ModelCharter
ModelCharter Team

ISO 42001 Explained: The AI Management Standard

ISO certification standards representing the ISO 42001 AI management system

Photo: qmicertification design / Pexels

Key takeaways

  • ISO/IEC 42001, published in December 2023, is the first international standard built specifically for AI management systems.
  • It follows the same high-level management-system structure as ISO 27001, clauses covering context, leadership, planning, support, operation, evaluation and improvement, plus AI-specific Annex A controls.
  • Most small and mid-sized businesses are 'deployers' under the standard, not 'providers', which means lighter duties: a policy, a system inventory, controls, and records, not model-development documentation.
  • Certification is optional. Alignment with the standard's structure is useful, and achievable, even if you never book an auditor.
  • The standard pairs well with the EU AI Act: implementing 42001's structure tends to produce the evidence the Act's deployer duties expect.

ISO/IEC 42001 is the first international standard built specifically for managing AI responsibly inside an organisation. Published in December 2023, it gives you a structure for AI governance the way ISO 27001 gave the world a structure for information security: named clauses, required processes, and, if you want it, a certificate at the end. For a business that just uses AI tools rather than builds them, the standard sounds heavier than it is. This guide covers what the clause structure actually contains, whether you're a 'deployer' or a 'provider' under it (the distinction that determines how much work you're in for), how it stacks up against ISO 27001 and against the EU AI Act, and how to use it as a blueprint even if certification is years away or never happens at all.

What ISO 42001 Actually Covers

Unlike ISO 27001, which addresses information security broadly, 42001 is built around the specific ways AI systems behave badly: training data that's biased or poor quality, models that can't explain their own outputs, and a regulatory landscape that keeps moving under your feet. It asks organisations to set AI-specific objectives, manage AI-specific risks, and keep evidence that governance is active rather than a policy filed and forgotten. That last part is what trips people up. A well-written policy that nobody's looked at in a year doesn't satisfy the standard's intent even if the document itself is fine; the standard wants a live system, reviewed and updated as your AI use changes. Our ISO 42001 framework hub has the compliance-checklist version of what follows, and ISO's own explainer is worth a look for the primary source.

The Clause Structure, in Plain English

Like other modern ISO management-system standards, 42001 follows a common high-level structure spread across clauses 4 to 10: context (who you are and what AI systems you run), leadership (who's accountable), planning (your AI risk objectives), support (resources, competence, awareness, this is where the EU AI Act's literacy duty overlaps neatly), operation (running your AI system inventory and treating the risks you've found), performance evaluation (monitoring and internal audit), and improvement (fixing what the audit finds). On top of that sits Annex A: a set of AI-specific controls covering things like data quality, transparency to users, and how you manage third-party AI suppliers. The full clause text is in the official ISO/IEC 42001 standard, sold rather than published free, but the structure above is the part that matters for planning your governance.

Deployer or Provider: Which Duties Apply to You?

ISO 42001 distinguishes between providers, organisations that build or supply AI systems, and deployers, organisations that use AI systems someone else built. A 30-person accounting firm using Microsoft 365 Copilot is a deployer. Microsoft is the provider. This matters because provider duties are the heavy ones: documenting how a model was trained, its data lineage, its testing regime. Deployer duties are lighter: have a policy, know what AI you're running, control the risks it creates, and keep records. Almost every small and mid-sized business reading this is a deployer. The one exception worth flagging: if you fine-tune a model on your own data or build an in-house tool on top of a foundation model's API, you've picked up at least some provider-style duties around that specific system, even if you're still a deployer for everything else you use off the shelf.

The Four Things the Standard Expects From Deployers

Strip out the certification apparatus and deployer expectations map to four things: a documented AI policy suited to your risk context, a register of the AI systems in use and what data they touch, controls addressing the risks those systems create, and records proving the governance is live. Those four map almost exactly onto ModelCharter's three artefacts, a generated usage policy, an AI tool risk directory entry for each tool, and an attestation trail, plus the vendor risk assessment that covers the controls layer. A useful system inventory entry looks a lot like a registry entry under any other framework: tool name, what it's used for, what data category it touches, its assigned risk tier, and who approved it. If you can't answer those five questions for every AI tool in active use, that's the actual gap, not the paperwork around clause numbers.

