Home · Insights · Digital

ISO 42001: the management system standard for artificial intelligence

Artificial intelligence now has a certifiable management system standard of its own. If you already run ISO 9001 or ISO 27001, you own more of it than you think.

Key takeaways

  • ISO/IEC 42001 is the first international management system standard for artificial intelligence, published in December 2023.
  • It is built on the same harmonised structure as ISO 9001, 14001, 45001 and 27001, so it integrates rather than duplicates.
  • Accredited certification became available after UKAS granted accreditation in January 2026.
  • The EU AI Act became fully applicable on 2 August 2026, with high-risk system enforcement already running since February 2026.
  • For an organisation with a working ISO 27001 system, implementation typically runs six to nine months.
  • This is a governance standard, not a technology standard. It asks who is accountable, not which model you used.

For most of the last decade, the honest answer to "how does your business govern its use of artificial intelligence" was that it did not. There was no framework to point at, no recognised way to demonstrate control, and no certificate anyone could ask for.

That has changed. ISO/IEC 42001, published in December 2023, is the first international management system standard for artificial intelligence. Accredited certification became available after UKAS granted accreditation in January 2026. And the EU AI Act became fully applicable on 2 August 2026, with enforcement for high-risk systems running since February.

The question is no longer whether AI governance becomes a formal requirement. It is how much work it will be when your customer asks.

What the standard actually asks for

ISO 42001 is a governance standard, not a technology standard. It does not tell you which model to use, what accuracy to reach, or how to build anything. It asks a much more uncomfortable set of questions.

Who is accountable when an AI system produces a decision that affects a person? How did you assess the risk before deploying it? What human oversight exists, and is it real oversight or a rubber stamp? How would you explain a decision to someone affected by it? What happens to the system across its lifecycle, as data drifts and the world changes around it? How do you know it is not producing biased outcomes?

These are the questions that arrive in a customer due-diligence questionnaire, and increasingly in a tender. The standard gives you a structured way to have answered them in advance.

How much of it you already have

This is the part that surprises people, and it is the practical reason ISO 42001 is far less daunting than it sounds.

ISO 42001 is written to the harmonised structure, the shared framework that governs how every modern ISO management system standard is written. Clause 4 is context. Clause 5 is leadership. Clause 6 is planning. Clause 7 is support. Clause 9 is performance evaluation. Clause 10 is improvement. They are the same clauses, in the same order, with much of the same core text, as the standards you may already run.

ClauseWhat you already have from ISO 9001 or ISO 27001What ISO 42001 adds
4. ContextInterested parties, scope, external and internal issuesYour role in the AI supply chain: are you a developer, provider or user?
5. LeadershipPolicy, roles, responsibilities and authoritiesAn AI policy, and named accountability for AI decisions
6. PlanningRisk and opportunity, objectivesAI risk assessment and AI system impact assessment. This is the genuinely new work
7. SupportCompetence, awareness, communication, documented informationCompetence in AI-specific risks, including bias and explainability
8. OperationOperational planning and controlLifecycle controls: data quality, human oversight, monitoring after deployment
9. PerformanceInternal audit, management review, monitoringThe same mechanics, pointed at AI system performance and impact
10. ImprovementNonconformity and corrective actionThe same mechanics, applied when an AI system behaves in a way it should not

Read down the middle column. If your business runs a functioning quality or information security management system, you already operate roughly seventy percent of the skeleton. The work concentrated in clause 6, the AI risk and impact assessment, is the part that is genuinely new.

This is exactly what the harmonised structure was designed to do, and it is why an integrated management system pays for itself over time. Every new standard costs less than the one before it.

Why this is arriving now

Two forces are pushing in the same direction.

The first is regulatory. The EU AI Act became fully applicable on 2 August 2026, and obligations for high-risk systems have been enforceable since February. Its reach is not limited to European companies. It applies where an AI system is placed on the EU market or where its output is used within the EU. A South African manufacturer supplying a European customer, or a services business whose analysis is used in the EU, may be inside its scope without ever having considered the question.

