Overview
ISO/IEC 42001 is the first international management system standard for artificial intelligence. ISO and the IEC published it in December 2023 through ISO/IEC JTC 1/SC 42, the joint committee on AI. It's still the first edition. The standard sets requirements for establishing, running, and improving an AI management system, or AIMS, for organizations that develop, provide, or use AI-based products and services.
Like ISO/IEC 27001, it follows the harmonized structure of clauses 4 to 10 and is risk based. It adds AI-specific duties, such as AI risk assessment, AI risk treatment, and AI system impact assessments that consider effects on individuals, groups, and society. Annex A lists 38 reference controls under 9 control objectives, Annex B gives implementation guidance for them, and Annexes C and D cover possible objectives, risk sources, and use across sectors. Not every control must apply. As with ISO/IEC 27001, the organization records its control choices in a Statement of Applicability.
Certification bodies are audited against ISO/IEC 17021-1 and ISO/IEC 42006:2025, which ISO published in July 2025 to set extra requirements for bodies that audit and certify an AIMS. In Canada, the Standards Council of Canada offers an AI management systems accreditation program based on ISO/IEC 42001. Demand for certification in Canada comes mainly from customers, by voluntary commitments such as the federal code of conduct for advanced generative AI systems, and by foreign rules such as the EU AI Act. Many pair it with ISO/IEC 27001.
Who it applies to in Canada
Organizations of any size, sector, or type that develop, provide, or use AI systems, including public agencies and not-for-profits. It covers the governance of AI rather than the technical performance of a single model.
Canadian AI developers and the organizations that buy from them use ISO/IEC 42001 to show responsible AI governance to customers, partners, and investors. The Standards Council of Canada was early to offer accreditation for AI management systems certification bodies, after a pilot completed in 2023.
Controls at a glance
Clauses 4 to 10 set the management system requirements, and Annex A lists 38 reference controls under 9 control objectives numbered A.2 to A.10.
Context and leadership (clauses 4 and 5)
- Determine the organization's roles in relation to AI
- Identify interested parties and their AI requirements
- Define the AIMS scope
- Top management sets an AI policy and assigns roles
Planning (clause 6)
- Assess AI risks against defined criteria
- Plan AI risk treatment and select controls
- Produce a Statement of Applicability
- Carry out AI system impact assessments
- Set AI objectives and plan changes
Support and operation (clauses 7 and 8)
- Provide resources, competence, awareness, and communication
- Control documented information
- Run AI risk assessments, treatment, and impact assessments as planned
- Control externally provided AI-related processes
Evaluation and improvement (clauses 9 and 10)
- Monitor and measure AIMS performance
- Run internal audits and management reviews
- Correct nonconformities and keep improving
Policies and internal organization (A.2 and A.3)
- Document an AI policy aligned with other policies
- Review the AI policy at planned intervals
- Define AI roles and responsibilities
- Set up a way to report concerns about AI
Resources and impact assessment (A.4 and A.5)
- Document data, tooling, computing, and human resources
- Assess impacts of AI systems on individuals and groups
- Assess societal impacts of AI systems
- Document impact assessment results
AI system life cycle and data (A.6 and A.7)
- Set objectives for responsible AI development
- Define requirements, design, verification, and validation
- Plan deployment, operation, monitoring, and event logs
- Manage data acquisition, quality, and provenance
- Document data preparation methods
Interested parties, use, and third parties (A.8 to A.10)
- Give users and affected parties information about the system
- Plan how incidents are communicated
- Define processes and objectives for responsible AI use
- Use AI systems as intended
- Allocate responsibilities with suppliers, partners, and customers
Certification and assessment
A certification body audits the AIMS in stage 1 and stage 2 audits, checking the AI risk and impact assessments, the Statement of Applicability, and evidence that controls operate. If it conforms, the body issues a certificate for a defined scope. Certification bodies follow ISO/IEC 17021-1 and ISO/IEC 42006:2025.
Dates to know
- 2023-12
- ISO/IEC 42001:2023 published
- 2025-07
- ISO/IEC 42006:2025 published, setting requirements for AIMS certification bodies
Resources
Official texts and free tools for ISO 42001. Links open the publisher’s site.
- ISO/IEC 42001:2023 Artificial intelligence management system, ISO
- ISO/IEC 42006:2025 Requirements for AIMS audit and certification bodies, ISO
- Artificial intelligence management systems accreditation, Standards Council of Canada
- Voluntary code of conduct on the responsible development and management of advanced generative AI systems, Innovation, Science and Economic Development Canadaguidance
- IAF CertSearch, International Accreditation Forumtool
Need help? Browse the directory or read the guides.
References
- ISO/IEC 42001:2023 Artificial intelligence management system, ISO
- ISO/IEC 42006:2025 Requirements for AIMS audit and certification bodies, ISO
- SCC launches artificial intelligence management systems accreditation, Standards Council of Canada
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.