International Organization for Standardization (ISO) and International…
International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 controls, adoption, reputation, and evolution
- ISO/IEC 42001:2023 is the first certifiable international management-system standard dedicated to organisational AI governance, and its public clause structure centres on context, leadership, planning, support, operation, performance evaluation, and continual improvementISO (2023)ISO ISO 42001 explained (n.d.)Microsoft (2025)
- Publicly accessible mappings indicate that Annex A contains 38 controls in nine objectives, A.2 through A.10, covering policy, internal organisation, resources, impact assessment, lifecycle, data, information for interested parties, responsible use, and third-party relationshipsCyber (2026)Isms (n.d.)Microsoft (2025)
- The standard's most important public risk mitigations are impact assessment, lifecycle verification and validation, event logging, data provenance and quality controls, user and regulator information duties, intended-use constraints, and supplier-accountability controlsCyber (2026)Isms (n.d.)ISO ISO 42001 explained (n.d.)
- ISO/IEC 42001 is designed to certify management-system discipline rather than the correctness of individual AI outputs, so it works best as a governance baseline and weakest as a standalone proof of technical safety or legal sufficiencyISO (2023)Cloudsecurityalliance (n.d.)Deloitte (2025)Oetsch (2024)
- Public adoption evidence since publication shows genuine market traction, because certification bodies, accreditation authorities, and large vendors have all stood up public ISO/IEC 42001 programmes or disclosures, but the evidence remains directional rather than census-gradeCouncil (2025)Societe (2025)Schellman (2026)Microsoft (2023)Systems (n.d.)International (n.d.)
- Enterprise and assurance-market sources present the standard positively, with Microsoft, Systems, Applications, and Products in Data Processing (SAP), Societe Generale de Surveillance (SGS), Klynveld Peat Marwick Goerdeler (KPMG), Schellman, Cloud Security Alliance, and Deloitte all framing it as a trust, auditability, and regulatory-readiness mechanismMicrosoft (2023)Systems (n.d.)Societe (2025)Switzerland (2025)Schellman (2026)Alliance (2026)Deloitte (2025)
- Regulator-facing and research-oriented sources treat ISO/IEC 42001 as necessary but not sufficient, because they pair it with accreditation rules, impact-assessment methods, or additional technical criteria rather than relying on certification aloneISO (2025)Council (2025)Bundesamt (n.d.)Bogucka et al. (2024)Oetsch (2024)
- SC 42 was established in 2017, ISO/IEC 42001 was published in 2023, and ISO/IEC 42006 followed in 2025, while public companion-standard evidence shows the ecosystem continuing to expand around certification and impact governanceISO (n.d.)ISO (2023)ISO (2025)Registro (2024)
Research Question
What is International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 for an Artificial Intelligence Management System (AIMS), and which specific controls in Annex A and the main body mitigate key Artificial Intelligence (AI) risks? How widely has the standard been adopted and certified since publication, how is it perceived by enterprises, regulators, certification bodies, and AI ethics experts, and what development milestones, amendments, and planned revisions define its evolution?
Findings
Executive Summary
ISO/IEC 42001:2023 is a useful but incomplete governance baseline for organisational AI, because it converts AI risk, lifecycle, accountability, and stakeholder-information duties into a certifiable management system without certifying model outputs themselves. Publicly accessible material shows a main-body structure centred on leadership, planning, support, operation, performance evaluation, and improvement, plus an Annex A catalogue of 38 controls across nine objectives that collectively target impact assessment, lifecycle governance, data quality, transparency, intended use, and third-party accountability. Adoption and certification activity are real but still early: accreditation programmes and certification-body rules have matured quickly, and major vendors such as Microsoft and Systems, Applications, and Products in Data Processing (SAP) now publicise ISO/IEC 42001 coverage, yet accessible public evidence does not support a simple global count of certified organisations. The standard's reputation is strongest as an auditable due-diligence and procurement signal, while expert and regulator-oriented sources still treat it as a foundation that needs technical, legal, and sector-specific overlays.
Key Findings
- ISO/IEC 42001:2023 is the first certifiable international management-system standard dedicated to organisational AI governance, and its public clause structure centres on context, leadership, planning, support, operation, performance evaluation, and continual improvement.
- Publicly accessible mappings indicate that Annex A contains 38 controls in nine objectives, A.2 through A.10, covering policy, internal organisation, resources, impact assessment, lifecycle, data, information for interested parties, responsible use, and third-party relationships.
- The standard's most important public risk mitigations are impact assessment, lifecycle verification and validation, event logging, data provenance and quality controls, user and regulator information duties, intended-use constraints, and supplier-accountability controls.
- ISO/IEC 42001 is designed to certify management-system discipline rather than the correctness of individual AI outputs, so it works best as a governance baseline and weakest as a standalone proof of technical safety or legal sufficiency.
- Public adoption evidence since publication shows genuine market traction, because certification bodies, accreditation authorities, and large vendors have all stood up public ISO/IEC 42001 programmes or disclosures, but the evidence remains directional rather than census-grade.
