ISO/IEC 42001

AI adoption rarely follows a neat rollout plan. A development team starts using a coding assistant. Marketing tests a generative writing tool. Someone connects an AI agent to internal documents. Before long, the organization depends on systems that security and compliance teams may not fully understand.

ISO/IEC 42001 provides organizations with a structured approach to governing AI activities. It does not prescribe a specific technical architecture or promise risk-free AI. Instead, it outlines how an organization should establish, operate, review, and continually improve an artificial intelligence management system.

What Is ISO/IEC 42001?

Published in December 2023, ISO/IEC 42001 is the first international management system standard specifically for AI. It applies to organizations that develop, provide, or use AI systems, regardless of industry or size.

The standard focuses on the Artificial Intelligence Management System, usually abbreviated as AIMS. An AIMS integrates policies, responsibilities, risk processes, operational controls, and evidence into a single coordinated framework.

This distinction matters. ISO 42001 does not certify that a particular model is accurate, ethical, or secure. Certification assesses whether the organization has a functioning management system for identifying and addressing AI-related risks and opportunities.

What Does the Standard Require?

The standard follows the Plan-Do-Check-Act model used across many ISO management systems. Organizations must define what their AIMS covers, identify interested parties, assign responsibilities, assess risks, implement controls, measure performance, and correct weaknesses.

ISO/IEC 42001

The standard’s requirements and supporting Annex A controls address areas such as:

  • Defining an AI policy and measurable objectives
  • Assigning ownership and accountability for AI systems
  • Maintaining an inventory of relevant AI systems
  • Assessing AI risks and potential impacts
  • Managing data, suppliers, and system lifecycles
  • Documenting operational processes and decisions
  • Monitoring performance and control effectiveness
  • Conducting internal audits and management reviews
  • Addressing nonconformities through corrective action

The supporting controls cover areas such as data quality, transparency, human oversight, responsible use, third-party relationships, and communication with affected parties. Not every control needs to be implemented in the same way. The organization should select and justify controls based on its context and risk assessment.

Why AI Inventory Comes First

A company cannot govern AI systems it does not know about. Yet AI inventories become outdated quickly when employees adopt browser-based assistants, extensions, local applications, and AI-enabled SaaS features without formal deployment.

An inventory should include more than product names. Useful details include the system owner, business purpose, users, data accessed, model provider, integrations, risk classification, and applicable controls. Third-party services should be included in the inventory alongside internally developed models.

This is where workspace visibility can support AI compliance efforts. Pluto Security can help security teams identify which AI tools employees use and apply controls to risky interactions. Such technical evidence may support an AIMS, but it is only one part of certification. Governance decisions, documentation, training, audits, and leadership oversight remain organizational responsibilities.

Turning Policies Into Operational Controls

A policy that prohibits sensitive data from entering unapproved AI tools sounds reasonable, but proving that it works is harder.

Teams need observable controls for real-world use. Depending on the environment and risk, these could include tool discovery, approved-tool lists, role-based policies, sensitive-data protection, activity records, and incident escalation. Supplier reviews are also necessary because an external AI provider may change its models, retention practices, integrations, or security terms.

The goal is not to collect logs for their own sake. Evidence should help an auditor trace a requirement across policy, implementation, monitoring, and improvement. If a control fails, the organization should be able to show what happened, how it responded, and what changed afterward.

Preparing for Certification

Certification is voluntary and conducted by an independent certification body, not by ISO. A typical program begins by defining the AIMS scope and completing a gap assessment. The organization then builds or adapts its governance processes, operates them long enough to gather evidence, and conducts an internal audit and management review.

The certification audit generally assesses whether the management system has been appropriately designed and whether it operates effectively. Passing the audit is not the end. Surveillance audits and continual improvement keep the AIMS active as tools, risks, and business needs change.

FAQ

1. How long does it typically take an enterprise to achieve ISO/IEC 42001 certification?

There is no standard certification timeline. Preparation may take several months or longer, depending on the AIMS scope, governance maturity, the number of AI systems, risk complexity, and existing management-system processes. Any six- to twelve-month estimate should be treated as a planning benchmark rather than an ISO requirement.

2. Does certification apply to companies using third-party AI tools, or only those building AI?

It applies to both. The standard covers organizations that develop, provide, or use AI systems. A company using third-party assistants must still understand their purpose, data exposure, suppliers, risks, and controls. Purchasing the technology does not transfer the organization’s responsibility for how employees use it.

3. How does ISO/IEC 42001 interact with existing certifications like ISO 27001?

The standards cover distinct yet related areas. ISO/IEC 27001 addresses information security, while ISO/IEC 42001 addresses AI-specific risks and obligations. Both standards use the ISO harmonized management system structure, enabling organizations to share processes such as risk management, audits, document control, corrective action, and leadership review.