ISO 42001: what an AI management system certifies
ISO 42001 certifies how an organisation governs artificial intelligence, not whether any particular AI system works. What the auditor examined is the supplier’s method: how a system gets approved for release, what testing it has to pass, who watches it afterwards. Whether the thing they built is any good stays your question to ask.
That limit is the most useful thing about the standard, and it is the thing buyers most often get wrong when they write it into a specification.
The starting point is not blocking anything. It is finding out what is actually reaching your site, because the analytics most teams rely on count a substantial amount of automation as people.
What is ISO 42001?
ISO/IEC 42001:2023 is an international standard specifying requirements for an artificial intelligence management system, and the first standard of its kind. It was published on 18 December 2023 as edition 1.0, under the title “Information technology - Artificial intelligence - Management system”.
It sets requirements for establishing, implementing, maintaining and improving the way an organisation manages AI across its business. It applies to any organisation that provides or uses products and services involving AI, whatever its size or sector.
Structurally it works the way ISO 27001 works for information security. There is a defined scope, a risk assessment, a set of controls, management review, internal audit and a certification audit by an external body. If your organisation already runs a certified information security management system, the shape will be familiar and a good deal of the machinery is reusable.
What does ISO 42001 certify, and what does it not?
ISO 42001 certifies the management system. It makes no claim about the accuracy, safety or performance of any individual model or product.
A certificate tells you the organisation has a documented process for identifying AI risks, assigning ownership, testing before release, monitoring after release and withdrawing something that turns out to be wrong. It tells you an external auditor has examined that process and found it operating.
It does not tell you the chatbot gives correct answers. It does not tell you the model was trained on data anyone had the right to use. It does not tell you the system in front of you was built inside the certified scope at all.
Both questions are worth asking and they are different questions. A supplier with a well-run management system and a weak product is a real possibility, and so is the reverse.
Where UK accreditation actually stands
This is the part that moves fastest and the part most published summaries have wrong.
Accreditation is the layer above certification. A certification body issues your certificate; a national accreditation body confirms that the certification body is competent to issue it. Without accreditation, a certificate is an opinion from a company you have not checked.
UKAS granted BSI the first UK accreditation for certification of AI management systems to ISO/IEC 42001:2023 on 15 January 2026. The accreditation sits under ISO/IEC 17021-1, the standard governing bodies that audit and certify management systems. Seven certification bodies took part in the UKAS pilot programme: Alcumus ISOQAR, BSI Assurance UK, Intertek Certification, LRQA, NQA Certification, Schellman Compliance and TUV UK.
The supporting standard now exists too. ISO/IEC 42006:2025 was published on 7 July 2025 and sets the additional requirements a certification body has to meet before it can audit and certify against 42001. It is what turns a general competence in management system auditing into a specific competence in AI.
Two practical consequences follow. A UK certificate issued before 15 January 2026 was not UKAS-accredited, although it may have been accredited by another national body or issued without accreditation at all. And the population of certified organisations in the UK is currently small, because the accreditation route has been open for months rather than years.
Should we require ISO 42001 from suppliers?
Not yet as a mandatory requirement, in most procurements. UK accreditation has been available since January 2026, so a buyer who makes certification a pass or fail condition today will produce a very short bidder list, and the shortlist will be selected for procurement sophistication rather than for AI competence.
The version that works now is to score it rather than gate it, and to ask every bidder the question the standard asks. How do you decide an AI system is fit to release. Who signs that off. What evidence would make you withdraw it. A supplier without the certificate who answers those three well is a better bet than a certified supplier who cannot.
Revisit the position in twelve to eighteen months. Requirements that were unreasonable in the first year of a standard become normal in the third, and the buyers who set the expectation early are the reason.
How to check an ISO 42001 certificate
The generic checks apply and they are the same ones that apply to any management system certificate. Our guide to checking a supplier’s ISO 27001 certificate covers verifying the certificate against the certification body’s own register rather than the supplier’s PDF, and reading the scope statement rather than the logo.
