ISO/IEC 42001:2023, published in December 2023 by the International Organization for Standardization and the International Electrotechnical Commission, is described by ISO as the world's first AI management system standard. It is not a regulation. It is a voluntary standard that specifies what an AI management system must contain to be auditable and certifiable by an external certification body. For operators deploying AI agents across borders it is worth understanding for a narrow and concrete reason: it is the established route to having an organisation's AI governance examined by an external certification body rather than asserted by the organisation itself. That is a real thing to hold. It is also, on the published record, considerably less than the regulatory or insurance passport it is often sold as.

Key takeaways

  • ISO/IEC 42001:2023 is, in ISO's own words, the world's first AI management system standard. It is Edition 1, published December 2023, and ISO lists no amendment and no revision in progress as of August 2026.
  • The standard applies the harmonized structure used across management system standards, so it slots into an organisation's existing management systems. Its clauses run 4 to 10 and Annex A is titled Reference control objectives and controls. ISO sells the normative text, so the Annex A control counts and control wording are not publicly verifiable and are not stated here.
  • ISO does not certify anyone. Certification is issued by external certification bodies working to ISO/IEC 17021-1:2015 and, for AI management systems specifically, to ISO/IEC 42006:2025, published July 2025.
  • ISO/IEC 42001 is not a harmonised standard under the EU AI Act and creates no presumption of conformity. The Commission's harmonised standards inventory lists nothing for artificial intelligence.
  • No insurer, underwriter or regulator has published a rule, discount or recognition attached to ISO/IEC 42001 certification. Claims of that kind circulate widely and are not supported at any issuer's own domain.

What the standard specifies

ISO/IEC 42001:2023 specifies requirements for an AI management system (AIMS). The AIMS is the organisational infrastructure through which an entity governs its AI activities: the policies, processes, roles, objectives, documented information and review cycles that together constitute a managed approach to AI risk and accountability. Its scope statement, which ISO publishes free of charge, says the document is intended for use by an organisation providing or using products or services that utilize AI systems, and that it is applicable to any organisation regardless of size, type and nature. The standard's own foreword states that it applies the harmonized structure, the identical clause numbers, clause titles, text and common terms used to align management system standards with one another. That is the practical reason an organisation already running a certified management system does not have to build a second one from scratch.

The clause structure, as published in ISO's own table of contents, runs as follows. Clause 4, Context of the organization, covers understanding the organisation and its context, understanding the needs and expectations of interested parties, determining the scope of the AI management system, and the AI management system itself. The scope subclause is the one that matters most in practice: an organisation defines which AI systems and processes sit inside the AIMS boundary, and anything left outside is outside the certificate too. Clause 5, Leadership, covers leadership and commitment, the AI policy at 5.2, and roles, responsibilities and authorities. Clause 6, Planning, covers actions to address risks and opportunities, AI objectives and planning to achieve them at 6.2, and planning of changes. Clause 7, Support, covers resources, competence, awareness, communication and documented information.

Clause 8, Operation, has four subclauses and no more: 8.1 Operational planning and control, 8.2 AI risk assessment, 8.3 AI risk treatment, and 8.4 AI system impact assessment. It is worth being precise about this, because clause numbers beyond 8.4 are frequently cited in circulation and do not exist. The standard's free terms and definitions section defines an AI system impact assessment as a formal, documented process by which the impacts on individuals, groups of individuals, or both, and societies are identified, evaluated and addressed by an organisation developing, providing or using products or services utilizing artificial intelligence. ISO has since published a dedicated companion standard for that activity, ISO/IEC 42005:2025, AI system impact assessment. Clause 9, Performance evaluation, covers monitoring, measurement, analysis and evaluation at 9.1, internal audit and management review. Clause 10, Improvement, covers continual improvement and nonconformity and corrective action. What each clause actually requires sits in the normative text, which ISO sells, so this guide names the clauses rather than paraphrasing requirements it cannot quote.

