---
title: "ISO/IEC 42001: what an AI Management System is and who really needs it"
url: https://zerofive.ai/en/blog/compliance/iso-42001-ai-management-system
canonical: https://zerofive.ai/en/blog/compliance/iso-42001-ai-management-system
language: en
published: 2026-02-19
updated: 2026-09-18
author: "ZeroFive.AI"
tags: ISO IEC 42001, AI Management System, AI certification, AIMS, AI governance standard
abstract: "ISO/IEC 42001 is the first certifiable standard for AI management: how it is built, what it demonstrates, its relationship with the AI Act and who certification makes sense for now."
---

# ISO/IEC 42001: what an AI Management System is and who really needs it

In the AI governance conversations of recent months one acronym has started circulating with growing insistence, pushed by the consultants selling it and by the enterprise clients beginning to demand it from suppliers: ISO/IEC 42001. As happens to every young standard, disproportionate expectations have formed around it in both directions, those treating it as the pass that solves the AI Act and those dismissing it as yet another badge. It is worth looking at it for what it is, because certain organisations really need it, others do not yet, and the difference can be stated with precision.

## A management system, not an exam on models

ISO/IEC 42001:2023, published at the end of 2023, is the first certifiable international standard for an artificial intelligence management system, an AI Management System. The word that carries weight is "management": the standard does not evaluate your models, does not measure output accuracy, does not pass or fail algorithms. It certifies that the organisation has built the machine to govern them: policies and objectives, roles and responsibilities, assessment of AI systems' risks and impacts across the lifecycle, operational controls, monitoring, continuous improvement, all within the harmonised structure that anyone familiar with ISO 9001 or ISO/IEC 27001 will recognise at first glance, plus an annex of AI-specific controls covering everything from system lifecycles to data, from stakeholder transparency to responsible use.

The kinship with 27001 is not a technical detail, it is the good news for many companies: whoever already runs an information security management system owns the scaffolding, the internal audit processes, the documentary culture, and the extension to AI is an incremental workstream instead of a foundation from scratch. In the journeys we observe, this is the variable that more than any other separates the six-month projects from the eighteen-month ones.

## The relationship with the AI Act, said without shortcuts

The question everyone asks is whether certification shelters you from the European regulation, and the honest answer has two halves. The first: no, ISO 42001 does not equal AI Act conformity, because the standard is voluntary and organisational while the regulation imposes specific obligations per system and per risk category, and no certificate replaces the classification of your use cases, the technical documentation where required, the transparency obligations. Whoever sells you the certification as "guaranteed AI Act compliance" is selling a phrase that we, as a matter of policy, never use.

The second half, though, weighs in the opposite direction: the regulation asks organisations for exactly the kind of evidence an AIMS produces by construction, assigned roles, risks assessed and recorded, documented processes, periodic reviews. The standard is the organisational machine that generates the evidentiary material, and reaching the regulation's deadlines with that machine running changes the nature of the work: you compile what exists instead of reconstructing what is missing. It is the same principle that holds for 27001 with respect to GDPR, never equivalence, always equipment.

## Who needs it now, who does not yet

The profile that needs certification today is recognisable. Suppliers of AI solutions and services to enterprise clients, for whom the certificate is becoming a procurement requirement, as happened with 27001 a decade ago. Organisations in regulated or exposed sectors, where board, audit and supervisors ask for demonstrable guarantees and an accredited certificate speaks their language. International groups wanting a single apparatus spendable across jurisdictions, since the standard travels where national regulations diverge.

The opposite profile is just as recognisable: the organisation with few tools in use and a governance still to be founded, for which starting from certification means buying the scaffolding before the house. The figure from the Politecnico di Milano Observatory presented in February, 9% of large companies with structured AI governance, says the majority sits in this second profile, and for the majority the sensible sequence remains the one we have been writing about for weeks: first the inventory, the classification, the responsibilities, then, once governance exists and needs demonstrating, the standard that certifies it. Certification is the photograph of a maturity, and photographing an empty room produces only an empty certificate.

For those in the first profile, the realistic path deserves its true timeline on the agenda: gap analysis against the standard, implementation of the missing controls, two-stage certification audit, annual surveillance, with horizons that in practice are measured in two or three semesters rather than months.

Our trade sits on the step before: the AI Rating measures where you stand against what the standard would ask, the Risk dimension produces the gap analysis, and the roadmap says whether and when certification sensibly enters the plan, because this too, like everything in this series, is a decision to be taken with evidence: calendly.com/fabiolalli/zerofive, or hello@zerofive.ai. The preliminary test, meanwhile, costs one question in committee: if the certification audit were six months away, which chapter of your management system today does not exist even as a draft?