Three checks are specific to ISO 42001.
Accreditation is granted scheme by scheme. A body accredited to certify ISO 27001 is not automatically accredited to certify ISO 42001, so confirm the accreditation covers this standard and check the accreditation body’s register rather than the certification body’s marketing.
The scope statement has to name the thing you are buying. An AI management system certificate scoped to a research division tells you nothing about the delivery team building your service. Scope drift is the most common gap in management system certificates generally, and with a standard this new the certified scope is often small on purpose.
The issue date matters more than usual, for the accreditation reason above. Ask what accreditation was in place when the certificate was issued, not what the body holds today.
How this sits alongside the certifications you already ask for
ISO 42001 does not replace anything. It sits on top of an information security management system and reuses most of it.
The overlap is substantial. Asset management, access control, supplier management, incident response, internal audit and management review are all common to ISO 27001 and ISO 42001. What 42001 adds is specific to AI: impact assessment on affected individuals, data quality and provenance for training and operation, a documented position on what the system is and is not for, and a lifecycle that includes withdrawal.
For a buyer, the useful inference is that a supplier with a mature ISO 27001 certificate has most of the scaffolding for 42001 already, and a supplier with neither is starting from further back than the gap between the two certificates suggests.
We hold ISO 27001, ISO 27017, ISO 27018, ISO 9001, ISO 14001 and Cyber Essentials Plus, all certified through BSI. We do not hold ISO 42001. AI sits inside the information security management system those certificates already cover, and that sentence is worth nothing until we show you which controls reach it and what evidence exists, so ask us for both. Every supplier you read this article against should expect the same from you, including us.
What to do with this before your next AI procurement
Take the AI requirement in whatever you are about to issue and check what it actually asks for. Most drafts either say nothing about AI governance or demand a certificate almost nobody holds, and both produce a field you cannot tell apart.
The middle position is to ask for evidence of the process, score the answers, and note whether the supplier is working towards certification and with which body. That distinguishes bidders today and it will still be the right question when certification is common.
Our guide to the controls to agree before you integrate AI covers the governance side of the same problem from the buying organisation’s own perspective.
Send us the AI section of a specification before it goes out and we will mark it up. An hour of our time, no obligation on yours.
Frequently asked questions
Is ISO 42001 mandatory in the UK?
No. There is no UK legal requirement to hold ISO 42001, and no sector regulator currently mandates it. It is a voluntary certification. The obligations that do bite come from elsewhere: data protection law, the Algorithmic Transparency Recording Standard where you are a central government department or an arm’s-length body, and whatever your own regulator has said about who answers for an automated output.
Can a small organisation certify to ISO 42001?
Yes. The standard is written to apply to any organisation regardless of size, and the amount of work scales with the scope you certify. A small supplier certifying a single service is a realistic proposition, and a narrow scope honestly stated is more useful to a buyer than a wide scope thinly evidenced.
What is the difference between ISO 42001 and ISO 42006?
ISO/IEC 42001:2023 is the standard an organisation certifies against. ISO/IEC 42006:2025 is the standard the certification body has to meet in order to audit and issue that certificate. Buyers deal with the first and are affected by the second, because it determines whether the audit behind a certificate was competent.
References
- ISO/IEC 42001:2023, Information technology - Artificial intelligence - Management system, edition 1.0, published 18 December 2023: https://webstore.iec.ch/en/publication/90574
- ISO/IEC 42006:2025, Information technology - Artificial intelligence - Requirements for bodies providing audit and certification of artificial intelligence management systems, edition 1.0, published 7 July 2025: https://webstore.iec.ch/en/publication/108460
- UKAS, UKAS grants first accreditation for ISO/IEC 42001, 15 January 2026: https://www.ukas.com/resources/latest-news/ukas-grants-first-aims-accreditation/
- UKAS, Artificial Intelligence Management Systems (AIMS) development programme, listing the seven pilot certification bodies: https://www.ukas.com/accreditation/about/developing-new-programmes/development-programmes/aims/