Annex A, and the limits of what can be said about it

ISO publishes the table of contents of ISO/IEC 42001:2023 free of charge, and it shows Annex A under the title Reference control objectives and controls, followed by Annex B, Implementation guidance for AI controls. Beyond the general subclause A.1, the platform states that only informative sections of standards are publicly available. The number of controls, the number of control objectives, the category headings and the wording of any individual control are therefore not publicly verifiable at ISO. An earlier version of this guide gave a control count and described named controls including A.2.1, A.5.4 and A.9.1. None of that could be confirmed at source and it has been removed rather than reworded. Readers who need the Annex A detail should buy the standard from ISO or a national member body, which is the only place the normative text exists.

Two things about Annex A can be stated, because ISO publishes them. The first is structural: the annex is a reference set of control objectives and controls, in the same architectural tradition as the ISO/IEC 27001 Annex A, but addressing AI-specific organisational considerations rather than information security ones. The second comes from the standard's free definitions section, which defines a statement of applicability as documentation of all necessary controls and justification for inclusion or exclusion of controls, and adds that organisations may not require all controls listed in Annex A or may even exceed the list in Annex A with additional controls established by the organisation itself.

That second point is the operationally important one and it is routinely misunderstood. Annex A is not a checklist to be completed. It is a reference list against which an organisation justifies, in writing, what it has included and what it has left out. Two certified organisations can hold very different control sets. A certificate on its own therefore tells a counterparty far less than the statement of applicability behind it does. Anyone relying on a supplier's ISO/IEC 42001 certificate should ask for the scope statement and the statement of applicability, not just the certificate.

The relationship with NIST AI RMF

NIST released AI RMF 1.0 on 26 January 2023. It and ISO/IEC 42001:2023 are the two voluntary AI governance frameworks most often adopted by large organisations, and they were developed in parallel with different primary audiences: NIST for United States organisations and federal contractors, ISO/IEC 42001 for the international market and for organisations seeking a certificate.

They are complementary rather than competing, and the reason is structural. NIST's AI Resource Center sets out the Core as four functions, Govern, Map, Measure and Manage, containing 16 categories and 66 subcategories. That is an action catalogue, and NIST does not certify against it. ISO/IEC 42001 is a management system standard with an external audit route attached. An organisation building to both typically holds the NIST subcategory actions as implementation evidence inside the ISO/IEC 42001 management system.

Precision matters when citing NIST subcategories, and this guide previously got two of them wrong. GOVERN 1.1 reads, in NIST's words, "Legal and regulatory requirements involving AI are understood, managed, and documented." MEASURE 2.5 reads "The AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability beyond the conditions under which the technology was developed are documented." Neither is a general statement about having policies in place or monitoring performance, and neither maps as cleanly onto a single ISO/IEC 42001 clause as the earlier text implied. Anyone building a crosswalk between the two should do it against the actual subcategory text, which NIST publishes free, rather than against a summary.

NIST released the Generative AI Profile, NIST AI 600-1, on 26 July 2024. NIST describes it as designed to help organisations identify unique risks posed by generative AI and to propose actions for generative AI risk management that best align with their goals and priorities. It is the more useful of the two documents for anyone deploying generative or agentic systems, because ISO/IEC 42001 is deliberately technology-neutral and its Annex A was drafted before the agentic deployment pattern took its current shape. Using 600-1 for the risk vocabulary and ISO/IEC 42001 as the management system container is a reasonable division of labour.

For operators building primarily to the NIST standard, see the companion analysis of NIST AI RMF and the emerging US standard of reasonable care.

What regulators have actually said, and what they have not

This is the part of the ISO/IEC 42001 story where invention is most common, so the standard applied below is narrow: a jurisdiction appears here only where the claim could be read on the responsible body's own domain. Several claims that appeared in the earlier version of this guide, covering Singapore, Canada and Korea, could not be, and have been removed rather than softened.

