The most common questions from organizations pursuing ISO 42001 certification for the first time.
What is ISO 42001 and who needs it?+
ISO/IEC 42001:2023 is the world's first internationally recognized standard for an Artificial Intelligence Management System (AIMS). It provides a framework for organizations to responsibly develop, deploy, and use AI systems β covering governance, risk management, data quality, human oversight, and transparency. Any organization that builds AI products, deploys AI in decision-making, or uses AI services from third parties can benefit from ISO 42001. It's increasingly required by enterprise customers, regulators, and organizations selling to EU markets under the EU AI Act.
How is ISO 42001 different from ISO 27001?+
ISO 27001 manages information security risks β data breaches, unauthorized access, system vulnerabilities. ISO 42001 manages AI-specific risks β bias, model drift, lack of transparency, unintended consequences, and ethical impact. Both use the same High-Level Structure (clauses 4β10, PDCA cycle) so they're designed to work together. Having ISO 27001 doesn't mean you have ISO 42001 β but it gives you a strong head start on structure and documentation. Many organizations pursue both simultaneously to reduce overall effort.
Do I have to implement all 38 Annex A controls?+
No β you select controls based on your AI risk assessment and the nature of your AI systems. However, you must document your selection and exclusions in a Statement of Applicability (SoA), with justified reasons for any exclusions. Auditors use your SoA as their primary reference. Some controls will be clearly inapplicable β for example, a company that only uses AI for internal tools may exclude certain customer-facing transparency controls. But exclusions must be defensible.
How long does ISO 42001 certification take?+
For most organizations, 6β12 months from start to certification. If you already have ISO 27001, expect 3β6 months due to the shared governance structure. The timeline depends on: number and complexity of AI systems in scope, current maturity of AI governance, internal resource availability, and how quickly you can assemble an evidence package. The external audit itself (Stage 1 + Stage 2) typically takes 3β6 days of auditor time depending on scope.
What is an AI Impact Assessment under ISO 42001?+
An AI Impact Assessment evaluates the potential effects of an AI system on individuals, groups, and society β covering ethical risks, bias, privacy implications, and unintended consequences. ISO 42001 requires impact assessments to be conducted before deploying AI systems (especially high-risk ones) and reviewed when systems change significantly. It's similar in concept to a Data Protection Impact Assessment (DPIA) under GDPR, but specifically focused on AI risks rather than personal data risks.
How does ISO 42001 relate to the EU AI Act?+
The EU AI Act is regulation β it creates legal obligations for AI systems used in the EU, with strict requirements for "high-risk" AI systems. ISO 42001 is a voluntary standard β it provides a governance framework but doesn't create legal obligations on its own. However, ISO 42001 certification is increasingly recognized as evidence of compliance with AI governance requirements, and the EU AI Act's requirements for high-risk AI systems overlap significantly with ISO 42001 controls. Organizations selling to EU customers or regulated by the EU AI Act should treat ISO 42001 as a strong foundation for compliance.
What documentation does ISO 42001 require?+
Mandatory documentation includes: AI Policy, AIMS scope document, AI risk assessment methodology and results, AI risk treatment plan, Statement of Applicability, AI impact assessments for each in-scope system, model cards or system documentation, data provenance records, human oversight procedures, internal audit program and results, management review records, and nonconformity and corrective action records. If you have ISO 27001, much of the management system documentation can be shared or extended rather than created from scratch.
How often must ISO 42001 be renewed?+
ISO 42001 follows the same 3-year certification cycle as ISO 27001. Annual surveillance audits are required in years 1 and 2 to confirm the AIMS is being maintained and improved. A full recertification audit occurs in year 3. Given the rapid pace of AI development, many organizations conduct more frequent internal reviews β particularly after significant model changes, new AI system deployments, or AI-related incidents β to stay ahead of surveillance requirements.