20 certification schemes

ISO 42001:2023

ISO 42001 Certification

The management system standard for organisations that develop, supply or use artificial intelligence systems and must govern them.

Standard
ISO 42001:2023
Indicative timeline
12-20 weeks, depending on scope and readiness
Discipline
Specialised Standards
Assessment type
Independent third-party assessment

The standard

Overview

ISO 42001:2023 is the first management system standard for artificial intelligence. It follows the harmonised clause structure and adds Annex A, a set of controls covering AI policy, internal roles, resources for AI systems, impact assessment, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems and third-party relationships.

Certification shows that AI is governed through defined roles, documented decisions and recorded impact assessments rather than informal practice. Organisations placing AI systems on the EU market use it to organise the evidence the EU AI Act expects. In the UK, where there is no single cross-cutting AI statute, sector regulators apply existing law and look for comparable governance.

UKCert assesses in two stages. Stage 1 reviews the AIMS scope, the organisation's role as provider, developer or user, the Annex A statement of applicability and the impact assessment method. Stage 2 tests how named AI systems are built, monitored, overseen and withdrawn.

Who this is for

  • Developers of AI models, tools and product features
  • SaaS providers embedding AI in customer-facing services
  • Organisations using AI in hiring, credit or clinical decisions
  • Public bodies operating automated decision support
  • Suppliers asked to evidence AI governance in tenders

What it gives you

Why organisations certify

What a certified ISO 42001:2023 assessment gives you once the certificate is issued.

Defined AI accountability

Roles for AI policy, oversight and sign-off are assigned by name, so decisions about deployment, retraining, change and withdrawal have an accountable owner.

Impact assessment discipline

Impacts on individuals and groups are assessed before deployment and reviewed afterwards, producing records that hold up when an automated decision is challenged.

Regulatory readiness

Risk management, data governance, technical documentation and human oversight map closely to EU AI Act obligations and to what UK sector regulators already expect.

Data governance for AI

Training, validation and operational data are traced to source, with quality, provenance, bias and preparation steps recorded rather than assumed.

Buyer assurance

Procurement teams increasingly ask how AI systems are governed. A certified AIMS and statement of applicability answer those questions in a form buyers recognise.

Life cycle control

Objectives, design, verification, deployment, monitoring and decommissioning follow a defined route, so models are not left running without review or an owner.

Scope

What the assessment covers

The areas an assessor works through. Your final scope is confirmed in writing before any audit is booked.

  • AI policy and Annex A statement of applicability
  • AI roles: provider, developer, user and partner
  • AI system impact assessment method
  • AI system life cycle management
  • Data provenance, quality and preparation records
  • Human oversight and intervention controls
  • Transparency and information for interested parties
  • Third-party, supplier and customer responsibilities

How it runs

The assessment, stage by stage

From first enquiry to certificate. Each stage is agreed with you before it starts.

  1. Scope and AI role

    We establish which AI systems fall in scope and whether the organisation develops, provides, deploys or uses them, since Annex A applicability follows directly from that role.

  2. Stage 1 review

    A review of AIMS documentation: AI policy, statement of applicability, risk and impact assessment method, data governance records and the inventory of AI systems.

  3. Readiness period

    Gaps from Stage 1 are closed and the system runs long enough to generate evidence: completed impact assessments, monitoring output, internal audit and a management review.

  4. Stage 2 assessment

    Auditors follow named AI systems through the life cycle, testing data handling, evaluation, human oversight, change control, incident handling and the information given to users.

  5. Certification decision

    Nonconformities are graded and closed out. An independent reviewer who took no part in the audit takes the certification decision, and the certificate is issued.

  6. Surveillance and recertification

    Annual surveillance covers new and materially changed AI systems, monitoring results and incidents. A full recertification audit is carried out before the three-year certificate expires.

Questions

ISO 42001:2023 — frequently asked

Anything here that does not cover your situation, put it to an assessor rather than guessing at it.

Ask a question

Twelve to twenty weeks is a realistic range, set by how many AI systems are in scope and whether the organisation builds models or deploys third-party ones. Impact assessment usually takes longest, because it needs input from legal, product and engineering together. Organisations with an existing ISO 27001 system tend to move faster, as the management system elements already exist.

Certificates run for three years, with annual surveillance and a recertification audit before expiry. AI scope changes more often than most, so new models, materially retrained systems or new deployment contexts should be notified between audits and will be examined at the next surveillance visit. The certificate names the AI systems or categories covered.

No. ISO 42001 is voluntary and no law requires it. The EU AI Act places obligations on providers and deployers according to risk classification, and the harmonised standards under that Regulation are separate from ISO 42001. The UK currently has no single cross-cutting AI statute; existing regulators apply current law within their sectors.

Surveillance samples the AI management system each year. It covers the AI system inventory, impact assessments completed since the last audit, monitoring and performance data, incidents and complaints, changes to suppliers or models, internal audit and management review. Systems added or materially retrained since the previous visit are the usual focus of sampling.

They are separate instruments. The AI Act is law and applies to AI systems placed on or used in the EU market, with duties set by risk classification. ISO 42001 is a voluntary management system standard and confers no presumption of conformity. Its controls on risk management, data governance, documentation, logging and human oversight align closely with what the Act expects.

Certifying against more than one standard?

Where you hold several standards, shared clauses are assessed once in a combined visit rather than as separate audits. Talk it through with an assessor before you decide what ISO 42001:2023 should sit alongside.