Built to Scale|Logiciels sur mesure · IA · Automatisation
NEW – First international AI standard

ISO/IEC 42001
AI Management System (AIMS)
ISO/IEC 42001:2023

ISO/IEC 42001 is the world's first international standard for AI management systems. It provides a certifiable governance framework for responsible AI – complementing the EU AI Act with demonstrable, auditable structures for risk, data, and human oversight.

Secure your advantage now

The standard was published in December 2023. Anyone developing or deploying AI can use an ISO/IEC 42001 certification today to demonstrate trustworthy AI to customers and regulators – and to prepare for the EU AI Act.

Standard

ISO/IEC 42001:2023

ISO 42001

First AI management standard worldwide

Dec 2023

Published

Accred. audit

Certifiable via

EU AI Act

Complements

iso-42001

Who is ISO/IEC 42001 relevant for?

The standard targets organizations that build AI or deploy AI. Both groups benefit from a structured, auditable AI governance framework.

AI Providers & Builders

  • SaaS products with AI features
  • Automation & agent providers
  • Machine learning platforms
  • AI-powered analytics tools
  • Providers of high-risk AI
  • Software companies with AI features
🏭

AI Deployers & Operators

  • Companies using AI in business processes
  • HR & recruiting systems with AI
  • Customer service with AI agents
  • Data-driven decision systems
  • Authorities & public bodies
  • Organizations in regulated sectors

Voluntary, but strategic: Unlike the EU AI Act, ISO/IEC 42001 is not a law but a voluntary standard. That is precisely what makes it valuable: a certification is objective, third-party-confirmed proof that your AI is managed responsibly. In tenders, audits, and with regulated customers, it is increasingly expected.

What does ISO/IEC 42001 specifically require?

The standard defines the requirements for an AI management system (AIMS) across the entire lifecycle – from governance to continual monitoring.

AI policy & governance

A documented AI policy with clear roles, responsibilities, and objectives. Top management anchors responsible AI organizationally.

AI risk assessment

Systematic identification and evaluation of AI-specific risks – from bias and malfunction to security and reputational risks.

AI impact assessment (AIA)

Assessment of how AI systems affect individuals, groups, and society. Documented impact assessments as a mandatory component.

Data & model lifecycle

Governance over data quality, provenance, training, validation, and model maintenance. Traceability across the entire lifecycle.

Transparency & human oversight

Explainable AI decisions, informing affected parties, and effective human control over AI systems (human oversight).

Continual monitoring

Ongoing monitoring, internal audits, and continual improvement of the AIMS. AI systems are reviewed permanently in operation.

Development & Context

The path of ISO/IEC 42001 – from publication to certification in your company.

1
December 2023

ISO/IEC 42001 published

The world's first international standard for AI management systems is released, establishing a global governance baseline.

2
2024

Accredited certification available

Certification bodies begin auditing organizations against ISO/IEC 42001. The first companies get certified.

3
2025 / 2026 (now)

EU AI Act phases in

With the EU AI Act, pressure for demonstrable AI governance rises. ISO/IEC 42001 becomes the practical implementation framework.

Act now
4
Ongoing

Market expectation grows

Customers, partners, and tenders increasingly require proof of responsible AI. Certification becomes a competitive advantage.

How we help you with ISO/IEC 42001

From the AI inventory to certification support – we guide you through three clearly structured phases to a robust AI management system.

Phase 1

Analysis & Gap Assessment

We catalog your AI systems, compare the current state against ISO/IEC 42001, and map risks and impacts.

  • AI inventory of all systems & use cases
  • Gap analysis against ISO/IEC 42001
  • Risk & impact mapping
  • Mapping of relevant EU AI Act obligations
2–4 weeks · report included
Phase 2

Implementation & AIMS build

We build the AI management system – with policy, controls, documentation, and end-to-end lifecycle processes.

  • AI policy & governance structures
  • Risk & impact assessment processes
  • Data & model lifecycle controls
  • Transparency & human oversight mechanisms
  • Complete AIMS documentation
6–12 weeks · complete documentation
Phase 3

Support & Certification

We guide you through the audit and ensure your AIMS stays effective over time and aligned with the EU AI Act.

  • Monitoring & internal audits
  • Certification preparation & support
  • Alignment with the EU AI Act
  • Continual improvement & updates
Ongoing · monthly reports

Frequently Asked Questions about ISO/IEC 42001

Is your AI ISO 42001-ready?

Let us check together where your AI governance stands today – and what path takes you to a certifiable AI management system. Free initial consultation, concrete assessment.

Schedule free initial consultation

We will get back to you within 24 hours.

© 2025 THE BARK — Vedat EGE · Oberhausen · the-bark.de