ISO 42001: The New Global Standard For AI Governance

Two men in an office looking at a computer monitor, with one seated and pointing at the screen while the other leans over the desk.

Artificial intelligence is now embedded in everyday business processes, often faster than governance frameworks can keep pace. As AI adoption accelerates across sectors, organizations are increasingly being asked to demonstrate how AI is governed, controlled and assured.

ISO/IEC 42001 is the world’s first international management system standard specifically focused on artificial intelligence governance. It provides a structured, auditable framework for managing AI risks, impacts and responsibilities across the full AI lifecycle, helping organizations move from informal or fragmented AI use to demonstrable assurance. 

In January 2026, NQA (a Kiwa company) was granted UKAS accreditation for the certification of ISO/IEC 42001, enabling organizations to achieve accredited, independently verified certification to this emerging and increasingly important standard.

Why ISO/IEC 42001 matters now 

AI is no longer a future consideration. It is already shaping how organizations analyze data, make decisions, interact with customers and manage risk. One of the most consistent challenges seen across organizations is the prevalence of so-called shadow AI, where AI tools or features are adopted informally by teams without central oversight.

ISO/IEC 42001 exists to address a practical and increasingly urgent question: How can organizations govern AI in a way that is structured, repeatable and credible, without needing to inspect algorithms or source code?

The standard provides a framework to:

  • identify where and how AI is used
  • assess risks and real-world impacts
  • define accountability, oversight and controls
  • embed competence and awareness across relevant roles
  • demonstrate responsible AI practices to customers, regulators and other interested parties

ISO/IEC 42001 is a management system standard, not a technical specification. Its focus is on governance, decision-making, lifecycle control and continual improvement, rather than on the internal mechanics of AI models.

What is ISO/IEC 42001? 

ISO/IEC 42001 sets out the requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System, often referred to as an AIMS.

It applies to organizations that develop AI systems, deploy AI-enabled services, or use AI within their operations. The structure aligns with other modern ISO management system standards, supporting integration with existing governance frameworks such as quality, information security or environmental management.

For organizations already operating an integrated management system, this alignment can significantly reduce duplication while strengthening overall governance.

Digital infrastructure

ISO/IEC 42001 and the EU AI Act

A common question from organizations exploring ISO/IEC 42001 is how it relates to the EU AI Act.

The two serve different but complementary purposes. The EU AI Act is legislation, introducing legal obligations based on the level of risk associated with AI use cases and the role an organization plays, such as provider or deployer. ISO/IEC 42001 is a governance framework that helps organizations identify regulatory obligations, manage risks and demonstrate oversight over time.

The EU AI Act entered into force in August 2024 and becomes fully applicable from August 2026, with phased requirements before and after that date. For organizations operating in, or supplying into, EU markets, ISO/IEC 42001 provides a structured and auditable foundation that supports regulatory readiness and ongoing compliance.

Key themes emerging from AI governance in practice 

Across organizations exploring or implementing ISO/IEC 42001, several consistent themes are emerging.

You cannot govern what you cannot see 

Many organizations begin with an AI policy but quickly discover that policies alone do not reveal where AI is already in use. Effective AI governance starts with honest discovery, identifying tools, use cases and data flows across the organization.

This typically involves mapping AI use by function, understanding what information is shared with which tools, and making informed decisions about approved and restricted technologies.

Designed for integration, not isolation 

ISO/IEC 42001 aligns with the structure of other ISO management system standards, enabling AI governance to be embedded into existing controls rather than managed separately. In practice, AI governance frequently overlaps with information security, supplier management, quality assurance and lifecycle-based risk thinking.

Supplier and contractual risk must be actively managed 

AI services evolve quickly, including changes to functionality, data handling and contractual terms. ISO/IEC 42001 requires organizations to actively manage supplier relationships and monitor changes over time, rather than treating AI procurement as a one-time decision. 

Impact assessment is central 

A defining feature of ISO/IEC 42001 is the requirement to assess AI impacts. Understanding who may be affected by AI systems, how harm could arise and what oversight is required is essential. Organizations that approach impact assessment seriously often find that risk management and control selection become clearer and more effective. 

Competence and oversight are critical 

AI governance depends on people as much as technology. Organizations must be able to demonstrate that relevant roles are competent to manage AI responsibly. This includes defining competence requirements, providing appropriate training or awareness, and establishing clear routes for raising concerns or incidents related to AI use.

Building trust through accredited certification 

As demand for AI assurance grows, confidence depends on credible, consistent certification. ISO/IEC 42006 sets additional requirements for bodies certifying AI management systems, supporting rigor and consistency in how ISO/IEC 42001 is audited and certified.

Who Should Consider ISO/IEC 42001?

ISO/IEC 42001 is relevant for organizations that:

  • develop, deploy or use AI systems
  • need to demonstrate trustworthy and responsible AI practices
  • operate in markets affected by emerging AI regulation
  • want structured governance as AI use scales

It is particularly valuable where AI influences decisions, outcomes, safety, compliance or reputation.

Source: This article was originally published by NQA, part of the Kiwa Group, and has been republished as part of the Why Trust Matters campaign. For the latest version and related resources, view the original article on the NQA website.

Ready to move forward?

Taking the next step towards ISO/IEC 42001 certification

As expectations around AI governance continue to rise, many organisations are moving from exploration to implementation, and increasingly towards accredited certification.

Those ready to move forward can request a quote about certification scope and next steps.

Kiwa