What is ISO/IEC 42001?
ISO/IEC 42001 is the international management-system standard for artificial intelligence. It
specifies requirements for establishing, implementing, maintaining and continually improving an AI
management system (AIMS) — governance roles, AI-specific risk and impact assessment, policies,
controls, and the records that show the system operates. It is structured like ISO/IEC 27001 and
ISO 9001, so an organization already running a certified management system will recognize the
shape of it.
How is ISO 42001 different from ISO 27001?
ISO 27001 governs information security — protecting the confidentiality, integrity and
availability of information. ISO 42001 governs the AI system itself, and asks questions security
standards do not: what the system is for, who it affects, how it was trained and on what data, how
outputs are monitored, and what happens when it behaves unexpectedly. It adds an AI impact assessment
covering effects on individuals and society, not just on the organization. The two overlap in
structure rather than in subject, which is why an existing ISMS is a head start rather than a
substitute.
Who is asking for ISO 42001?
Most commonly enterprise customers running vendor AI reviews, procurement teams that have added AI
questions to their security questionnaires, and organizations preparing for regulatory expectations
such as the EU AI Act. It is also used internally as a structure for governing AI a company already
deploys, without any certification goal — the standard is useful as a framework whether or not a
certificate follows.
Does Cyberneza certify us against ISO 42001?
No, and no consultancy can. Certification audits and certification decisions are performed by
independent accredited certification bodies, and the same firm cannot both prepare you and certify you
without compromising that independence. Cyberneza provides readiness, implementation, advisory and
coordination — defining scope, building the management system, running internal audits, and
preparing the evidence — and the certification body performs the audit.
Do we need ISO 42001 if we only use AI vendors rather than building models?
Possibly. The standard applies to organizations that provide or use AI systems, so a company that only
buys AI still has obligations around what it deploys, what data it exposes to those systems, and how
it oversees outputs. In practice the scope for an AI user is narrower than for an AI developer, and
settling that scope honestly is the first piece of work rather than something to assume in either
direction.
Where should we start if we do not know what AI we are running?
With discovery, because a management system cannot govern what nobody has inventoried. Shadow AI
— tools adopted by individual teams without review — is common and is usually where the
data-exposure risk sits. A Security Health Check or a scoped AI discovery pass establishes what is
actually in use before any decision about certification is worth making.
See AI risk and governance →