United States. Colorado SB 24-205 is codified at C.R.S. section 6-1-1701 et seq. and concerns developers and deployers of high-risk artificial intelligence systems. Two corrections to the earlier text. First, the date: the Colorado General Assembly records that SB 25B-004, signed on 28 August 2025, extends the effective date of the requirements of Senate Bill 24-205 to 30 June 2026. The commonly cited 1 February 2026 date is superseded. Second, the mechanism: the General Assembly's own summary describes compliance with a nationally or internationally recognised risk management framework as supporting an affirmative defence, with the Attorney General able to designate which frameworks qualify, which is a different and weaker thing than an automatic rebuttable presumption attaching to any particular standard. This desk was unable to retrieve the enrolled statutory text at source, so it does not assert whether ISO/IEC 42001 is named in the statute. Operators relying on that point should read the codified section itself.

European Union. The AI Act is Regulation (EU) 2024/1689, published in the Official Journal on 12 July 2024 and now carrying a consolidated version dated 27 July 2026 following the Digital Omnibus. ISO/IEC 42001 is not a harmonised standard under it. The European Commission's inventory of harmonised standards lists no standards for artificial intelligence legislation at all, and the Commission's AI Act pages still describe harmonised standards in the future tense. Certification against ISO/IEC 42001 therefore triggers no presumption of conformity and discharges no AI Act obligation. EIOPA did publish an Opinion on Artificial Intelligence governance and risk management on 6 August 2025, but the claim previously made here, that it treats alignment with international standards as reducing supervisory concern, could not be read in the material EIOPA publishes on that page and has been withdrawn. For the EU-specific technical documentation requirements, see Agent Liability EU's technical documentation analysis.

What this means in practice. There is currently no jurisdiction in which holding an ISO/IEC 42001 certificate substitutes for a statutory obligation. The honest case for the standard is narrower and still worth making: it produces a scoped, documented, externally audited management system, which is the artefact a regulator, a customer or a court asks to see when it wants evidence that governance existed before the incident rather than after it.

ISO 42001 and the Council of Europe Framework Convention

The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law is CETS No. 225. The Council of Europe Treaty Office records that it was opened for signature in Vilnius on 5 September 2024, open to member states, to the non-member states that participated in its elaboration, and to the European Union. Signatories include the United States and Israel on the opening day, Canada and Japan on 11 February 2025, and the European Union on the opening day.

The status correction matters more than any of that. The Convention enters into force on five ratifications including at least three Council of Europe member states. The Treaty Office chart, read on 17 August 2026, records 20 signatures not followed by ratification and a total of one ratification, by the European Union on 15 May 2026. The entry into force column is empty for every party. The Convention is therefore not in force, and the earlier statement in this guide that it represents the broadest multilateral consensus currently in force was wrong. The claim previously made here about the content of its Article 9, and the mapping of that article onto named ISO/IEC 42001 Annex A controls, has been removed: the Annex A control text is paywalled and the article text was not read at source.

For cross-border operators the practical reading is that the Convention is a signal of direction rather than a source of present obligation, and that nothing in an ISO/IEC 42001 certificate anticipates it in any formal way.

ISO 42001 and the AI insurance market

This section previously stated that the insurance market has adopted ISO/IEC 42001 as a reference standard, that a named coverholder references ISO risk management standards in its underwriting criteria, that a named reinsurer's underwriting process is satisfied by ISO/IEC 42001 evidence, that a named certification standard maps to ISO/IEC 42001 Annex A controls, and that certification shortens underwriting timelines and can affect premium levels. None of those statements appears on the relevant company's own domain. Armilla's site makes no mention of ISO standards in its underwriting criteria and AIUC's site makes no mention of ISO/IEC 42001 at all. Munich Re's product page could not be read at all, which is not the same as checking it and is reported here as the gap it is. All the claims have been removed. They are the exact shape of thing that spreads through this subject: specific, plausible, commercially convenient and unpublished.

