and scheduled review dates. Serious incident reporting workflow with national authority selection, 15-day preliminary report deadline tracking, and authority reference number recording. Incident escalation triggers Art. 73 workflow automatically.
Statement of Applicability
All 32 Annex A controls. Pre-seeded and EU AI Act cross-referenced.
| ISO Ref | Control | In AIG | EU AI Act mapping |
|---|---|---|---|
| A.2.2 | AI policy | ✓ | Art. 9 |
| A.2.3 | Internal communication of AI policy | ✓ | — |
| A.2.4 | External communication related to AI | ✓ | — |
| A.3.2 | AI roles and responsibilities | ✓ | Art. 17 |
| A.3.3 | Reporting of concerns | ✓ | — |
| A.4.2 | AI system impact assessment | ✓ | Art. 9, Art. 27 |
| A.4.3 | AI risk assessment | ✓ | Art. 9 |
| A.4.4 | AI risk treatment | ✓ | Art. 9 |
| A.5.2 | Establishing objectives for responsible AI | ✓ | — |
| A.5.4 | Documentation | ✓ | Annex IV |
| A.6.1.1 | Allocation of AI system responsibilities | ✓ | Art. 17 |
| A.6.1.2 | Internal support to AI subjects | ✓ | — |
| A.6.1.3 | AI system impact on individuals | ✓ | Art. 27 |
| A.6.1.4 | Responsible use of AI for individuals | ✓ | Art. 25 (Omnibus) |
| A.6.1.5 | Human oversight of AI systems | ✓ | Art. 14 |
| A.6.2.1 | Specifying the data for AI systems | ✓ | Art. 10 |
| A.6.2.2 | Data acquisition for AI systems | ✓ | Art. 10 |
| A.6.2.3 | Protection of data and AI model | ✓ | Art. 9(2)(a) |
| A.6.2.4 | Information for interested parties of AI systems | ✓ | Art. 13 |
| A.6.2.5 | Addressing AI system incidents and problems | ✓ | Art. 73 |
| A.6.2.6 | Recording of AI system outcomes | ✓ | Art. 12 |
| A.6.2.7 | Assessing AI systems for impacts | ✓ | Art. 9, Art. 72 |
| A.6.3.1 | Suppliers and third parties — AI objectives | ✓ | Art. 25 |
| A.6.3.2 | Responsible use by third parties | ✓ | Art. 26 |
| A.6.4 | AI awareness and training | ✓ | — |
| A.6.5 | AI system transparency | ✓ | Art. 13, Art. 50 |
| A.6.6 | Complaint handling | ✓ | — |
| A.6.7 | Allocation of rights | ✓ | — |
| A.7.2 | AI-specific criteria — impact and performance metrics | ✓ | Art. 15 |
| A.7.3 | AI system safeguards | ✓ | Art. 9(8) |
| A.7.4 | Bias mitigation in AI systems | ✓ | Art. 10, Art. 4a (Omnibus) |
| A.8.2 | Continual improvement of AI systems | ✓ | Art. 72 |
How AIG Compares
Why ISO 42001 needs a purpose-built platform.
General GRC platforms — Vanta, Drata, even ISO 27001 tools — are not designed for ISO 42001. They can hold documents, but they cannot manage the AIMS lifecycle the standard requires.
| Capability | Endaxi AIG | General GRC | Spreadsheets & SharePoint |
|---|---|---|---|
| All 32 Annex A controls pre-seeded with EU cross-refs | ✓ | ✗ | ✗ |
| AI-specific risk taxonomy (hallucination, bias, prompt injection, drift) | ✓ | ✗ | ✗ |
| FRIA (Art. 27) — all EU Charter rights | ✓ | ✗ | ✗ |
| Internal audit module with finding severity and lifecycle | ✓ | Generic only | ✗ |
| Management Review with required ISO inputs/outputs | ✓ | ✗ | ✗ |
| Full CAPA lifecycle with root cause analysis and effectiveness review | ✓ | Partial | ✗ |
| Prompt & RAG governance — version control, source inventory | ✓ | ✗ | ✗ |
| Append-only audit log on every governance action | ✓ | Partial | ✗ |
| SoA JSON export for certifying bodies | ✓ | ✗ | ✗ |
| EU AI Act obligations cross-referenced throughout | ✓ | ✗ | ✗ |
Common Questions
ISO 42001 frequent questions
Is ISO 42001 mandatory?
Not yet — and for most organisations in most jurisdictions, formal certification remains voluntary. However, the commercial pressure to certify is real and growing. Enterprise customers, particularly in financial services, professional services, and the public sector, are already including ISO 42001 in supplier questionnaires and procurement conditions. Organisations that certify early are ahead of an increasingly common requirement, not ahead of a theoretical one.
How does ISO 42001 relate to the EU AI Act?
They are complementary, not competing. The EU AI Act is a legal regulation that imposes specific obligations on AI providers and deployers. ISO 42001 is a management system standard that provides the governance framework within which those obligations — and more — can be systematically managed. An ISO 42001 AIMS implementation provides much of the infrastructure the EU AI Act requires: risk management, human oversight, technical documentation, post-market monitoring, and incident reporting. Endaxi AIG cross-references every ISO 42001 Annex A control to the relevant EU AI Act article, so you build evidence for both frameworks simultaneously.
We already have ISO 27001. Does that help?
Yes — significantly. ISO 42001 uses the same high-level structure (HLS) as ISO 27001. If you already have a management system with an internal audit programme, management review cycle, CAPA process, and document control discipline, you have the foundation. ISO 42001 adds AI-specific requirements on top of that foundation: AI risk taxonomy, impact assessments, human oversight controls, and the Annex A AI-specific controls. The integration project is substantially smaller than building from scratch. Endaxi AIG is designed to sit alongside your existing GRC tooling rather than replace it.
How long does it take to get certified?
Typically 3–9 months for a focused implementation, depending on the size of your AI estate, your existing governance maturity, and the availability of your chosen certification body. The process involves a Stage 1 audit (document review — the certifier checks your AIMS documentation and SoA) and a Stage 2 audit (implementation review — the certifier checks that your controls are operating as documented). Endaxi AIG generates the SoA, Annex IV documentation, audit packs, and management review records that Stage 1 and Stage 2 assessors will ask to see.
Does Endaxi AIG guarantee ISO 42001 certification?
No — and any platform that claims to do so is misleading you. Certification is awarded by an independent, accredited certification body following an audit of your actual practices. Endaxi AIG provides the governance infrastructure, the management system workflows, and the audit-ready evidence — but certification depends on how your organisation uses the platform and whether your AI governance practices are genuinely embedded. We provide the system; you provide the governance discipline.
What is a Statement of Applicability and why does it matter?
The Statement of Applicability (SoA) is a document that lists every control in ISO 42001 Annex A, states whether it is applicable to your organisation, gives the justification for inclusion or exclusion, and records its implementation status. It is a central evidence artefact for certification — your certifying body will review it at Stage 1 and test a sample of implemented controls at Stage 2. Endaxi AIG pre-seeds your SoA with all 32 Annex A controls and their EU AI Act cross-references, so you start from a complete baseline rather than building it from scratch. The SoA is exportable in JSON format at any time.
Ready to start your ISO 42001 AIMS?
Endaxi AIG implements the complete standard — all 10 clauses, all 32 Annex A controls — pre-seeded and ready to use from day one.
