Published in December 2023, ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining, and improving an AI management system. It follows the same management-system structure as ISO 27001, covering leadership, planning, risk assessment, operational controls, and continual improvement.

Unlike the NIST framework, it supports formal third-party certification.

Alternative Names:

ISO 42001, AI Management System Standard

Why it Matters?

Certification provides an independently verified answer to enterprise buyers asking how a vendor governs AI, which matters in legal technology procurement where the buyer bears professional responsibility for the tool's outputs. For firms and carriers, requiring or preferring certified vendors is becoming a straightforward way to discharge diligence obligations.

Frequently Confused with

Related terms

Frequently asked questions

Can a company be certified against ISO/IEC 42001?

Can a company be certified against ISO/IEC 42001?

Yes. It is a management system standard supporting third-party certification, unlike the NIST AI RMF which is a voluntary framework without certification.

How does it relate to ISO 27001?

How does it relate to ISO 27001?

It shares the same management-system structure and is commonly implemented alongside it, with 27001 covering information security and 42001 covering AI governance.