Unlike the NIST AI RMF, a voluntary management framework with no certification, ISO/IEC 42001:2023 does allow a third-party audit that ends in a formal certificate. That makes it the more credible option in front of clients and partners when you need to demonstrate, not just declare, that you have an operational AI management system (AIMS).

The blocks the auditor evaluates

ClauseWhat it requiresTypical evidence
4. Context of the organizationIdentify interested parties and the AIMS scopeAIMS scope document
5. LeadershipManagement commitment, AI policy and assigned rolesSigned AI policy, role organization chart
6. PlanningRisk assessment and measurable AI objectivesRisk register, objectives with KPI and deadline
7. SupportResources, competencies and communicationTraining plan, competency matrix
8. OperationOperational controls over the AI system lifecycleDevelopment procedures, impact assessments
9. Performance evaluationInternal audits and management reviewInternal audit minutes, review minutes
10. ImprovementNonconformity management and continuous improvementNonconformity and corrective action register

Annex A: the AI-specific controls

Beyond the structure common to other ISO standards (42001 follows the high-level structure, similar to ISO 27001), Annex A adds AI-specific controls: training data management, transparency toward users, impact assessment and management of third-party AI providers. This block overlaps most with the data quality dimensions and with AI Act Article 10 — if you already have that documented, you're well ahead on this part.

What most delays a certification: it's not the lack of technical controls, it's the lack of documentary evidence that the controls have been running for a while. An ISO 42001 auditor asks for history, not a snapshot from audit day.
Governance Audit Dashboard 10 KPIs in Excel referenced directly to AI Act Art. 10 and ISO 42001 — the continuous evidence auditors ask for, not a one-off snapshot. €69 VAT incl.
Buy →

Pre-flight checklist before contacting a certification body

  • Is there an AI policy signed by management, not just an internal draft?
  • Is there an AI risk register with at least one review already completed?
  • Has at least one internal AIMS audit been done before the external one?
  • Do the Annex A roles (who approves, who reviews, who documents) have a name attached, not just a generic title?

If you don't even have the governance foundation in place yet, start with the Data Governance Framework guide before thinking about certification — ISO 42001 builds on solid data governance, it doesn't replace it.