Hero Image
ISO/IEC 42001

ISO 42001 Navigator BETA

The world's first international management system standard for artificial intelligence — ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system — establishing requirements for organisations to govern the development, provision, and use of AI systems through a certifiable AI Management System (AIMS) covering policy, risk treatment, lifecycle controls, and continual improvement.

GUIDED PATHWAYS

New to ISO 42001? Start with what applies to you

Our guided pathways filter the ISO/IEC 42001 Standard by role, sector and AI system type, so you spend your time on the clauses and Annex A controls that carry obligations for your AIMS — and skip the ones that do not.

🏢 What is ISO/IEC 42001
A plain-language introduction to AIMS — the certifiable management system at the core of ISO/IEC 42001:2023. Covers what an AI Management System actually is, how it compares to ISO 27001 and ISO 9001, the role of policy, risk treatment, objectives, internal audit, and management review, and what "establishing an AIMS" means in practice for an organisation developing, providing, or using AI systems.
6 ITEMS · 4 ART. · 2 ANN.
🎯 What is the ISO/IEC 42001:2023 Standard
A structural walkthrough of the Standard itself: the ten main clauses (Context, Leadership, Planning, Support, Operation, Performance Evaluation, Improvement) and the four supporting Annexes — Annex A controls, Annex B implementation guidance, Annex C AI-related organisational objectives and risk sources, and Annex D domain and sector use. Explains what is normative, what is informative, and where each obligation sits.
6 ITEMS · 4 ART. · 2 ANN.
📅 ISO 42001 and the EU AI Act
How the voluntary management system standard maps to the binding regulation. Covers where AIMS controls evidence EU AI Act obligations (risk management, data governance, technical documentation, human oversight, post-market monitoring), where the two diverge in scope and legal effect, and how certification to ISO 42001 supports — but does not substitute for — conformity with the Act.
8 ITEMS · 8 ART.
⚠️ ISO 42001 Annex A Controls Explained
A control-by-control walkthrough of the 38 Annex A controls across nine objectives — from policies for AI and internal organisation through resources, impact assessment, system lifecycle, data management, information for interested parties, AI system use, and third-party relationships. Explains what each control requires, what evidence demonstrates implementation, and which controls most often appear in certification audits.
13 ITEMS · 11 ART. · 2 ANN.
🤖 ISO 42001 Certification Process and Audit Readiness
What certification actually involves: selecting an accredited certification body, Stage 1 (documentation review) versus Stage 2 (implementation audit), the three-year certification cycle with annual surveillance audits, typical nonconformities, and how to prepare evidence — Statement of Applicability, risk register, AI impact assessments, internal audit reports, management review minutes — that auditors expect to see.
9 ITEMS · 7 ART. · 2 ANN.
⚖️ ISO 42001 vs ISO 27001, ISO 9001 and NIST AI RMF
How ISO 42001 relates to adjacent frameworks: shared Annex SL structure with ISO 27001 (information security) and ISO 9001 (quality), where AIMS extends beyond both, and how the Standard aligns with the NIST AI Risk Management Framework's Govern–Map–Measure–Manage functions. Covers integrated management systems and which controls can be evidenced once across multiple certifications.
8 ITEMS · 8 ART.