ISO 42001 Certification
The management system standard for organisations that develop, supply or use artificial intelligence systems and must govern them.
- Standard
- ISO 42001:2023
- Indicative timeline
- 12-20 weeks, depending on scope and readiness
- Discipline
- Specialised Standards
- Assessment type
- Independent third-party assessment
The standard
Overview
ISO 42001:2023 is the first management system standard for artificial intelligence. It follows the harmonised clause structure and adds Annex A, a set of controls covering AI policy, internal roles, resources for AI systems, impact assessment, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems and third-party relationships.
Certification shows that AI is governed through defined roles, documented decisions and recorded impact assessments rather than informal practice. Organisations placing AI systems on the EU market use it to organise the evidence the EU AI Act expects. In the UK, where there is no single cross-cutting AI statute, sector regulators apply existing law and look for comparable governance.
UKCert assesses in two stages. Stage 1 reviews the AIMS scope, the organisation's role as provider, developer or user, the Annex A statement of applicability and the impact assessment method. Stage 2 tests how named AI systems are built, monitored, overseen and withdrawn.
Who this is for
- Developers of AI models, tools and product features
- SaaS providers embedding AI in customer-facing services
- Organisations using AI in hiring, credit or clinical decisions
- Public bodies operating automated decision support
- Suppliers asked to evidence AI governance in tenders
What it gives you
Why organisations certify
What a certified ISO 42001:2023 assessment gives you once the certificate is issued.
Defined AI accountability
Roles for AI policy, oversight and sign-off are assigned by name, so decisions about deployment, retraining, change and withdrawal have an accountable owner.
Impact assessment discipline
Impacts on individuals and groups are assessed before deployment and reviewed afterwards, producing records that hold up when an automated decision is challenged.
Regulatory readiness
Risk management, data governance, technical documentation and human oversight map closely to EU AI Act obligations and to what UK sector regulators already expect.
Data governance for AI
Training, validation and operational data are traced to source, with quality, provenance, bias and preparation steps recorded rather than assumed.
Buyer assurance
Procurement teams increasingly ask how AI systems are governed. A certified AIMS and statement of applicability answer those questions in a form buyers recognise.
Life cycle control
Objectives, design, verification, deployment, monitoring and decommissioning follow a defined route, so models are not left running without review or an owner.
Scope
What the assessment covers
The areas an assessor works through. Your final scope is confirmed in writing before any audit is booked.
- AI policy and Annex A statement of applicability
- AI roles: provider, developer, user and partner
- AI system impact assessment method
- AI system life cycle management
- Data provenance, quality and preparation records
- Human oversight and intervention controls
- Transparency and information for interested parties
- Third-party, supplier and customer responsibilities
How it runs
The assessment, stage by stage
From first enquiry to certificate. Each stage is agreed with you before it starts.
-
Scope and AI role
We establish which AI systems fall in scope and whether the organisation develops, provides, deploys or uses them, since Annex A applicability follows directly from that role.
-
Stage 1 review
A review of AIMS documentation: AI policy, statement of applicability, risk and impact assessment method, data governance records and the inventory of AI systems.
-
Readiness period
Gaps from Stage 1 are closed and the system runs long enough to generate evidence: completed impact assessments, monitoring output, internal audit and a management review.
-
Stage 2 assessment
Auditors follow named AI systems through the life cycle, testing data handling, evaluation, human oversight, change control, incident handling and the information given to users.
-
Certification decision
Nonconformities are graded and closed out. An independent reviewer who took no part in the audit takes the certification decision, and the certificate is issued.
-
Surveillance and recertification
Annual surveillance covers new and materially changed AI systems, monitoring results and incidents. A full recertification audit is carried out before the three-year certificate expires.
Questions
ISO 42001:2023 — frequently asked
Anything here that does not cover your situation, put it to an assessor rather than guessing at it.
Same discipline
Other schemes in Specialised Standards
Certifying against more than one standard?
Where you hold several standards, shared clauses are assessed once in a combined visit rather than as separate audits. Talk it through with an assessor before you decide what ISO 42001:2023 should sit alongside.