ISO/IEC 42001:
The AI Management System Standard

The first international standard for managing AI responsibly across its lifecycle. It won't satisfy the EU AI Act on its own, but it's the clearest way to show clients, regulators, and partners that your AI governance isn't improvised.

9+ Years of Compliance Expertise
Saudi Arabia
Oman
Bahrain
End-to-End Execution
Europe
ISO/IEC 42001, published in December 2023, is the first global standard defining how to build, run, and continually improve an AI management system (AIMS). It applies to any organisation that develops, provides, or uses AI - not just tech companies. Certification requires an accredited external certification body; no consultancy, including AML Zone, can issue the certificate itself. The realistic timeline from gap assessment to certificate is 6-12 months, or 3-4 months for organisations that already run ISO 27001.
  • What Makes a System "High-Risk"
    There are two routes into high-risk classification. The first is Annex
    III: a fixed list of use-cases the Act treats as inherently high-stakes,
    regardless of the underlying technology. The second is Annex I: an AI
    system that functions as a safety component of a product already subject
    to EU product-safety legislation (machinery, medical devices, toys, and
    similar), where that legislation already requires third-party conformity
    assessment.
What the Standard Actually Requires
ISO 42001 follows the same high-level structure as other ISO management system standards (like ISO 27001), built around seven core areas:
  • Leadership and organisational context
    Defining scope, roles, and top-management commitment to the AIMS
  • AI policy and objectives
    Documented policy governing how AI is developed, deployed, and used
  • Risk management for AI systems
    Identifying and treating AI-specific risks across the system lifecycle
  • Data governance and system lifecycle controls
    Managing data quality, provenance, and AI system changes over time
  • Transparency and information provision
    Ensuring people affected by an AI system have the information they need
  • Performance evaluation and monitoring
    Measuring whether the AIMS is actually working
  • Continual improvement
    Formal cycle for closing gaps found through audits and monitoring
How Certification Actually Works

Stage 1 - Readiness Assessment

Duration: 1-2 days

Auditors review your AIMS documentation: scope, AI policy, risk assessments, management review records, and decide whether you're ready to proceed to Stage 2, proceed with noted concerns, or need to close gaps first.
Stage 2 - Implementation Verification
Duration: 2-5 days on-site

Auditors confirm your controls are actually operating, not just documented - through interviews, document review, and technical assessment of your AI systems, sampling higher-risk systems more closely.
Surveillance Audits
Duration: Years 2 and 3 of the cycle

Shorter annual audits (roughly 30-50% the length of the original) confirm the AIMS is still working, reviewing internal audits, management reviews, and control effectiveness.
Recertification
Duration: Year 4

A full audit renews the certificate for another three-year cycle, checking the complete AIMS remains fit for purpose.
  • Who Can Actually Certify You
    Only certification bodies accredited by a recognised national accreditation body - IAS, UKAS, ANAB, JAS-ANZ, or DAkkS, among others - can issue a valid ISO 42001 certificate.

    AML Zone can prepare your AIMS and get you audit-ready, but cannot issue the certificate itself: that has to come from an independent, accredited body with no role in building your system in the first place. Treat any offer to both build your AIMS and certify it as a conflict of interest, not a shortcut.
What's Included

Gap assessment against ISO 42001's requirements and Annex A controls

Building the AI management system documentation: policy, risk assessments, data governance procedures, monitoring processes
Preparing your organisation for Stage 1 and Stage 2 audits with an accredited certification body of your choosing
Ongoing support between surveillance audits to keep the AIMS current as your AI systems change

Frequently Asked Questions

Related

Not sure if ISO 42001 or a different framework fits your situation?
By submitting this form, I acknowledge that I have read and agree to the Privacy Policy, and I consent to the processing of my personal data.


Please note: We do not provide any personalized investment advice, token selection guidance, or transaction recommendations. AMLzone is a compliance consultancy and project management services provider, not a Virtual Asset Advisor.