Everyone is deploying AI. Very few can prove they’re governing it. ISO 42001 is the first international standard built to close that gap. Here’s what it actually asks of you, and where the real governance work lives.
Ask a room of managers whether they’re using AI responsibly and every hand goes up. Ask them to prove it, the room goes quiet. For years there was no agreed answer to “how would you demonstrate that your AI is well governed?” In December 2023, one arrived: ISO/IEC 42001, the world’s first international standard for an AI management system. The first that an organisation can be formally certified against.

If you’ve come across ISO 27001 for information security or ISO 9001 for quality, you already understand the shape of it. Those standards don’t hand you a firewall or inspect a single product. They ask whether you have a proper system for managing security or quality, across the whole organisation. ISO 42001 does the same thing for artificial intelligence.
What it Actually is
The single most important thing to understand about ISO 42001 is what kind of standard it is. It is a management system standard, not a technical one.
That means it will not tell you which model to choose, how to reduce bias in a dataset, or what accuracy threshold to hit. It says something more fundamental: put in place a system including policies, roles, processes, records and controls for governing AI across its entire life, from the first idea to the day you switch it off. Then keep improving that system as the technology and the risks move underneath you.
Like its ISO relatives, it runs on a simple loop that anyone who has managed anything will recognise: plan, do, check, act. Decide what your AI is for and what could go wrong. Put controls in place. Measure whether they’re working. Fix what isn’t, and go round again. That loop is deliberately chosen, because AI is not a problem you solve once. It’s a moving target, and a governance system that can’t keep moving with it is already out of date.
So ISO 42001 is not a safety certificate for a particular AI system. It’s evidence that your organisation knows how to govern AI.
What Makes it AI-specific
If it’s shaped like other ISO standards, what’s genuinely new? Three things stand out.
First, it asks you to weigh not just risk but impact. A security standard mostly asks “what could hurt the organisation?” 42001 also asks “what could this AI do to the people it affects, and to society?” That outward-facing question, e.g., the effect on a customer denied a loan, a candidate filtered out, a patient mis-triaged, is written into the standard. It’s a wider lens than most enterprises are used to applying.
Second, it expects you to actually know what AI you have. That sounds obvious until you go looking, and discover models scattered across teams, embedded in tools, bought from vendors, and spun up on someone’s corporate card. You cannot govern what you cannot see, so an inventory of your AI systems is the foundation.
Third, it makes accountability, transparency, human oversight and data governance recurring themes rather than afterthoughts. These are exactly the ideas that separate governed AI from AI that merely works.
The Shape of the Standard
The main body follows the familiar ISO pattern, and you can read it as a sequence of plain questions the organisation has to answer.
- Context: where does AI fit in what we do, and who is affected by it?
- Leadership: who at the top owns this, and is there a real AI policy, or just a slogan?
- Planning: what are our AI risks and impacts, and what are we going to do about them?
- Support: do the people, skills and resources exist to make this real?
- Operation: how do we actually run the day-to-day, e.g., assessing systems, building or buying them, and managing them across their lifecycle?
- Performance evaluation: how do we check it’s working?
- Improvement: how do we fix and get better when it isn’t?
Alongside this sits a set of reference controls, a menu of specific governance practices covering things like AI policies, clear roles and responsibilities, managing the AI system lifecycle, governing the data that feeds AI, being transparent with the people affected, and handling AI you obtain from third parties. The standard doesn’t force every control on you. It asks you to decide, deliberately and on the record, which apply and why. That “on the record, with a reason” quality is the whole point: governance you can show, not just assert.
Where the AI Governance Actually Lives
Here is where it gets interesting, and where ISO 42001 stops being an abstract framework and starts touching the real decisions I keep writing about. The standard is essentially a formal, auditable expression of a handful of governance ideas. It’s worth walking through where each one bites.
- Accountability: ISO 42001 pushes accountability up to leadership and insists on clear roles. This matters because AI cannot be accountable for anything. Software is not a legal person. When an AI system causes harm, a human has to answer for it. The standard forces the question every organisation avoids until it’s too late: who, by name, is responsible when this goes wrong?
- Knowing your systems: the inventory-and-impact requirement is really action-tiering in disguise. Once you can see all your AI and how consequential each system is, you can do the thing that makes governance affordable. Put light controls on the low-stakes, reversible uses and concentrate your real scrutiny on the few that are high-stakes or hard to undo. This is the heart of governing the action, not the agent: you don’t govern every system equally, you govern by consequence. ISO 42001 gives that instinct a paper trail.
- Human oversight: the standard expects meaningful human involvement in consequential AI decisions. A human rubber-stamping 1000+ AI outputs a day is oversight in name only. Real oversight is a gate on the consequential action: the moment something irreversible or high-impact is about to happen, a person with the authority and the information to say no is in the loop. Governed AI isn’t AI with a human watching. It’s AI with a human able to intervene where it counts.
- Transparency and data governance: ISO 42001 leans hard on being able to explain what a system does, on what data, and why. This is the same property that makes a retrieval-based assistant trustworthy. An answer you can trace to a source is an answer you can govern. A confident black box is not. Governing the data that feeds AI, e.g., where it came from, whether you’re allowed to use it, whether it’s current and representative, is where a surprising amount of real-world AI failure is actually born.
- The whole lifecycle: this standard governs AI from design through retirement, not just at go-live. That matters more every year, because modern AI doesn’t stand still after deployment. It gets retrained, it drifts, and some systems improve themselves between one review and the next. A one-time sign-off is worthless against a system that changes. ISO 42001’s continual loop is built precisely for things that don’t hold still.
- AI you didn’t build: most organizations don’t train their own models. They buy them, or build on someone else’s. The standard’s attention to third-party AI is a quiet acknowledgement that your governance boundary now extends into your suppliers. If a vendor’s model makes a consequential decision inside your process, “we didn’t build it” is not a defence, you still own the outcome.
- A governance system that improves itself: finally, the plan-do-check-act loop means your governance is never finished. It’s meant to get better as you learn. This is exactly the balance I’ve argued for between control and innovation: governance that never evolves calcifies, and a standard built on continual improvement is designed to keep the circle turning.
Two Honest Caveats
Before anyone treats a certificate as a finish line, two things are worth saying plainly.
An ISO 42001 certificate proves you have a well-managed system for governing AI. It does not prove any individual AI system is safe, fair, or accurate. Just like an ISO 27001 certificate never promised you’d not be breached. It raises the floor but it doesn’t guarantee the ceiling.
And because it’s a management-system standard, it’s deliberately non-prescriptive. It tells you what to govern, not exactly how. That flexibility is a strength. It means different certified organizations can be governing AI at very different levels. The certificate is a strong signal, not a substitute for judgement.
The Bridge from Principle to Practice
For all the clause numbers, ISO 42001 is saying something simple, and something I’ve been circling for a while now: govern AI on purpose. Know what you have. Understand what it could do to people. Put a human in charge of the consequential moments. Write down your decisions so you can defend them. And keep the whole thing improving, because the technology won’t wait for you.
If my other posts make the case for why you govern the action rather than the agent, ISO 42001 is the framework that lets you prove you’re doing it. It’s where the principle becomes an auditable practice.