Atheros AIAtheros.AI
Reference · ISO/IEC 42001

ISO/IEC 42001, and the part no consultancy can sell you.

ISO/IEC 42001:2023 is the first AI management system standard an organisation can be certified against. This page covers what it actually requires — the clauses, the 38 Annex A controls, how it differs from the EU AI Act, and how long a real certification path takes.

Last reviewed 6 September 2026. Written by our ISO 42001 Lead Auditors. A summary of the standard, not a substitute for it.

Structure

Seven clauses, thirty-eight controls

The standard follows the Annex SL harmonised structure, which is why it interlocks with ISO 27001 and ISO 9001 rather than duplicating them. Clauses 4 to 10 carry the requirements; Annex A carries the controls you select from, and justify not selecting.

Cl. 4

Context of the organisation

Scope of the AIMS, the organisation's role in the AI value chain — provider, deployer or both — and the interested parties whose expectations bind it.

Cl. 5

Leadership

An AI policy, accountable ownership at the top, and roles with real authority rather than a nominated coordinator.

Cl. 6

Planning

AI risk assessment and treatment, the Annex A statement of applicability, and AI system impact assessment — the clause that reaches beyond the organisation to affected individuals.

Cl. 7

Support

Competence, awareness, communication and documented information. This is also where the AI Act's Article 4 literacy duty is discharged in practice.

Cl. 8

Operation

Running the risk, impact and lifecycle processes — where the standard stops being a document and starts producing records.

Cl. 9

Performance evaluation

Monitoring, measurement, internal audit and management review. Certification auditors ask for the outputs of this clause first.

Cl. 10

Improvement

Nonconformity handling, corrective action and continual improvement.

Annex A groups 38 controls under nine objectives: AI policies, internal organisation, resources for AI systems, assessing the impact of AI systems, the AI system lifecycle, data for AI systems, information for interested parties, responsible use, and third-party and customer relationships. Annex B gives implementation guidance, Annex C catalogues AI-related objectives and risk sources, and Annex D covers sector-specific application.

Comparison

ISO 42001 or the EU AI Act — which one are you actually being asked about?

These get conflated in almost every first meeting. They are different instruments doing different jobs, and only one of them is optional.

EU AI ActISO/IEC 42001
What is it?Binding EU law — Regulation (EU) 2024/1689.A voluntary international standard.
What does it govern?Specific AI systems, by risk tier and intended purpose.The organisation's management system for AI as a whole.
Who has to follow it?Providers, deployers, importers and distributors in scope of Article 2 — no opt-out.Any organisation that chooses to, at any scale.
What proves it?Conformity assessment, an EU declaration of conformity and CE marking for high-risk systems.A certificate issued by an accredited certification body after a Stage 1 and Stage 2 audit.
What happens if you ignore it?Administrative fines up to €35 million or 7% of worldwide turnover.No penalty. You lose the certificate, and the commercial access that depends on it.
Does one satisfy the other?No. A certificate is not compliance.No — but a working AIMS produces most of the evidence the Act demands, and covers the Article 17 quality management system.

The obligation side is set out in full on the EU AI Act reference.

Path

A certification path with honest durations

The step nobody quotes is step three. Several clauses require records of the system operating over a period, and no amount of consulting compresses elapsed time — which is why "certified in 90 days" offers should be read carefully.

01

Gap assessment

3–5 weeks

Your current state against all seven clauses and the 38 Annex A controls, with the findings ranked by how long they take to remediate rather than by severity — because evidence-over-time findings dictate the certification date.

02

AIMS design

6–10 weeks

AI policy, governance roles, risk and impact assessment methodology, the statement of applicability, and the control library mapped to your existing ISO 27001 or 9001 system where one exists.

03

Operate and evidence

3–6 months

The system runs and produces records: risk assessments, impact assessments, lifecycle controls, supplier reviews. Nothing here can be compressed — auditors ask for records over a period, not a folder created last week.

04

Internal audit and management review

2–4 weeks

A full internal audit against the standard and a documented management review. Clause 9 outputs are the first thing a Stage 1 auditor reads.

05

Certification audit

Set by the body

The accredited certification body runs Stage 1 (documentation and readiness) and Stage 2 (implementation). We prepare the evidence pack and support the audit; we do not, and cannot, sit on the certification side.

Who issues the certificate. Not us. Under ISO/IEC 17021 the body that certifies a management system must be independent of the body that built it. Atheros AI prepares you for the audit; an accredited certification body performs it. Any consultancy offering to do both is describing something that would not survive an accreditation review.

FAQ

ISO 42001, asked plainly

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the international standard for an artificial intelligence management system, published in December 2023. It is the first AI standard that an organisation can be certified against. It specifies requirements for establishing, implementing, maintaining and continually improving an AIMS — the governance structure, roles, risk and impact assessments, and lifecycle controls through which an organisation manages its use and development of AI.

Is ISO 42001 certification mandatory under the EU AI Act?

No. ISO/IEC 42001 is a voluntary standard and holding the certificate is not itself compliance with Regulation (EU) 2024/1689. The two work together: the AI Act imposes binding, system-level obligations for specific risk tiers, while ISO 42001 gives you the organisation-level management system that produces and maintains the evidence those obligations require. A certified AIMS makes the Article 17 quality management system substantially easier to demonstrate.

Can Atheros AI issue our ISO 42001 certificate?

No, and no consultancy can. Under ISO/IEC 17021 the body that certifies a management system must be independent of the body that designed or implemented it, and certificates are issued only by certification bodies accredited for the scheme. Atheros AI prepares organisations for that audit — gap assessment, AIMS design, internal audit and management review — and the accredited body performs the certification audit.

How long does ISO 42001 certification take?

For an organisation that already runs a certified ISO 27001 or ISO 9001 management system, six to nine months from gap assessment to Stage 2 audit is realistic, because the shared Annex SL clauses are already in place. Starting from no management system, nine to fifteen months is more typical. The dominant constraint is not documentation but evidence: several clauses require records of the system operating over time, and those records cannot be produced retrospectively.

What is in Annex A of ISO 42001?

Annex A lists 38 controls grouped under nine control objectives, covering AI policies, internal organisation and roles, resources for AI systems, assessment of AI system impacts, the AI system lifecycle, data for AI systems, information provided to interested parties, responsible use of AI systems, and third-party and customer relationships. Annex B gives implementation guidance for each control, Annex C catalogues AI-related objectives and risk sources, and Annex D covers applying the standard across domains and sectors.

How does ISO 42001 relate to ISO 27001?

Both follow the Annex SL harmonised structure, so clauses 4 to 10 — context, leadership, planning, support, operation, performance evaluation and improvement — are structurally the same and can share the same governance body, internal audit programme and management review. The difference is scope: ISO 27001 manages information security risk to the organisation, while ISO 42001 manages AI risk, including impacts on individuals and society that a purely security-focused system does not consider.

Start with the gap assessment, not the certificate.

Our Lead Auditors run your current state against all seven clauses and the 38 controls, and give you a dated plan to a realistic audit window.