Back to Resources
    Articles
    ISO 42001

    What Is ISO 42001? AI Management Systems Explained for SMEs

    ByNicole Webb·
    Share:
    ISO 42001 AI Management System illustration showing governance, risk management, transparency, performance evaluation, and continuous improvement for SMEs

    Artificial intelligence has moved from a future-facing technology to a daily business reality faster than most regulatory frameworks anticipated. Businesses of all sizes are now using AI tools to generate content, analyse data, screen job applicants, price products, detect fraud, and make operational decisions. Most are doing so without a systematic framework for governing how those tools are selected, deployed, monitored, or reviewed.

    ISO 42001 exists to close that gap. Published in December 2023, it is the world''s first international standard for artificial intelligence management systems. It gives organisations a structured, auditable framework for governing AI responsibly, drawing on the same Plan-Do-Check-Act methodology that underpins ISO 9001 and ISO 27001.

    This guide explains what ISO 42001 is, who it applies to, what it requires, and what SMEs should be thinking about as the AI governance landscape evolves. It is written for business owners, operations managers, and anyone responsible for how their organisation uses AI, not for data scientists or AI engineers.

    What ISO 42001 Is: The One-Sentence Version

    ISO/IEC 42001:2023 is an international management system standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within an organisation.

    If that sounds familiar, it is because it uses exactly the same structure and language as ISO 9001 (quality management) and ISO 27001 (information security). Organisations already familiar with either of those standards will find the architecture of ISO 42001 recognisable: a policy, a scope, risk assessments, documented controls, internal audits, management review, and continual improvement. The difference is the subject matter: instead of managing quality or information security, you are managing how your organisation develops, deploys, and uses AI systems.

    ISO 42001 does not certify AI systems. It certifies the management system an organisation uses to govern its AI activity. This is an important distinction. A certificate tells stakeholders that your organisation has a structured, independently verified approach to AI governance, not that any specific AI model or output has been approved or validated.

    Who Needs ISO 42001?

    The standard is relevant to three broad categories of organisation.

    • AI providers: organisations that develop or sell AI-powered products or services. If you build software that uses machine learning, natural language processing, computer vision, or any other AI capability, this category applies to you.

    • AI deployers: organisations that use AI systems from third-party providers in their operations. This includes businesses that use AI tools for customer service, recruitment, pricing, fraud detection, content generation, or any other operational function.

    • Organisations in AI supply chains: businesses that are part of a supply chain where a customer or client requires evidence of responsible AI governance as a condition of doing business.

    The third category is where ISO 42001 is most immediately relevant to SMEs in 2026. Enterprise clients, government agencies, and regulated-sector buyers are beginning to include AI governance requirements in their supplier qualification criteria, particularly in sectors such as financial services, healthcare, legal, and public sector contracting. For a business that uses AI tools to deliver services to enterprise clients, certification may become a commercial requirement rather than a choice within the next two to three years.

    If your organisation does not develop AI systems and uses only basic AI tools (a spell-checker, a simple chatbot, or a marketing automation platform with AI features), ISO 42001 certification is unlikely to be a priority today. But if AI is central to how you deliver value or how you make decisions that affect customers, the standard is directly relevant.

    How ISO 42001 Compares to ISO 9001 and ISO 27001

    Most businesses asking about ISO 42001 are already familiar with ISO 9001 or ISO 27001. The comparison is useful because it clarifies what ISO 42001 adds rather than duplicates.

