Guide · AI governance
ISO 42001 explained: the AI management standard, in plain English
If your organisation builds or uses artificial intelligence, ISO/IEC 42001 is the framework you'll increasingly be asked about — by customers, boards and regulators. Here's what it is, who it's for, how it's put together, and how to approach it without turning it into a project from scratch.
What is ISO 42001?
ISO/IEC 42001, published in 2023, is the first international management-system standard for artificial intelligence. It defines requirements for establishing, implementing, maintaining and continually improving an AI management system (often shortened to AIMS) — a structured way for an organisation to govern how it develops, provides or uses AI.
If you've worked with ISO 27001 for information security or ISO 9001 for quality, the shape will feel familiar. Like those standards, ISO 42001 follows the common management-system structure used across modern ISO standards, and it is designed to be independently certified.
Why does it exist?
AI systems create risks that traditional governance wasn't built for: opacity in how decisions are made, bias in data and outputs, questions of accountability when something goes wrong, and rapid change in the systems themselves. Regulators are responding — the EU AI Act being the most prominent example — and buyers are starting to ask suppliers how their AI is governed.
ISO 42001 gives organisations a recognised, auditable way to answer that question. Rather than a set of technical rules for building models, it is a governance framework: it asks you to know which AI systems you have, understand their impact, manage their risks, and improve continually.
Who needs it?
ISO 42001 is relevant to any organisation that develops, provides or uses AI systems — not only AI vendors. That includes:
- Companies building AI features into their products
- Organisations deploying third-party AI in operations, hiring, customer service or decision-making
- Providers who want to demonstrate responsible AI governance to enterprise customers
- Regulated businesses anticipating AI-specific compliance obligations
You don't have to be a technology company. If AI touches decisions that affect people or the business, the standard is designed to apply.
How is ISO 42001 structured?
The standard follows the same high-level structure as other modern ISO management systems, which makes it straightforward to run alongside them. In broad terms it asks an organisation to:
- Understand its context — the internal and external factors, and the interested parties, relevant to its use of AI
- Show leadership — an AI policy, clear roles and accountability, and management commitment
- Plan — identify AI-related risks and opportunities and set objectives
- Provide support — resources, competence, awareness and documented information
- Operate — including assessing the impact of AI systems on individuals and society
- Evaluate performance — monitoring, internal audit and management review
- Improve — corrective action and continual improvement
It also includes a set of reference controls and implementation guidance in its annexes — again, a pattern familiar to anyone who has worked with ISO 27001's Annex A. One requirement worth highlighting is the AI system impact assessment: a structured look at how a given AI system could affect individuals and groups, which sits at the heart of the standard's approach to responsible AI.
The overlap advantage. Because ISO 42001 shares its backbone with ISO 27001 and ISO 9001, an organisation that already runs one of those has much of the machinery — document control, risk management, internal audit, management review — already in place. Adding AI governance becomes an extension of an existing system rather than a standalone build.
How should you approach it?
A sensible route in, especially if you already hold another ISO certification:
- Inventory your AI. You can't govern what you haven't listed. Start with every AI system you build or use, and who's responsible for it.
- Assess impact and risk. For each system, understand what it does, who it affects and what could go wrong.
- Set the governance. An AI policy, clear ownership, and the controls that fit your risks.
- Reuse what you have. Map your existing management-system processes onto the 42001 requirements rather than duplicating them.
- Run it as a live system. Evidence, audits and reviews on cycle — so certification is a checkpoint, not a scramble.
Where Kavorly fits
Kavorly runs ISO 42001 as a live management system on the same platform as your other standards — AI policy and governance, system impact assessments, risk, evidence and readiness — so AI governance isn't a fourth disconnected project. If you already run ISO 27001 in Kavorly, the shared machinery carries most of the load.
See how Kavorly runs ISO 42001 →
This guide is a general introduction, not certification advice or a substitute for the standard itself. For the authoritative requirements, refer to the published text of ISO/IEC 42001 or speak to a certification body.