ISO 42001 — the certification
standard for AI governance.

What it covers

ISO 42001 follows the standard high-level structure (HLS) shared by ISO 27001, ISO 9001, and other management system standards. It covers:

  • Understanding the context in which AI is used in your organisation
  • Leadership, accountability, and AI policy
  • Risk assessment and treatment specific to AI
  • Operational controls — 32 controls across 8 domains in Annex A
  • Impact assessments — societal, fundamental rights, and safety
  • Internal audit, management review, and continual improvement
  • Nonconformity management and corrective action

Who it applies to

ISO 42001 applies to any organisation that:

  • Develops, provides, or uses AI systems
  • Wants to demonstrate responsible AI governance to customers, regulators, or partners
  • Is seeking to meet enterprise procurement requirements that demand an AI governance framework
  • Is pursuing EU AI Act compliance and wants a supporting management system

There is no minimum size threshold. ISO 42001 is designed to scale from a small organisation with a handful of AI tools to a large enterprise with complex AI programmes.

Why ISO 42001 certification is becoming non-negotiable.

Certification is not yet a legal requirement for most organisations — but the commercial and regulatory pressure to certify is accelerating faster than most compliance teams anticipated.

Large enterprises and public bodies are increasingly requiring suppliers to demonstrate AI governance maturity. ISO 42001 certification — like ISO 27001 before it — is becoming a standard procurement condition. Early certification gives you a competitive advantage and avoids losing contracts.

ISO 42001 and the EU AI Act share significant structural overlap. An ISO 42001-certified AI management system provides much of the governance infrastructure the Act requires — risk management, technical documentation, human oversight, and post-market monitoring. Building both simultaneously is the most efficient path to compliance with either.

Certification by an accredited third-party body is the most credible way to demonstrate to regulators, insurers, and your own board that AI governance is not just documented on paper but embedded in operating practice. It provides independent assurance that your AIMS is functioning as intended.

As AI concerns grow among end customers, ISO 42001 certification — like a privacy seal or ISO 27001 — signals that your organisation takes AI responsibility seriously. For B2B vendors in particular, it is increasingly a differentiator in sales conversations.

Cyber and technology liability insurers are beginning to ask about AI governance practices. An ISO 42001-aligned programme — whether certified or not — provides evidence of due diligence that is relevant to underwriting assessments and claims handling.

Beyond external drivers, ISO 42001 provides a structured discipline for managing AI consistently across an organisation — clear ownership, documented controls, regular review cycles, and a corrective action programme. Organisations that implement it report cleaner AI decision-making and fewer governance surprises.

1

Define scope

Establish your AIMS boundaries, AI roles (provider/deployer), and interested parties

2

Set policy

Document your AI policy, measurable objectives, and KPIs with ownership

3

Assess risk

Classify and risk-assess every AI system; complete impact assessments for high-risk systems

4

Implement controls

Apply Annex A controls; build evidence; track implementation and test dates

5

Audit & review

Internal audit against all clauses; management review with documented inputs and outputs

6

Improve

Log nonconformities; root cause analysis; corrective actions with effectiveness review

Ten modules. Every clause of ISO 42001 implemented.

Endaxi AIG implements the full ISO/IEC 42001:2023 standard across ten dedicated modules — from AIMS scope through to CAPA. Each module maps directly to the relevant clauses and, where applicable, to the corresponding EU AI Act articles.

AIMS Scope & Context

Versioned scope statements defining your AI Management System boundaries, in-scope business units, AI role declaration (Provider, Deployer, Importer, Distributor), internal and external issues register with climate change relevance tracking, and full version history.

Interested Parties & Requirements

Structured tracking of stakeholder expectations across seven party types — Internal, External, Regulator, Customer, Supplier, Employee, Public — with AIMS-addressed flags for traceability to controls and objectives.

AI Policy & Objectives

Versioned AI Policy with approval workflow — only one version current at a time. Measurable AI Objectives with KPI, target value, current value, status tracking (On Track, At Risk, Behind, Achieved), and named owner accountability.

EU AI Act Classification Engine

Guided classification wizard applying the Act’s precedence logic. Generates a Legal Classification Certificate with rationale, assessor identity, and timestamp. Omnibus-current — updated for May 2026 amendments. Covers all 5 risk tiers and GPA.

Risk & Impact Assessment Framework

Pre-seeded 5×5 risk criteria matrix with three appetite levels. Eight AI-specific risks pre-loaded. Per-system risk assignment with treatment type, residual scoring, and accepted-by tracking. Includes FRIA (Art. 27) and ASIA (Art. 9) assessment modules.

Statement of Applicability

All 32 ISO/IEC 42001:2023 Annex A controls pre-seeded, each cross-referenced to the relevant EU AI Act articles. Implementation status, justification, and exclusion rationale tracked per control. SoA JSON export for certifying bodies.

Controls Library & Assessment Engine

Ten pre-seeded AI-specific controls mapped to Annex A and EU AI Act articles. Per-system control assignment with implementation status, test dates, and owner. Four assessment templates: Intake, Security Review, Annual Review, Change Triggered.

Internal Audit & Management Review

Internal audit module with lead auditor assignment, finding severity classification (Observation, Minor NC, Major NC, OFI), and full lifecycle. Management Review with required inputs (previous actions, AIMS performance, risk updates, audit results) and structured output recording.

Nonconformity & CAPA

Full corrective action lifecycle: Open → Root Cause Analysis → Corrective Action Planned → In Progress → Effectiveness Review → Closed. ISO clause and EU article cross-referencing. Overdue corrective action alerting. Ownership chain: raised by, owner, closed by.

Post-Market Monitoring & Regulatory Reporting

Monitoring plans with KPI tracking and scheduled review dates. Serious incident reporting workflow with national authority selection, 15-day preliminary report deadline tracking, and authority reference number recording. Incident escalation triggers Art. 73 workflow automatically.

