Definition · AI governance
ISO/IEC 42001
ISO/IEC 42001 is the international standard for an AI management system: the policies, objectives and processes an organisation sets up to develop, provide or use AI responsibly. Published on 18 December 2023, it specifies requirements for establishing, running and continually improving that system, and applies to organisations of any size that build, provide or use AI.
Last reviewed
Key points
- ISO/IEC 42001:2023 sets requirements for an AI management system, the policies, objectives and processes through which an organisation governs how it develops, provides or uses AI. It was published on 18 December 2023.
- The standard is for organisations of any size and any industry, public or private, that develop, provide or use AI. ISO says it offers a way to manage AI risks across the organisation rather than the details of specific AI applications.
- Certification bodies can audit an organisation's AI management system and certify it according to ISO/IEC 42001. ISO/IEC 42006 (2025) sets requirements for those bodies.
- NIST has mapped its AI Risk Management Framework to the final draft of ISO/IEC 42001. Colorado's 2024 AI law named both; a 2026 law replaces that text, mostly from 1 January 2027, with one that names neither.
- A 2024 EU Joint Research Centre brief says the standard is "not aligned in objectives and approach" with the EU AI Act.
ISO’s page is at iso.org/standard/42001. We draw on that page, ISO’s open metadata, and NIST, Colorado and EU documents.
What the standard covers
ISO/IEC 42001 sets requirements for how an organisation manages AI, not for any single AI model. ISO calls the result an AI management system: the organisation’s policies and objectives, and the processes to meet them, for developing, providing or using AI responsibly. The organisation runs them in a Plan-Do-Check-Act cycle: plan, do the work, check the results, act on what the checks find. ISO says the standard offers a way to manage AI risks and opportunities across the organisation, rather than the details of specific AI applications.
NIST mapped every subcategory of its AI risk management framework to clauses and annex items of the standard’s final draft. The clauses it maps to include leadership, AI risk assessment and treatment, AI system impact assessment, monitoring and continual improvement. The annex items include an AI policy and suppliers.
Two companion standards followed in 2025, according to ISO’s open data. ISO/IEC 42005 covers AI system impact assessment. ISO/IEC 42006 sets requirements for the bodies that audit and certify AI management systems according to 42001.
Why it matters
ISO/IEC 42001 gives an organisation a published standard that its AI governance can be checked against. ISO lists showing responsible use of AI among its benefits, and certification bodies can audit against it.
Colorado’s 2024 AI law also named the standard, next to NIST’s framework, as a reference for deployers of high-risk AI systems. A 2026 law replaces that text, mostly from 1 January 2027, with one that names neither.
Trade-offs
ISO/IEC 42001 and the EU AI Act aim at different things. The EU Joint Research Centre said in 2024 that the standard is “not aligned in objectives and approach” with the Act. In a separate passage on international standards in general, the brief says they tend to protect the objectives of organisations using AI. Standards for the Act, it says, must put first the risks to people’s health, safety and fundamental rights.
Our reading: an organisation the Act covers cannot treat a 42001 system, or a 42001 certificate, as meeting the Act. It still has to check the Act’s own requirements. The brief does see some overlap: some of the standard’s clauses could be referenced by new EU quality management standards, if those stay focused on the Act’s own risks and objectives.
What Colorado’s 2024 law said
As signed in 2024, Colorado’s AI law, Senate Bill 24-205, requires deployers of high-risk AI systems to run a programme against algorithmic discrimination. Some deployers under 50 full-time equivalent staff are exempt. The programme must be reasonable considering size, systems and data, and a framework: NIST’s, ISO/IEC 42001, another nationally or internationally recognised framework that is substantially equivalent to or stricter than the law’s own requirements, or one the attorney general designates.
The act also offers an affirmative defence, which the accused party must prove, in actions the attorney general brings. The party must find and cure a violation through feedback it encourages, adversarial testing or red teaming, or internal review. It must otherwise comply with one of three: the NIST framework and ISO/IEC 42001 together, another nationally or internationally recognised framework that is substantially equivalent to or stricter than the law’s own requirements, or one the attorney general designates.
The act was to start on 1 February 2026; a 2025 law moved that to 30 June 2026. Senate Bill 26-189, approved on 14 May 2026, then repealed and reenacted the act’s provisions. Most of the new text, on automated decision-making, takes effect on 1 January 2027. It does not mention ISO/IEC 42001, NIST or a risk management programme.
Questions and answers
What is ISO/IEC 42001?
ISO/IEC 42001:2023, "Information technology — Artificial intelligence — Management system", is the international standard for an AI management system, published on 18 December 2023. It sets requirements for the policies, objectives and processes an organisation uses to develop, provide or use AI responsibly, and for improving them over time. It applies to organisations of any size, in any industry, including public sector agencies and non-profits.
Can an organisation be certified to ISO/IEC 42001?
Yes. Certification bodies audit and certify an organisation's AI management system according to ISO/IEC 42001. A separate standard, ISO/IEC 42006, published in July 2025, sets requirements for the bodies that do this auditing and certification.
How does ISO/IEC 42001 relate to the NIST AI Risk Management Framework?
NIST published a crosswalk that maps each subcategory of its AI Risk Management Framework to clauses and numbered annex items in the final draft of ISO/IEC 42001. Colorado's 2024 AI law named both as reference points for the risk programmes of deployers of high-risk AI systems. A 2026 Colorado law replaces that text, mostly from 1 January 2027, with one that names neither.
What does the EU say about ISO/IEC 42001 and the AI Act?
A 2024 brief from the European Commission's Joint Research Centre says ISO/IEC 42001 is "not aligned in objectives and approach with the AI Act". The brief adds that some of its clauses could be referenced by new EU standards on quality management for AI, as long as those standards stay focused on the risks and objectives in the Act.
Sources
- ISO Open Data, ISO deliverables metadata (JSON Lines, latest)ISO
- ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system (iso.org standard page)ISO
- NIST AI RMF to ISO/IEC FDIS 42001 AI Management system CrosswalkNIST
- Colorado Senate Bill 24-205, Consumer Protections for Artificial Intelligence (signed act)Colorado General Assembly, May 2024
- SB25B-004, Colorado General Assembly bill pageColorado General Assembly, Aug 2025
- Senate Bill 26-189, Session Laws of Colorado 2026, chapter 131Colorado General Assembly, 14 May 2026
- Harmonised Standards for the European AI Act (JRC139430, science for policy brief)European Commission Joint Research Centre, 1 Jan 2024