Back to blog
Compliance·Jun 22, 2026·4 min read

What is ISO 42001? The AI management system standard, explained

ISO 27001 told the world you could be trusted with information. ISO 42001 is how you say the same thing about your AI.

ISO 42001 is the first international management-system standard for artificial intelligence, and it is fast becoming the way organisations prove they govern AI responsibly. Where the EU AI Act is a legal obligation for certain systems, ISO 42001 is a voluntary certification you can hold up to customers, partners and auditors as evidence that AI risk is managed by design rather than by chance.

This guide explains what ISO 42001 is, what an AI management system involves, and how it relates to the standards and laws you may already follow.

What ISO 42001 is

ISO 42001 specifies the requirements for an AI management system, or AIMS: a structured set of policies, roles, processes and controls for governing AI across its lifecycle. It follows the same management-system pattern as ISO 27001 for information security, which means it is certifiable by an external body and built around continual improvement rather than a one-time assessment.

What an AI management system involves

Implementing ISO 42001 means establishing the machinery to govern AI on an ongoing basis. That includes a clear AI policy and objectives, defined roles and accountability, a process for identifying and assessing AI risks and their impact on people, controls to manage those risks, and a cycle of monitoring, review and improvement. The emphasis is on a living system, not a document, which is why an accurate inventory of the AI systems in scope is the precondition for the whole thing.

ISO 42001 versus ISO 27001

The two are siblings, not substitutes. ISO 27001 governs information security; ISO 42001 governs AI specifically, covering risks that security management was never designed to address, such as bias, transparency and the societal impact of automated decisions. An organisation already certified to ISO 27001 has the management-system habits in place and can extend them, rather than starting over. The full comparison is in the ISO 42001 versus ISO 27001 guide.

For teams building that AI layer on top of ISO 27001, Grasp handles managing AI under ISO 27001 with the live inventory and evidence the management system depends on.

ISO 42001 and the EU AI Act

They reinforce each other. ISO 42001 is a voluntary standard you choose to certify against; the EU AI Act is law that applies whether you certify or not. The value of the standard is that much of what it requires, risk assessment, oversight, documentation and continual review, maps directly onto the AI Act's expectations, so a certified AI management system becomes strong evidence of compliance. Both treat governance as continuous, the theme of continuous compliance versus periodic audits.

Frequently asked questions

What is ISO 42001?

ISO 42001 is the first international standard for an AI management system. It sets out the requirements for governing AI across its lifecycle through policies, roles, risk processes and controls, and it can be independently certified like ISO 27001.

What is an AI management system?

An AI management system, or AIMS, is the set of policies, responsibilities, processes and controls an organisation uses to govern its AI on an ongoing basis. ISO 42001 specifies what such a system must include and how to keep improving it.

What is the difference between ISO 42001 and ISO 27001?

ISO 27001 governs information security; ISO 42001 governs AI specifically, addressing risks like bias, transparency and the impact of automated decisions. They share the same management-system structure, so the two extend rather than replace each other.

Is ISO 42001 mandatory?

No. It is a voluntary certification, not a law. Organisations pursue it to demonstrate responsible AI governance to customers and auditors, and because it aligns closely with legal regimes such as the EU AI Act.

Does ISO 42001 help with EU AI Act compliance?

Yes. Much of what ISO 42001 requires, including risk assessment, human oversight, documentation and continual review, maps onto the AI Act's obligations. A certified AI management system is therefore strong supporting evidence, though it does not replace the Act's specific legal duties.

Grasp maintains the live AI inventory and risk evidence an ISO 42001 management system depends on, so certification and audit become a confirmation rather than a scramble. See the compliance readiness solution →