ISO/IEC 42001 is the first international, certifiable standard for AI management systems (AIMS): a framework for governing how an organization develops, deploys and uses AI responsibly. It does for AI what ISO 27001 did for information security: turns good intentions into an auditable management system.
Key facts:
- Published in 2023, it follows the same management-system structure as ISO 27001, so organizations with an ISMS can extend rather than start over.
- It covers the AI lifecycle: policy, risk assessment, impact assessment, data governance, human oversight and continuous improvement.
- It is voluntary but increasingly cited in procurement as buyers look for proof of AI governance, and it aligns naturally with EU AI Act preparation.
What certification involves
An accredited body audits your AIMS: documented AI policy and objectives, an inventory of AI systems in scope, risk and impact assessments, controls over data and models, defined human oversight, and management review. As with ISO 27001, the certificate attests to the system of governance, not to any individual AI product being "safe".
The inventory problem, again
The standard's quiet assumption is that you know which AI systems you have. In organizations where employees adopt AI tools freely, the AIMS scope is incomplete on day one, and an auditor finding significant unmanaged AI use will treat it as a gap. Shadow AI discovery is therefore not adjacent to ISO 42001 work; it is step zero of it, and connects the AIMS to the broader AI governance function.
Where email security fits, honestly
Sentaro does not certify anyone. Its contribution is the live AI inventory that an AIMS scope depends on: Sentaro discovers AI service adoption and OAuth access continuously in Google Workspace and Microsoft 365, so the management system governs reality. The policies, assessments, oversight and audits remain organizational work.
This page is general guidance, not legal advice.