ISO 42001 vs the EU AI Act: Standard vs Law

These solve different problems and don't compete. The EU AI Act is law with enforcement behind it; ISO 42001 is a voluntary standard that gives you a management-system route to meeting obligations like the Act's. Businesses working towards Article 4's AI-literacy duty (see our guide to employee AI training) often find they've already built most of what 42001's 'support' clause expects, without setting out to.

Do You Need to Get Certified?

No, and most small companies don't. Certification means paying an accredited body to audit you against the full standard, which makes sense if a specific contract or tender requires the certificate, or if AI is central to what you sell. If neither applies, you can still use the standard's structure as a blueprint, matching your policy, registry, controls and records to its clauses, and get the governance benefit without the audit fee. Treat certification as a business decision, separate from the governance work itself. The honest question to ask before booking an auditor: has a customer or a tender actually asked for the certificate by name, or are you assuming they will? If it's the latter, alignment now and certification later, once there's a specific deal that needs it, is the cheaper order to do things in.

Where to Start Without a Dedicated Compliance Team

A 45-person fintech company chasing its first enterprise contract found this out the hard way: the prospective customer's security questionnaire asked directly whether they held ISO 42001 or an equivalent AI governance programme. They didn't have either, and didn't have six months to get certified before the deal closed. What got them through underwriting was the deployer-level equivalent: a written AI policy, a register of the three AI tools they actually used, and a signed attestation from every employee with system access. That's the realistic starting point for most companies in the same position, three artefacts, not a certificate.

Closing the Gap to Full Alignment

Once the policy, registry and attestation trail exist, the distance to full ISO 42001 alignment is smaller than the standard's length suggests. Generate the policy, log your tools, and start the attestation record, that's the deployer-level foundation the standard is really asking for.

Clause / elementWhat it coversModelCharter equivalent
Clauses 4-6: context, leadership, planningScope, accountability, AI risk objectivesAI usage policy
Clause 7: supportResources, staff competence and awarenessAttestation records (overlaps with EU AI Act literacy duty)
Clause 8: operationRunning an AI system inventory and treating riskAI Tool Risk Directory + vendor risk assessment
Clauses 9-10: evaluation, improvementMonitoring, internal audit, fixing gapsPolicy review cycle + attestation refresh
Annex A controlsAI-specific controls: data quality, transparency, third-party AI suppliersVendor risk assessment
ISO 42001's structure at a glance
ISO/IEC 42001 provides organizations of any size or sector with a framework for developing, providing or using AI systems responsibly.
ISO 42001 explained, ISO.org

Frequently asked questions

Is ISO 42001 mandatory?
No. It's a voluntary standard. You might be asked for it by a customer or a tender, but no government currently requires it by law, unlike the EU AI Act.
How is ISO 42001 different from ISO 27001?
ISO 27001 covers information security generally. ISO 42001 is built specifically for AI systems, adding controls for things like training data quality, model transparency, and third-party AI supplier management that 27001 doesn't address.
Do small businesses need to get ISO 42001 certified?
Rarely. Certification makes sense if a specific contract or tender requires it. Most small businesses get the governance benefit from aligning with the standard's structure, policy, registry, controls, records, without paying for the audit.
How long does ISO 42001 certification take?
It varies by scope and auditor availability, but a realistic range for a small organisation with existing documentation is several months, not weeks. Building the deployer-level foundation (policy, tool registry, attestation) happens far faster and stands alone as useful governance regardless of certification timing.
Does ISO 42001 replace the need to comply with the EU AI Act?
No. ISO 42001 is a standard; the EU AI Act is law. They're complementary, 42001's structure tends to produce much of the evidence the Act's deployer duties expect, but holding the certificate doesn't exempt you from the Act's specific requirements.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator