What the standard is

ISO/IEC 42001 defines a management system for artificial intelligence: policy, roles, risk assessment, controls and continual improvement. It does not say which models to use or what technology to buy. It describes how an organisation takes responsibility for what it deploys.

It is one of the three sources our catalogue is built on, together with the EU AI Act and NIST AI RMF. The three overlap considerably: one control often answers to more than one.

What we do

We translate the requirements into concrete controls, with owners and evidence, and place the organisation on a four-level scale — from informal use to auditable operation — so the path is a sequence rather than a list of a hundred pending items.

The outcome is readiness: controls operating and evidence available on the day an external verification takes place.

What we cannot do

We do not certify. Certification is issued by an accredited certification body, independent from whoever prepared the organisation — and that independence is precisely what gives it value. Any consultancy offering to certify is misdescribing what it sells.

Frequent questions

Is it mandatory?
No. It is a voluntary standard. It becomes relevant when a client, a funder or a regulator asks for it, or when the organisation wants an external reference rather than its own criterion.
How does it differ from the EU AI Act?
The AI Act is regulation with enforceable obligations according to the system's risk. The standard is a voluntary management framework. Meeting the standard helps with the regulation but does not replace it.
Is it useful if we do not operate in Europe?
It is useful as a management framework, which is jurisdiction-independent. AI Act obligations depend on where the system is offered, not where the company sits.
Where do you start?
With the inventory and risk classification of what is already in use. Without that, any policy is written blind.