ISO RefControlIn AIGEU AI Act mapping
A.2.2AI policyArt. 9
A.2.3Internal communication of AI policy
A.2.4External communication related to AI
A.3.2AI roles and responsibilitiesArt. 17
A.3.3Reporting of concerns
A.4.2AI system impact assessmentArt. 9, Art. 27
A.4.3AI risk assessmentArt. 9
A.4.4AI risk treatmentArt. 9
A.5.2Establishing objectives for responsible AI
A.5.4DocumentationAnnex IV
A.6.1.1Allocation of AI system responsibilitiesArt. 17
A.6.1.2Internal support to AI subjects
A.6.1.3AI system impact on individualsArt. 27
A.6.1.4Responsible use of AI for individualsArt. 25 (Omnibus)
A.6.1.5Human oversight of AI systemsArt. 14
A.6.2.1Specifying the data for AI systemsArt. 10
A.6.2.2Data acquisition for AI systemsArt. 10
A.6.2.3Protection of data and AI modelArt. 9(2)(a)
A.6.2.4Information for interested parties of AI systemsArt. 13
A.6.2.5Addressing AI system incidents and problemsArt. 73
A.6.2.6Recording of AI system outcomesArt. 12
A.6.2.7Assessing AI systems for impactsArt. 9, Art. 72
A.6.3.1Suppliers and third parties — AI objectivesArt. 25
A.6.3.2Responsible use by third partiesArt. 26
A.6.4AI awareness and training
A.6.5AI system transparencyArt. 13, Art. 50
A.6.6Complaint handling
A.6.7Allocation of rights
A.7.2AI-specific criteria — impact and performance metricsArt. 15
A.7.3AI system safeguardsArt. 9(8)
A.7.4Bias mitigation in AI systemsArt. 10, Art. 4a (Omnibus)
A.8.2Continual improvement of AI systemsArt. 72

Why ISO 42001 needs a purpose-built platform.

General GRC platforms — Vanta, Drata, even ISO 27001 tools — are not designed for ISO 42001. They can hold documents, but they cannot manage the AIMS lifecycle the standard requires.

CapabilityEndaxi AIGGeneral GRCSpreadsheets & SharePoint
All 32 Annex A controls pre-seeded with EU cross-refs
AI-specific risk taxonomy (hallucination, bias, prompt injection, drift)
FRIA (Art. 27) — all EU Charter rights
Internal audit module with finding severity and lifecycleGeneric only
Management Review with required ISO inputs/outputs
Full CAPA lifecycle with root cause analysis and effectiveness reviewPartial
Prompt & RAG governance — version control, source inventory
Append-only audit log on every governance actionPartial
SoA JSON export for certifying bodies
EU AI Act obligations cross-referenced throughout

Is ISO 42001 mandatory?

Not yet — and for most organisations in most jurisdictions, formal certification remains voluntary. However, the commercial pressure to certify is real and growing. Enterprise customers, particularly in financial services, professional services, and the public sector, are already including ISO 42001 in supplier questionnaires and procurement conditions. Organisations that certify early are ahead of an increasingly common requirement, not ahead of a theoretical one.

How does ISO 42001 relate to the EU AI Act?

They are complementary, not competing. The EU AI Act is a legal regulation that imposes specific obligations on AI providers and deployers. ISO 42001 is a management system standard that provides the governance framework within which those obligations — and more — can be systematically managed. An ISO 42001 AIMS implementation provides much of the infrastructure the EU AI Act requires: risk management, human oversight, technical documentation, post-market monitoring, and incident reporting. Endaxi AIG cross-references every ISO 42001 Annex A control to the relevant EU AI Act article, so you build evidence for both frameworks simultaneously.

We already have ISO 27001. Does that help?

Yes — significantly. ISO 42001 uses the same high-level structure (HLS) as ISO 27001. If you already have a management system with an internal audit programme, management review cycle, CAPA process, and document control discipline, you have the foundation. ISO 42001 adds AI-specific requirements on top of that foundation: AI risk taxonomy, impact assessments, human oversight controls, and the Annex A AI-specific controls. The integration project is substantially smaller than building from scratch. Endaxi AIG is designed to sit alongside your existing GRC tooling rather than replace it.

How long does it take to get certified?

Typically 3–9 months for a focused implementation, depending on the size of your AI estate, your existing governance maturity, and the availability of your chosen certification body. The process involves a Stage 1 audit (document review — the certifier checks your AIMS documentation and SoA) and a Stage 2 audit (implementation review — the certifier checks that your controls are operating as documented). Endaxi AIG generates the SoA, Annex IV documentation, audit packs, and management review records that Stage 1 and Stage 2 assessors will ask to see.

Does Endaxi AIG guarantee ISO 42001 certification?

No — and any platform that claims to do so is misleading you. Certification is awarded by an independent, accredited certification body following an audit of your actual practices. Endaxi AIG provides the governance infrastructure, the management system workflows, and the audit-ready evidence — but certification depends on how your organisation uses the platform and whether your AI governance practices are genuinely embedded. We provide the system; you provide the governance discipline.

What is a Statement of Applicability and why does it matter?

The Statement of Applicability (SoA) is a document that lists every control in ISO 42001 Annex A, states whether it is applicable to your organisation, gives the justification for inclusion or exclusion, and records its implementation status. It is a central evidence artefact for certification — your certifying body will review it at Stage 1 and test a sample of implemented controls at Stage 2. Endaxi AIG pre-seeds your SoA with all 32 Annex A controls and their EU AI Act cross-references, so you start from a complete baseline rather than building it from scratch. The SoA is exportable in JSON format at any time.

Ready to start your ISO 42001 AIMS?