Unlike the NIST AI RMF, a voluntary management framework with no certification, ISO/IEC 42001:2023 does allow a third-party audit that ends in a formal certificate. That makes it the more credible option in front of clients and partners when you need to demonstrate, not just declare, that you have an operational AI management system (AIMS).
The blocks the auditor evaluates
| Clause | What it requires | Typical evidence |
|---|---|---|
| 4. Context of the organization | Identify interested parties and the AIMS scope | AIMS scope document |
| 5. Leadership | Management commitment, AI policy and assigned roles | Signed AI policy, role organization chart |
| 6. Planning | Risk assessment and measurable AI objectives | Risk register, objectives with KPI and deadline |
| 7. Support | Resources, competencies and communication | Training plan, competency matrix |
| 8. Operation | Operational controls over the AI system lifecycle | Development procedures, impact assessments |
| 9. Performance evaluation | Internal audits and management review | Internal audit minutes, review minutes |
| 10. Improvement | Nonconformity management and continuous improvement | Nonconformity and corrective action register |
Annex A: the AI-specific controls
Beyond the structure common to other ISO standards (42001 follows the high-level structure, similar to ISO 27001), Annex A adds AI-specific controls: training data management, transparency toward users, impact assessment and management of third-party AI providers. This block overlaps most with the data quality dimensions and with AI Act Article 10 — if you already have that documented, you're well ahead on this part.
Pre-flight checklist before contacting a certification body
- Is there an AI policy signed by management, not just an internal draft?
- Is there an AI risk register with at least one review already completed?
- Has at least one internal AIMS audit been done before the external one?
- Do the Annex A roles (who approves, who reviews, who documents) have a name attached, not just a generic title?
If you don't even have the governance foundation in place yet, start with the Data Governance Framework guide before thinking about certification — ISO 42001 builds on solid data governance, it doesn't replace it.