- Enterprise and assurance-market sources present the standard positively, with Microsoft, Systems, Applications, and Products in Data Processing (SAP), Societe Generale de Surveillance (SGS), Klynveld Peat Marwick Goerdeler (KPMG), Schellman, Cloud Security Alliance, and Deloitte all framing it as a trust, auditability, and regulatory-readiness mechanism.
- Regulator-facing and research-oriented sources treat ISO/IEC 42001 as necessary but not sufficient, because they pair it with accreditation rules, impact-assessment methods, or additional technical criteria rather than relying on certification alone.
- SC 42 was established in 2017, ISO/IEC 42001 was published in 2023, and ISO/IEC 42006 followed in 2025, while public companion-standard evidence shows the ecosystem continuing to expand around certification and impact governance.
Assumptions
- Assumption: Publicly announced certificates represent a floor rather than a full count of adoption. Justification: the available public verification infrastructure is built for validation, and ISO states that certification is voluntary and handled by independent certification bodies.
Analysis
The evidence supports a narrow conclusion rather than a sweeping one. ISO's own materials clearly establish what the standard is for and how it is positioned, while secondary public breakdowns make the control catalogue visible enough to map the dominant risk families even though the full wording is paywalled. The central trade-off is between breadth and precision, because ISO/IEC 42001 gives organisations a repeatable, auditable management framework but does not by itself answer whether a particular model is robust, lawful, or safe in a specific deployment context. That interpretation is consistent with prior repository work showing that principle-level governance standards still need technical controls and runtime evidence to control real AI deployment risk. A rival interpretation is that certification could become a de facto substitute for deeper review in procurement or regulation, but the consulted regulator-facing and research sources do not support that stronger reading because they consistently add accreditation, impact-assessment, or sector-specific criteria on top of the management-system baseline.
Risks, Gaps, and Uncertainties
- Annex A control numbering and wording in this item rely on public secondary summaries rather than the licensed full standard text.
- The consulted public sources do not expose a simple authoritative global count of ISO/IEC 42001-certified organisations.
- Public ISO pages give publication metadata and high-level summaries, but not enough full-text detail to evaluate every clause-level implementation nuance.
- Publicly accessible evolution evidence is strongest for ISO/IEC 42006 and ISO/IEC 42005 packaging, so this item treats broader companion-guidance claims conservatively.
Open Questions
- How many organisations have achieved accredited ISO/IEC 42001 certification by region and sector, once a transparent public registry or market dataset becomes available?
- Which technical overlays are becoming the most common complements to ISO/IEC 42001 in high-risk sectors such as finance, health, and critical infrastructure?
- How quickly will accreditation bodies harmonise audit expectations now that ISO/IEC 42006 has been published?
sources
- [x] ISO ISO/IEC 42001:2023 Artificial intelligence management system
- [x] ISO ISO 42001 explained: what it is
- [x] ISO Joint Technical Committee 1/Subcommittee 42 (JTC 1/SC 42) Artificial intelligence committee page
- [x] ISO ISO/IEC 42006:2025 Requirements for bodies providing audit and certification of artificial intelligence management systems
- [x] Microsoft (2025) Overview of ISO/IEC 42001 and AI system conformity assessment
- [x] Mindset Cyber (2026) ISO 42001 Annex A Controls: Complete List and Implementation Guide
- [x] ISMS.online ISO 42001 Annex A Controls
- [x] National Institute of Standards and Technology (NIST) (2023) Artificial Intelligence Risk Management Framework (AI RMF 1.0)
- [x] Systems, Applications, and Products in Data Processing (SAP) Trust Center Certifications and Compliance
- [x] Microsoft Learn ISO/IEC 42001:2023 overview
- [x] Societe Generale de Surveillance (SGS) (2025) ISO/IEC 42001: Trustworthy Certification in the Age of AI
- [x] Singapore Accreditation Council (2025) Launch of ISO/IEC 42001 Artificial Intelligence Management Systems accreditation programme
- [x] Registro Italiano Navale (RINA) (2024) Supplementary appendix: ISO/IEC 42001
- [x] Klynveld Peat Marwick Goerdeler (KPMG) Switzerland (2025) ISO/IEC 42001 Certification: The Global Standard for AI Management Systems
- [x] Schellman and risk3sixty (2026) Lessons Learned from Auditing and Implementing ISO 42001
- [x] Cloud Security Alliance (2026) Understanding ISO 42001: Responsible AI Governance in an Evolving Regulatory Landscape
- [x] Deloitte (2025) Navigating AI assurance: spotlight on ISO/IEC 42001
- [x] Bundesamt fuer Sicherheit in der Informationstechnik (BSI) Criteria Catalogue for AI Cloud Services (AIC4)
- [x] International Accreditation Forum (IAF) CertSearch Search Certified Entities
- [x] Oetsch (2024) Interplay of Information Security Management Systems and Artificial Intelligence Management Systems in context of the European Union Artificial Intelligence Act
- [x] Bogucka et al. (2024) Co-designing an AI Impact Assessment Report Template with AI Practitioners and AI Compliance Experts
- [x] Mitchell (2026) Data Governance Standards and Regulations Applied to Artificial Intelligence Systems and Multi-Step Autonomous AI Deployments
Identified but not consulted
| version | date | commit | summary |
|---|---|---|---|
| 1.0 | 2026-05-12 | aaa167d | Initial completion |