ISO 42001 in Practice: What the AI Management System Standard Requires

What ISO 42001 actually requires, how it differs from ISO 27001, and how to read a certificate when you are assessing an AI vendor's governance claims.

A supplier assessment lands on your desk with a question near the top that was not there last year: does the vendor hold ISO 42001 certification? Your procurement template has a tick-box for it. Nobody in the room can say with confidence what a certificate would prove if it existed, or what the absence of one should cost the supplier in the scoring.

This guide sets out what ISO 42001 actually requires, how it differs from the information security standard most readers already know, and how to read a certificate when it appears in a vendor's documentation. It sits beneath our AI governance framework for regulated enterprises, which covers the wider architecture; here the scope is deliberately narrow, because the practical value of the standard lies in a small number of details that the tick-box hides.

What ISO 42001 actually is

ISO/IEC 42001, published in 2023, is the first international standard for an artificial intelligence management system, usually abbreviated to AIMS. The word that carries the weight is "management". It is a management system standard, in the same family and broadly the same shape as ISO 27001 for information security and ISO 9001 for quality.

That has one consequence which governs everything else, and it is the point the tick-box hides: the standard certifies an organisation, not a product. A certificate is evidence that the supplier runs a disciplined process for deciding how AI is developed, deployed, and reviewed. It is not a statement that any particular system that organisation sells is safe, accurate, or well governed. A firm with a genuine certificate can still ship a product whose controls you would reject on inspection.

Unlike guidance documents, which describe good practice without a conformity route, ISO 42001 is certifiable: an accredited registrar audits the management system and issues a certificate with a declared scope and a validity period. That makes it comparable to the certifications procurement teams already know how to read, which is both its strength and the source of the confusion, because the thing being certified is less intuitive than "our information is secure".

What the standard requires

ISO 42001 follows the common high-level structure shared across modern ISO management system standards, so the obligations will feel familiar to anyone who has been through an ISO 27001 audit. The substance sits in five areas.

A defined scope and an AI policy

The organisation has to state which of its activities and systems the management system covers, and publish a policy setting out its intentions for AI. The scope statement is the most practically useful artefact for a buyer, because it bounds everything the certificate can be taken to mean. A scope covering internal AI use tells you nothing about a product sold to customers.

Risk assessment, and an impact assessment

This is where ISO 42001 departs from its predecessors. Alongside a conventional risk assessment, the standard requires the organisation to assess the impact of its AI systems on individuals and, more broadly, on society. Information security standards ask whether data is protected. This one also asks who could be affected by an AI system behaving as designed, which is a different and less comfortable question. For a data protection officer (DPO), this is the requirement that maps most closely onto existing data protection impact assessment practice.

Controls over data and documented information

An AI management system has to account for the data its systems draw on: where it came from, whether its use is appropriate, and how quality is maintained. In practice this is the requirement that exposes whether governance is real or notional, because it forces an organisation to be explicit about a corpus it may never have deliberately curated.

Lifecycle management and monitoring

AI systems are expected to be managed across their lifecycle rather than assessed once at procurement. That means defined responsibilities for deployment, monitoring of behaviour in operation, and a route for withdrawing or changing a system when monitoring shows it is no longer performing as intended.

Internal audit, management review, and improvement

As with every certifiable management system standard, the organisation must audit itself, review the results at management level, and demonstrate that findings lead to change. This is the machinery that distinguishes a management system from a policy document, and it is what the registrar spends most of its time examining.

ISO 42001 and ISO 27001 compared

Most readers meet ISO 42001 with ISO 27001 as their reference point. The two are complementary rather than overlapping, and the differences matter when deciding what a supplier's certificate portfolio actually covers.

ISO 27001 ISO 42001
Governs Information security management Development and use of AI systems
Core question Is information protected against loss, disclosure, and alteration? Is AI developed and operated deliberately, with known effects?
Distinctive requirement Risk treatment against a defined set of security controls Assessment of impact on individuals and society
Data emphasis Confidentiality, integrity, availability Provenance, appropriateness of use, and quality of the data a system draws on
What a certificate proves The management system operates as described, within its declared scope The same, for the AI management system

The practical reading: a supplier certified to ISO 27001 has demonstrated that it protects information. That is necessary and it is not sufficient, because an AI system can be perfectly secure while answering from documents nobody approved. ISO 42001 exists to cover the second question, and neither standard says anything about the accuracy of a specific answer a specific product gives on a specific day.

