← Glossary

ISO 42001

ISO/IEC 42001 is the first international, certifiable standard for AI management systems, governing how organizations develop and use AI responsibly.

Updated

ISO/IEC 42001 is the first international, certifiable standard for AI management systems (AIMS): a framework for governing how an organization develops, deploys and uses AI responsibly. It does for AI what ISO 27001 did for information security: turns good intentions into an auditable management system.

Key facts:

  • Published in 2023, it follows the same management-system structure as ISO 27001, so organizations with an ISMS can extend rather than start over.
  • It covers the AI lifecycle: policy, risk assessment, impact assessment, data governance, human oversight and continuous improvement.
  • It is voluntary but increasingly cited in procurement as buyers look for proof of AI governance, and it aligns naturally with EU AI Act preparation.

What certification involves

An accredited body audits your AIMS: documented AI policy and objectives, an inventory of AI systems in scope, risk and impact assessments, controls over data and models, defined human oversight, and management review. As with ISO 27001, the certificate attests to the system of governance, not to any individual AI product being "safe".

The inventory problem, again

The standard's quiet assumption is that you know which AI systems you have. In organizations where employees adopt AI tools freely, the AIMS scope is incomplete on day one, and an auditor finding significant unmanaged AI use will treat it as a gap. Shadow AI discovery is therefore not adjacent to ISO 42001 work; it is step zero of it, and connects the AIMS to the broader AI governance function.

Where email security fits, honestly

Sentaro does not certify anyone. Its contribution is the live AI inventory that an AIMS scope depends on: Sentaro discovers AI service adoption and OAuth access continuously in Google Workspace and Microsoft 365, so the management system governs reality. The policies, assessments, oversight and audits remain organizational work.

This page is general guidance, not legal advice.

Questions we get asked.

What is ISO 42001 in simple terms?

A certifiable standard for how an organization governs its AI use and development: policies, risk assessments, oversight and improvement, audited like ISO 27001 but for AI.

Who should consider ISO 42001?

Organizations building AI products, and increasingly organizations whose AI use is significant enough that customers ask for proof of governance. It also structures EU AI Act readiness.

How does ISO 42001 relate to ISO 27001?

Same management-system skeleton, different subject: 27001 governs information security, 42001 governs AI. They share processes and can be audited in combination.

Do we need ISO 42001 to comply with the EU AI Act?

No, the Act does not require it, but an AIMS is a structured way to meet and evidence many of the Act's expectations, much as ISO 27001 supports NIS2 work without being mandated by it.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.