The second is commercial, and it will reach most South African businesses sooner. Large customers have begun asking suppliers how they govern AI, in the same way they began asking about information security a decade ago. The first few times, an articulate answer is enough. Then it becomes a questionnaire, and then it becomes a certificate.

We have watched this pattern run before with ISO 27001. Businesses that treated the early questions as a nuisance ended up doing the work under deadline pressure, usually because a contract depended on it.

What this means for a South African business

Very few businesses in South Africa need ISO 42001 certification today. Rather more will need a defensible answer within two years, and the gap between those two positions is where sensible planning happens.

A reasonable sequence looks like this. Establish where AI is already being used in your business, which is usually more places than the executive team expects, because tools arrive through individual departments rather than through procurement. Decide who is accountable for those uses. Assess the risk of the ones that affect people, whether that is candidates, customers, or employees. Then decide whether certification is warranted, or whether a documented internal position is sufficient for now.

That sequence is useful even if you never certify, because it answers the customer question, and it prevents the more common failure, which is discovering that a business-critical decision has quietly been delegated to a tool nobody owns.

The wider point about digital systems

There is a pattern worth naming here. The management system model, the one that has governed quality since 1987 and information security since 2005, is being applied to each new area of organisational risk as it emerges. Environment. Occupational health and safety. Information security. Now artificial intelligence.

The model persists because it is not really about the subject matter. It is about a simple, durable idea: decide what good looks like, assign accountability, check whether you are achieving it, and correct when you are not. That works for a welding process and it works for a machine learning model.

Which is why the businesses that handle each new standard most easily are not the ones with the most technology. They are the ones whose existing systems are genuinely used, so there is something real to extend. A system that only exists in a binder cannot absorb a new standard, because there was never anything running to build on.

Where to start

If AI is already making or informing decisions in your business, the useful first step is an honest inventory of where, and who owns each one. That single document answers most early customer questions, and it tells you whether ISO 42001 is a near-term requirement or a two-year watching brief.

If you would like to think through where your business stands, or how ISO 42001 would sit alongside a management system you already run, contact us. We work across ISO 9001, 14001, 45001 and 27001 with businesses in South African industry, and the integration question is the one worth getting right before anyone starts writing procedures.

Frequently asked questions

What is ISO/IEC 42001?
It is the first international management system standard for artificial intelligence, published in December 2023. It sets out how an organisation should govern its use and development of AI: accountability, risk assessment, human oversight, bias, explainability and lifecycle management. It is certifiable, in the same way ISO 9001 is.
Can you actually get certified to it?
Yes. Accredited certification became available after UKAS granted accreditation in January 2026, so certificates issued under that accreditation carry the same chain of accountability as any other accredited ISO certificate.
Does this apply to us if we are not an AI company?
Almost certainly yes, if you use AI at all. The standard covers organisations that use AI systems, not only those that build them. If AI touches recruitment, credit decisions, customer service, quality inspection or safety monitoring in your business, it is in scope.
Does the EU AI Act affect a South African business?
It can. The Act reaches organisations whose AI systems are placed on the EU market or whose outputs are used in the EU, regardless of where the organisation sits. If you export, serve EU customers, or supply a business that does, it is worth establishing your position.
How much of it do we already have?
More than you would expect. ISO 42001 follows the harmonised structure, so context, leadership, planning, competence, internal audit, management review and improvement are the same clauses you already operate under ISO 9001 or ISO 27001. What is genuinely new is the AI-specific risk and impact assessment.
How long does implementation take?
For a mid-size organisation with an existing ISO 27001 information security management system, roughly six to nine months to implement, and longer to reach a first external certification audit. Starting from no management system at all takes longer.
Is this going to replace ISO 9001 or ISO 27001?
No. It sits alongside them. ISO 9001 governs quality, ISO 27001 governs information security, ISO 42001 governs artificial intelligence. In practice they are best run as one integrated system rather than three.

Reading up because you have a decision to make?

Skip ahead. An obligation-free consultation gives you the honest answer for your specific business.

087 150 3022