How to read a certificate as a buyer

Two habits make the tick-box useful rather than decorative.

Read the scope statement, not the logo. Ask for the certificate itself and check the registrar, the certificate number, the validity date, and the declared scope. A certificate whose scope covers consultancy services does not cover a software product, even when the same company sells both. This is exactly the detail that a logo on a website omits, and it is the only part of the document that tells you what was audited.

Ask the product question separately. Because the standard certifies process rather than product, the certificate cannot tell you whether the system you are buying governs its own knowledge. That question has to be asked directly: which documents is this system permitted to answer from, who decided each was eligible, and can a given answer be reconstructed afterwards. Our guide to AI governance tools and platforms sets out the full assessment; the point here is only that a certificate does not answer it for you.

The same logic applies to regulation. Standards are the usual route to demonstrating compliance in practice, and the EU AI Act will lean on harmonised standards for exactly that purpose, but conformity with a management system standard is evidence of process rather than a legal safe harbour. For the wider regulatory picture, our guide to AI knowledge management for regulated industries places these obligations in their procurement context. Readers concerned specifically with how knowledge itself is managed may also find ISO 30401:2018, the knowledge management standard, a useful companion; we cover it in our guide to ISO 30401 and knowledge management.

How AnswerVault approaches this

AnswerVault is a governed AI knowledge layer that connects an organisation's existing document sources, including SharePoint, Google Drive, and Confluence, and delivers source-backed answers through web chat, Microsoft Teams, Slack, CLI, and API.

Catapult CX Ltd, AnswerVault's operating entity, is certified to ISO 27001, alongside ISO 9001 and ISO 20000. AnswerVault's ISO 42001 certification is in progress: the Stage 1 audit is complete and the Stage 2 audit is planned. The registrar, certificate numbers, and scope statements behind the existing certifications are on our security and compliance page, so a procurement team can check them rather than take a logo on trust.

On the substance the standard is reaching for, the design intent is that the controls are structural rather than procedural. A document becomes eligible for AI answers because a named subject-matter expert approved it, with the approval and its date written into the audit trail at the moment it happens. When a document is superseded, the record of which version was canonical on which date is preserved. Answers carry citations that resolve to specific documents and versions, so reconstructing how an answer was produced is a lookup rather than an investigation. Those are the artefacts an AI management system audit asks for, and they are easier to produce when the system generates them by default than when they have to be assembled from logs on request.

Where to start

If ISO 42001 has appeared in your supplier assessments, the useful first move is not to add a tick-box. It is to separate the two questions the tick-box conflates: does this supplier run a disciplined process for governing AI, and does the specific system we are buying govern the knowledge it answers from. The certificate speaks to the first. Only a direct assessment of the product speaks to the second.

For the architecture behind that second question, read our AI governance framework and map your candidate systems against its three layers. AnswerVault's Starter tier is free, so if you would rather test the behaviour than read about it, connect a document source and see how governed knowledge search works: get started with AnswerVault.

AnswerVault is built by Catapult CX, an enterprise technology consultancy. The product was originally developed for a global pharmaceutical company with strict data governance requirements; the same architecture now powers the SaaS platform.

Frequently asked questions

Is ISO 42001 a product certification?

No. It certifies an organisation's artificial intelligence management system, meaning its policies, risk assessments, roles, and review cycles. A supplier holding the certificate can still sell a product with weak controls, which is why the certificate and the product assessment are separate questions.

How is ISO 42001 different from ISO 27001?

ISO 27001 governs information security, meaning whether data is protected. ISO 42001 governs the development and use of AI systems, and it adds a requirement to assess the impact of those systems on individuals and society, which has no equivalent in ISO 27001.

What does the scope statement on an ISO 42001 certificate tell me?

It bounds everything the certificate can be taken to mean. A certificate is issued against a declared scope of activities, so one covering an organisation's internal AI use says nothing about a product it sells to customers. The scope statement, not the logo, is the part worth reading.
Try AnswerVault

Ready to put your documents to work?

Connect your document sources and start querying in minutes.