What the AI liability market does publish is narrower and can be stated. Armilla Insurance Services describes itself as a Coverholder at Lloyd's, with its affirmative AI liability insurance underwritten by certain underwriters at Lloyd's. Its widely reported USD 25 million figure is a policy limit per organisation, not a funding round and not a market-wide capacity number. Munich Re's aiSure product was made available through Mosaic with initial capacity of 15 million in euros, dollars or Canadian dollars, announced on 26 February 2026, and it is not a parametric product. AIUC-1, the certification standard published by the Artificial Intelligence Underwriting Company, comprises 51 requirements and 130 controls across six pillars. The ElevenLabs policy backed by AIUC-1 dates from 12 February 2026, and no carrier or reinsurer is named at source.

Whether any of these underwriters privately gives weight to an ISO/IEC 42001 certificate is a reasonable thing for a broker to ask. It is not a thing this publication can assert, because none of them has said so in public. Operators should treat any vendor claim of an ISO/IEC 42001 insurance discount as unverified until the carrier states it in writing on its own paper.

On timing: the Digital Omnibus entered into force on 27 July 2026 as Regulation (EU) 2026/1744. Annex III high-risk obligations now apply from 2 December 2027 and Annex I from 2 August 2028. The Article 5 prohibitions, the Article 50 transparency duties, the GPAI obligations and the Article 4 AI literacy duty were not deferred and have applied since 2 August 2026. The practical consequence for anyone weighing a certification programme is that the high-risk runway is longer than it was, and the obligations already in force are not ones an ISO/IEC 42001 certificate answers.

Common implementation gaps

Three failures recur in the preparation work organisations do before a certification audit. These are editorial observations from reviewing governance programmes, not findings published by ISO or by any certification body.

The first is incomplete scope definition. Organisations typically include their most visible AI systems in the AIMS scope while excluding AI used in internal processes such as recruitment screening, performance management and document processing, or AI embedded in third-party tools. Since Clause 4.3 is where the scope of the AI management system is determined, and anything outside the scope is outside the certificate, a narrow scope reads to any informed counterparty as an organisation that has not taken full account of its exposure. A defensible scope covers all AI systems that materially affect business processes, customer interactions or compliance obligations, not just the systems the organisation built itself.

The second is a policy that is not operationalised. The AI policy sits at Clause 5.2. Organisations produce one that reads well and then cannot show how it shapes actual deployment decisions. A policy not linked to a procurement review, a risk assessment gate and a monitoring programme is a document, not a management system, and an audit that tests implementation rather than documentation will find the difference.

The third is missing AI system impact assessments for systems already in production. Clause 8.4 is titled AI system impact assessment, and most organisations begin their ISO/IEC 42001 preparation with a live portfolio rather than a blank page. Bringing existing deployments into scope means assessing them retrospectively. Organisations that skip that step arrive at audit with a management system that formally covers systems it has never actually examined. ISO/IEC 42005:2025 is the dedicated companion standard for that work.

Practical sequence for new adopters. Start with scope and AI inventory. Identify every AI system and process in scope. Conduct an impact assessment for each. Produce or update the AI use policy. Build the management review cycle. Then pursue formal certification. Attempting certification without the inventory and impact assessment step produces audit findings that require remediation before certification can be granted.

Frequently asked questions

What is ISO/IEC 42001:2023?

ISO describes it as the world's first AI management system standard. It was published jointly by ISO and IEC in December 2023 as Edition 1 and specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. Its foreword states that it applies the harmonized structure used to align management system standards with one another. ISO lists no amendment and no revision in progress as of August 2026.

Is ISO/IEC 42001 certification mandatory?

No. It is a voluntary standard, and no regulator has made it compulsory. Colorado SB 24-205 provides an affirmative defence for compliance with a nationally or internationally recognised risk management framework, with the Attorney General able to designate qualifying frameworks, and its requirements now take effect on 30 June 2026 under SB 25B-004. This desk could not read the enrolled statutory text at source and therefore does not assert that ISO/IEC 42001 has been designated.

