ISO 42001 AI Certification: What It Is [2026]
ISO/IEC 42001 is the first international standard for AI management systems. What it covers, how certification works, and how it connects to AI literacy.
ISO/IEC 42001 is the world's first international standard for AI management systems. Published in 2023, it provides a structured framework for governing AI risks, controls, and accountability — similar to what ISO 27001 does for information security. If your organisation develops, deploys, or uses AI systems, this standard defines how to manage them responsibly.
This guide explains what ISO 42001 covers, how the certification process works, how it connects to the EU AI Act, and where individual AI skills assessment fits in.
What ISO/IEC 42001 Covers
ISO 42001 is an organisational standard, not an individual certification. It certifies that your organisation has a functioning AI Management System (AIMS) — the policies, processes, risk controls, and accountability structures needed to govern AI responsibly.
The standard follows the familiar Plan-Do-Check-Act (PDCA) cycle used in other ISO management systems:
| Clause | What it requires |
|---|---|
| Clause 4: Context | Understand the internal and external factors affecting your AI systems, and your stakeholders' expectations |
| Clause 5: Leadership | Management commitment, clear AI policies, assigned roles and responsibilities |
| Clause 6: Planning | Identify and address AI-related risks and opportunities |
| Clause 7: Support | Provide adequate resources, competencies, and awareness for people working with AI |
| Clause 8: Operation | Design and control AI development, acquisition, and usage processes |
| Clause 9: Evaluation | Monitor, measure, and evaluate AIMS performance |
| Clause 10: Improvement | Act on evaluation results to continuously improve the system |
The standard also includes Annex A controls covering AI-specific areas: AI impact assessment, lifecycle management, third-party relationships, data governance, and responsible AI usage policies.
Clause 7 and the competency requirement
Clause 7 (Support) is particularly relevant for anyone thinking about AI skills. It requires organisations to ensure that people working with AI systems are competent — that they have the necessary knowledge, skills, and awareness to perform their roles.
The standard does not prescribe how to measure competence. It requires that you:
- Determine the competence needed for each AI-related role
- Ensure people meet that standard through education, training, or experience
- Take action where gaps exist
- Retain evidence of competence
This is the bridge between ISO 42001 (the organisational framework) and individual AI skills assessment (the measurement instrument). The standard says you need competent people and evidence of their competence. It leaves the "how" to you.
How ISO 42001 Certification Works
The certification process mirrors other ISO management system certifications:
Stage 1: Gap assessment
An accredited certification body reviews your documentation — AI policies, risk assessments, competency frameworks, process controls. They identify gaps between your current state and the standard's requirements.
Stage 2: Certification audit
Auditors assess whether your AIMS is implemented, operating, and performing as documented. They interview staff, review evidence, and verify that policies translate into practice.
Certification and surveillance
If you pass, you receive a 3-year certificate. Annual surveillance audits verify ongoing compliance. At the end of the cycle, a full recertification audit renews the certificate.
Timeline and cost
Neither is fixed. Timeline depends on your organisation's size, the maturity of your existing AI governance, and whether you've done a gap assessment. Organisations with existing ISO 27001 or ISO 9001 systems often move faster because the management system structure is familiar.
Costs vary by certification body, audit scope, and organisational complexity. Budget for the gap assessment, the certification audit itself, and annual surveillance fees.
ISO 42001 and the EU AI Act
ISO 42001 and the EU AI Act share objectives — risk-based AI governance, transparency, accountability — but they are not the same thing.
ISO 42001 certification does not automatically satisfy EU AI Act compliance. The A-LIGN analysis puts it clearly: "While both share common objectives around risk-based AI governance, transparency, and accountability, the certification does not constitute legal compliance with the EU AI Act."
