Skip to content
Compliance

ISO 42001

Updated Aug 2026 1 min read
Definition

ISO/IEC 42001 is the first international standard for AI management systems (AIMS). Published in December 2023, it provides requirements for establishing, implementing, maintaining, and continually improving how organizations govern AI systems across their lifecycle, from design through deployment and retirement.

Why It Matters

ISO 42001 does for AI what ISO 27001 did for information security: it gives organizations a certifiable framework for managing risk, building trust, and demonstrating responsible practice to auditors, partners, and regulators.

The standard covers leadership commitment, risk assessment, system lifecycle management, third-party supplier oversight, and continuous improvement. It is structured around the same Plan-Do-Check-Act cycle familiar from other ISO management system standards.

As of mid-2026, ISO 42001 is voluntary but increasingly referenced by regulators. The EU AI Act's Article 17 requires a quality management system for high-risk AI providers, and ISO 42001 provides the structural foundation. For organizations deploying AI agents, the standard's risk management and audit trail requirements intersect directly with agent governance.