Key takeaways
- ISO/IEC 42001 is the first international management system standard for artificial intelligence, published in December 2023.
- It is built on the same harmonised structure as ISO 9001, 14001, 45001 and 27001, so it integrates rather than duplicates.
- Accredited certification became available after UKAS granted accreditation in January 2026.
- The EU AI Act became fully applicable on 2 August 2026, with high-risk system enforcement already running since February 2026.
- For an organisation with a working ISO 27001 system, implementation typically runs six to nine months.
- This is a governance standard, not a technology standard. It asks who is accountable, not which model you used.
For most of the last decade, the honest answer to "how does your business govern its use of artificial intelligence" was that it did not. There was no framework to point at, no recognised way to demonstrate control, and no certificate anyone could ask for.
That has changed. ISO/IEC 42001, published in December 2023, is the first international management system standard for artificial intelligence. Accredited certification became available after UKAS granted accreditation in January 2026. And the EU AI Act became fully applicable on 2 August 2026, with enforcement for high-risk systems running since February.
The question is no longer whether AI governance becomes a formal requirement. It is how much work it will be when your customer asks.
What the standard actually asks for
ISO 42001 is a governance standard, not a technology standard. It does not tell you which model to use, what accuracy to reach, or how to build anything. It asks a much more uncomfortable set of questions.
Who is accountable when an AI system produces a decision that affects a person? How did you assess the risk before deploying it? What human oversight exists, and is it real oversight or a rubber stamp? How would you explain a decision to someone affected by it? What happens to the system across its lifecycle, as data drifts and the world changes around it? How do you know it is not producing biased outcomes?
These are the questions that arrive in a customer due-diligence questionnaire, and increasingly in a tender. The standard gives you a structured way to have answered them in advance.
How much of it you already have
This is the part that surprises people, and it is the practical reason ISO 42001 is far less daunting than it sounds.
ISO 42001 is written to the harmonised structure, the shared framework that governs how every modern ISO management system standard is written. Clause 4 is context. Clause 5 is leadership. Clause 6 is planning. Clause 7 is support. Clause 9 is performance evaluation. Clause 10 is improvement. They are the same clauses, in the same order, with much of the same core text, as the standards you may already run.
| Clause | What you already have from ISO 9001 or ISO 27001 | What ISO 42001 adds |
|---|---|---|
| 4. Context | Interested parties, scope, external and internal issues | Your role in the AI supply chain: are you a developer, provider or user? |
| 5. Leadership | Policy, roles, responsibilities and authorities | An AI policy, and named accountability for AI decisions |
| 6. Planning | Risk and opportunity, objectives | AI risk assessment and AI system impact assessment. This is the genuinely new work |
| 7. Support | Competence, awareness, communication, documented information | Competence in AI-specific risks, including bias and explainability |
| 8. Operation | Operational planning and control | Lifecycle controls: data quality, human oversight, monitoring after deployment |
| 9. Performance | Internal audit, management review, monitoring | The same mechanics, pointed at AI system performance and impact |
| 10. Improvement | Nonconformity and corrective action | The same mechanics, applied when an AI system behaves in a way it should not |
Read down the middle column. If your business runs a functioning quality or information security management system, you already operate roughly seventy percent of the skeleton. The work concentrated in clause 6, the AI risk and impact assessment, is the part that is genuinely new.
This is exactly what the harmonised structure was designed to do, and it is why an integrated management system pays for itself over time. Every new standard costs less than the one before it.
Why this is arriving now
Two forces are pushing in the same direction.
The first is regulatory. The EU AI Act became fully applicable on 2 August 2026, and obligations for high-risk systems have been enforceable since February. Its reach is not limited to European companies. It applies where an AI system is placed on the EU market or where its output is used within the EU. A South African manufacturer supplying a European customer, or a services business whose analysis is used in the EU, may be inside its scope without ever having considered the question.
The second is commercial, and it will reach most South African businesses sooner. Large customers have begun asking suppliers how they govern AI, in the same way they began asking about information security a decade ago. The first few times, an articulate answer is enough. Then it becomes a questionnaire, and then it becomes a certificate.
We have watched this pattern run before with ISO 27001. Businesses that treated the early questions as a nuisance ended up doing the work under deadline pressure, usually because a contract depended on it.
What this means for a South African business
Very few businesses in South Africa need ISO 42001 certification today. Rather more will need a defensible answer within two years, and the gap between those two positions is where sensible planning happens.
A reasonable sequence looks like this. Establish where AI is already being used in your business, which is usually more places than the executive team expects, because tools arrive through individual departments rather than through procurement. Decide who is accountable for those uses. Assess the risk of the ones that affect people, whether that is candidates, customers, or employees. Then decide whether certification is warranted, or whether a documented internal position is sufficient for now.
That sequence is useful even if you never certify, because it answers the customer question, and it prevents the more common failure, which is discovering that a business-critical decision has quietly been delegated to a tool nobody owns.
The wider point about digital systems
There is a pattern worth naming here. The management system model, the one that has governed quality since 1987 and information security since 2005, is being applied to each new area of organisational risk as it emerges. Environment. Occupational health and safety. Information security. Now artificial intelligence.
The model persists because it is not really about the subject matter. It is about a simple, durable idea: decide what good looks like, assign accountability, check whether you are achieving it, and correct when you are not. That works for a welding process and it works for a machine learning model.
Which is why the businesses that handle each new standard most easily are not the ones with the most technology. They are the ones whose existing systems are genuinely used, so there is something real to extend. A system that only exists in a binder cannot absorb a new standard, because there was never anything running to build on.
Where to start
If AI is already making or informing decisions in your business, the useful first step is an honest inventory of where, and who owns each one. That single document answers most early customer questions, and it tells you whether ISO 42001 is a near-term requirement or a two-year watching brief.
If you would like to think through where your business stands, or how ISO 42001 would sit alongside a management system you already run, contact us. We work across ISO 9001, 14001, 45001 and 27001 with businesses in South African industry, and the integration question is the one worth getting right before anyone starts writing procedures.
