ISO/IEC 42001
The first certifiable management system standard for AI — the ISO 27001 shape applied to how an organization builds and operates AI systems.
2023 · ISO/IEC 42001:2023 · published 2023-12-18
00Answer
01Standing
Named, with the authority's acquisition path recorded; onboarding is refused until a control set is registered.
ISO/IEC 42001 cannot be onboarded yet: Acquisition required before authoritative verbatim inventory generation. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
ISO/IEC 42001 cannot be onboarded yet: Acquisition required before authoritative verbatim inventory generation. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
02Registry record
- Registry status
- Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- AI management system · Risk assessment · Impact assessment · AI lifecycle
- Applies to
- AI · technology · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| 2023 | Current edition | 2023-12-18 |
06Related frameworks
- EU AI ActRegulation (EU) 2024/1689
Also applies to AI · The EU's risk-tiered regime for AI systems — prohibited practices, high-risk obligations, general-purpose model duties, and transparency requirements.
- ISO/IEC 238942023
Also applies to AI · International guidance for integrating AI-specific risk management into organizations that develop, provide, deploy, or use AI systems. It complements ISO/IEC 42001 and is guidance, not a standalone certification.
- ISO/IEC 420052025
Also applies to AI · International guidance for repeatable AI-system impact assessments across the system lifecycle. It complements ISO/IEC 42001, ISO/IEC 23894, and applicable AI laws; it is not an AI certification by itself.
Also applies to AI · The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.