Glossary

ISO 42001

ISO 42001 is the AI counterpart to ISO 27001: it certifies a management system — an AIMS — governing how your organization develops, deploys, and uses AI. Risk assessment for AI systems, impact assessments, data governance for training and inference, human oversight, and the same plan-do-check-act loop that runs an ISMS.

Why it’s suddenly in questionnaires

Enterprise buyers adopted AI features faster than their procurement processes could evaluate them, and “are you ISO 42001 certified or aligned?” became the questionnaire shorthand for “prove your AI governance exists.” Regulatory pressure compounds it: the EU AI Act’s obligations map naturally onto an AIMS, making 42001 the anticipated compliance vehicle.

Who should actually pursue it

Companies whose product is AI selling into enterprises or regulated sectors — for them, early certification is real differentiation while the standard is young. Companies merely using AI internally usually need something lighter first: an AI use policy, a tool registry, DPIAs on AI features, and vendor AI-clause reviews.

The efficient build

If you run ISO 27001, the machinery transfers — same loop, new subject matter. The genuinely new work is the AI system inventory and impact assessments. Certification bodies began offering 42001 audits in 2024–2025; accreditation coverage is still maturing, so check the body’s credentials with extra care.

Related Terms

DPIA — A DPIA is GDPR's structured risk assessment for high-risk processing — increasingly triggered by AI features. What it covers and when you must run one.

EU AI Act — The EU AI Act regulates AI by risk tier — prohibited, high-risk, limited, minimal — with obligations phasing in through 2026–2027. What SaaS teams must do.

ISMS — An ISMS is the management system ISO 27001 certifies — the loop of risk assessment, controls, internal audit, and review that runs your security program.