Who is ISO 42001 relevant to?
ISO/IEC 42001:2023 is intended for organisations that develop, provide or use AI. Size and sector alone do not determine whether the standard is useful. First decide which AI applications and parts of the organisation you want to manage.
- You develop or integrate AI: clarify who makes decisions about its use, data, risks and changes.
- You use third-party AI: record what employees may use the application for and what you need from the supplier.
- Customers ask for accountability: discuss which services they expect evidence or certification for.
Choosing a management system and choosing certification are separate decisions. First establish the outcome required.
From an AI inventory to a workable approach
Start with your applications and existing arrangements. The sequence below offers practical preparation, not a complete checklist of the standard. BSI describes the implementation and assessment of an AI management system.
- Take stock and define the scope: which AI do you use or provide, for what purpose, involving which parties and owners?
- Assess your starting point: compare policies and practices with the standard and record missing elements in a gap analysis.
- Assess risks and impacts: consider the consequences for the organisation and the people affected by the application. Record decisions and controls.
- Put arrangements into practice: allocate tasks, adapt policies and gather evidence from day-to-day operations.
- Check and improve: plan internal audits and a management review, follow up findings and prepare for external certification if required.
What does DCA do and what remains your responsibility?
DCA supports AI inventories, gap analysis, AI risk analysis, policy documentation and preparation for internal and external audits. The Compliance Tool enables you to bring the standard, tasks, documents and evidence together. During the initial discussion, we agree which elements of the implementation support you will use and who will carry out each task.
- DCA: helps structure the initial assessment, develop the work plan and follow up agreed actions and documentation.
- Your management: defines scope and priorities, allocates resources and makes decisions about risks and the use of AI.
- Your employees and process owners: provide knowledge of applications and suppliers, implement agreed controls and demonstrate how these work in practice.
- The certification body: conducts the external assessment and makes the certification decision independently.
Discuss separately whether specialist legal analysis, technical model assessment or additional audit support is needed. These activities are not automatically included in every implementation project.
What evidence demonstrates your approach?
Link arrangements to specific applications, decisions and responsible people. Practical examples include an overview of AI use, an approved usage policy, a recorded risk assessment and follow-up of a change or incident. These are preparation examples, not evidence that an organisation is already certified.
For each item, clarify who maintains it and what has been done with it. A completed template alone does not demonstrate effectiveness. An internal audit or readiness assessment can help identify where arrangements and implementation still differ.
How does ISO 42001 relate to the AI Act and other requirements?
AI Act: the legislation sets obligations depending on factors including your role and the AI application. An AI management system can help organise these, but an ISO 42001 certificate does not automatically demonstrate legal compliance. Have the applicable requirements assessed separately. See the European Commission’s explanation and the current consolidated AI Act.
GDPR and sector-specific rules: the applicable privacy rules continue to apply to personal data. The AI Act does not replace those rules. Contractual arrangements and any sector-specific obligations also require separate assessment.
ISO 27001: existing processes for documents, audits and improvement actions can be reused. Keep AI-specific risks and impacts on people visible. BSI explains the relationship and differences. Also explore our ISO 27001 approach and the article on ISO 42001 and the AI Act.
Certification, planning and costs
An external certification body assesses the management system within the agreed scope. Check the body’s accreditation and scope, and the evidence your client requires. ISO explains the role of certification bodies; ISO does not issue certificates itself.
The schedule depends on the number and type of applications, existing arrangements, available staff and audit planning. There is no fixed lead time or guarantee of certification.
In the work plan, distinguish between software, support, your own time, any additional assessments and external certification costs. View the cost breakdown and discuss which activities your scope requires.
Frequently asked questions about ISO 42001
Is ISO 42001 the same as complying with the AI Act?+
No. ISO 42001 concerns the AI management system. For the AI Act, you must separately determine which roles, applications and obligations apply to your organisation. A certificate does not automatically demonstrate legal compliance.
Can we use our existing ISO 27001 system?+
Yes, existing arrangements for documents, audits and improvement actions can provide a starting point. Also assess AI-specific risks, impacts and responsibilities; an ISO 27001 certificate does not automatically cover these.
Does DCA issue the ISO 42001 certificate?+
No. DCA provides software and agreed implementation and audit preparation support. An independent certification body assesses the management system and decides on certification.
Official sources
For implementation, use the current standard and the legislation applicable to your situation.