    Dimension

    ISO 9001 / ISO 27001

    ISO 42001

    What it manages

    Quality of products/services (9001) or information security (27001)

    How the organisation governs its AI systems across their lifecycle

    Standard structure

    High Level Structure (Plan-Do-Check-Act), Clauses 4-10

    Same High-Level Structure, Clauses 4-10, plus AI-specific Annex A controls

    Core document

    Quality manual / ISMS policy

    AI policy, AIMS scope, Statement of Applicability for Annex A controls

    Key risk tool

    Risk register for quality or security risks

    AI risk assessment + AI system impact assessment (societal and ethical)

    Unique requirement

    None relative to 42001

    AI system impact assessments; transparency and explainability controls; human oversight requirements; bias and fairness considerations

    Existing certification benefit

    Strong overlap: 30-50% of documentation effort transfers

    Organisations with ISO 27001 certification can save significant implementation costs and time

    Certification body

    UKAS (UK), ANAB (US), INAB (Ireland) accredited bodies

    Same accreditation bodies; BSI was the first UKAS-accredited body for ISO 42001

    The most important practical point: if your organisation already holds ISO 27001 or ISO 9001, you have a meaningful head start on ISO 42001 implementation. The management system infrastructure, document control practices, internal audit habits, and management review cycle all transfer directly. The incremental work is the AI-specific content: defining your AI systems, completing impact assessments, and implementing the Annex A controls relevant to your AI activity.

    What ISO 42001 Actually Requires

    The standard is organised around Clauses 4 through 10, following the High Level Structure shared by all modern ISO management system standards. The requirements specific to AI management sit in two places: the operational requirements of Clause 8, and the controls of Annex A.

    The core management system requirements (Clauses 4-10)

    • Clause 4: Organisational context. Understand the internal and external factors that affect your AI activity. Identify interested parties: customers, regulators, employees, affected communities. Define the scope of your AIMS.

    • Clause 5: Leadership. Top management must demonstrate commitment to responsible AI governance. Establish an AI policy. Assign roles and responsibilities for AI management.

    • Clause 6: Planning. Conduct a formal AI risk assessment. Identify opportunities and risks associated with your AI systems. Set measurable AI management objectives.

    • Clause 7: Support. Ensure the competence of staff involved in AI systems. Maintain documented information. Establish communication processes for AI governance matters.

    • Clause 8: Operation. Plan and control AI system development, deployment, and use. Conduct AI system impact assessments. Manage AI system changes. Control third-party AI providers.

    • Clause 9: Performance evaluation. Monitor and measure AIMS performance. Conduct internal audits. Hold management review meetings covering AI governance performance.

    • Clause 10: Improvement. Address nonconformities. Implement corrective actions. Drive continual improvement of the AIMS.

    Annex A: The AI-specific controls

    Annex A contains 38 controls in the ISO 42001 standard, organised across eight categories. Unlike the controls in ISO 27001''s Annex A, which are primarily technical and organisational, the ISO 42001 controls address AI-specific concerns including transparency, fairness, bias, human oversight, and societal impact. Not all 38 controls will apply to every organisation; a Statement of Applicability documents which controls are implemented and which are excluded, with justification.

    Control category

    Focus area

    What it covers for SMEs

    A.2: Policies

    AI governance policies

    Establishing a documented AI policy aligned with the organization''s values and risk appetite

    A.3: Internal organisation

    Accountability structures

    Defining who is responsible for AI systems and how decisions about AI are made and documented

    A.4: Resources for AI systems

    Data and tooling governance

    How AI systems are resourced, including data quality, sourcing, and retention practices

    A.5: Assessing AI system impacts

    Impact assessments

    Evaluating the potential effects of AI systems on individuals, groups, and society before and during deployment

    A.6: AI system lifecycle

    Lifecycle management

    Controls covering AI system design, development, testing, deployment, monitoring, and decommissioning

    A.7: Data for AI systems

    Data management

    Data collection, validation, labelling, storage, and deletion practices for AI-related data

    A.8: Information for interested parties

    Transparency and communication

    How the organisation communicates about its AI systems to customers, employees, regulators, and the public

    The two requirements that surprise SMEs most

    AI system impact assessments (Clause 6.1.4): The standard requires organizations to assess the potential impacts of their AI systems not just on the business but on affected individuals and society. For a business using an AI recruitment tool, this means assessing whether the tool could produce biased or discriminatory outcomes. For a business using AI-generated pricing, it means assessing whether the pricing could disadvantage particular customer groups. This is a materially different kind of risk assessment from anything required by ISO 9001 or ISO 27001.

