KI FÜR MÜNCHEN AI adoption. Done right.

GOVERNANCE · 6 July 2026 · 8 min READ

ISO/IEC 42001 explained: What the standard demands of mid-sized companies

ISO/IEC 42001 is the first certifiable standard for AI management systems — and still a blank spot for most. What it contains, who needs certification and what building it realistically looks like.

“ISO 42001? Never heard of it.” That is the most common reaction when the standard comes up in conversation — and it is understandable: the standard is young, published at the end of 2023, and the market of consultants who genuinely know it is small. At the same time, pressure is building from two directions: the EU AI Act demands organised AI accountability, and the first OEMs and large corporates are beginning to ask about their suppliers’ AI management in supplier audits.

Time for a clear-headed overview: what ISO/IEC 42001 is, what it demands — and who genuinely needs certification.

What ISO 42001 is

The shortest explanation: what ISO 27001 is to information security, ISO/IEC 42001 is to artificial intelligence. It describes a management system — the AI management system, AIMS for short — through which an organisation governs its use of AI systematically: from policy through roles and risk assessment to monitoring and improvement.

Important to understand: the standard does not certify that your AI is “good” or “safe”. It certifies that your organisation manages AI responsibly — that rules exist, that someone is accountable, that risks are assessed and that lessons are learned from mistakes. That is precisely what customers, auditors and regulators want to see.

ISO 42001 follows the same basic structure as ISO 9001 and ISO 27001. Anyone already operating one of these management systems can integrate the AIMS rather than building a parallel system — in practice by far the most efficient route.

What the standard actually demands

Translated out of standards language, ISO 42001 essentially demands seven things:

1. Know where you stand. Context, interested parties, scope: what role does AI play in your organisation — user, developer, both? Which applications exist? Without this stocktake, everything that follows is theatre.

2. Leadership that owns it. An AI policy from top management, clear roles and responsibilities. The standard forces the answer that is missing in most companies: who is accountable for AI decisions?

3. Assess risks AND impacts. Alongside classic risk assessment, ISO 42001 requires an AI Impact Assessment: what consequences does the system have for the people affected by it — employees, customers, third parties? This outside perspective is the real innovation compared with older management standards.

4. Have the lifecycle under control. Requirements for the development, procurement, operation and decommissioning of AI systems — including data quality and documentation. Engineers will find this familiar: it is lifecycle thinking, as the V-model has exemplified for decades, applied to AI.

5. Include suppliers. Anyone sourcing AI from third parties — and today that is everyone — must assess their role and risks. The cloud provider, the foundation model, the purchased tool: all part of the system.

6. Measure and monitor. Does the system work? Are the rules actually followed? Internal audits and management reviews ensure the AIMS remains an operating system rather than becoming a ring binder.

7. Keep improving. Nonconformities, incidents, new models, new regulation — the AIMS learns as it goes. AI governance is not a project with an end date.

All of this is underpinned by a catalogue of concrete controls (Annex A) — from resource planning through data management to communication with affected parties — from which each organisation selects and justifies those applicable to it.

Does my company need certification?

Honest answer: Everyone needs the principles; not everyone needs the certificate.

Three scenarios argue for certification: you supply regulated industries or major customers who will demand evidence — whoever holds the certificate when the first tender asks for it wins. You build AI into your products — in which case the AIMS is the framework within which the provider obligations of the EU AI Act become manageable. Or you want the trust signal in the market while it still carries scarcity value.

If none of these scenarios applies, you do well to build the AIMS according to the principles of the standard — certification-ready, but without the audit. You save the cost of the certificate; you still have the substance. And you upgrade when the market demands it.

On the relationship with the EU AI Act: ISO 42001 certification is not an automatic proof of conformity under the regulation. But it is the management foundation on which the AI Act obligations — risk register, human oversight, documentation, training records — can be organised cleanly, rather than patched together as isolated measures.

What building it realistically looks like

The good news for mid-sized companies: building an AIMS is not a year-long project. Realistic — depending on maturity and scope — is weeks to a few months: stocktake and gap analysis first, then policy, roles and risk register, then the controls where the gaps are, with training of key roles in parallel. Anyone operating an ISO 27001 or 9001 docks onto existing processes and saves half the journey.

The most common mistake is the same as with any management system: building it for the auditor instead of for your own operations. An AIMS that consists only of documents falls apart at the first real incident. One that describes and governs the actual AI processes makes operations measurably calmer — the certificate is then a by-product.

We speak from twofold experience here: we ourselves work to the principles of ISO/IEC 42001 and 27001 — in an organisation that runs entirely AI-led — and support the build at client companies as a TÜV Süd certified AI Officer and AI Coordinator. Our own ISO/IEC 42001 certification is in preparation; for ISO/IEC 27001 we work to the principles of the standard without being certified ourselves. The first step is always the same and costs nothing: knowing where you stand.

This article was created with AI assistance and editorially reviewed under the responsibility of Stephan Walkowiak. See our AI transparency statement for details.

NEXT STEP

Apply this to your company?

In an initial consultation we discuss what this topic looks like in your specific case — honestly, even if the answer is "not yet".