Information and technology
ISO/IEC 42001:2023
Artificial intelligence management systems
ISO/IEC 42001 sets out requirements for an artificial intelligence (AI) management system.
A certified organisation that develops, provides or uses AI systems has defined how it governs them: it sets policies and objectives for responsible AI, assesses the risks of its AI systems and their impact on people and society, applies controls across the AI life cycle, and monitors and improves its approach.
Who it suits
Organisations that develop AI models or products, provide services built on AI, or use AI in decisions that affect customers, employees or the public, including software and platform companies, financial services, healthcare, recruitment, public services and outsourcers. It suits organisations that want a structured way to show customers, partners and regulators how they manage AI.
What certification involves
ISAO, or a certification body accredited for ISO/IEC 42001, audits the system in two stages. Stage 1 reviews the scope (which AI systems, and whether the organisation develops, provides or uses them), the AI risk assessment, the AI system impact assessment and the statement of applicability that lists the controls chosen. Stage 2 tests how those controls and processes work in practice across the life cycle of the AI systems in scope. Certification covers the management system: it does not certify a particular AI system or model, or show that legal requirements for AI have been met. Certificates are normally valid for three years, with surveillance audits at least once a year and a recertification audit before expiry. ISAO carries out this certification itself, and also accredits certification bodies to do it. Every certificate ISAO issues, and every certificate issued under ISAO accreditation, is recorded on the public register.
Key themes
- An AI policy, with roles and accountability for AI across the organisation
- Assessing AI risks, and the impact of AI systems on individuals, groups and society
- Choosing and justifying controls in a statement of applicability
- Managing the data used by AI systems and the information given to users and others affected
- Controls across the life cycle, from design and development to deployment, operation and retirement
- Responsible use of AI, and relationships with suppliers and customers
- Monitoring, internal audit and improvement
Edition
- Current edition
- ISO/IEC 42001:2023
ISO/IEC 42001:2023 is the first edition, published in December 2023, and the current one. It is published jointly by ISO and the International Electrotechnical Commission (IEC). As there is no earlier edition, no transition applies.
Check a certificate for ISO/IEC 42001:2023
- Enter the certificate number or verification code at Verify a certificate, or scan the QR code on the certificate. The record shows the certificate's status today, for example valid, suspended, withdrawn or expired.
- Compare the organisation name, scope and sites on the record with the copy you were given. Check which AI systems, products or services, and which roles, the scope covers.
- Check who issued the certificate, as named on the record. Where a certification body accredited by ISAO issued it, the record shows the status of that accreditation and its accreditation number, and says so if the accreditation did not cover ISO/IEC 42001:2023 when the certificate was issued.
- If the certificate is not on the register, ISAO cannot confirm it: it may have been issued under another accreditation, or a detail may be wrong. Ask the issuing body, and report a concern if something does not look right.
Related standards
This is ISAO’s own summary, not the text of the standard. Copies of ISO/IEC 42001:2023 can be bought from ISO or from national standards bodies.