    Human oversight requirements: ISO 42001 requires organizations to define where and how humans remain in the loop for AI-driven decisions, particularly decisions that affect individuals. A business cannot simply delegate a decision to an algorithm and consider governance complete. The AIMS must document what human review exists, when it is triggered, and what authority a human has to override an AI output.

    The EU AI Act Connection

    ISO 42001 and the EU AI Act are related but distinct. The EU AI Act, which began phased enforcement in 2024, is a regulation that imposes legal obligations on organisations developing or deploying AI systems in the European Union, with the most stringent requirements applying to high-risk AI applications. ISO 42001 is a voluntary management system standard.

    The relationship between them is that ISO 42001 provides a systematic management framework that helps organisations meet many of the governance, risk management, documentation, and transparency requirements of the EU AI Act. Research from several compliance specialists suggests approximately 40 to 50 per cent overlap between the high-level requirements of the two frameworks. Certification to ISO 42001 is not a legal substitute for EU AI Act compliance, but it substantially reduces the compliance burden for organisations subject to the Act. For a deeper comparison, see our ISO 42001 vs EU AI Act guide.

    For US-based businesses, ISO 42001 is currently voluntary, and there is no direct federal AI legislation that references it. However, several US states have introduced or are considering AI governance legislation, enterprise buyers are beginning to require evidence of responsible AI governance in procurement processes, and the standard is increasingly cited in federal agency guidance on responsible AI use. The practical trajectory is toward ISO 42001 becoming a de facto commercial requirement in regulated and enterprise markets on both sides of the Atlantic.

    What ISO 42001 Certification Costs and How Long It Takes

    ISO 42001 is a younger standard than ISO 9001 or ISO 27001, and the market for certification services is still maturing. This has two practical effects: certification costs are currently higher than those of an equivalent ISO 27001 certification, and the number of accredited auditors with genuine AI governance expertise is limited. Both of these factors are expected to improve over the next two to three years as the market develops.

    Timeline

    For an SME with fewer than 50 employees implementing ISO 42001 from scratch, the certification journey realistically takes between six and twelve months. Organisations that already hold ISO 27001 or ISO 9001 can typically reduce this to four to six months by leveraging existing management system infrastructure, documented information practices, and audit cycles.

    The longest phase for most SMEs is the scoping and impact assessment work. Defining which AI systems fall within the AIMS scope and completing meaningful impact assessments for each requires analytical effort that is unfamiliar to most compliance teams. This is the phase where experienced consultant support has the highest return on investment.

    Cost

    For a small organisation with under 50 employees and a defined, relatively narrow AI scope, total certification costs (including gap analysis, implementation support, and certification audit fees) typically range from £10,000 to £25,000. Organisations that already hold ISO 27001 consistently report 30 to 50 per cent cost savings on implementation, because the management system framework, documented information controls, and internal audit infrastructure are already in place.

    Certification body fees for the Stage 1 and Stage 2 audit cycle run from £4,000 to £12,000 for initial certification, depending on scope complexity and auditor availability. Annual surveillance audits thereafter run approximately 30 to 40 per cent of the initial audit fee. The three-year recertification cycle mirrors ISO 27001 and ISO 9001.

    The most commonly underestimated cost is internal staff time: completing AI system inventories, conducting impact assessments, building documented controls, and preparing evidence for auditors. Organisations that have not previously implemented a management system should budget for the equivalent of at least 0.5 to 1.0 FTE of internal effort over the implementation period.

    Use our free calculator to get an estimate of the likely costs for your organisation, or fill in our form to get three free quotes from verified providers.

    Should your SME pursue ISO 42001 now?

    Pursue certification now if:

    • Your business develops or sells AI-powered products or services

    • Enterprise or government clients are already asking about AI governance

    • You are subject to EU AI Act requirements or expect to be

    • You already hold ISO 27001 and the incremental cost is manageable

    Monitor and prepare if:

    • You use AI tools in your operations but do not develop AI systems

    • Your clients have not yet required AI governance certification

    • You are in the early stages of ISO 27001 or ISO 9001 implementation

    In all cases: begin building an inventory of the AI tools and systems your organization uses. This is the first step in any ISO 42001 implementation and costs nothing to start.

    Where to Start if ISO 42001 Is on Your Roadmap

    The practical starting point for any organisation considering ISO 42001 is not documentation or policy writing. It is an AI system inventory: a structured list of every AI tool or system your organisation uses, what decisions or processes it is involved in, and what data it processes. Many organisations, when they complete this exercise for the first time, find they are using significantly more AI-enabled tools than they realised.

    Once the inventory is complete, a gap analysis against the ISO 42001 requirements identifies where formal controls, documentation, and governance structures need to be built. From that baseline, implementation follows the same logic as any other management system: build the governance structure, document the controls, test them through internal audit, and present the evidence to a certification body. Our ISO 42001 gap analysis tool is a useful starting point.

    Organisations already certified to ISO 27001 should approach ISO 42001 as an extension of their existing management system rather than a separate program. The shared High-Level Structure means the two systems can be integrated: one internal audit program, one management review meeting, one set of documented information controls, with AI-specific content added alongside the information security content.

    About The Author

    Nicole Webb is an ISO compliance specialist with extensive experience in ISO management systems, accreditation and internal auditing, providing a strong foundation for writing practical, expert-led articles on ISO topics. She has managed accredited management systems and supported Global compliance teams across ISO 9001, ISO 14001, ISO 45001, ISO 22301, ISO 27001 and ISO 13485, giving her a broad, cross-standard perspective that informs her writing. She now runs ISOLiteBites, an ISO-focused training company delivering both e-learning courses and bespoke training for businesses of all sizes.

    Frequently Asked Questions

    What is ISO 42001?
    ISO/IEC 42001:2023 is the world's first international standard for Artificial Intelligence Management Systems (AIMS). Published in December 2023 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), it specifies requirements for establishing, implementing, maintaining, and continually improving a management system for responsible AI governance. The standard applies to any organization that develops, provides, or uses AI systems, and follows the same Plan-Do-Check-Act structure as ISO 9001 (quality management) and ISO 27001 (information security management).
    Who needs ISO 42001 certification?
    ISO 42001 is relevant to three types of organization: AI providers (those that develop or sell AI-powered products or services), AI deployers (organizations that use AI systems from third-party providers in their operations), and organizations in AI supply chains where customers require evidence of responsible AI governance. For SMEs, the most immediate trigger is typically a requirement from an enterprise client or government agency. Organizations in regulated sectors such as financial services, healthcare, legal services, and public sector contracting are most likely to face early pressure to demonstrate ISO 42001 compliance.
    What does ISO 42001 require that ISO 27001 does not?
    ISO 42001 shares the High Level Structure and many foundational requirements of ISO 27001, but adds AI-specific requirements that go beyond information security. The most significant additions are: AI system impact assessments, which evaluate the potential effects of AI systems on individuals, groups, and society (not just the business); human oversight requirements, which specify where and how humans must remain in the loop for AI-driven decisions; and Annex A controls covering AI-specific concerns including transparency, explainability, bias and fairness, and AI system lifecycle management. Organizations with existing ISO 27001 certification typically save 30 to 50 percent on ISO 42001 implementation costs because the management system framework transfers directly.
    How much does ISO 42001 certification cost for a small business?
    For a small organization with fewer than 50 employees and a defined AI scope, total ISO 42001 certification costs typically range from $15,000 to $40,000, including gap analysis, implementation support, and certification audit fees. Organizations already certified to ISO 27001 report significant cost savings because existing management system infrastructure, documented information practices, and internal audit cycles can be extended rather than built from scratch. Certification body fees for the initial Stage 1 and Stage 2 audit cycle run $7,000 to $20,000 depending on scope and auditor availability. Annual surveillance audits run approximately 30 to 40 percent of the initial audit fee.
    Share:

    Need Help With ISO Certification?

    Get quotes from accredited registrars and ISO experts.