1ST
The first AI governance standard
Published December 2023, ISO 42001 is the world's first international AI management system standard — the credential procurement teams are starting to require.
ISO 42001 is the world's first AI management system standard — and fast becoming the credential enterprise buyers ask for before they'll trust your AI. It's an independently certified governance program built on 38 AI controls, and the strongest foundation for the EU AI Act. We build the system and the certification.
Book an ISO 42001 Strategy Call →// WHY ISO 42001, WHY NOW
1ST
Published December 2023, ISO 42001 is the world's first international AI management system standard — the credential procurement teams are starting to require.
38
Across nine areas and four operational domains, selected through a Statement of Applicability — with the AI Impact Assessment as the substantive core.
EU AI ACT
Its 38 controls map onto many high-risk EU AI Act requirements. ISO 42001 is the governance backbone — a strong start toward the Act, though not legal compliance by itself.
// A POLICY ISN'T A SYSTEM
A policy on a page isn't governance a buyer can verify. ISO 42001 certifies an AI management system: an AI inventory, an AI Impact Assessment that weighs societal and ethical risk, lifecycle and data-governance controls, human-oversight mechanisms, and a Statement of Applicability — all independently audited and continually improved. The difference between "we have an AI policy" and a certified AIMS is the difference between a claim and third-party-validated proof that survives an enterprise security review.
// THE FOUR ANNEX A CONTROL DOMAINS
Annex A's 38 controls group into four operational domains. AI System Lifecycle & Risk is the substantive core — the AI Impact Assessment and responsible-AI work that justify a separate standard. The other three are the management-system foundation it sits on.
The reason ISO 42001 exists apart from ISO 27001: the AI Impact Assessment, AI lifecycle management, and AI risk treatment, plus the responsible-AI principles — bias, explainability, human oversight, model drift, fundamental rights. The three domains below provide the governance scaffolding; this is the AI-specific substance the rest exists to support.
// CONTEXT & LEADERSHIP
Organizational Context
AI policy committed by leadership, defined AI roles, and how AI fits your risk landscape.
// RESOURCES & DATA
Data Governance
Compute, data, human, and supplier resources; data quality, lineage, and training-data governance.
// OPERATIONS & IMPROVEMENT
Operations
Transparency to interested parties, responsible-use guidance, and third-party AI relationships.
Controls are risk-selected via a Statement of Applicability — scope decides what applies.
// THE PATH
The familiar ISO management-system path — if you've done ISO 27001, it'll feel recognizable. The amber stages are where the accredited certification body enters: the Stage 1 and Stage 2 audits.
Scope
AI Inventory & Context
WK 1–4
Build
AIMS + Impact Assessment
MO 1–3
Implement
Annex A + Internal Audit
MO 3–7
Stage 1
Documentation Audit
MO 7–8
Stage 2
Implementation Audit
MO 8–10
Sustain
Surveillance & Recert
Y1 / Y2 / Y3
Amber stages are where the accredited certification body enters — the Stage 1 documentation audit and Stage 2 implementation audit. Certification runs on a three-year cycle: annual surveillance, full recertification in year three.
// IS THIS YOU?
// 01 // BUYER ASK
Enterprise security reviews now include AI-governance questions you can't answer with a policy doc. An ISO 42001 certificate is the credible answer that unblocks the deal.
// 02 // YOU SHIP AI
If AI is in your product or workflows, you carry risks — bias, drift, explainability, data lineage — that no security framework covers. ISO 42001 is built for exactly that.
// 03 // EU AI ACT
You sell into the EU or expect to. ISO 42001 is the governance foundation its high-risk requirements map onto — build it first, then gap-map to the Act.
// WHAT WE DO
// Phase 01 · Scope
We inventory your AI systems and AI-enabled features, define the AIMS boundary, and run a gap analysis against the 38 Annex A controls — the decision that shapes everything after it.
// Phase 02 · Build
We build the management system and the AI Impact Assessment, then implement your selected Annex A controls across lifecycle, data, and operations — ready for audit, not just on paper.
// Phase 03 · Certify
We carry you through Stage 1 and Stage 2 audits to certification, sustain the program, and gap-map your controls to the EU AI Act where it applies to you.
// AI GOVERNANCE IS A BUYING CRITERION NOW
// FREQUENTLY ASKED
ISO/IEC 42001:2023, published December 2023, is the world's first international standard for an AI management system (AIMS) — how an organization establishes, maintains, and improves the governance around how it builds and uses AI. It's becoming the credential enterprise customers and procurement teams ask for as evidence you govern AI responsibly.
The reason to certify is usually commercial before regulatory: an accredited certification is independent, third-party proof of AI governance maturity that shortens vendor reviews and differentiates you in deals where buyers are nervous about AI risk. Because it follows the same Annex SL structure as ISO 27001, it integrates with an existing ISMS rather than standing up a separate program.
No — and the distinction matters. The EU AI Act is a law; for in-scope organizations its obligations are a legal requirement. ISO 42001 is a voluntary management-system certification — a governance maturity and commercial signal. They're complementary but not interchangeable, and you should never represent the certification to customers or regulators as EU AI Act compliance.
That said, it's the strongest practical foundation: there's substantial overlap between its 38 Annex A controls and the Act's high-risk requirements, and several core articles have direct counterparts. Build the AIMS first as the backbone, then classify your AI against the Act's risk tiers and gap-analyze anything high-risk. Note the Act's high-risk timelines are still moving — a simplification package is under consideration — so we treat regulatory dates as current-but-subject-to-change and keep the program anchored on durable governance.
Less than you'd fear, because the two share the same Annex SL backbone — context, leadership, planning, support, operation, performance evaluation, improvement — so the management-system machinery from ISO 27001 (governance, internal audit, management review, document control, corrective action) carries over to the AIMS.
What's genuinely new is the AI-specific substance in Annex A: an AI policy and roles, an AI system inventory, the AI Impact Assessment that evaluates societal and ethical risk rather than just security, AI lifecycle management, data and training-data governance, and responsible-AI principles like bias, explainability, human oversight, and drift. Mature ISO 27001 programs reuse the management layer and focus effort on the AI risk and lifecycle domain — exactly where the standard earns its separate existence. We scope to leverage what you have rather than rebuild it.
It follows the familiar ISO management-system path. You scope the AIMS and inventory your AI systems; build the management system and AI Impact Assessment; implement your selected Annex A controls and run an internal audit; then an accredited certification body conducts a Stage 1 documentation audit and a Stage 2 implementation audit. Passing Stage 2 yields certification, maintained over a three-year cycle with annual surveillance and recertification in year three.
A first certification commonly takes on the order of ten to twelve months depending on governance maturity and how many AI systems are in scope; organizations with a strong existing management system move faster. As with every ISO standard, the biggest determinant of timeline is scope and the quality of your documentation and evidence — which is where readiness work pays off before the certification body arrives.
// THE NEXT MOVE
Book a 30-minute ISO 42001 strategy call with a WatchUr6 advisor. Bring how you use or build AI, whether customers are asking about AI governance, whether you hold ISO 27001, and whether the EU AI Act is in play. You'll walk away with a scoped AIMS plan, an honest read on your readiness, and a realistic path to certification — whether you hire us or not.
Book an ISO 42001 Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED