Skip to main content
AI Governance Certification

ISO/IEC 42001 — AI Management System (AIMS) Certification

ISO/IEC 42001, published in December 2023, is the first international standard for an Artificial Intelligence Management System (AIMS) — a certifiable framework for governing how an organisation designs, develops, deploys, and monitors AI systems responsibly. It follows the same high-level management-system structure as ISO 27001, making it a natural extension for organisations that already hold an ISO 27001 certificate and are now building or deploying AI capability.

Mutex Systems supports AIMS gap analysis and implementation for organisations building AI-powered products or deploying AI systems internally, mapping ISO 42001 requirements alongside the AI security stack already used in our AI and automation practice.

Category
Compliance Framework
Jurisdiction
International
Issuing Body
International Organization for Standardization (ISO) / IEC
Current Version
ISO/IEC 42001:2023 — published December 2023
Who It's For
Organisations developing AI products, deploying AI systems at scale, or needing to demonstrate responsible AI governance to enterprise customers, regulators, or procurement processes that increasingly ask for it.
Read the official source
What It Covers

Core Domains

AI policy, roles, and organisational context for AI use
AI risk assessment and impact assessment for affected stakeholders
AI system lifecycle management — design, development, deployment, and monitoring
Data governance for training, validation, and operational data
Transparency, explainability, and human oversight requirements
Third-party and supply-chain AI risk management
How It Works

A Practical Compliance Path

  1. 01

    AIMS Scoping

    Define which AI systems, use cases, and organisational units fall inside the management system scope.

  2. 02

    Risk & Impact Assessment

    Assess AI-specific risks — bias, explainability, data provenance, model drift — alongside conventional information-security risk.

  3. 03

    AIMS Implementation

    Build the policy, process, and control set required by ISO 42001, using the same Annex SL high-level structure as ISO 27001 where an ISMS already exists.

  4. 04

    Certification Audit

    Stage 1 and Stage 2 audit with a certification body, followed by surveillance audits — mirroring the ISO 27001 certification cycle.

Our Approach

Built on the AI Security Stack We Already Use

ISO 42001 implementation is mapped alongside the AI security framework stack already applied across Mutex's AI and automation practice, rather than treated as an isolated compliance exercise.

  • AIMS built on the same high-level structure as ISO 27001, minimising duplicate documentation where both are in scope
  • AI-specific risk assessment covering bias, explainability, and data provenance alongside conventional security risk
  • Positioned as an extension of an existing ISMS for organisations that already hold ISO 27001
View Cybersecurity Services
Compliance, Continuously

AI Risk Tracked Alongside the ISMS It Extends

grComply's framework engine loads ISO 42001's AIMS requirements the same way it loads ISO 27001 — as a versioned control set — so an organisation extending an existing ISMS to cover AI governance sees both frameworks side by side rather than as disconnected compliance programmes.

  • AI-specific risk entries — bias, explainability, data provenance, model drift — sit in the same structured risk register and heat-map view as conventional information-security risk
  • Cross-framework mapping means AI governance evidence shared with ISO 27001 controls (access management, third-party risk, incident response) is uploaded once and linked to both
  • The Claude-powered AI assistant drafts AIMS policy language and explains AI-specific control gaps — a genuinely useful reflexive fit, given the assistant itself is an example of the AI governance the standard asks organisations to manage
  • Custom fields via the Dynamic Schema Engine track AI-specific metadata — model version, training-data source, deployment context — without a platform code change

grComply is Mutex Systems' own multi-tenant GRC automation platform — the framework library, hybrid scanning, risk and audit workflow, and AI-assisted compliance behind every point above are live in production today.

See How grComply Works
FAQs

Common Questions About ISO 42001

What does ISO/IEC 42001 actually certify?

It certifies that an organisation has a functioning Artificial Intelligence Management System (AIMS) — documented policy, risk management, lifecycle controls, and oversight covering how it designs, develops, deploys, and monitors AI systems. It does not certify that a specific AI model is "safe" or "unbiased" in isolation; it certifies the management system governing AI use.

Is ISO 42001 the same as the NIST AI Risk Management Framework?

No. ISO/IEC 42001 is a certifiable management-system standard with a formal audit and certificate, following the same Annex SL structure as ISO 27001. The NIST AI RMF is a voluntary, non-certifiable framework organised around Govern, Map, Measure, and Manage functions. Many organisations use NIST AI RMF as an internal risk-assessment reference while pursuing ISO 42001 as the externally auditable output.

Do we need ISO 27001 before pursuing ISO 42001?

Not strictly — ISO 42001 can be implemented as a standalone management system. But because both standards share the same Annex SL high-level structure, organisations that already hold ISO 27001 can typically extend their existing management system to cover AI governance with meaningfully less duplicated documentation than building an AIMS from scratch.

Who is asking for ISO 42001 right now?

Demand is early but growing fastest among enterprise buyers procuring AI-powered products and regulated organisations (financial services, healthcare, public sector) deploying AI internally, who want independently verified evidence of AI governance rather than a vendor's own assurances. Given how new the standard is, ISO 42001 certification is currently a differentiator rather than a baseline expectation.

Can Mutex Systems support an ISO 42001 implementation?

Yes. Mutex Systems supports AIMS gap analysis and implementation, mapped alongside the AI security framework stack already used across our AI and automation practice.

Let's Talk

Ready to Start Your ISO 42001 Programme?

Send us your current posture and timeline. Within two working days you will receive a written response and a proposed scoping call.

No commitment requiredResponse within 2 working daysConfidential brief handling