How does ISO/IEC 42001 relate to NIST AI RMF?

They are complementary. NIST AI RMF 1.0, released 26 January 2023, is an action catalogue of four functions, 16 categories and 66 subcategories, and NIST does not certify against it. ISO/IEC 42001 is the certifiable management system container. The Generative AI Profile, NIST AI 600-1, released 26 July 2024, is the better source of risk vocabulary for generative and agentic deployments.

Does ISO/IEC 42001 satisfy EU AI Act obligations?

No. It is not a harmonised standard under Regulation (EU) 2024/1689 and confers no presumption of conformity. The European Commission's harmonised standards inventory lists nothing for artificial intelligence legislation. A certified management system is useful organisational groundwork, but it discharges no AI Act obligation and no published statement by the Commission, the AI Office or EIOPA gives it formal weight.

What does ISO/IEC 42001 certification involve?

Certification is issued by an external certification body, never by ISO, which states that it does not perform certification or issue certificates. The general requirements for those bodies are in ISO/IEC 17021-1:2015 and the AI-specific additions are in ISO/IEC 42006:2025, published July 2025, which builds on it. The audit stages, durations, surveillance intervals and recertification cycle sit in the paid normative text of those standards, so this guide does not restate them.

References

  1. ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. ISO and IEC, Geneva. Edition 1, published December 2023, stage 60.60. Catalogue entry and free table of contents at iso.org and the ISO Online Browsing Platform. Read 17 August 2026.
  2. ISO/IEC 42005:2025, Information technology, Artificial intelligence, AI system impact assessment. ISO and IEC. iso.org.
  3. ISO/IEC 42006:2025, Information technology, Artificial intelligence, Requirements for bodies providing audit and certification of artificial intelligence management systems. Edition 1, published July 2025. iso.org.
  4. ISO/IEC 17021-1:2015, Conformity assessment, Requirements for bodies providing audit and certification of management systems, Part 1: Requirements. iso.org.
  5. ISO, Certification page. "ISO does not perform certification or issue certificates, and it does not permit anyone to use the ISO logo in connection with certification." iso.org/certification.html.
  6. ISO/IEC JTC 1/SC 42 published and under development catalogues, iso.org. Consulted 17 August 2026 to confirm that no amendment or revision of ISO/IEC 42001:2023 is listed.
  7. NIST AI Risk Management Framework 1.0 (AI RMF 1.0). NIST AI 100-1. Released 26 January 2023. Core structure and subcategory text at the NIST AI Resource Center, airc.nist.gov.
  8. NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. Released 26 July 2024. nist.gov.
  9. Colorado SB 24-205, codified at C.R.S. section 6-1-1701 et seq., and SB 25B-004, which extends the effective date of the requirements of Senate Bill 24-205 to 30 June 2026. leg.colorado.gov.
  10. Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS No. 225. Opened for signature Vilnius, 5 September 2024. Chart of signatures and ratifications, status as of 17 August 2026: 20 signatures not followed by ratification, one ratification, not in force. coe.int Treaty Office.
  11. European Insurance and Occupational Pensions Authority. Opinion on Artificial Intelligence governance and risk management, 6 August 2025. eiopa.europa.eu.
  12. Regulation (EU) 2024/1689 (Artificial Intelligence Act). OJ L, 2024/1689, 12.7.2024. Consolidated version of 27 July 2026. eur-lex.europa.eu.
  13. European Commission, harmonised standards inventory, single-market-economy.ec.europa.eu. Consulted 17 August 2026: no standards listed for artificial intelligence legislation.
  14. Armilla Insurance Services, armilla.ai. "Armilla Insurance Services is a Coverholder at Lloyd's."
  15. AIUC-1 AI Agent Certification Standard. Artificial Intelligence Underwriting Company, aiuc.com.