However, the overlap is substantial:
| Requirement | ISO 42001 | EU AI Act |
|---|---|---|
| AI risk assessment | Required (Clause 6) | Required (Article 9) |
| Transparency & documentation | Required (Annex A) | Required (Articles 11-14) |
| Human oversight | Required (Annex A) | Required (Article 14) |
| AI competency / literacy | Required (Clause 7) | Required (Article 4) |
| Continuous monitoring | Required (Clause 9) | Required (Article 72) |
| Third-party governance | Required (Annex A) | Required (Article 25) |
An organisation with ISO 42001 certification has a significant head start on EU AI Act compliance. The framework covers much of the governance infrastructure the Act requires. The gaps are primarily in the Act's specific technical requirements for high-risk AI systems (conformity assessments, CE marking, registration) and in Article 4's individual AI literacy requirement, which ISO 42001 addresses at an organisational level but not at an individual assessment level.

Curious about your AI Fluency?
AISA helps you measure, prove and improve your AI skills — free report in a 20-minute chat.
Where Individual AI Skills Assessment Fits In
This is where the two standards leave a gap that neither fills on its own.
ISO 42001 requires that you ensure competence (Clause 7) and retain evidence of it. But it does not provide the measurement instrument — it is a management system standard, not an assessment tool.
EU AI Act Article 4 requires sufficient AI literacy for all staff using AI systems. But it does not define what "sufficient" means or how to measure it.
Both require evidence of individual competence. Neither provides a standardised way to produce that evidence.
An AI fluency assessment that scores individuals against a published rubric fills this gap. Each assessment produces a scored profile across 5 dimensions and 11 criteria, with every score backed by an evidence quote from the conversation. That scored profile is the "retained evidence of competence" ISO 42001 Clause 7 requires and the documented AI literacy Article 4 demands.
Data from 1,200+ assessed professionals shows the scale of the competency challenge: the median score is 48 out of 100, professionals overestimate their skills by 18.5 points on average, and within-team gaps span 50-70 points. An ISO 42001 audit that relies on self-assessed competence — which is what most organisations fall back on — is building on unreliable foundations.
Should Your Organisation Get ISO 42001 Certified?
ISO 42001 is most valuable for organisations where:
- AI is central to the product or service (AI-native companies, HealthTech, FinTech)
- Customers or regulators require evidence of AI governance (enterprise sales, regulated industries)
- You are a provider under the EU AI Act and need to demonstrate governance to downstream deployers
- You have existing ISO certifications (27001, 9001) and the management system muscle is already built
It is less immediately valuable for organisations that:
- Use AI tools but do not develop or deploy AI systems at scale
- Operate primarily outside the EU and do not serve EU customers
- Have fewer than 50 employees and limited AI governance complexity
For organisations in the second category, the more pressing need is usually individual AI literacy measurement — knowing where your people stand and where the gaps are — before investing in a full management system standard.
Related reading: EU AI Act Article 4: AI Literacy Guide — what Article 4 requires and how to document compliance.
Related reading: AI Readiness Assessment — measure workforce AI readiness with evidence-based scoring.
Related reading: AI Skills Gap Analysis: Real Data — where the actual gaps are, measured across 1,200+ professionals.
Frequently Asked Questions
What is ISO 42001 certification?
ISO/IEC 42001:2023 is the first international standard for AI management systems. It certifies that your organisation has policies, risk controls, and accountability structures for governing AI responsibly — similar to ISO 27001 for information security. It is an organisational certification, not an individual one.
Does ISO 42001 satisfy EU AI Act compliance?
No. ISO 42001 and the EU AI Act share objectives (risk governance, transparency, accountability) but certification does not automatically constitute legal compliance. The Act has specific requirements — particularly for high-risk AI systems and individual AI literacy (Article 4) — that go beyond what the management system standard covers.
How long does ISO 42001 certification take?
Timeline depends on organisation size, AI governance maturity, and whether you have existing ISO certifications. Organisations with ISO 27001 experience typically move faster. The process involves a gap assessment, a two-stage certification audit, and ongoing annual surveillance audits.
Does ISO 42001 require AI skills assessment?
Clause 7 requires that people working with AI systems are competent and that you retain evidence of their competence. The standard does not prescribe a specific assessment method — it requires you to determine competence needs, verify they are met, and document the evidence. An AI fluency assessment that produces scored profiles is one way to satisfy this requirement.

Curious about your AI Fluency?
AISA helps you measure, prove and improve your AI skills — free report in a 20-minute chat.
